Privacy Statement
Last updated: April 29, 2026
1. Information We Collect
We collect information you provide directly: account registration details (name, email, company name), uploaded documents (supplier PDFs, Excel files, CSVs), quote and inventory data you enter, and communication with our support team. We also collect usage data automatically: IP address, browser type and version, operating system, pages visited, referring URLs, and interaction patterns. We use cookies for session management, language preferences, and analytics — session cookies expire when you close your browser; preference and analytics cookies persist for up to one year.
2. How We Use Your Information
We use your information to: (a) provide and maintain the Service; (b) process your documents through our AI pipeline to generate draft quotes; (c) manage your account and subscriptions; (d) send service-related communications (billing, feature updates, security notices); (e) understand how users interact with the Service so we can improve usability and prioritize features; (f) monitor system performance, diagnose errors, and detect security incidents through server-side logs; (g) provide customer support; (h) comply with legal obligations.
3. AI Data Processing
Our AI features process documents you upload to extract product, pricing, and supplier information. Document processing uses third-party AI providers (currently OpenAI). We send only the document content necessary for extraction; we do not send your account credentials, payment information, or unrelated tenant data. Processed documents are stored in our infrastructure and are not used to train third-party AI models.
4. Data Sharing and Sub-Processors
We do not sell your personal data. We share data only: (a) with third-party AI providers as necessary for document processing and draft generation (currently OpenAI); (b) with payment processors to handle billing (currently Stripe); (c) with authentication providers you choose to use (Google, Microsoft); (d) with analytics providers to understand product usage (currently PostHog); (e) with infrastructure and monitoring providers for log collection, error tracking, and system observability (currently Grafana Cloud); (f) as required by law or to protect our rights; (g) with your explicit consent. A complete list of sub-processors is available upon request.
5. Data Security
We use industry-standard security measures: encryption in transit (TLS 1.3) and at rest (AES-256), logical tenant isolation in our multi-tenant database architecture, role-based access controls, and regular security reviews. Server-side logs are collected for error diagnosis and security monitoring; these logs may include timestamps, request paths, status codes, and anonymized user identifiers but never contain passwords, payment details, or full document content. No method of electronic storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. Upon account cancellation, your data is retained for 30 days during which you may request a data export. After 30 days, your data is permanently deleted from our active systems. Backup archives may retain data for up to 90 additional days. You may request early deletion by contacting us.
7. Your Rights
Depending on your jurisdiction, you may have rights to: access, correct, or delete your personal data; export your data in a portable format; object to or restrict processing; withdraw consent where processing is based on consent; lodge a complaint with a supervisory authority. To exercise these rights, contact us at privacy@quotery.io. We will respond within 30 days.
8. Contact and Updates
For privacy-related inquiries, contact us at privacy@quotery.io. Our Data Protection Officer can be reached at dpo@quotery.io. We may update this Privacy Statement from time to time. Material changes will be communicated via email or in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Statement.