Cookie Policy

Effective August 13, 2026

What QuoCAD stores on your device, and which parts you control.

1. What are cookies?

Cookies are small text files stored on your device by your web browser. They allow websites to remember information about your session and preferences.

QuoCAD uses a small number of cookies. Some are required for the app to work at all; the analytics ones load only if you allow them. We use no advertising cookies, and we do not track you across other websites for advertising or behavioural marketing. Third parties we embed for the service to function — our payment provider, our map provider, and our error and product-analytics tools — set their own cookies under their own policies, which the sections below and the Subprocessors page identify.

2. Strictly necessary cookies

Session authentication — set by Supabase when you sign in. These cookies carry a secure session token that authenticates your requests. They are httpOnly and secure, and are cleared when you sign out. Your session refreshes automatically while you are active; we do not apply a separate idle timeout.

Sidebar state (sidebar_state) — remembers whether the workbench sidebar is expanded or collapsed. It stores a single true/false value and no personal data. It is set by the page rather than the server, so it is readable by scripts on our own site.

These cookies are required for QuoCAD to work and are not subject to consent. Blocking them prevents you from signing in.

3. Analytics cookies (consent required)

We use PostHog for product analytics — which features are used, and how the app performs. PostHog is served through our own domain, so its cookies and local storage entries are first-party.

PostHog does not load at all until you accept analytics in the consent banner. If you decline, it is never initialised and any previously stored PostHog data on your device is reset. You can change your mind at any time using the button below; withdrawing is as easy as granting.

One limitation, stated plainly: a small number of events are recorded on our SERVERS rather than in your browser — account creation, sign-in, and checkout. Those are not set by a cookie and are not affected by this choice, because they are part of operating and securing the account rather than analysing behaviour. They record your user and workspace identifiers, not page-by-page activity.

4. Browser storage we use besides cookies

Your cookie choice (quocad-cookie-consent) — stored in local storage so we can honour it and re-ask if this policy materially changes.

Offline job data (takeoff_jobs_v1, takeoff_contacts_v1, and related IndexedDB entries) — when cloud sync is unavailable, QuoCAD keeps jobs, contacts and images on your device so you can keep working. This can include your customers' names and contact details, so treat a shared or public computer accordingly. Clearing site data removes it permanently, including anything not yet synced.

5. What we do NOT use

No advertising cookies, no behavioural tracking for advertising, and no social-media cookies.

No Google Analytics, no Facebook Pixel, and no marketing trackers. We also do not use Vercel Analytics or Speed Insights — performance measurements go through the same consent-gated analytics as everything else.

We do not sell cookie data, and we do not share it with data brokers or advertising networks.

6. Third-party services that may set storage

Supabase — authentication and database — sets the session cookies described above.

Stripe — payment processing — may set cookies during checkout and on payment pages, including fraud prevention.

PostHog — product analytics — only after consent, as described above.

Sentry — error monitoring — records diagnostic information when something breaks. It may use browser storage to link the events of a single session.

Mapbox and Azure Maps — map and satellite imagery — may set storage when map imagery is rendered.

Vercel — hosting — may set a cookie on preview deployments. It is not used on the live site.

Each of these processes data under its own terms. A current list of every provider we use, and what each one receives, is on our Subprocessors page.

7. Managing cookies

You can change or withdraw your consent for optional cookies at any time using the button below — withdrawing is as easy as granting consent.

You can also control cookies through your browser settings. Blocking the session authentication cookie will prevent you from signing in.

For most browsers, you can find cookie controls under Settings → Privacy or Settings → Security.

Clearing cookies will sign you out of QuoCAD.

8. Changes to this policy

We may update this Cookie Policy. For a change that is not material — a clarification, a contact detail, or something the law requires — the update takes effect when we post it and update the effective date above.

For a material change that affects you adversely, we will give you at least 30 days' notice by email to the address of your workspace owner and by a notice inside the product, and the change takes effect on the date that notice states. Where the change adds a new category of optional cookie, we will re-ask for your consent rather than relying on the one you already gave.

Continuing to use QuoCAD after an updated policy takes effect means the updated policy applies to your use of the service. If you do not accept a material change, you can withdraw analytics consent, stop using QuoCAD, and close your account before it takes effect.

If you need the version of this policy that applied on a particular date, contact us and we will provide it.

9. Contact

Questions about our use of cookies can be sent to support@quocad.com.

For the full list of providers that receive data, see the Subprocessors page.