Privacy Policy
Effective September 5, 2026. This policy explains what Quote and Sign collects, why, and what you can do about it. It is written to meet Canada's PIPEDA, the EU and UK GDPR, and the California CCPA. A designated Privacy Officer is accountable for this policy and can be reached through the contact form; their name is provided on request.
Who this covers
- Account holders: people who sign in and send proposals.
- Recipients: people who open a proposal link, ask a question, decline or accept.
- Visitors: people who read the homepage.
What we collect and why
Account holders
- Email address, to sign you in with a one-time link and to send you service emails such as "your proposal was opened".
- Business name, colour, logo, page style, payment link and team email addresses, to put on your proposals.
- Your proposals: the text, prices, client names and client email addresses you enter.
- Billing status from our payment provider (which plan, whether it is active). Card details never reach us.
- A security log of sign-ins, sends and account changes, with a hashed IP address.
Recipients
- When a proposal is opened: the time, a hashed IP address, the browser type and country, and how long each section stayed on screen. The sender sees counts and timings, never your IP address.
- When you ask a question or decline: the name, email and message you type, sent to the sender.
- When you accept: the name you type, your email address, the time, your IP address and browser, the options you chose and the consent sentence you agreed to. This is the acceptance record. It exists to prove who agreed to what and when, and is shared with the sender and emailed to you. Your IP address is kept in the record because it is part of that proof.
Visitors
Only standard server logs and privacy-preserving, cookieless analytics from our hosting provider. No advertising trackers.
Cookies
We use one strictly necessary cookie to keep you signed in, and one to remember a proposal password you entered. Neither tracks you across sites, so no cookie banner is shown. Your theme choice is stored in your browser only.
Legal bases (GDPR)
- Performance of a contract: providing the service to account holders.
- Legitimate interests: security logs, fraud prevention, the acceptance record, service emails.
- Consent: nothing is sent to you for marketing without it. You can withdraw consent at any time.
- Legal obligation: keeping records where the law requires.
Who else sees data
We use three subprocessors and no others: Cloudflare (hosting, database, file storage and network security; data is encrypted at rest and in transit), Polar (payments; they see your email and billing details), and Resend (email delivery; they see the addresses and content of emails we send). We do not sell personal information and we do not share it for advertising. We disclose data when the law requires it or to protect people from harm, and we will tell you if we lawfully can.
Where data lives
Our infrastructure runs on Cloudflare's global network; data may be stored and processed in Canada, the United States and the EU. Transfers out of the EU and UK rely on standard contractual clauses held by our subprocessors.
How long we keep it
- Drafts and unsigned proposals: until you delete them or your account.
- Signed proposals and acceptance records: as long as either party may need them, because they are the proof of an agreement. When an account is deleted, signed records stay readable at their links with the sender's contact details removed.
- Sign-in links: 15 minutes. Sessions: 30 days. Security logs: 12 months. Rate-limit counters: 24 hours.
- Emails sent through Resend: per Resend's retention, typically 30 days of logs.
Your rights
You can access, correct, export or delete your data. Account holders can do all of this from the Brand page: export everything as one file, or delete the account. Recipients can email us to ask what we hold about them. We answer within 30 days. You may also complain to your privacy regulator: in Canada the Office of the Privacy Commissioner, in the EU your national authority, in the UK the ICO.
Security
Passwordless sign-in, encryption at rest and in transit, unguessable proposal links, optional link passwords and expiry, rate limits, strict content security policies, and uploads limited to images checked by content. No system is perfectly secure; if a breach creates a real risk of significant harm we will notify affected people and the regulator as soon as feasible, and in any case within 72 hours of confirming it where the GDPR applies.
Children
The service is for business use by adults. We do not knowingly collect data from anyone under 18.
Changes
We will post changes here with a new effective date and email account holders about material changes.
Contact
The Privacy Officer, Quote and Sign, through the contact form. The officer's name and a postal address are provided on request.