Privacy policy
In force from 30 July 2026.
The short version
We hold your business details, your quotes, and the contact details of the clients you quote. We don't sell any of it. We don't use one customer's data to serve another. Your clients' names, addresses and quote contents are not visible to us in the admin tools — that's a deliberate limit, described below.
Who is responsible
Noah Nicholas Coulson, ABN 98 983 308 378, Newmarket QLD 4051, Australia. Contact: the contact form, or hello@getquickquote.com.au
What we collect, and why
| What | Why |
|---|---|
| Your email address | To sign you in and to contact you about the service. |
| Your business details — name, ABN, phone, suburb, logo, bank details | They go on the quotes you send. Bank details are shown only to your own clients, never used by us. |
| Your rates and settings | To price your quotes. |
| Your quotes, and your clients' names, addresses and email addresses | To produce the quote you then send them yourself. Provided by you. |
| Site photos you attach | Your own record of the job. They are not put on the quote and are never sent to your client. |
| Photos of your handwritten notes | Read once to turn the handwriting into text, then discarded. We don't store the image, and only the transcribed words are kept — in the quote you go on to write. |
| Usage events — signed up, built a quote, read a photo of notes | Counts and timestamps only, so we know whether the product is working. |
Your clients' information
When you quote someone, you give us their name, address and email. We use it for exactly one thing: producing that quote, which you then send yourself. We never email your clients. We don't market to them, we don't build a list from them, and we don't pass them to anyone.
The admin tools deliberately show activity only about your account — how many quotes, total value, when you were last active. They do not open up your clients' names, addresses, or what any quote says. A support tool that can read private client data is a risk that isn't worth taking.
We do not record anything about your client's behaviour — not whether they opened the quote, not whether they accepted it. QuickQuote hands you a document and stops there; what happens next is between you and them, in your own inbox.
Cold outreach
If you got an unsolicited email from us, it went to a business address published online, about software for the work that business does — inferred consent under the Spam Act 2003. Every message carries a working unsubscribe link. Use it and you're removed permanently and immediately; we keep only your address on a suppression list, purely so we never email you again.
Who else touches your data
- Cloudflare — hosting and the database. Data is stored in the Oceania region.
- Stripe — payments. They get your email and business name to bill you. We never see your card number.
- An email provider — to deliver your sign-in codes and our own messages to you. Never anything to your clients.
- Anthropic — only if you use "Snap your notes". The photo is sent to them to be read and is not used to train their models. Neither they nor we keep the image.
That's the whole list. No advertising networks, no analytics products, no data brokers. The site sets no tracking cookies — the only cookie is the one that keeps you signed in.
How long we keep it
While your account is open, and for 12 months after you cancel so you can come back or export it. Then it's deleted. Suppression-list entries are kept indefinitely, because forgetting them would mean emailing someone who asked us not to.
Your rights
You can ask for a copy of everything we hold about you — or just press Export everything in the app, which gives you the same thing immediately. You can ask us to correct it, or to delete it. Email the contact form and you'll get an answer within 30 days.
If you're not happy with how we've handled a privacy matter, tell us first. If we can't resolve it you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Security
There are no passwords to steal — sign-in is a six-digit code emailed to you, good for ten minutes and usable once. Traffic is encrypted. Every database query is scoped to your account, and that scoping is enforced by the database itself as well as by the application.
If a breach ever occurs that is likely to cause you serious harm, you'll be told, and so will the OAIC, as the Notifiable Data Breaches scheme requires.
Changes
If this policy changes in a way that matters, you'll get an email at least 14 days beforehand.