Q
Quotely
Back to home

Privacy Policy

Last updated: 23 March 2026 (rev. 2)

1. Who we are

Quotely (quotely.ie) is a quote management and follow-up platform for Irish contractors and service businesses. For the purposes of the General Data Protection Regulation (GDPR) and the Data Protection Acts 1988–2018, Quotely is the data controller of the personal data described in this policy.

Contact us at: hello@quotely.ie

2. What data we collect and why

Account data

When you create an account we collect your email address, business name, and optionally your full name. This is necessary to provide the service (GDPR Art. 6(1)(b) — performance of a contract).

Customer data you enter

When you create quotes or invoices you may enter your customers' names and email addresses. This data is stored on your behalf so you can send quotes and invoices and manage follow-ups. You are responsible for ensuring you have a lawful basis to share your customers' data with us. Our legal basis for processing it is to fulfil our contract with you (Art. 6(1)(b)).

Usage and audit data

We maintain an audit log of key actions (quotes created, invoices sent, etc.) to support account security and troubleshooting. Audit logs are retained for up to 2 years and do not contain personal data beyond user and business identifiers.

Technical data

Our servers may record standard web server logs (IP address, browser type, pages visited) for security monitoring. These logs are not linked to your account and are retained for a short period only.

3. Cookies

Quotely uses strictly necessary session cookies only. These cookies are required to keep you signed in and cannot be disabled without preventing the service from working. We do not use any advertising, tracking, or analytics cookies. No third-party cookies are set by Quotely.

The session cookie is set by Supabase (our authentication provider) and is scoped to quotely.ie. It expires when you sign out or after a period of inactivity.

4. Who we share data with

We use the following sub-processors to deliver the service:

  • Supabase — database and authentication (EU region, Irish data residency available)
  • Mailgun — transactional email delivery (EU region)
  • Stripe — payment processing (no customer quote/invoice data is shared)
  • Vercel — application hosting (primary region: EU; edge functions may execute globally)

We do not sell, rent, or share your personal data with any third party for marketing purposes.

International transfers

Some sub-processors (Vercel edge network) are based in or may process data in the United States. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) under GDPR Article 46(2)(c), or on an applicable adequacy decision, to ensure an equivalent level of data protection. You may request a copy of the relevant SCCs by emailing hello@quotely.ie.

5. How long we keep your data

Data typeRetention
Account & business dataUntil you delete your account
Quotes, invoices, customer recordsUntil you delete your account
Audit logs2 years
Follow-up task records (completed)2 years

6. Your rights under GDPR

As a data subject in the EEA you have the following rights:

  • Right of access — request a copy of the personal data we hold about you.
  • Right to erasure — delete your account and all associated data at any time from Settings → Danger Zone.
  • Right to rectification — correct inaccurate data via your account settings.
  • Right to portability — request an export of your data in a machine-readable format.
  • Right to object — object to processing based on legitimate interest, including follow-up emails (each follow-up email contains an unsubscribe link).
  • Right to restriction — request that we restrict processing in certain circumstances.

To exercise any of these rights, email us at hello@quotely.ie. We will respond within 30 days.

You also have the right to lodge a complaint with the Data Protection Commission (Ireland).

7. Security

We use industry-standard security measures including encryption in transit (TLS), database-level row security policies (RLS), nonce-based Content Security Policy, and role-based access controls. We conduct periodic security reviews and apply security patches promptly.

In the event of a personal data breach, we will notify the Data Protection Commission within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (GDPR Article 34).

8. Data Processing Agreement (DPA)

If you are a business using Quotely to process your own customers' personal data, a Data Processing Agreement (DPA) is available under GDPR Article 28. You can request a signed copy by emailing hello@quotely.ie. We aim to respond within 5 business days.

Our DPA covers the scope and purpose of processing, your instructions to us as processor, our obligations regarding security, sub-processors, and data subject rights assistance.

9. Changes to this policy

We may update this policy from time to time. We will notify you of material changes by email or via a notice in the application. The date at the top of this page indicates when the policy was last revised.

10. Contact

For any privacy-related questions or requests, please contact us at: hello@quotely.ie