← Back to QuoteHub

Privacy Policy

Last updated: 16 September 2026

Who we are

QuoteHub is a business-management app for Australian sole traders and small trade businesses (“tradies”). It lets you manage your clients, jobs, quotes, invoices and calendar from the web app and from our native iOS and Android apps. This policy explains what information we handle, how we use it, who we share it with, and the rights you have over it.

In this policy, “you” means the tradie who holds a QuoteHub account. “Your customers” means the people and businesses you record in QuoteHub as your own clients.

The QuoteHub service is operated by Pelican Drop Studios (ABN 58 562 829 179), based in Australia. We are the entity responsible for your personal information under the Australian Privacy Act 1988 (Cth). If you have any questions about this policy or your data, or wish to access, correct or delete your information, contact us at support@quotehub.net.au and we will provide a postal address for written correspondence on request.

What data we collect

QuoteHub is a tool you use to run your business, so most of the data in it is data you enter yourself. We collect and store the following:

Account and sign-in information

Your name and email address (your email is your login identity), and a securely hashed version of your password — we never store your password in plain text. To keep your account secure we also record session and security data when you sign in, including your IP address, the browser or device user-agent, and session/verification tokens. If you ask to verify your email or reset your password, we hold short-lived tokens tied to your email until they expire.

Your business profile

The business details you set up for your quotes and invoices: your business name and owner name, ABN, licence number, contact phone, email and address, your bank account details (account name, BSB and account number) so they can be printed on invoices for payment, your business logo image, and your document templates, default rates and numbering preferences.

Your client records

The information you record about your customers, which may include their name, one or more phone numbers, email address, physical (site or billing) address, ABN, free-text notes, and additional contact people (such as a site supervisor or accounts contact, with their own name, role, phone and email). You can type these in or, on the mobile apps, import them from your phone’s contacts. Because this is information about other people, you are responsible for having a proper basis to store it in QuoteHub.

Job, quote and invoice content

The content of the work you record: titles and descriptions, job-site addresses, purchase-order numbers, schedule dates and times, line items with quantities and rates, labour/hours logs, calendar events, payments received, and free-text notes. Your quotes, jobs and invoices are linked to the relevant client record.

Photos and videos

Any photos and videos you attach to a job are stored as part of that job record in our database. Captured photos and videos are quality-reduced on your device before upload. These media files are not placed in any separate public photo store or content-delivery network.

Push-notification and device information

If you enable notifications on a mobile device, we store that device’s push-notification token, its platform (iOS or Android), your time zone and your reminder preferences, so we can send you reminders such as an upcoming-job alert or an overdue-invoice summary. The notifications themselves are written to be free of customer details (they do not show a customer name, amount or invoice number on your lock screen).

Email send records

When you email a quote or invoice to a customer, we keep a short record of the send (the recipient email address, the type of document, and a delivery reference) so we can avoid sending duplicates and help with support. We do not store the generated PDF on our servers after it is sent.

Card payment records

If you connect a Stripe account and take card payments — either with Tap to Pay on iPhone or by sending a customer a pay-now link — we store your Stripe account identifier, whether that account is able to accept charges, and, for each payment, the amount, the date, a Stripe payment reference and which invoice it belongs to.

We never receive or store your customer’s card number. With Tap to Pay on iPhone, the card is read by secure hardware in the phone and the encrypted card data goes straight to Stripe. With a pay-now link, your customer enters their card on a page hosted by Stripe. In both cases the money goes to your own Stripe account — QuoteHub never holds your funds.

Quotie AI assistant

If you use the in-app Quotie assistant, the messages you send it (and any image you attach to the conversation) are sent to our AI provider to generate a reply, along with the details of the job, quote, client or invoice you are asking about. Your conversations are stored against your account so you can come back to them, and we keep a record of the actions Quotie proposed and whether you approved them. Quotie never changes your data on its own. It can only propose a change that you approve.

Premium Quotie voice sends the reply text to OpenAI to generate spoken audio. This can include business or customer details contained in the reply. QuoteHub does not store the generated audio on its server. The free device voice reads the text on your phone. This speech feature does not send microphone recordings to OpenAI.

