Back to home

Legal

Privacy Policy

Effective date: August 29, 2026

This Privacy Policy explains how QuoCAD collects, uses, stores, and protects information when you use our website and services. It is written in plain language so it is easy to follow.

1. Overview

This Privacy Policy explains how QuoCAD may collect, use, store, and share information when you use our website, workbench, takeoff tools, layout tools, quote features, reports, and related services.

QuoCAD is designed for parking lot striping contractors. The information you enter may include business, customer, property, job, image, measurement, quote, and report details.

2. Information you provide

You may provide information such as your name, email address, account details, organization or company profile, job names, customer names, property names, addresses, quote settings, notes, pricing details, approval text, and support or demo request information.

You may also upload job-related images, site plans, drone or aerial imagery you are permitted to use, measurements, layouts, markings, symbols, line quantities, reports, and other project data needed to use QuoCAD features. When you upload imagery you confirm that your organization owns it or has permission to use it; we record that confirmation with your name and the date.

3. Information collected automatically

QuoCAD may collect basic technical information such as browser type, device information, app session activity, approximate usage data, diagnostics, error details, and security-related logs.

The app may use cookies, authentication tokens, local storage, IndexedDB, and similar browser storage to keep you signed in, remember preferences, store local jobs, save images, and provide core app functionality.

4. Local and cloud storage

When cloud sync is not configured or available, QuoCAD may store jobs, settings, images, and preferences locally in your browser. Local data can be affected by browser settings, device changes, clearing site data, or private browsing modes.

When cloud-backed features are configured, QuoCAD may use services such as Supabase for authentication, organization workspaces, synced jobs, snapshots, and related storage. Some workflows may use both local and cloud storage.

5. Map and satellite features

If you use satellite, map, geocoding, or location-based features, QuoCAD may send map searches, coordinates, viewport details, addresses, or related requests to third-party mapping providers.

QuoCAD does not store satellite imagery from those providers. Map imagery is requested live each time you open a job. What we save is the map view you confirmed for the job — provider, style, centre coordinates, zoom, bearing and pitch — so the same view can be shown again, together with the markings you drew.

Jobs created before August 2026 may still have a saved background image captured under the previous behaviour. Those are retained so existing work and already-sent quotes keep displaying correctly, and they are not used for new captures.

Those providers process information according to their own terms and privacy practices. You should avoid entering sensitive location or customer information into map features unless you are allowed to use it for the job.

Do not enter, upload, or ask us to process special category information — health, biometric, genetic, racial or ethnic, political, religious, trade union, sex life or sexual orientation data — criminal offence data, government identifiers such as social insurance, social security, driver's licence or passport numbers, payment card or financial account numbers, protected health information, or personal information about anyone under 18, into map searches, job notes, contact notes, or any other free-text field. QuoCAD has no feature that asks for any of it, is not designed or offered for it, and if we become aware of it we may ask you to remove it. Section 3 of our Data Processing Addendum carries the same rule and the same list.

6. How we use information

We use information to provide and improve QuoCAD, authenticate users, save jobs, generate layouts, calculate takeoffs, prepare quotes and reports, support users, maintain reliability, secure accounts, troubleshoot issues, and communicate about the service.

We may also use aggregated or de-identified information to understand product usage, improve workflows, and prioritize improvements.

7. How information is shared

We do not sell personal information, and we do not share it with advertisers or data brokers.

We share information with the service providers that operate QuoCAD: Supabase (authentication, database, file storage), Stripe (subscription billing, and card payments from your customers), Square (an alternative card processor, used only if you connect a Square account), Mapbox and Azure Maps (map imagery, and geocoding of job addresses), Resend (transactional email, including quotes and invoices you send to your customers), Vercel (hosting), Sentry (error monitoring), PostHog (product analytics — analytics in your browser runs only if you accept it, but a small number of server-side events such as account creation, sign-in and checkout are recorded regardless of that choice, because they are recorded on our servers where the browser's consent state is not readable), and Upstash (rate limiting, which receives your user identifier and IP address).

