QuercusQuote
TermsSign in

PRIVACY NOTICE · VERSION 2026-09-07

Privacy notice

Effective 7 September 2026

Pre-launch notice: these documents remain subject to final solicitor review and public paid subscriptions are not yet open.

This notice explains how QuercusQuote Ltd, company number 17427337, registered in England and Wales, of 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ (“we” or “QuercusQuote”) uses personal data through our website, application, support and subscriptions. We are the controller for account, billing, website and service-administration data.

1. When we act as processor

Arborist businesses may enter information about their customers, employees, contractors and job contacts. For that Customer Data, the subscribing business is normally the controller and we act as its processor, using the data only to provide, secure and support the service and follow lawful documented instructions. Questions about Customer Data should normally be directed first to the business that entered it.

2. Information we collect

  • Account data: name, verified email address, identity-provider identifier, business name, role and authentication events.
  • Workspace data: business costs, staff and contractor labels, job addresses, specifications, quotes, notes, actual outcomes and uploaded or generated records.
  • Derived data: margins, forecasts, cost averages and other results calculated from workspace data.
  • Subscription data: plan, billing status, transaction references, tax and invoice information. Our payment provider handles full card details.
  • Product feedback: survey answers, ratings, willingness-to-pay responses and feature requests.
  • Product-usage data: sign-ins and important in-app actions such as cost setup, quote comparison, quote saving, customer-PDF creation and job review. Quote events may include rounded first-figure and calculated totals so we can measure whether the comparison is useful, but not customer names or addresses. We do not use third-party advertising trackers for these owner analytics.
  • Support data: messages, requests and information supplied while resolving a problem.
  • Technical and security data: IP address, device and browser information, request times, session records, error logs and security events.
  • Website preferences: necessary cookies and, where separately consented to, analytics or marketing preferences.

Please do not enter health, biometric, criminal-offence or other special-category information unless we have expressly agreed that use in writing.

3. How and why we use personal data

PurposeTypical lawful basis
Create accounts, authenticate users and provide subscribed featuresContract; legitimate interests where the contract is with the user’s business
Save, back up, export and delete workspace dataContract; processor instructions
Administer billing, taxation and accounting recordsContract; legal obligation
Secure the service, prevent misuse and investigate incidentsLegitimate interests; legal obligation
Respond to support requests and improve reliabilityContract; legitimate interests
Measure product use, analyse beta feedback and improve the quoting workflowLegitimate interests; consent where a particular optional technology requires it
Send essential service, legal and account messagesContract; legal obligation; legitimate interests
Send optional marketingConsent where required; otherwise legitimate interests with an opt-out

Our legitimate interests include operating a reliable B2B software service, protecting accounts, understanding service performance and improving features without overriding individual rights.

4. Calculations and automated processing

The service calculates quotes, margins, forecasts and suggestions using values supplied by users and recorded job history. These outputs support human decisions. We do not use them to make solely automated decisions about individuals that produce legal or similarly significant effects.

5. Who receives data

We use vetted providers for:

  • cloud hosting, databases, storage, backups and security;
  • identity, password recovery and multi-factor authentication;
  • subscription payments, invoices and billing administration;
  • transactional email, customer support and service monitoring; and
  • analytics or marketing only where implemented with appropriate notice and consent controls.

Our current and planned providers are listed in the Subprocessor Schedule. Providers may use data only under contract and for the relevant service. We may also disclose information where required by law, to protect rights or security, or as part of a business sale or reorganisation subject to appropriate safeguards.

6. International transfers

Some providers may process data outside the UK. Where the destination does not benefit from UK adequacy regulations, we use an appropriate safeguard such as the UK International Data Transfer Agreement, the UK Addendum to standard contractual clauses, or another lawful transfer mechanism, together with supplementary measures where needed.

7. Retention, export and deletion

  • Account and live workspace data is retained while the account is active.
  • Workspace owners can export structured data and initiate permanent deletion from the Account area.
  • Deleted live data is removed promptly; residual encrypted backups are isolated from normal use and age out through scheduled cycles, ordinarily within 90 days.
  • Billing, tax and transaction records may be retained for up to six years after the relevant financial year or longer where law requires.
  • Security logs are normally retained for up to 12 months, and support records for up to three years, unless an incident or legal claim requires longer.

We may retain minimal records of legal acceptance, account deletion, disputes and suppression preferences where needed to demonstrate compliance or respect an opt-out.

8. Security

We use encrypted connections, specialist identity services, secure session cookies, server-side workspace membership checks, tenant separation, access controls and platform-backed backups. Access is limited according to role and operational need. No online service can guarantee absolute security; users must also protect their devices and credentials.

9. Cookies

Necessary cookies support authentication, security and session continuity and do not require optional consent. If we add non-essential analytics or advertising cookies, we will explain them and request consent where required before they are set. You can change optional choices through the cookie controls when available.

Our current owner analytics are recorded on our own service when an authenticated user completes a small set of important product actions. They do not depend on advertising cookies or cross-site tracking.

10. Your rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or objection, and may withdraw consent at any time where consent is the basis. These rights can be limited by law and by our role as processor. Contact privacy@quercusquote.app. We may need to verify your identity.

You may complain to the UK Information Commissioner’s Office at ico.org.uk, but we would appreciate the opportunity to address the concern first.

11. Children

The service is for business users aged 18 or over and is not directed to children.

12. Changes and contact

We may update this notice as the product, providers or law changes. Material changes will be communicated through the service or by email. Privacy questions may be sent to privacy@quercusquote.app or by post to 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

QuercusQuote Ltd · Company 17427337 · Registered in England and WalesRegistered office: 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ
TermsPrivacySecurityContact