Privacy Policy

Effective date: 31 May 2026 · Last updated: 3 August 2026

This Privacy Policy explains how Up Top Technologies ("QuotaFlo", "we", "us") collects, uses, and shares information when you use the QuotaFlo AI application and website (the "App").

Contact: support@quotaflo.com
Operator / data controller: Up Top Technologies, Greymouth, West Coast, New Zealand
Privacy Officer: Martyn Scott — support@quotaflo.com

1. Summary (plain English)

2. Who this applies to

The App is intended for business users (sole traders and tradespeople). You may enter information about your clients (names, addresses, phone numbers, job details, prices). You are responsible for having a lawful basis to enter that information and for telling your clients how their information is used (for example, under the NZ Privacy Act 2020 (IPP 3/3A), the Australian Privacy Act 1988 (APP 5), the GDPR / UK GDPR, where those apply to you). For that client information, you are the controller and we act as your processor, processing it only to provide the App's features to you. Our Data Processing Addendum sets out those processor commitments formally and forms part of our Terms.

Our legal basis (where the GDPR / UK GDPR applies). We process your account data (email, name, company, hashed password, subscription status) to perform our contract with you (Art. 6(1)(b)); we process limited technical and AI-usage data to operate, secure and meter the service under our legitimate interests (Art. 6(1)(f)); and we rely on your consent (Art. 6(1)(a)) for optional device permissions such as location, camera and microphone, which you can withdraw at any time in your device settings.

3. What we collect and why

3.1 Information stored on your device only

The following is stored in your browser's local storage on your device and is not sent to our servers by the App in normal use:

This data stays on your device unless you choose to (a) use a feature that sends specific data to a third party (Section 3.2), (b) create a backup (Section 7) or turn on Automatic cloud backup (Section 3.10), or (c) share a quote for approval (Section 3.3).

3.2 Information processed by AI features

When you use an AI feature, the relevant input is sent over an encrypted (HTTPS) connection to our server, which forwards it to a third-party AI provider, and the result is returned to you:

FeatureWhat is sentSent to
Voice → quoteA text transcript of your speech (see voice note below) and the quote detailsOur server → Anthropic
Generate quote / AI assistant / JSAThe job/quote text and details you provideOur server → Anthropic
Safety packThe job details you provide and any site photos you attach (for hazard detection)Our server → Anthropic
Scan invoiceThe photo you capture and the data extracted from itOur server → Anthropic
Snap & Quote (plan / notes take-off)The photo of your handwritten notes, plans or job site that you capture, and the data extracted from itOur server → Anthropic
Scan receipt (expenses)The photo of the receipt you capture and the data extracted from it (vendor, date, total, tax)Our server → Anthropic
Read-aloud (text-to-speech)The text to be spokenOur server → ElevenLabs
Voice note: Speech-to-text is performed by your browser's built-in speech recognition (the Web Speech API). In some browsers (e.g. Google Chrome) the audio of your voice is sent by the browser to the browser vendor (e.g. Google) for transcription. The App itself does not record, store, or transmit your voice audio to our servers — we only ever receive the resulting text. This processing is governed by your browser vendor's privacy policy.

3.3 Quote approval

If you send a client a quote-approval link, the quote and an approval status are stored in our database (Supabase) so the client can approve it from their device. This may include the client's name and the quote contents.

When your client signs: to sign, your client types their full name. That typed name is sent to our server, which records the time of signing and includes both in the confirmation email sent to you — that email is your record of the approval. The typed signature itself is not stored in the quote-approval record in our database.

3.4 Account and authentication

If you create an account, we (via Supabase) collect your email address, your name and company name (which you enter at sign-up), and a securely hashed password to sign you in. Our server also stores your subscription/trial status and simple AI-usage tallies (counts of AI actions only, used to enforce fair-use limits) against your account — never the content of your quotes or jobs.

Preventing free-trial abuse. The free trial is intended to be one per person, and our Terms prohibit creating multiple or aliased accounts to obtain extra trials. Your trial status is held as part of your account record and is deleted when you delete your account. We may take reasonable technical steps to detect and limit trial abuse and automated or bulk sign-ups. Our separate public waitlist sign-up form keeps a pseudonymised hash of the sign-up IP address — never your raw IP — only to rate-limit automated bulk sign-ups to that form.

3.5 Payments

Subscriptions are processed by Stripe via a hosted checkout page on our website. We do not receive or store your full card details; Stripe handles payment information under its own privacy policy. We receive a subscription status.

3.6 Location

If you enable weather or mileage tracking, the App uses your device location to:

You can decline the location permission; those features then do not work, but the rest of the App does.

