1. Who we are
Quotara is a software-as-a-service platform operated from Kitchener-Waterloo, Ontario, Canada. This policy explains how we collect, use, and protect your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), applicable Ontario privacy law, and the California Consumer Privacy Act (CCPA) for US residents.
2. Information we collect
We collect the following categories of information:
- Account information: Your name, email address, and shop name when you register.
- Business data: Customer records, quotes, work orders, and pricing information you enter into the Service.
- RFQ content: When you use the RFQ Import feature, the text or file content you submit is sent to Anthropic's API for processing. See Section 6 for full details.
- Payment information: Billing details processed by Stripe. We never store credit card numbers on our servers.
- Usage data: How you interact with the Service, including pages visited and features used.
- Technical data: IP address, browser type, and device information collected automatically.
3. How we use your information
- To provide, maintain, and improve the Service
- To process billing and send invoices
- To send transactional emails (quote confirmations, alerts, account notices)
- To respond to support requests
- To detect and prevent fraud or abuse
- To comply with legal obligations
We do not sell your personal information to third parties. We do not use your business data (customers, quotes, work orders) for any purpose other than providing the Service to you.
4. Data storage and security
Your data is stored on Supabase infrastructure hosted in the United States. We use industry-standard encryption in transit (TLS) and at rest. Access to production data is restricted to authorized personnel only. We implement row-level security so that each organization's data is completely isolated from other users of the platform.
5. Third-party services
We use the following third-party services to operate the platform:
- Supabase — database and authentication hosting
- Vercel — application hosting and deployment
- Stripe — payment processing
- Resend — transactional email delivery
- Anthropic — AI processing for the RFQ Import feature (see Section 6)
Each of these providers has their own privacy policy and data processing agreement. We select providers that meet appropriate security standards.
6. AI-powered RFQ import
Quotara offers an optional RFQ Import feature that uses artificial intelligence to parse request-for-quote documents and automatically populate quote drafts. When you use this feature:
- The text or file content you submit is sent to Anthropic, PBC ("Anthropic") via their API for processing.
- Anthropic processes your submission solely to return a structured response to Quotara. Anthropic does not use API inputs or outputs to train its AI models.
- Anthropic does not retain your data beyond what is necessary to process the request.
- You should avoid submitting information that is personally sensitive or that is subject to confidentiality obligations that would prohibit sharing with a third-party processor.
- Use of this feature is optional. You may create quotes manually at any time without using the RFQ Import feature.
For more information on how Anthropic handles data, see Anthropic's privacy policy at anthropic.com/privacy.
7. Your rights
Under PIPEDA, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Withdraw consent to certain uses of your information
- Request deletion of your account and associated data
- Receive a copy of your data in a portable format
To exercise any of these rights, contact us at privacy@getquotara.ca. We will respond within 30 days.
8. Data retention
We retain your account data for as long as your account is active. If you cancel, your data is retained for 30 days in case you wish to reactivate, then permanently deleted. You may request immediate deletion by contacting us. Billing records are retained for 7 years as required by Canadian tax law.
9. Cookies
We use cookies solely for authentication (to keep you logged in) and basic analytics. We do not use advertising cookies or share cookie data with ad networks.
10. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: You may request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to delete: You may request deletion of personal information we have collected about you, subject to certain exceptions.
- Right to opt-out: We do not sell personal information. You therefore have no need to opt-out of the sale of personal information.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights.
To exercise your California privacy rights, contact us at privacy@getquotara.ca. We will respond within 45 days.
11. Changes to this policy
We may update this policy from time to time. We will notify you by email and post the updated policy on this page with a new "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
12. Contact
Privacy questions or requests: privacy@getquotara.ca
Kitchener-Waterloo, Ontario, Canada