⚠ Placeholder document
This privacy policy has not yet been reviewed by a legal professional. It must be completed before DashQuote is made available to the public.
Privacy Policy
Last updated: [DATE]
1. Who we are
DashQuote (“we”, “us”, “our”) is operated by [COMPANY NAME], registered in England and Wales (Company No. [NUMBER]).
Our registered address is: [ADDRESS]
We are the data controller for personal data processed through this service. If you have any questions about this policy or how we handle your data, contact us at: [PRIVACY EMAIL]
2. What data we collect
We collect the following categories of personal data:
- Account data: your email address, business name, phone number, and business email.
- Business content: quotes, invoices, job descriptions, photos, and voice recordings you create and upload.
- Customer data: names, email addresses, phone numbers, and addresses of your customers, which you provide to us.
- Billing data: your subscription status and payment method, managed by Stripe. We do not store card details directly.
- Usage data: log data including IP address, browser type, and pages accessed, collected automatically.
3. How we use your data
We use your data to:
- Provide and operate the DashQuote service
- Generate quote and invoice documents using AI
- Deliver quotes and invoices to your customers by email
- Process subscription payments via Stripe
- Send transactional emails (quote delivery, invoice delivery, payment notifications)
- Improve and maintain the service
- Comply with our legal obligations
Our legal basis for processing is contract performance (providing the service you signed up for) and, where applicable, legitimate interests (improving the service and preventing fraud).
4. Your customers' data
When you enter your customers' personal data (name, email, phone, address) into DashQuote, you are the data controller for that information and we act as your data processor. You are responsible for ensuring you have a lawful basis for sharing that data with us and for complying with your own obligations under UK GDPR.
5. Third parties we share data with
- Supabase — database and file storage (EU region)
- Anthropic — AI processing for quote generation
- OpenAI — voice note transcription
- Resend — transactional email delivery
- Stripe — subscription billing and payment processing
- Vercel — application hosting
We do not sell your data to any third party.
6. Data retention
We retain your account data and business content for as long as your account is active. If you delete your account, your data is permanently removed from our systems within [X days], except where we are required to retain it by law (e.g. financial records).
7. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data (“right to be forgotten”) — you can do this directly from your account settings
- Restrict or object to processing in certain circumstances
- Data portability — request a copy of your data in a machine-readable format
- Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at [PRIVACY EMAIL]. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Cookies
DashQuote uses only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.
9. Security
We use industry-standard measures to protect your data including encryption in transit (TLS) and at rest, row-level security on our database, and access controls. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email or by a notice within the app. Continued use of DashQuote after changes take effect constitutes acceptance of the updated policy.
11. Contact
For any privacy-related queries: [PRIVACY EMAIL]