QuickQuoteFlowFor office & job site

Privacy Policy

for the QuickQuote software · Version: 26 August 2026

English courtesy translation of the German legal text. In case of discrepancies, the German version shall prevail.

1. Controller

The controller responsible for data processing in connection with the use of the QuickQuote software is:

Lukas Keßler / QuickQuote
Buergermeister-Fuchs-Strasse 70
68169 Mannheim
Email: privacy@quickquote.tech

Note: As soon as a company is incorporated (for example a UG or GmbH), that company shall replace the natural person named above as controller.

2. General Information

This Privacy Policy explains the nature, scope and purpose of the processing of personal data when using the QuickQuote software, the web application at app.quickquote.tech, the website quickquote.tech and the mobile apps for iOS and Android.

Personal data means any information by which you can be personally identified.

3. Data Collected

When using QuickQuote, the following data may be processed:

Order and site inspection data that the business records about its customers is processed by the provider as a processor on behalf of the business pursuant to Art. 28 GDPR. Details are governed by the data processing agreement (DPA). The data processing agreement is concluded upon registration and also applies to the free enquiry tier.

Absence information and uploaded evidence may contain health data within the meaning of Art. 9 GDPR. The respective business as controller is responsible for the lawfulness of collection and for determining the retention period; QuickQuote processes this data solely on its instructions as processor.

This data is processed solely for providing the functions of the software.

4. Purpose and Legal Bases of Processing

Data is processed for the following purposes:

Legal bases:

5. Hosting and Infrastructure (Google Firebase, Netlify)

The QuickQuote software (web application at app.quickquote.tech) is provided through Google Firebase (Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA). Firebase is used for the following services:

The server-side Cloud Functions are configured in the europe-west1 region; Cloud Firestore is operated in the European multi-region eur3. Certain globally provided Firebase services, in particular Authentication, Cloud Messaging, Analytics and Crashlytics, may also process data outside these regions.

In this context, personal data (for example email address, name, project data, technical usage data) may be processed on Google's servers. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google. Google LLC is certified under the EU-U.S. Data Privacy Framework; additionally, standard contractual clauses pursuant to Art. 46 GDPR are in place.

Legal basis: Art. 6(1)(b) GDPR.

Optional telemetry: Usage analytics and error diagnostics are disabled by default. Only after explicit device-specific consent are screen views, selected usage events, app and device versions and technical crash and error data transmitted to Firebase Analytics or Crashlytics. In the web application, after consent, minimised error records containing time, error type, route, build, platform and user ID may be stored in Cloud Firestore. Consent can be withdrawn at any time in the profile settings with effect for the future; collection then stops on the respective device. The legal basis is Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

Account management page: Firebase Authentication and Firebase Cloud Functions are also used on the account management page at quickquote.tech/en/account. When this page is opened, the required Firebase JavaScript files are loaded from www.gstatic.com. Google may process technically necessary connection data, in particular the IP address, time, and browser and device information. When signing in, the email address and password are sent to Firebase Authentication for verification. The account page does not write the entered password to browser storage. After successful sign-in, the session data required for authentication is sent to a Cloud Function in europe-west1 to create a Stripe customer portal session; the browser is then redirected to Stripe. These operations are not used for advertising or audience measurement.

The marketing website quickquote.tech (not the web application) is hosted by Netlify, Inc., 512 2nd Street, Suite 200, San Francisco, CA 94107, USA. This does not affect the use of Firebase on the account management page described above. When the website is accessed, Netlify processes technically necessary server log data (in particular the IP address, time of access, page requested, user agent) in order to deliver the website and ensure its security. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Netlify; the transfer to the USA is based on standard contractual clauses pursuant to Art. 46 GDPR.

When starting a paid subscription via the checkout form on the pricing page, interested parties provide the owner email address and company name as required information. We also process the confirmation of business status, acceptance of the Terms and DPA, acknowledgement of the Privacy Policy, the relevant document versions, language and the selected number of additional licenses. This data is used to prepare the order, create a secure checkout session with Stripe and keep evidence of the legal confirmations (see Section 7 “Payment Processing (Stripe)”). If the pricing page is opened with a ref source parameter, this value is sent to the server together with the checkout information, recorded in the Stripe metadata of the checkout session and used for a daily source counter. This solely measures which of our own referrals initiated a checkout; we do not use cookies or cross-browser identifiers for this purpose and do not create a cross-site usage profile. It is not used for advertising purposes or shared with third parties for advertising purposes.