Most of those providers handle information only on our instructions and only to provide their service to us. Four of them — Stripe, Square, Mapbox and Azure Maps — also handle some data for their own purposes, as independent controllers rather than as our subprocessors; section 7a of our Data Processing Addendum explains what that means and what we can answer for.

That list is maintained on our Subprocessors page, which records what each provider receives and why. We update it when a provider is added or removed.

We may also disclose information if required by law, to protect rights and safety, to investigate misuse, to enforce our terms, or as part of a business transaction such as a merger, acquisition, or asset transfer.

7a. Who is responsible for your customers' information

QuoCAD holds two different kinds of personal information, and the responsibility for each is different.

For your own account — your name, email, workspace and billing details — we decide how the information is used. In data-protection terms we are the controller, and this policy governs it.

For the information you enter about YOUR customers — their names, phone numbers, email addresses, property addresses, notes, and the quotes and invoices you send them — you decide what is collected and why. You are the controller and we are your processor: we hold and process that information to provide QuoCAD to you, and we do not use it for our own purposes other than the operational records described in section 4a of our Data Processing Addendum, do not sell it, and do not use it to train models.

This matters if one of your customers asks to see or delete their information. We cannot answer that request for you, because it is your record and we have no way to verify who they are. Send it to us and we will help you find and remove the data — section 8 of our Data Processing Addendum sets out how much of that help is included and when we would quote for it — but the obligation and the decision are yours. Your customers should contact you, not us.

The terms governing that processor relationship are set out in full in our Data Processing Addendum.

You are responsible for having a lawful basis to enter your customers' information into QuoCAD, and for telling them how you use it — section 2 of our Data Processing Addendum sets out the confirmations you give us about that, and section 2a what happens if a claim arises.

7b. Where information is processed

QuoCAD is operated from Canada. Our providers process and store information in the United States and, depending on the provider, other countries.

If your customers are in the European Economic Area, the United Kingdom, or another region with transfer restrictions, that means information is transferred outside your region. We rely on our providers' standard contractual clauses and equivalent safeguards for those transfers. We also rely on the Standard Contractual Clauses directly between us where section 12 of our Data Processing Addendum says they apply.

The documentation of these transfers, and of everything else we do as your processor, is our Data Processing Addendum. It applies automatically when you accept the Terms of Service, so there is nothing to request; it records the transfer safeguards we rely on, our security measures, and our subprocessors. Contact us if you need a countersigned copy.

7c. People who receive the documents you send

When you send a quote or invoice from QuoCAD, the person who receives it opens a page we host. Two different things happen on that page, and they belong to two different people.

What belongs to you: the document, its contents, the record that it was opened, and the name someone types to accept a quote. You are the controller of all of it, exactly as section 7a of this policy describes, and telling that person how you use their information is your job rather than ours.

What belongs to us: we record that a page was opened or a payment attempted, and we use the visitor's IP address to rate-limit the page, block abuse, and meter our own costs. Our hosting provider keeps its own request logs, which include the browser's user agent, under its retention. We hold these as a controller, on the basis of our legitimate interest in operating the service securely, and section 9 says how long we keep them.

We do not use anything from those pages to market to the recipient, and we do not add them to any list of ours.

8. Your controls and choices

Edit or delete jobs, contacts, quotes and settings in the app at any time.

Export your workspace — Settings → Backup & data, available to owners and admins. It produces a download link valid for 24 hours containing your jobs, contacts, quotes and their revisions, invoices and their line items, payment records, workspace settings, and the record rows describing your job media and site photos. For media the export carries the metadata rows — file name, type, size, who uploaded it and when — rather than the image files themselves; ask us if you need the images and we will produce them.

Delete your account — Settings → Account → Delete my account. You will be asked to confirm your password. One thing to understand before you use it: if you are the ONLY member of your workspace, deleting your account permanently deletes the entire workspace, including every job, contact, quote, invoice and uploaded image. If your workspace has other members, we cannot delete it from under them — you will be asked to transfer ownership first, and deleting your account then removes only you.

