1. Scope and who is responsible

This draft describes the reviewed design of the Quote Your Jobs (QYJ) marketing website, contractor application and customer-facing document features. Production deployment and provider settings must be checked before the notice becomes effective. The legal name, registered address, country/state and official privacy contact of the operator have not yet been supplied. “We” in this draft refers to that operator once identified.

For account administration, service security, our business communications and our own relationship with subscribers, the operator generally decides why and how information is used. Where applicable law uses these terms, it acts as a controller or business for those purposes.

For customer contacts, job records and documents entered by a contractor, the contractor generally determines the business purpose and instructs QYJ to process the information. QYJ generally acts as its processor or service provider for that work, subject to the applicable agreement and law. The contractor’s own privacy notice also matters. This notice does not substitute for a required data processing agreement or independently authorize the contractor to collect information.

2. Account and business information

Registration collects name, email, a password, phone number, business name, an optional website, industry and declared team size. The application stores a password hash rather than the plaintext password. Account records can also contain memberships, roles, verification status, authentication and security settings, company branding, contact preferences and profile updates you submit.

Signup can save your selected base plan, billing preference, referral information and the time of registration. Website links may also carry a parameter identifying the AI Quoter offer; current signup does not reserve or activate that feature. Account records can also include required acceptance or notice events and optional marketing preferences separately. Recording a preference or consent event does not by itself activate paid billing, marketing delivery or an AI feature.

3. Customer records, work and attachments

A contractor and its authorized users may provide customer names, emails, phone numbers, service or billing addresses, property details, requests, notes, service descriptions, estimates, invoice information, schedules, assignments and records of manual payments. Customers may also provide information through enabled request forms, document responses or approval workflows.

Uploaded images and documents can include photos, PDFs and job evidence, together with the original filename, file type, size, dimensions and upload details. Files may contain information about other people or embedded metadata, including location metadata in a photo. Do not assume this information is automatically removed before storage or sharing. Only submit information appropriate for the job and which you are authorized to provide.

Current invoice payment records document payments entered manually by the business. They do not require payment-card credentials or constitute payment processing. Do not place card security codes, bank passwords, government identifiers, medical records or unnecessary sensitive information in notes or attachments. Any future payment integration needs a separate review of what the payment provider and QYJ receive.

4. Website visits, referral details and technical records

Request delivery involves technical information such as the requested page, time, IP address and browser or device information. Hosting, proxy or CDN providers may process this information to deliver and protect the service. Their actual production logs and retention settings have not yet been verified for this notice.

When you enter an email in a website signup form, it is passed to the application in the signup URL so the form can be prefilled. Permitted campaign and referral parameters may travel with it, including UTM tags, advertising click IDs, partner or visitor identifiers and an industry selection. URL parameters can appear in browser history and in logs of systems handling that request. The application removes the prefilled email from its visible URL after loading; that does not erase copies already recorded elsewhere.

Account and security records may include session identifiers, browser information, timestamps, authentication attempts, actions taken and hashed IP or browser evidence. Customer document access and acceptance can record the contact, document version, response, signer details and time of the action. Hashes and identifiers are not necessarily anonymous information.

5. Cookies, local storage and offline data

The public marketing website uses Google Analytics 4 to understand page visits and traffic sources. Google Analytics can use first-party cookies and process browser, device and interaction information. The website's tag does not enable Google signals or advertising personalization. Its page URL configuration excludes signup email, session identifiers and other non-campaign query parameters. The separate signup application continues to receive permitted attribution and the email you enter. Google Analytics account settings and any hosting or proxy processing require separate review. Learn more about how Google uses information from sites that use its services.

The application uses session and request-security cookies for authentication and account protection. It can store account or workspace display information and a device identifier in browser local storage. Offline features can store drafts, queued changes and conflict copies in the browser’s IndexedDB database, while a service worker caches application resources. These records can include personal and business information on your device.

