1. Scope of this policy
This policy describes how ReplyToQuote handles information in the ReplyToQuote service, including the marketing website, the application, hosted proposal pages and vendor-request pages. Where a customer uses ReplyToQuote to process information about their own customers or vendors, that customer decides what to upload and share; we process it on their behalf.
2. Information you provide
We process what you enter or upload: proposals and their contents, messages, questions, responses, notes, project records, files and form submissions such as contact requests.
3. Account and company information
Name, work email address, password credentials handled by our authentication provider, job title where given, company name, workspace membership and role.
4. Proposal, quote, project and work-order documents
Uploaded PDFs and generated proposals, line items, amounts, scope, schedules, terms, revisions and related project records. Files are kept in private storage and reached through short-lived authorized links.
5. Recipient and vendor invitation information
Names, email addresses and company names of the recipients, vendors and collaborators a user invites, together with invitation status, verification state and the secure link records needed to control access.
6. Proposal activity and engagement information
When someone opens a tracked proposal or vendor request, we may record activity such as the time of access, link and page activity, coarse browser and device information, email opens and clicks where a message was sent, and events such as questions, change requests and recorded decisions.
This information may be shown to the organization that sent the proposal or vendor request. We do not always know the verified identity of the person using a forwarded link; where the identity is not verified, the activity is presented as an additional or unidentified session and never as a positively identified person. Raw IP addresses are not shown to proposal senders.
7. Device, browser, IP address and log information
Our infrastructure providers process IP addresses, user-agent strings, request paths and timestamps to deliver pages, prevent abuse and diagnose faults. We use this for security, reliability and filtering automated traffic out of activity records.
8. Payment and subscription information
No payment provider is connected today, so we do not collect payment card details. When billing is enabled, payments will be processed by a payment provider (none is connected today) and we will hold only subscription status and billing records, not full card numbers.
9. Support and communication records
Contact form submissions, support correspondence, privacy requests and delivery records for the emails we send you.
11. How information is used
- to provide proposal, buyer-workspace and vendor-request features;
- to authenticate users and enforce workspace and project permissions;
- to deliver transactional email such as proposal links, responses, reminders and security messages;
- to produce the activity and decision records the participants rely on;
- to prevent abuse, detect automated traffic and keep the service secure;
- to provide support and respond to requests;
- to meet legal, tax and accounting obligations.
13. Service providers and subprocessors
These providers process information so that the service can operate:
- Edge application hosting (Cloudflare network) — Application hosting and content delivery.
- PostgreSQL database and object storage — Database, authentication and document storage.
- Transactional email service (sending domain notify.replytoquote.com) — Delivery of transactional email such as proposal links and notifications.
- a payment provider (none is connected today) — Subscription billing. No payment provider is connected yet, so no payment data is processed.
This list is kept current as providers change.
14. Information shared by users with project participants
Proposals, questions, decisions and project records are visible to the workspace members, invited collaborators and intended recipients involved in that proposal or project. Vendors invited to the same project do not see each other’s submissions. A participant’s email address is only revealed to other participants in the same proposal, project or request.
15. Data retention
We keep information while the account is active and while it is needed to provide the service, maintain accurate records for the participants, resolve disputes and meet legal obligations. When it is no longer needed we delete or anonymize it. Deleted items may persist for a short period in system copies held by our infrastructure providers.
16. Security practices
ReplyToQuote uses third-party infrastructure providers to store and process information. We use administrative, technical and organizational safeguards designed to protect stored and transmitted data. Additional information about relevant security practices may be made available where appropriate. See the Security page.
17. Your choices and privacy rights
Depending on where you live you may have rights to access, correct, delete, export, restrict or object to the processing of your personal information, and to withdraw consent. You can also adjust optional email notifications in your account settings; transactional messages about security, decisions, vendor invitations and deadlines are always sent. We do not discriminate against anyone for exercising a privacy right.
18. Account deletion and data requests
Send access, correction, deletion, export, restriction or objection requests to privacy@replytoquote.com or through the contact form using the “Privacy request” topic. Each request is recorded internally and tracked to completion. We verify that you control the account before we act, and we deliver exports through a secure authenticated channel rather than as an unprotected email attachment. If you are a recipient or vendor and want your details removed, contact the organization that invited you, or write to us and we will assist.
19. International data transfers
Our infrastructure providers operate globally, so information may be processed in countries other than your own. Where transfers of personal information out of your region require a safeguard, we rely on the mechanisms our providers make available. The applicable regions and mechanisms are being confirmed with each provider.
20. Children’s privacy
ReplyToQuote is a business tool that is not directed to children and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has provided information, contact us and we will delete it.
21. Changes to this policy
We may update this policy. Each version carries a date and version identifier, and we notify account holders of material changes before they take effect.
22. Contact information
ReplyToQuote, our registered business address, available on request. Privacy enquiries: privacy@replytoquote.com.
Questions about this document
Write to support@replytoquote.com or use the contact form. Legal notices should be sent to ReplyToQuote at our registered business address, available on request.
