Privacy Policy
Effective: April 22, 2026 · Version 1.0
This Privacy Policy explains how Quoteloop, Inc. ("Quoteloop," "we," "us") collects, uses, shares, and protects personal information in connection with our contractor quoting service (the "Service"). It also describes your rights and choices.
1. Two Types of People, Two Legal Roles
Quoteloop serves two kinds of people, and our legal role is different for each:
- Contractors (our customers): These are the professionals who sign up, pay us, and use the Service. For their personal information, Quoteloop is the data controller. We decide what to collect and why.
- End-users (the contractor's customers, e.g. homeowners): These are the people the contractor is quoting. The contractor uploads their details. For end-user personal information, Quoteloop is a data processor acting on the contractor's instructions, and the contractor is the controller.
This distinction matters because it determines who is responsible for notices, consents, and data rights. End-users with questions or rights requests should generally direct them to the contractor who sent them the quote. Quoteloop will assist and honor valid requests we receive directly.
2. What We Collect
2.1 From Contractors
| Category | Examples | Purpose |
|---|---|---|
| Account | Name, email, password (hashed) | Authentication, support |
| Business | Company name, license #, logo, address, phone | Branding on quotes |
| Billing | Stripe customer ID, plan tier, billing history | Subscription management |
| Rate card | Labor rates, material costs, markup % | Quote generation |
| Usage | Features used, quote counts, login times, device info, IP | Service improvement, fraud prevention |
| Communications | Support emails, in-app messages | Customer support |
2.2 From Contractors About End-Users
| Category | Examples | Purpose |
|---|---|---|
| Identity | Name, phone, email, job address | Quote delivery |
| Job data | Photos of property, voice notes, scope | Quote drafting |
| Engagement | Quote views, signatures, responses | Contractor analytics |
We collect the minimum end-user data necessary to deliver the Service. We do not collect government IDs, SSNs, financial account numbers, or health information about end-users.
2.3 Automatically Collected
Like most web services, we collect limited technical data (IP address, browser type, device type, referrer, timestamps) via cookies and similar technologies, used for security, analytics, and service operation. We do not use third-party advertising cookies.
3. How We Use Information
- To provide, maintain, and improve the Service
- To process payments and manage subscriptions
- To generate quotes (including sending your content to AI providers for processing)
- To deliver quotes via your selected channels (email, SMS, links)
- To communicate with you about the Service, updates, and support
- To monitor for fraud, abuse, and security threats
- To comply with legal obligations and enforce our agreements
We do not sell personal information. We do not share personal information with third parties for their own marketing purposes.
4. Who We Share Information With (Sub-Processors)
We share information only with service providers who help us run Quoteloop, under contracts that require them to protect your data and use it only for the purpose we've specified. Current sub-processors:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase / AWS | Database, auth, file storage | All account + quote data |
| Vercel | Application hosting | Traffic, logs |
| Stripe | Payment processing | Billing info (we never see full card data) |
| Anthropic | AI quote drafting | Voice transcripts, photo analysis inputs, rate card context |
| OpenAI | Voice transcription + AI fallback | Voice audio, scope text |
| Twilio | SMS delivery (if you use SMS send) | End-user phone, message content |
| Resend / Postmark | Email delivery | End-user email, message content |
| PostHog | Product analytics (anonymized) | Usage events, no PII |
We will update this list when we add or change sub-processors. Material changes will be communicated by email to active contractor accounts.
5. International Transfers
Quoteloop is based in the United States. Your information is stored and processed in the United States. If you access the Service from outside the US, your information will be transferred to the US. By using the Service, you consent to this transfer.
6. Data Retention
- Active accounts: We retain your data as long as your account is active.
- Cancelled accounts: We retain your data for 90 days after cancellation to allow reactivation, then purge it.
- Voice recordings: Purged within 30 days of upload after processing, unless retained for debugging a specific support issue with your consent.
- Legal obligations: We may retain limited data longer if required by law (e.g., tax records, audit logs).
- End-user opt-outs: If an end-user requests deletion or opts out, we process the request within 45 days.
7. Security
We use industry-standard safeguards to protect personal information:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Passwords hashed with industry-standard algorithms; never stored in plaintext
- Payment processing via PCI-DSS-compliant Stripe (we never store raw card data)
- Access controls and audit logging
- Regular security reviews
No system is 100% secure. If we become aware of a breach affecting your personal information, we will notify you without undue delay, as required by law.
8. Your Rights
8.1 Contractor Rights
You can:
- Access, update, or correct your account information from Settings
- Export your data (including all quote history and customer data) to CSV
- Delete your account at any time
- Opt out of non-essential emails (we'll still send transactional emails related to your account)
8.2 California Residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, to delete personal information, to correct inaccurate personal information, and to not be discriminated against for exercising these rights. We do not sell personal information as defined by California law. To exercise these rights, email [email protected].
8.3 EU/UK Residents (GDPR)
If you are in the EU/UK, you have rights to access, rectify, erase, restrict, port, and object to processing of your personal data. Our lawful bases for processing are: contract performance (providing the Service), legitimate interests (service improvement, fraud prevention), and consent (where required). To exercise rights, email [email protected]. You may also lodge a complaint with your local data protection authority.
8.4 End-Users
If you received a quote through Quoteloop and want to know more about or delete your data, first contact the contractor who sent it to you. They are the data controller. You can also contact us at [email protected] and we will forward your request and assist in its fulfillment.
9. Children
Quoteloop is intended for use by businesses and adults. We do not knowingly collect personal information from children under 13 (or 16 in the EU/UK). If you believe a child has provided us personal information, contact us and we will delete it.
10. Cookies
We use essential cookies for authentication and security, and optional analytics cookies to understand feature usage. You can manage cookie preferences from your browser. Disabling essential cookies will prevent the Service from functioning.
11. Changes to This Policy
We may update this Privacy Policy over time. Material changes will be posted on quoteloop.app and communicated to active account holders by email at least 30 days before taking effect.
12. Contact
Questions about this Privacy Policy, or to exercise your rights:
Quoteloop, Inc.
Email: [email protected]
Web: quoteloop.app
Last updated April 22, 2026.