Legal basis for website hosting: Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website). Legal basis for the checkout form: Art. 6(1)(b) GDPR (performance of pre-contractual measures). Source attribution is based on Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our own referrals).

5a. Public Enquiry Forms of Businesses

Businesses using QuickQuote can create a public enquiry link with a QR code and share it with their customers. The associated form page is provided as part of the web application via Google Firebase at app.quickquote.tech (see Section 5). The business's customers can use it to submit an enquiry to the business without needing an account of their own. The following data is collected: name (required), description of the request (required), phone number and/or email address (at least one of the two) and, optionally, the desired service, postcode and town.

Allocation of roles: For the contents of the enquiry, the respective business is the controller within the meaning of the GDPR. QuickQuote processes this data solely as a processor on behalf of the business pursuant to Art. 28 GDPR. The privacy information of the respective business displayed directly on the enquiry form (with details of the controller, purpose, legal basis, categories of data, retention period and data subject rights) is authoritative for the processing of the contents.

Technical operation of the form page: QuickQuote is a controller in its own right for the provision of the form page itself and for security and abuse protection. To protect against automated submissions, we use an invisible control field (honeypot) and server-side rate limiting. For rate limiting, the IP address is not stored in plain text but processed exclusively as a business-specific hash value; this data is deleted after approximately 24 hours. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure provision and protection against abuse).

No automated AI processing: Enquiries received through the form are not processed automatically by AI services; only technical validation and normalisation of the entries and storage in Cloud Firestore take place. AI features (see Section 6) are only used once a business deliberately adopts the enquiry into a project.

Retention: Enquiries that are not opened by the business are deleted automatically 30 days after receipt. Otherwise, the business as controller determines the retention period.

Confirmation and notifications: After submitting an enquiry, customers receive a confirmation with a reference number directly in the browser; no confirmation email is sent. Authorised employees of the business may be informed of new enquiries via internal push notifications.

QuickQuote uses the data collected through the form solely to make it available to the respective business, and not for its own advertising, personalised analytics or the training of AI models.

6. Use of AI Services (OpenAI)

To support certain functions, the API of OpenAI Ireland Ltd., 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland is used. Before another AI service provider is used, this Privacy Policy will be updated accordingly and the change will be communicated under the rules governing sub-processors.

Depending on the function, the following data is transmitted to the AI service:

Quey AI and voice assistant

Quey is an AI-supported text and voice assistant. For each request, QuickQuote creates a minimised working context on the server from workspace data available to the relevant user under that user's role. Depending on the role, this may include a project identifier and title, customer name, property or site address, trade, processing status, appointments, assigned employee and reviewer names, review notes, checklists and document status and, for owner, manager and office roles, invoice amounts and payment status. The context and the current user question are transmitted to OpenAI to generate the answer. Contact details, photos and complete files are not part of the automatically created Quey context, but may be processed if a user enters them directly in a question. QuickQuote does not maintain a conversation history for Quey.

For Quey voice input, the microphone recording is converted to text by the operating system's or browser's speech-recognition service. QuickQuote receives only the recognised text and transmits the raw Quey microphone recording neither to its own servers nor to OpenAI. Depending on the device, operating system and selected service, however, the microphone recording may be processed by the relevant device or browser provider on remote servers. For speech output, the answer text may likewise be transmitted to a network-based speech-synthesis service depending on the selected system voice.

After a successful Quey answer, QuickQuote records, for security, abuse-prevention and evidence purposes, the user ID and name, role, time, the user question (up to 400 characters) and the number of projects included. The answer, the complete system prompt and the generated workspace context are not stored in this audit record. Access is limited to authorised owner and manager roles of the relevant business. These Quey audit records are retained for no more than 30 days and then deleted.

Quey provides non-binding work guidance only. Quey does not change workspace data, send messages, grant approvals or make solely automated decisions that produce legal or similarly significant effects. Assessing or monitoring employee performance or behaviour is not a purpose of the feature.

Data is transmitted to OpenAI only when the relevant AI function is actively used. Only data necessary for that function is transmitted (principle of data minimisation pursuant to Art. 5(1)(c) GDPR). Temporarily stored raw audio files from other, deliberately started transcription features are deleted after transcription succeeds or fails; the resulting transcript may remain stored as part of the relevant workspace record. API content is not used by OpenAI for model training by default. QuickQuote has not enabled voluntary data sharing for model training. For the Responses API used by QuickQuote, application state is retained for at least 30 days by default unless different data controls are configured. In addition, abuse-monitoring logs containing customer content may generally be retained for up to 30 days; a shorter period applies only where corresponding data controls have been approved by OpenAI and configured for QuickQuote.