Use a protected device and browser profile, especially for shared devices. Logging out is designed to clear the app’s local account data and offline caches, but it cannot remove files you downloaded, screenshots or copies outside the app. Browser controls let you clear cookies and site data; doing so can sign you out and delete unsynchronized work. Do not treat local storage as an independently encrypted backup.

6. Product usage and diagnostics

The application records selected product and operational events to understand feature use, investigate failures and keep workflows reliable. Those events can be associated with a user or organization identifier. The event design restricts properties and excludes customer names, emails, phone numbers, addresses, photos, line-item descriptions and document monetary values from product analytics.

Error monitoring and performance tools may be enabled by the operator. Their reviewed design restricts diagnostic details, but the production providers, access settings, data locations and retention periods remain to be confirmed. Product analytics should not be described as completely anonymous merely because customer text is excluded.

7. Why information is used

Information is used to create and verify accounts; provide the requested workspace, documents, scheduling and customer workflows; apply permissions; synchronize supported offline changes; provide support; deliver account and authorized business messages; and process a business’s instructions to export or correct records.

It is also used for reasonable security, abuse prevention, audit trails, troubleshooting, service improvement, backups, dispute handling and legal obligations. Referral details help identify how a signup reached QYJ. Optional QYJ marketing uses the separate choices made for that purpose. A plan preference is used to present and retain the selected offer, not to charge a payment method.

Where a law requires a specific legal basis, the operator must document the appropriate basis for each purpose. Depending on the relationship and jurisdiction, that may include performing a contract, a legal obligation, a properly assessed legitimate interest or consent. This draft does not treat visiting a page as blanket consent, or select a legal basis without confirming the relevant circumstances.

8. Who may receive information

Your organization and chosen recipients. Authorized owners, administrators and team members can access records according to their permissions. Information you send, publish, download or share may reach the customer or other recipient you select. A person with a valid document link may access the content authorized by that link. Revoking it does not remove an email, PDF or copy already saved by a recipient.

Service providers. Depending on the actual deployment, providers support hosting and content delivery, databases, file storage and backups, transactional email, security, error monitoring and technical support. They receive the information necessary for their work, subject to applicable contractual restrictions. Names, service locations, access safeguards and any required subprocessor list must be confirmed before this policy becomes effective. We have not identified an unverified vendor as the live provider.

Connected services and other permitted disclosures. An integration you choose can receive information you direct to it under its own terms. Information may also need to be disclosed to professional advisers, authorities or other parties when lawfully required, to establish or defend legal claims, or to investigate a security incident. A corporate transaction could involve relevant records subject to lawful safeguards and any required notice; it would not remove existing privacy obligations.

9. Sale, advertising and browser privacy signals

No functionality for selling personal information or sending it for cross-context behavioral advertising is implemented in the reviewed website or product. Providing data to a contracted provider to run the service is a separate practice described above. The final operator must verify provider contracts and the complete live deployment before making a final representation about legal definitions of sale or sharing.

The reviewed website does not change its behavior in response to a browser “Do Not Track” signal. Google Analytics use is described in section 5. A production review must also confirm Global Privacy Control and other required opt-out signal handling wherever applicable law requires it. Do Not Track and Global Privacy Control are different mechanisms. Any future advertising or cross-site tracking must be reflected in the policy and the applicable choice controls before it is enabled.

10. Email, telephone details and marketing choices

Account verification, password recovery, invitations and other necessary service emails are distinct from optional QYJ marketing. A separate marketing preference can be changed through the application. Unsubscribing from marketing does not stop messages necessary to maintain an account or comply with a request or legal obligation.

Contractors control their customer communications and are responsible for appropriate notices and permissions. Current automations support email; sender acceptance does not prove receipt, opening or reading. Live SMS, automated calling, WhatsApp and email open/read tracking are not part of the reviewed automation implementation. A phone number or a stored notice version does not demonstrate that those channels are active or that every required consent has been obtained.

