Quote and Sign

Privacy Policy

Effective September 5, 2026. This policy explains what Quote and Sign collects, why, and what you can do about it. It is written to meet Canada's PIPEDA, the EU and UK GDPR, and the California CCPA. A designated Privacy Officer is accountable for this policy and can be reached through the contact form; their name is provided on request.

Who this covers

What we collect and why

Account holders

Recipients

Visitors

Only standard server logs and privacy-preserving, cookieless analytics from our hosting provider. No advertising trackers.

Cookies

We use one strictly necessary cookie to keep you signed in, and one to remember a proposal password you entered. Neither tracks you across sites, so no cookie banner is shown. Your theme choice is stored in your browser only.

Legal bases (GDPR)

Who else sees data

We use three subprocessors and no others: Cloudflare (hosting, database, file storage and network security; data is encrypted at rest and in transit), Polar (payments; they see your email and billing details), and Resend (email delivery; they see the addresses and content of emails we send). We do not sell personal information and we do not share it for advertising. We disclose data when the law requires it or to protect people from harm, and we will tell you if we lawfully can.

Where data lives

Our infrastructure runs on Cloudflare's global network; data may be stored and processed in Canada, the United States and the EU. Transfers out of the EU and UK rely on standard contractual clauses held by our subprocessors.

How long we keep it

Your rights

You can access, correct, export or delete your data. Account holders can do all of this from the Brand page: export everything as one file, or delete the account. Recipients can email us to ask what we hold about them. We answer within 30 days. You may also complain to your privacy regulator: in Canada the Office of the Privacy Commissioner, in the EU your national authority, in the UK the ICO.

Security

Passwordless sign-in, encryption at rest and in transit, unguessable proposal links, optional link passwords and expiry, rate limits, strict content security policies, and uploads limited to images checked by content. No system is perfectly secure; if a breach creates a real risk of significant harm we will notify affected people and the regulator as soon as feasible, and in any case within 72 hours of confirming it where the GDPR applies.

Children

The service is for business use by adults. We do not knowingly collect data from anyone under 18.

Changes

We will post changes here with a new effective date and email account holders about material changes.

Contact

The Privacy Officer, Quote and Sign, through the contact form. The officer's name and a postal address are provided on request.