Processing takes place automatically. The substantive accuracy or completeness of generated results cannot be guaranteed. Users are obliged to review AI-generated results on their own responsibility.

For customers established in the EEA, the Data Processing Addendum with OpenAI Ireland Ltd. applies. Where OpenAI transfers data to affiliates or sub-processors outside the EEA, the Data Processing Addendum provides for standard contractual clauses or an adequacy decision.

Where QuickQuote processes workspace content on behalf of the customer, it acts as a processor on the customer's documented instructions pursuant to Art. 28 GDPR. The customer, as controller, determines the applicable legal basis, in particular for customer and employee data. Where QuickQuote processes its own account, security or evidence data as controller, the processing is based on Art. 6(1)(b) or (f) GDPR, as applicable.

7. Payment Processing (Stripe)

Payments are processed by Stripe, Inc., 510 Townsend Street, San Francisco, CA 94103, USA. When purchasing a paid license, data required for payment processing (for example name, email address, billing address) is transmitted to Stripe.

Complete payment data (for example card numbers) is processed exclusively by Stripe and is not stored on our servers. Stripe is PCI DSS certified. Subscription management takes place through the customer portal at quickquote.tech/en/account.

Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Stripe.

Legal basis: Art. 6(1)(b) GDPR.

8. Email Delivery (Resend)

For sending transactional emails (such as invitations, welcome emails, notifications), we use the service Resend, Inc., 2261 Market Street #4059, San Francisco, CA 94114, USA.

In this process, the recipient's email address, the respective email content and, for document delivery, the PDF selected by you are transmitted to Resend. For delivery and support documentation, QuickQuote stores in the associated business record the recipient address, time sent, Resend message ID and the name and size of any attachment sent.

Data transfers to the USA take place on the basis of standard contractual clauses pursuant to Art. 46 GDPR.

Legal basis: Art. 6(1)(b) GDPR.

9. Web Fonts

This website uses the fonts “Inter”, “Instrument Serif” and “Barlow” for consistent visual presentation. The font files are served from the same server as the website (first-party hosting), not via external Google servers. No connection to Google is established and no IP address or other data is transferred to Google or any third party for the purpose of loading fonts.

10. Cookies and Local Storage

On the publicly accessible content pages of quickquote.tech, we do not use cookies or other browser identifiers for advertising, tracking or analytics purposes.

On the account management page at quickquote.tech/en/account, Firebase Authentication stores the sign-in state and session data required for authentication in the browser's session storage. The sign-in is stored as a session-based rather than a permanent local sign-in. In accordance with the Firebase SDK settings, it ends when the tab or window is closed; signing out also removes the sign-in state. The account page does not store the entered password in session storage. This storage is used exclusively for sign-in and access to the Stripe customer portal.

The web application at app.quickquote.tech may use browser storage for technically necessary authentication sessions, app settings and temporary state. Persistent offline storage of Firestore application data in the browser is not currently enabled. No data is stored for tracking or advertising purposes.

The decision on optional usage and error diagnostics is stored locally on the respective device. Without explicit consent, Firebase Analytics, Crashlytics and web error diagnostics remain disabled.

For functional usage counts in the public demo, we store only event totals per calendar day. We do not use cookies, user identifiers or raw IP addresses for this counter and do not create user profiles. Irrespective of this, the infrastructure providers named in Section 5 may process connection data when the service is accessed.

The homepage contains a clearly marked external link that lets users select QuickQuote as a preferred source on Google. We do not embed a Google script or content from Google for this purpose. A connection to Google is established only when the link is deliberately clicked. Google is responsible for the subsequent processing under its own privacy terms.

Technically necessary storage of and access to information on the end device is carried out pursuant to Section 25(2) no. 2 TDDDG where it is required to provide the expressly requested sign-in, account management or app functionality. The legal basis for the associated processing of personal data is Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR applies to security and functional usage counters. Optional usage analytics and error diagnostics are carried out only with consent pursuant to Art. 6(1)(a) GDPR in conjunction with Section 25(1) TDDDG.

10a. Social Media Profiles

QuickQuote maintains public profiles on the following social networks:

When you visit one of these profiles, the relevant platform operator processes personal data under its own responsibility. This may include your IP address, device and browser data, and usage behaviour. If you are logged in, a link to your platform account may also be created. The operators may also use this data to create profiles and provide personalised advertising.

