Privacy Policy
Last updated 20 September 2026
This explains what Quotely collects, why, and what you can ask us to do about it. It is written to be read rather than to be defensible.
What we collect
- Your account. Name, email address, password (stored only as a hash we cannot reverse), and your business’s name, address, phone, email and tax number.
- What you create. Your customers’ names and contact details, your products and services, and your quotations, invoices and payment records.
- Payment records. Amounts, currency, status, the method reported by the provider (“upi”, “card”), and the provider’s reference.
- Technical logs. Request paths, timestamps and error details, kept to diagnose faults.
What we never collect
We never see or store card numbers, CVVs, UPI PINs or bank passwords. Card details are entered on the payment provider’s own checkout and never pass through Quotely.
Your customers’ data belongs to you
When you add a customer, that information is yours. We process it only to provide Quotely to you. We do not market to your customers, sell their details, or use them to train anything.
Why we collect it
- To run the service you signed up for — producing your documents and tracking payment.
- To take payment for your subscription.
- To keep the service secure and diagnose faults.
- To meet legal and tax obligations.
Who else sees it
- Razorpay — payment processing. Handles the payment itself; receives the amount, currency and invoice reference.
- Our hosting and database providers — they store the data on our behalf under contract and do not use it for anything else.
- Anyone you send a link to. A quotation or invoice link shows that document to whoever holds it, which is the point of sharing it.
We do not sell your data to anyone, for any purpose.
How it is protected
- Everything travels over HTTPS.
- Passwords are hashed, never stored in a readable form.
- Payment-account credentials you connect are encrypted at rest with AES-256-GCM, under a key held separately from the database.
- Each business’s data is isolated. A request can only ever reach the data belonging to the signed-in account.
- Share links use unguessable tokens, and only a hash of each token is stored.
How long we keep it
For as long as your account exists, and afterwards only where law requires — financial records are generally kept for eight years under Indian tax rules. Technical logs are kept for up to 90 days.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete your account and everything in it. Email [email protected] and we will respond within one business day and complete the request within 30 days.
Cookies
Quotely uses browser storage to keep you signed in and to remember small preferences such as a filter you last chose. We do not use advertising or cross-site tracking cookies.
Changes
If this policy changes materially, we will tell account holders by email before it takes effect. The date at the top always reflects the current version.
Contact
Quotely
Kerala
India