Device permissions and why we ask

On the mobile apps, QuoteHub asks for the following device permissions. Each is requested only when needed for the matching feature, and you can decline or later change them in your device settings. The wording below is what your device shows you:

  • Camera & microphone — “QuoteHub uses your camera to attach photos and videos to job records” and “QuoteHub uses the microphone to record audio for job site videos.”
  • Photo library — “QuoteHub accesses your photo library to attach existing photos and videos to job records,” and may save captured media back to your library.
  • Contacts — “QuoteHub uses your contacts to import client details and to save your QuoteHub clients to your phone contacts so caller ID and Contacts search work for them.” This covers both reading a contact you choose to import and writing your QuoteHub clients into your device address book (see the one-way contacts sync section below).
  • Location — “QuoteHub uses your location to fill in site addresses and estimate your driving time when notifying a client you are on the way.” We request while-using-the-app access, not continuous background tracking — see “How we handle location” below.
  • Notifications — so we can send you the job and invoice reminders you opt into. You can turn these off at any time.
  • Face ID / Touch ID / biometrics — “QuoteHub uses Face ID to protect your client and job data.” Biometrics are used to unlock the app and to protect the stored sign-in token in your device’s secure Keychain/Keystore. Your biometric data never leaves your device and is never sent to us.

Saving your clients to your phone contacts (one-way sync)

If you grant contacts access, QuoteHub can write your QuoteHub client records into your device’s address book (currently on iOS) so caller ID and Contacts search work for them. This is a one-way sync from QuoteHub to your device — it writes the client’s name (tagged “(QuoteHub)”), company name, phone numbers, an email, a postal address and a note. These contacts stay on your device.

Please note: contacts QuoteHub has written into your device address book are not automatically removed when you delete your QuoteHub account. If you want them removed, you can delete the “(QuoteHub)”-tagged contacts yourself, or contact us for help.

How we handle location

Location helps you fill in an address or estimate driving time. When you tap to use your location, your device’s coordinates are sent once to a mapping service to look up a readable address, or used to bias address suggestions toward your area. Saved site addresses may include a captured map pin so navigation returns to the correct site. We only request “while using the app” location access.

On iPhone and CarPlay, Navigate & Notify Client can send your current location and destination to Apple Maps to calculate an approximate driving time. QuoteHub receives the estimated minutes, not your current coordinates, for inclusion in the client SMS. This is a bounded, user-initiated lookup, not continuous tracking. If an estimate is unavailable, no time is guessed.

How we use your data

We use the information described above to:

  • provide the core app — storing and showing your clients, jobs, quotes, invoices and calendar;
  • create and email quote and invoice PDFs to your customers when you ask;
  • authenticate you, keep your account secure, and prevent abuse (e.g. rate-limiting sign-in attempts);
  • send the reminders and notifications you opt into;
  • look up addresses you are entering;
  • take and record the card payments you choose to accept; and
  • provide support, fix problems, and keep the service reliable;
  • if you opt in, understand which QuoteHub screens and features are useful and where people get stuck.

We do not sell your data, and we do not use your data or your customers’ data for advertising.

Optional product analytics

QuoteHub uses Google Analytics on the marketing site and web app, and Firebase Analytics in the iOS and Android apps, only after you choose “Allow analytics”. We use this to understand visits, screen views and a small set of product actions such as creating a quote or invoice. Each event identifies whether it came from the marketing site, web app, iOS app or Android app.

Analytics may process an app-instance or browser identifier, device and operating-system information, approximate location derived from the network connection, and the page or app screen visited. QuoteHub strips record IDs, public-link tokens and URL query strings before recording a screen. We do not send Google your QuoteHub account ID, name, email, phone number, customer details, job titles, notes, addresses, quote or invoice content.

Advertising identifiers and personalised advertising signals are disabled. Analytics data is not used to track you across other companies’ apps or websites. Google may process analytics data outside Australia under its own service terms. Learn more about how Google uses information from sites or apps that use its services.

Your choice is stored on this browser or device. You can change it at any time; turning analytics off also resets the native app’s analytics instance data.

