Skip to content

Legal

Privacy policy

Last updated 9 August 2026

Quotely is an independent product built and operated by Minhaz. This page explains, in plain language, what the service stores about you and your clients, why it stores it, and how to get it removed.

Information collected

Quotely collects only what the product needs to work.

  • Account details. Your name, email address, business name, and a hashed password. Passwords are never stored in readable form.
  • Business data you enter. Customers, price book items, pricing rules, quote templates, and the quotes you build.
  • Quote activity. When a client opens a hosted quote link, Quotely records the timestamp so the quote can move from Sent to Viewed. That is what makes the pipeline status meaningful.
  • Technical logs. Standard server logs, including IP address, request path, and error traces, kept for security and debugging.

Quotely does not run advertising trackers, does not build behavioural profiles, and does not sell data to anyone.

How the information is used

  • To run your account and keep you signed in.
  • To build, send, and track the quotes you create.
  • To render the hosted quote page your client sees.
  • To investigate errors, abuse, and security incidents.
  • To send transactional email tied to an action you took, such as a password reset.

Client data you upload

When you add a customer to Quotely, you are the controller of that person’s information and Quotely processes it on your behalf. You are responsible for having a lawful basis to store it. Anyone holding a hosted quote link can see the quote it points to, so treat those links as confidential.

Cookies and local storage

Quotely uses a session token to keep you signed in and a stored preference for light or dark theme. Both are strictly functional. There are no analytics or marketing cookies.

Where data is stored

Application data lives in a PostgreSQL database behind the Quotely API. Access is restricted to the operator and is used only to keep the service running or to answer a support request from you. Traffic is encrypted over HTTPS.

Retention

Account and business data is kept for as long as your account is open. Delete a record in the app and it is removed from the active database. Ask for your account to be closed and the associated data is deleted within 30 days, except where a copy remains in backups until those backups roll over, or where the law requires it to be retained.

Your rights

You can request a copy of your data, correction of anything inaccurate, or deletion of your account and its contents. Most of this you can do yourself inside the app; for the rest, contact the operator and expect a reply within 30 days.

Changes to this policy

If this policy changes in a way that affects how your data is handled, the date at the top of this page is updated and material changes are announced in the app before they take effect.

Contact

Questions about privacy, or a request to export or delete your data, can be sent to hello@muhammadminhaz.dev.