11. AI Quoter and recordings

AI Quoter is a planned feature. Its current website preview uses fixed example responses: it does not record audio, analyze your images or send job information to a live AI API. Choosing the proposed US$39/month offer leads to account creation; it does not reserve, activate or charge for an AI subscription.

Before live AI is offered, the operator must identify the information sent to any transcription or model provider, provider retention and training settings, audio retention and deletion, applicable subprocessors, and any permissions needed to record others. This draft does not promise zero provider retention, give permission for model training, or treat a feature preview as consent to future processing.

12. Retention, closure and deletion

Retention should reflect the purpose of each category, the business’s instructions, account status, security needs, contract and tax records, dispute periods and legal obligations. The operator still needs to approve and publish the applicable periods or decision criteria for account data, customer records, attachments, logs, email records, local caches, exports and backups. The records should not be kept indefinitely simply because storage is available.

Account owners can use supported account tools to request an export or initiate closure. Closure can first restrict access, revoke sessions and sharing links, and place records in a retention workflow. It is not immediate complete erasure. Primary files, database records, replicas, backups, logs and providers’ copies have separate deletion or expiry processes that require operational verification. A displayed retention window is not proof that every copy will be erased at its end.

Information may need to be retained for a legal duty, a security investigation or a legitimate dispute, subject to applicable limits and restricted use. Copies in protected backups may persist until their verified expiry or deletion cycle. Files downloaded by a contractor or its customer, and records a contractor must retain, are not automatically removed by closing a QYJ account. No part of this section excuses a deletion duty imposed by applicable law.

13. Safeguards and international processing

The application includes account authentication, access roles, workspace separation, protected session handling, upload controls and restricted diagnostics. Their operation depends on correct production configuration and ongoing review. No security measure makes every system or device risk-free, and no security certification or absolute guarantee is made in this draft. Applicable incident response and notification duties continue to apply.

Information may be processed in countries where the operator or its contracted providers operate. The actual regions and any legally required cross-border safeguards have not yet been confirmed. This draft does not claim that all data stays in the United States, that a particular transfer framework applies, or that safeguards have already been contracted. Required transfer details must be completed before relevant processing.

14. Your choices and privacy requests

You can review or correct information in available account and business settings and manage supported communication preferences. Organization owners have account-level export and closure controls; ordinary users may need to ask their organization’s owner for help with workspace records. An export feature does not by itself guarantee that every attachment or category is included in one downloadable package.

Depending on your location, the operator’s activities and applicable law, you may have rights to access, correct, delete or obtain a copy of personal information; withdraw consent; object to or restrict processing; opt out of particular uses; or complain to a regulator or appeal a request decision. Exceptions and identity-verification requirements may apply. A business contact is not automatically excluded from privacy protection. We do not claim that CCPA, GDPR or every state privacy law applies to every user.

If your information was entered by a contractor, contact that contractor using the contact details on your estimate, invoice or existing correspondence. It ordinarily directs changes to its own customer records. QYJ should assist with valid requests in its applicable role. The official QYJ privacy request channel is still pending and must be established before this policy is effective; this draft provides no working request address. Exercising a statutory right must not result in unlawful discrimination.

15. Children and changes to this notice

QYJ is designed for adult business users, not children. Accounts are intended for people at least 18 years old. Do not submit children’s information unless it is necessary for an authorized business purpose and all relevant legal requirements have been addressed. Any report of inappropriate collection involving a child needs prompt review through the official privacy channel once established.

The final policy must show its effective date and describe how material changes are communicated, such as an in-product notice or an appropriate account message. Changes to data uses that require new consent or another lawful step cannot be authorized merely by changing text on this page. An earlier effective notice and applicable law continue to govern where required.

16. Operator and privacy contact — pending

The operator must provide its full legal name, registered mailing address, country/state and a monitored privacy email or request channel. A representative or data protection officer must be identified if required. These details, verified providers, retention rules and an effective date are unresolved. Do not treat sample addresses or a sales signup form as an official privacy-request channel.