Privacy Policy
Independent legal review still pending. The content below is complete and current, but two of the sharpest edges of the product — our processor / data-processing terms and the lawful basis for the missed-call text-back — are still to be checked by a legal professional before we take on real user volume. This is not legal advice.
QuoteSnap helps UK tradespeople catch missed calls (by texting the caller back) and turn job notes into professional quotes. Because of the first feature, we handle personal data about two very different groups of people, and this policy keeps them clearly separate — please read the part that applies to you.
1. Who we are
QuoteSnap ("QuoteSnap", "we", "us", "our") is a service operated by Jay Caldwell, a sole trader trading as QuoteSnap, based in the United Kingdom. As a sole trader we are not a registered company, so we have no company number or public registered-office address; the contact point for any privacy question is the email below.
- Website: https://getquotesnap.co.uk
- Privacy contact: hello@getquotesnap.co.uk
For most of the data we hold, whether we are the "controller" or merely a "processor" depends on whose data it is — section 2 explains this, because it is the most important thing to understand about QuoteSnap.
2. The two groups of people — and who is responsible
a) Our users (tradespeople). If you sign up for a QuoteSnap account, we decide how and why your account data is used. For that data we are the data controller, and this whole policy applies to you directly.
b) Our users' customers (callers). When a member of the public rings a tradesperson's business and doesn't get through, QuoteSnap may store that caller's phone number, the text messages exchanged, and the call timestamp — so the tradesperson can follow the lead up. That person never signed up with us.
For this caller data:
- The tradesperson is the data controller — it is their customer, their business, and their decision to text them back.
- QuoteSnap is the data processor — we only store and send that data on the tradesperson's instruction, to provide the service they asked for.
In plain English: when a tradesperson uses QuoteSnap to text their customer back, they decide to do that; we simply carry it out on their behalf. If you are a caller and you want your data changed or deleted, section 9 tells you how — you will need to contact the tradesperson (the controller), and we will help them action it.
3. What we collect about our users (tradespeople)
| Data | Why we hold it | Where it lives |
|---|---|---|
| Business name, owner name, trading name | Your account + quote branding | Supabase |
| Email address | Login, account notifications | Supabase Auth |
Mobile number (real_mobile) |
Account, missed-call divert setup, operator alerts | Supabase |
| Business address, city, postcode | Quote branding | Supabase |
| Public contact email / phone shown on quotes | Quote branding | Supabase |
| Gas Safe number, VAT number & VAT status | Quote branding | Supabase |
| Logo image | Quote branding | Supabase Storage (business-logos) |
| Your custom text-back message | The auto-reply sent to your callers | Supabase |
| Your assigned QuoteSnap (Twilio) number | Identifies your business for calls/texts | Supabase, Twilio |
| Subscription status & billing identifiers | Managing your subscription | Supabase (cache) + Stripe |
| Card / payment details | Taking subscription payment | Stripe only — we never store or see your card number |
Lawful basis for the above: performance of our contract with you (running the service); our legitimate interests (keeping the service secure, preventing misuse, alerting our team to a new signup, and improving the product); and legal obligation (keeping records required for tax and accounting). Where we ever ask to send you marketing, that will be on the basis of your consent.
4. What we collect about callers (our users' customers)
This is the data where the tradesperson is the controller and we are the processor (section 2). We process it only on the tradesperson's instruction.
| Data | Why it exists | Where it lives |
|---|---|---|
| Caller phone number | Identify the lead and send the text-back | Supabase, Twilio |
| SMS content (both directions) | The conversation thread between caller and tradesperson | Supabase, Twilio |
| Call timestamps / missed-call records | Create the lead; decide whether to text; audit log | Supabase, Twilio |
| "Do not text" / known-contact (suppression) list | So known contacts are never auto-texted | Supabase |
| Quote details (customer name, phone, job description) | The quote the tradesperson prepares | Supabase |
Lawful basis: determined by the tradesperson as controller. QuoteSnap processes this data only as a processor under Article 28 UK GDPR, acting on the tradesperson's documented instructions to provide the service they asked for.
5. How the AI quote features use what you type or dictate
When a tradesperson generates a quote:
- The typed job description is sent to Anthropic (Claude), which turns it into a structured list of materials. It is not used to set prices.
- If the job is dictated by voice, the audio recording is sent to OpenAI (Whisper) to convert it to text.
If a tradesperson types a customer's name, address or other details into a job description, that text is included in what is sent to these providers. Both are based in the United States (see sections 6 and 7). That content is sent only to produce your result and is handled under each provider's own business terms; the text you generate is then stored as part of your saved quote (see section 8 for how long we keep it).
6. Sub-processors
We use the following third parties to run QuoteSnap. Each processes personal data only to provide their service to us.
| Sub-processor | What it does | Data location |
|---|---|---|
| Supabase | Database, login/authentication, file storage (logos) | EU — Ireland (AWS eu-west-1) |
| Twilio | Voice calls and SMS (the text-back) | United States (Twilio US1) — see section 7 |
| Stripe | Subscription billing and card processing | United States / global; card data handled entirely by Stripe |
| Anthropic (Claude) | Turns a typed job description into structured materials | United States |
| OpenAI (Whisper) | Transcribes dictated voice notes to text | United States |
| Vercel | Website and application hosting. Also Vercel Web Analytics (page-view counts) — but only if you accept analytics cookies; see section 11 | Global edge network |
| Telegram | Alerts our team when you sign up or request a number (sends your business name + mobile) | Cloud messaging service |
| Meta Platforms (Facebook/Instagram advertising) | The Meta pixel — measures which of our adverts led to a visit or a signup. Loaded only if you accept advertising cookies; see section 11 | United States / global |
| PostHog | Server-side product analytics — records product events (e.g. signup, quote saved, subscribed) keyed to your business id. No browser tracking script, no analytics cookies. | EU cloud (eu.i.posthog.com) |
We keep this list current and update it whenever a provider changes.