Third parties and sub-processors

We use a small number of trusted service providers to run QuoteHub. They process data only to provide their service to us:

  • Railway — hosts the QuoteHub app and the database where all your data is stored. Automatic backups are enabled.
  • Resend — delivers the emails we send on your behalf, including the quote/invoice email and PDF attachment to your customer and password-reset emails to you. The recipient’s email address and the document contents are processed to deliver the message.
  • Firebase Cloud Messaging / Apple Push Notification service — deliver push notifications to your device. They receive your device push token and the (customer-detail-free) notification text.
  • Google Analytics / Firebase Analytics — if you opt in, processes the limited product usage and device information described above so we can improve QuoteHub.
  • Google Places API — powers address autocomplete and lookup. It receives the partial address text you type and, only if you have already granted location, an approximate location to bias suggestions toward your area.
  • OpenStreetMap / Nominatim — turns your device coordinates into a readable address when you use the “use my location” feature on mobile.
  • Apple Maps — receives the current location and navigation destination for iPhone/CarPlay driving-time estimates.
  • Stripe — processes the card payments you take, if you have connected a Stripe account. Stripe receives your customer’s card details directly (we never see them), the amount, and the invoice reference. Stripe is the controller of that card data and handles it under its own privacy policy.
  • OpenRouter routes your Quotie assistant messages to the AI model that answers them. It receives the conversation text, any image you attach, and the job/quote/client details relevant to your question. It does not receive your bank details or your password.
  • OpenAI generates premium Quotie speech from reply text. It receives the text being read, including any business or customer details in that reply.

Our service providers may process and store data outside Australia. Processing locations depend on each provider and the service configuration.

Subscriptions. QuoteHub does not currently charge a subscription fee. When paid plans are introduced, billing will be handled by a third-party payment processor and this policy will be updated before any subscription billing data is collected. (This is separate from the card payments you take from your own customers, which are described above and are live today.)

Data storage and security

Your data is stored in our hosted Postgres database. QuoteHub is multi-tenant: every record is tied to your account, and access is scoped so that one account cannot read or change another account’s data. Sign-in passwords are stored only as a strong one-way hash.

On the mobile apps, your sign-in token is kept in the device’s secure storage (iOS Keychain / Android Keystore) and the app can be protected with Face ID, Touch ID or your device biometric. No security measure is perfect, but we take reasonable steps to protect your information.

One feature creates a private calendar-subscription link containing a random token. Anyone who has that link can view that calendar feed without signing in, so only share it with people you trust. You can regenerate the link at any time from your settings to revoke old links.

Data retention and account deletion

We keep your data for as long as your account is active and you keep using QuoteHub. You can edit or delete individual clients, jobs, quotes, invoices and events at any time from within the app.

You can delete your entire account from Settings → Account → Delete account. For your protection you must confirm by typing your email address. Deleting your account removes your account record and the business and customer data associated with it from our database.

Please note two limitations of account deletion: (1) if you used the contacts sync, contacts QuoteHub wrote into your device’s own address book are not removed automatically — you can delete the “(QuoteHub)”-tagged contacts on your device; and (2) some minimal, non-identifying technical records (such as short-lived security/verification tokens that expire on their own) may persist briefly. Separately, if you took card payments, Stripe keeps its own transaction records under its own policy and its legal obligations — deleting your QuoteHub account does not delete those. If you would like assistance with deletion, contact us at support@quotehub.net.au.

Your privacy rights

QuoteHub is an Australian service and we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Subject to the Act, you have the right to:

  • Access the personal information we hold about you — most of it is visible to you directly in the app;
  • Correct information that is inaccurate, out of date or incomplete — you can edit most fields yourself in the app;
  • Delete your account and associated data using the in-app account-deletion flow described above; and
  • Complain if you believe we have mishandled your information.

To exercise any of these rights, or to make a privacy complaint, email us at support@quotehub.net.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

You are responsible for the customer information you store in QuoteHub. If one of your customers asks you to access, correct or delete the information you hold about them, you can do this directly within the app.

Children

QuoteHub is a tool for running a trade business and is not directed at children. We do not knowingly create accounts for, or collect personal information from, anyone under 16. If you believe a child has provided us with personal information, please contact us so we can remove it.

Changes to this policy

We may update this policy from time to time as the app evolves. When we do, we will change the “Last updated” date at the top of this page, and for significant changes we will take reasonable steps to let you know.

Contact us

If you have any questions about this Privacy Policy or how we handle your information, please contact us at support@quotehub.net.au.

QuoteHub · Last updated 16 September 2026