3.7 Camera and microphone

Both are only accessed when you actively use those features.

3.8 Notifications

With your permission, the App may show notifications on your device. There are two kinds:

3.9 Technical/diagnostic data

We may process limited technical data necessary to operate the service (e.g. request metadata to our API). Product analytics is optional and off by default. Only if you opt in (in the App's Settings, or when we ask you once) does the App send anonymous usage events — which features you use (for example, “quote sent”), never your names, client details, or the contents or amounts of your quotes and invoices — to PostHog. These events are processed in the EU; PostHog is configured not to store your IP address; and we do not identify you (an anonymous, random device identifier is used). You can withdraw consent at any time in Settings. Separately, we use Sentry for crash and error reporting on our server, to detect and fix faults and to help us meet our security-monitoring and breach-notification obligations. Sentry receives error events and technical diagnostics only — a stack trace, the error message, and request metadata such as the route and HTTP status. It does not receive your request bodies or headers (these are stripped before an event is sent), and email addresses, phone numbers, images and secrets are automatically redacted, so your business data and your clients’ details are not sent to it. Sentry acts as our sub-processor and processes this data in the European Union (Germany). This error reporting is carried out under our legitimate interests in operating and securing the service.

3.10 Automatic cloud backup (optional, off by default)

Automatic cloud backup is switched OFF unless you turn it on yourself. Nothing is uploaded until you opt in through the “Turn on backup” dialog or the Settings toggle, and you can turn it off again at any time.

What it does. When you turn it on, QuotaFlo takes a copy of the business data stored on your device — your jobs, quotes, invoices, materials, mileage and business profile, and your clients’ personal details (names, addresses, phone numbers, emails, job descriptions, prices and GST). Before any of this leaves your phone, it is encrypted on your device using AES-GCM-256 with a key created from your login password through PBKDF2 (600,000 iterations). That backup key never leaves your device and is never sent to anyone — not to us and not to our storage provider — so we only ever hold a scrambled copy that we cannot read (this is sometimes called zero-knowledge encryption). Your login password itself works like any normal sign-in: it is sent over an encrypted connection to our sign-in provider (Supabase) when you sign up or log in, where it is stored only as a secure hash — it is never stored with your backup, and the backup key is derived from it on your device (see Section 7). Because only you hold the key, if you forget your login password no one — including us — can recover or unlock your backup.

Why. The backup exists for one purpose: so you can restore your data onto a new, replaced or reinstalled device by re-entering your login password. It is not a sync feature and not a sharing feature. We do not sell it, do not share it, do not use it for advertising, and do not use it for any purpose other than storing it so you can restore it.

Where it is stored. Your encrypted backup is uploaded to a private, access-controlled record — protected by database row-level security so only your own account can reach it — held by our cloud database provider, Supabase, which holds it on our behalf as our storage provider, not as a separate recipient of your data. Supabase may store it in a data centre located outside your country. See Section 10 (International transfers) for how we protect that.

Your clients’ information. The backup includes personal information about your own clients. You remain responsible for that information — under the privacy law that applies to you, you are the controller of it (in New Zealand and Australia, the agency/APP entity holding it), and we act only as your processor/operator, on your instructions, and never use it for our own purposes. If one of your clients asks to see, correct or delete their information, you handle that request from the copy on your device, because we hold only encrypted data that we cannot read or edit.

Turning it off, retention and deletion. We keep only your most recent encrypted backup, and each new backup overwrites the previous one, for as long as the feature is on and your account exists. Turning cloud backup off stops any further backups; your last encrypted backup stays stored so you can still restore from it, and is removed when you delete your account. Deleting your account automatically and permanently deletes your stored backup.

4. How we use information

We do not sell your personal information. We do not use your business data or your clients' data to train our own models. AI providers process it to return a result; their use is governed by their terms (Section 5).