7. International data transfers
Some of our sub-processors are outside the UK — in particular Twilio processes call and SMS data in the United States (US1 region), OpenAI and Anthropic process AI inputs in the United States, and Meta processes advertising-pixel data in the United States if you have accepted advertising cookies. This means personal data (including a UK caller's phone number and message content) is transferred to the US.
Where data leaves the UK, we rely on appropriate safeguards — the UK International Data Transfer Agreement / Addendum (or the EU Standard Contractual Clauses) as offered by each provider under their published data-processing terms.
8. How long we keep data
We keep personal data only as long as we need it for the purposes above:
| Data | Retention |
|---|---|
| Tradesperson account data | For the life of your account; deleted within 60 days of account closure |
| Leads, messages, call events (caller data) | 24 months, then deleted (or sooner if the tradesperson deletes them) |
| Quotes | 24 months — you can download and keep your own copies of any quote at any time |
| Billing records | Kept as long as required by law for tax and accounting (currently 6 years) |
When you close or cancel your account we delete your data within 60 days, except billing records we are legally required to retain. You can export any quotes or lead data you want to keep before you close your account.
9. Your rights
Under UK GDPR you have the right to: access a copy of your data; rectification of inaccurate data; erasure; restriction of processing; data portability; and to object to certain processing.
- If you are a tradesperson (our user): email hello@getquotesnap.co.uk and we will respond within one month.
- If you are a caller (our user's customer): the tradesperson you contacted is the data controller for your data, so please raise your request with them. If you're not sure who that is, or you contact us first, we will help by passing your request to the relevant tradesperson and assisting them to action it — but the decision is theirs as controller.
10. The auto-text: texting people who called a business
This is the most important part of QuoteSnap to be open about, so we'll be plain:
- The text-back is sent on the tradesperson's instruction, automatically, in direct response to that person having just called the tradesperson's business. It is a reply to an enquiry, not marketing.
- The tradesperson is responsible for their contact / suppression list — numbers on it are never auto-texted — and for only using QuoteSnap for genuine missed-call responses, not marketing or spam. Our Terms require this.
- Every recipient can opt out: a caller can ask not to be texted again, and the tradesperson can add them to the "do not text" list so QuoteSnap never messages that number again.
11. Cookies and similar technologies
Cookies and scripts on QuoteSnap are grouped into three categories, and you choose them one category at a time. A banner asks on your first visit; your answer is stored for 12 months, so you are not asked again on every visit, and you can change it at any time using the Cookie settings link in the footer of any page — or open your cookie settings now.
a) Strictly necessary — always on. The login/session cookies used by our
authentication provider (Supabase), which keep you signed in and keep your
session secure, and the small cookie that remembers your cookie choice itself
(qs_consent). Under UK PECR these do not require consent, because the service
cannot work without them — you could not stay logged in, and without the second
one we would have to ask you the same question on every page.
b) Analytics — off unless you accept. We use Vercel Web Analytics to count page views and visits, so we can see which pages of the site are worth the work. It is used for that and nothing else: no advertising, no profiles, nothing sold on. The script is not loaded at all unless you accept the analytics category — if you reject it, or simply ignore the banner, it is never requested. If you accept and later change your mind, switching it off stops it from that point on.
c) Advertising — off unless you accept. We use the Meta (Facebook) pixel, so that when we advertise on Facebook or Instagram we can tell which adverts actually led someone to the site. It records that a page was viewed, and Meta may connect that to a Facebook or Instagram account. It is not loaded at all unless you accept the advertising category — if you reject it, or simply ignore the banner, nothing is requested from Meta and nothing is sent to them. If you accept and later change your mind, switching it off stops it from that point on.
The pixel records page views, and the fact that an account was created — so we can tell which adverts led to real signups rather than just clicks. That second event carries no personal details: not your name, email, phone number or business, only that a registration happened. Nothing is recorded about subscribing or paying; if we ever add that, we will say so here first.
Meta is listed in the sub-processor table in section 6, and this section is updated before anything new is added to this category.
How the banner behaves, because this is the part that is easy to get wrong: Reject all is the same size, in the same place and one tap, exactly like Accept all; nothing optional is pre-ticked; and it is not a cookie wall — it blocks nothing, and you can read and use the whole site without answering it.
When you subscribe, payment is taken on Stripe's own secure pages (you leave our site), so any cookies Stripe sets are set on Stripe's domain under Stripe's own policy, not ours.
Our product analytics (PostHog, section 6) is a separate thing and is not a browser cookie: it runs on our servers and records product events such as a signup or a saved quote, keyed to your business, with no tracking script in your browser.
12. Changes to this policy
If we make material changes we will update this page and the "last updated" date below, and notify account holders by email before the change takes effect.
13. Complaints
You can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO) — ico.org.uk — though we'd appreciate the chance to help first.
Last updated: 28 August 2026.