Legal
Privacy Policy
What personal data InstallerQuote handles, why, who else sees it, and the rights you have over it.
Version in effect from 2026-09-05.
1. Who is responsible for your data
Hyusein Rashid operates InstallerQuote. For questions about this policy or to exercise any right described below, contact privacy@installerquote.com.
This policy explains what we do with personal data. It covers our website, the installer application, and the public proposal pages we host on an installer's behalf.
2. Two different roles
Our responsibilities depend on whose data it is, and the distinction matters for your rights.
We are the controller for data about installers who register an account: the account holder's name and email address, organisation details, and records of how the account is used. We decide why and how that data is processed.
We are a processor for the data an installer enters about their own customers: names, email addresses, phone numbers, installation addresses, quotations and proposal responses. The installer is the controller for that data. We process it only on their instructions, under the Data Processing Agreement.
If you are a homeowner who received a proposal link, the installer who sent it is the controller of your data. Please direct requests to them in the first instance; their contact details appear on the proposal. We will assist them in responding.
3. What we collect
Account data. Your name and email address, verified through our authentication provider, and the organisation details you enter: company name, address, email, phone, tax number, website and logo.
Business records you create. Customer records (name, email, phone, address, notes), equipment catalogue entries, quotations, production tracking entries and quotation templates.
Proposal responses. When a homeowner accepts a proposal, the name and email address they enter, and the time of their response. When they decline, any reason they give. We also record how many times a proposal link was opened and when it was last opened.
Email delivery records. The recipient address, subject, status and provider message identifier of quotation emails sent through the Service.
Operational records. Audit entries recording who performed significant actions and when, so that account activity can be reconciled.
We do not use analytics, advertising or tracking services. There is no Google Analytics, advertising pixel, or third-party tracker on any page.
4. What we deliberately do not collect
We do not store your password. Authentication is handled by our provider and we never receive it.
We do not store visitor IP addresses in our database. An IP address is used momentarily to apply rate limits to public pages and is not written to storage by us.
We do not collect special category data (such as health or biometric data) and ask that you do not enter it.
We do not sell personal data, and we do not share it for advertising.
5. Why we process it, and on what basis
To provide the Service to you under our contract (Article 6(1)(b) GDPR): creating and running your account, storing your records, generating quotations and PDFs, and sending quotation emails at your instruction.
To keep the Service secure and working (Article 6(1)(f), our legitimate interest): authentication, rate limiting, abuse prevention, audit records, and diagnosing errors. We consider these necessary and expected, and they involve minimal data.
To meet legal obligations (Article 6(1)(c)) where accounting, tax or data protection law requires it.
Where we act as a processor for an installer's customer data, the lawful basis is the installer's to establish, not ours.
6. Who else receives it
We use a small number of sub-processors. They act on our instructions and are bound by contract:
- Cloudflare, Inc. — Application hosting, database storage (D1), and transactional email delivery. Location: United States, with processing in the EU where available.
- Clerk, Inc. — User authentication and session management for installer accounts. Location: United States.
A quotation email you send is transmitted to the recipient you choose and to the mail systems that carry it.
We may disclose data where the law requires it, or to establish or defend a legal claim. If we are involved in a merger or acquisition, data may transfer to the acquirer under this policy.
7. International transfers
Some sub-processors are established outside the European Economic Area. Where data is transferred outside the EEA, that transfer relies on the European Commission's Standard Contractual Clauses or another lawful transfer mechanism offered by that provider.
You can ask us for information about the safeguards applied to a particular transfer.
8. How long we keep it
Account and business records are kept for as long as your account is open, so that the Service works as you expect.
Quotations that have been shared as a proposal retain an immutable snapshot of what was sent. That record is deliberately preserved so that the document a customer saw can be evidenced later, and such quotations cannot be deleted while that history exists.
After an account is closed we delete or anonymise personal data within 90 days, except where we must keep records longer to meet a legal obligation or to defend a legal claim.
9. How we protect it
Each organisation's data is isolated: every query is scoped to the organisation resolved from the authenticated session, and the database enforces this through composite keys. Authorisation is checked again on the server for every request, never only in the interface.
Data is encrypted in transit, and encrypted at rest by our hosting provider. Access is restricted to the smallest number of people needed to operate the Service.
Public proposal links use a token of 32 random bytes, stored only as a cryptographic hash. We never store or log the link itself, so a stored copy of our database does not reveal working proposal links.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, you.
10. Cookies
We use only cookies that are strictly necessary to run the Service: a session cookie set by our authentication provider that keeps you signed in, and the security tokens that protect sign-in.
Because these are strictly necessary, they do not require consent under the ePrivacy Directive, and we do not show a cookie banner. We set no analytics, advertising or profiling cookies. If that ever changes we will ask for consent first.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy
- have inaccurate data corrected
- have data erased, where there is no overriding reason to keep it
- restrict or object to processing based on our legitimate interests
- receive data you gave us in a portable, machine-readable format
- withdraw consent, where processing is based on consent
To exercise any of these, email privacy@installerquote.com. We will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.
Account deletion is currently handled by request rather than through a button in the application. Email us and we will delete the account and its data, and confirm when it is done.
If you are unhappy with how we have handled your data you may complain to the Bulgarian Commission for Personal Data Protection (Комисия за защита на личните данни), or to the supervisory authority where you live or work.
12. Children
The Service is for businesses and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.
13. Changes to this policy
We may update this policy. The version date is shown at the top of this page. If a change materially affects how we use personal data we will give notice by email or in the Service before it takes effect.