5. Third parties we share with

ProviderPurposeWhat they receive
AnthropicAI generation (quotes, assistant, safety, invoice scan)The text/photo you submit to those features
ElevenLabsText-to-speechThe text to be spoken
SupabaseAccount sign-in, quote-approval storage, optional encrypted cloud backup, and optional Web Push subscriptionsEmail, your name and company name, hashed password, quote-approval records, subscription status, AI-usage counts, and — only if you turn on Automatic cloud backup — an encrypted (unreadable-to-us) copy of your on-device data; and — only if you turn on Web Push alerts — your device’s push subscription (endpoint + keys) and account email
Browser push services — Google (Firebase Cloud Messaging), Mozilla & AppleDelivering optional Web Push quote alerts to your device (only if you turn them on)The notification title and body (which can include a client’s name and the quote total), routed to your device
StripeSubscription paymentsPayment details (collected directly by Stripe)
Open-MeteoWeatherPrecise coordinates
BigDataCloudReverse geocoding (locality name)Precise coordinates
CARTO, RainViewer & OpenStreetMapMap tiles (weather radar & mileage trip maps)Precise coordinates (via tile requests) and IP address
Your browser vendor (e.g. Google)Speech-to-text (Web Speech API)Your voice audio, via the browser
Google (Gmail email delivery)Sending notification emails to you (e.g. when a client approves a quote) and occasional product updatesThe email content (e.g. a client's name and the total on an approved quote) and the recipient address
Render & Cloudflare PagesHosting the API (Render) and the App (Cloudflare Pages)Standard request data
Sentry (EU)Crash & error reporting (server) — to detect and fix faultsError events and technical diagnostics only (stack trace, error message, route/status); request bodies & headers stripped, and emails/phones/images/secrets redacted — no business or client data
PostHog (EU)Product analytics — only if you opt in (off by default)Anonymous events for which features you use (e.g. “quote sent”); no names, client details, or quote/invoice contents or amounts; IP not stored

Each provider acts under its own privacy policy (linked above).

Sharing a quote by text message or WhatsApp. When you choose to send a quote or invoice link by text message (SMS), WhatsApp, or any other app in your phone’s share sheet, the App hands the message and link to that app on your own device — we do not send it, and it does not pass through our servers. Whatever you send then travels under the terms and privacy policy of the app and network you picked (for example WhatsApp, or your mobile carrier for SMS), and those are outside our control. Because the message can include your client’s name and the quote total, please send it only to the client it is for.

6. Retention

7. Security — and an honest limitation

8. Your choices and rights

9. Children

The App is for business use and is not intended for anyone under 18. We do not knowingly collect information from children.

10. International transfers

QuotaFlo is operated from New Zealand, and some features send personal information to service providers located in other countries — primarily the United States (Anthropic for AI generation, ElevenLabs for text-to-speech, Stripe for payments, Render for API hosting), and to our database provider Supabase, which stores your account and quote-approval data — and, if you turn on Automatic cloud backup, your encrypted backup — in a region we select. Other providers listed in Section 5 may also be located overseas. This includes information you enter about your clients.

We make these transfers under each provider's data-processing terms, which require them to protect the information with safeguards comparable to those in your local law (for example, the NZ Privacy Act 2020 (IPP 12) for New Zealand users and the Australian Privacy Principles (APP 8) for Australian users — under which we take reasonable steps to ensure overseas recipients protect your information to a comparable standard — and Standard Contractual Clauses or equivalent mechanisms under the GDPR / UK GDPR (Arts. 44–49) where they apply). Where comparable safeguards are not available for a particular transfer, we will either not make it or will first ask for your express, informed consent on the basis that the overseas recipient may not be required to protect the information in a way comparable to your local law.

Automatic cloud backup. If you switch on Automatic cloud backup, your encrypted backup is stored by our provider Supabase and may be held in a data centre outside your country. The main safeguard is built into how the feature works: your backup is encrypted on your device before it is uploaded, with a key we never receive, so we transfer and hold only a scrambled copy that we cannot read (with the limitation described in Section 7: the key is derived from your login password, which Supabase — our sign-in provider as well as the store holding the backup — receives when you sign in, keeping only a secure hash of it). We store it under Supabase’s standard, published terms (its terms of service and its security and privacy commitments), under which Supabase acts only as our storage provider and does not use your data for its own purposes. For New Zealand and Australian users this reflects the reasonable-steps / comparable-safeguards approach under IPP 12 of the Privacy Act 2020 and APP 8. We have not put separate cross-border transfer contracts in place (such as the EU/UK Standard Contractual Clauses or a UK International Data Transfer Agreement); the on-device encryption — where the key never leaves your phone — is the safeguard we rely on for this backup. If you are in the UK or the EU (Ireland) and would like more detail before enabling backup, contact us at support@quotaflo.com; we will update this section if we add further mechanisms.

11. Changes

We may update this policy. We will change the "Last updated" date and, for material changes, provide notice in the App.

12. Contact

Up Top Technologies
Greymouth, West Coast, New Zealand
support@quotaflo.com

Our Privacy Officer (the person responsible under the New Zealand Privacy Act 2020 for handling privacy enquiries and complaints, and for our compliance with the Act) is Martyn Scott, contactable at support@quotaflo.com. If you are not satisfied with how we handle a privacy concern, you may complain to the Office of the Privacy Commissioner (privacy.org.nz).