We use our profiles to present QuickQuote and to respond to messages, comments and enquiries. We process the associated data on the basis of Art. 6(1)(f) GDPR (legitimate interest in public relations and communication). Where an enquiry concerns entering into or performing a contract, the legal basis is Art. 6(1)(b) GDPR. We delete messages and comments once they are no longer required for handling the matter, unless statutory retention obligations apply.

The platform operators are X Corp. or Twitter International Unlimited Company (X), Meta Platforms Ireland Limited (Instagram) and LinkedIn Ireland Unlimited Company (LinkedIn). Information about their processing, international data transfers and your rights is available in their respective privacy policies: X, Instagram and LinkedIn. Rights relating to processing for which a platform operator is solely responsible are most effectively exercised directly with that operator. For processing by QuickQuote, contact us at privacy@quickquote.tech.

11. Data Processing Agreements

Data processing agreements pursuant to Art. 28 GDPR apply to service providers acting as processors, in particular Google, Netlify, OpenAI Ireland Ltd. and Resend. Where a service provider acts as an independent controller for individual processing operations, the processing is additionally governed by that provider's statutory duties and privacy information.

12. Storage and Deletion of Data

Data is stored only as long as necessary to provide the software. Personal data is deleted as soon as the purpose of processing no longer applies, unless statutory retention obligations prevent deletion (for example tax retention periods pursuant to Section 147 AO).

Deletion of an individual user account (for example when an employee leaves):

When an individual user account is deleted within an existing workspace, login data (email, password) as well as personal profile data (name, phone number) are deleted irrevocably. The user's name is replaced systemically with "Former User." All content created in the workspace (projects, inspections, photos, notes) remains stored because it constitutes the customer's company and business data and is not attributed to the user's personal data inventory.

Termination of the workspace subscription:

After termination of the subscription, the workspace data is initially retained so that the subscription can be reactivated if needed. The workspace administrator can request the complete and irreversible deletion of all workspace data at any time by email to privacy@quickquote.tech; deletion takes place within 30 days of receipt of the request, unless statutory retention obligations (for example Section 147 AO) apply.

13. Data Export and Data Portability (Art. 20 GDPR)

QuickQuote provides the following export features:

Export of personal profile data (all users):

Each user can export a machine-readable copy of their personal profile data (name, email address, phone number, role, member since) in JSON format at any time through the account settings. This export is limited to once per calendar month. This satisfies the right to data portability pursuant to Art. 20 GDPR.

Export of workspace data (administrator/owner only):

The workspace administrator can trigger a complete export of all workspace data in JSON format through the app. This export includes: user profile, team data, all projects with inspections and links to stored media files (photos). The media files themselves can be accessed via the links contained in the JSON file. This export is also limited to once per calendar month.

Project data, construction site documentation and other content created in the workspace are company data of the customer (controller under the GDPR) and are not subject to an individual export claim of single users.

14. Account Deletion (Art. 17 GDPR)

Employees without an administrative role can delete their account at any time through the profile settings in the app. Owners or administrators of a workspace can have their account or the entire workspace deleted by email to privacy@quickquote.tech (the administrative role must be transferred beforehand, or the workspace deleted as a whole). Upon deletion, personal profile data (name, email address, phone number) is deleted irrevocably. Content created in the workspace (projects, inspections, photos, notes) remains with the company (see Section 12).

15. Rights of Data Subjects

You have the following rights with regard to your personal data:

To exercise your rights and for information requests pursuant to Art. 15 GDPR, please contact: privacy@quickquote.tech

Requests are processed within 30 days.

16. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority about the processing of your personal data. The competent supervisory authority is:

The State Commissioner for Data Protection and Freedom of Information Baden-Wuerttemberg
Lautenschlagerstrasse 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

17. Transactional Emails

In connection with the use of QuickQuote, the provider sends the following transactional emails:

These emails are technically necessary for operation of the software and are sent exclusively to the email address stored in the account. Legal basis: Art. 6(1)(b) GDPR.

18. Contact

If you have questions regarding data protection, please contact:
Email: privacy@quickquote.tech

Lukas Keßler · Buergermeister-Fuchs-Str. 70 · 68169 Mannheim · quickquote.tech

Contact by email: If you contact us by email (for example at support@quickquote.tech or privacy@quickquote.tech), we process your email address, the content you provide and the time of your message in order to handle your enquiry. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or its initiation, and otherwise Art. 6(1)(f) GDPR (legitimate interest in responding to enquiries). We delete the correspondence once it is no longer required for handling the matter, unless statutory retention obligations (for example for business correspondence under the German Commercial Code (HGB) and the German Fiscal Code (AO)) require continued storage.