The “request workspace removal” option under Settings → Backup & data files a request with our support team; it does not delete anything by itself. We will confirm with you before acting.

Data stored locally in your browser is removed by clearing site data or deleting the jobs in the app. Clearing local data permanently removes anything not yet synced.

Withdraw analytics consent at any time from the Cookie Policy page.

Depending on where you live, you may also have rights to access, correct, delete, or object to our use of your personal information, and to complain to a supervisory authority. Contact us and we will help. For information about YOUR customers, see section 7a of this policy — those requests belong to you, not to us.

9. Data retention

Your workspace content — jobs, contacts, quotes, invoices, snapshots and uploaded images — is kept until you delete it or until the workspace is deleted. We do not expire it on a schedule.

Deleted items are retained for at least 30 days before their underlying files are purged, so that an accidental deletion can be reversed if you ask us within that period. There is no self-service undelete: contact support as soon as you notice and we will try, but we do not guarantee that any particular item can be recovered. You can re-import a backup you exported earlier from Settings → Backup & data. Purging is a scheduled and operator-run maintenance task rather than something that happens at a fixed moment, so the interval is often longer in practice than the setting suggests. Keeping your own exports of records that matter to your business remains sensible, and we are not responsible for data that you or a member of your workspace deleted.

Export downloads expire after 24 hours; the generated file is removed afterwards.

Operational records — webhook payloads from payment processors, and email delivery events — are retained for at least 90 days and are removed by a monthly maintenance sweep after that. Each sweep is bounded, so an old row can survive a cycle. Provider delivery-event records — the bounce and complaint signals our email provider sends back — identify the recipient by a one-way hash rather than by the email address itself, so repeated failures to one mailbox can be grouped without our storing who it is. The record of who you sent a document to is part of your workspace content and is kept with it.

Request logs of the kind described in section 7c are kept only for as long as they are useful for security and abuse prevention. Rate-limiting counters are held briefly — long enough to count requests inside a window — and expire on their own. Request logs held by our hosting provider follow that provider's own retention.

Security and audit records are kept longer than ordinary content, because their purpose is to answer questions about the past: who signed in, who changed a permission, who accessed what. Your visible audit history depends on your plan; we retain the underlying records beyond that window for security and legal purposes.

Records of your acceptance of our Terms of Service, Privacy Policy and Data Processing Addendum — the accepting person, the email address used, which version was accepted, the date and time, and the IP address and browser the acceptance came from — are kept separately from your workspace and are not deleted when your account or workspace is deleted. They are what establishes the terms of our agreement with you, so we retain them on the basis of our legitimate interest in establishing, exercising and defending legal claims, for the applicable limitation period after our relationship ends. Along with the tax, accounting and audit records described in this section, they are one of the few things that deleting your account does not remove. We do not use them for any other purpose, do not share them other than with a provider that hosts them for us, and do not use them to market to you.

Records we are required to keep for tax, accounting or legal reasons — such as invoices and payment records — are retained for the period the law requires.

10. Security

Specific measures, rather than assurances:

Workspace isolation is enforced by the database itself. We require row-level security on tables carrying workspace data, keyed to an active membership, so one workspace cannot read another's rows even if application code were wrong. An automated cross-tenant isolation suite runs against a database rebuilt from scratch whenever we change the database, and a cross-tenant leak fails the build.

Traffic is encrypted in transit (HTTPS, with HSTS). Data at rest is encrypted by our database and storage provider.

Payment card numbers never reach our systems. Card entry is hosted by your payment processor — Stripe, or Square if you connect a Square account; we store only a payment reference, an amount and a receipt link.

Share links for quotes and invoices are stored as one-way hashes and expire. The link itself is never kept in our database, and a link stops working when the document it points to is voided, revised or refunded, and it can no longer take a payment once the invoice is paid.

Sign-in, permission changes, exports and administrative actions are written to an audit trail that application users cannot alter.

Requests are rate-limited, payment and email webhooks are signature-verified before processing, and the app sets a strict content security policy.

Support access to a workspace is authorised through a grant that records the reason and the scope, that expires, and that can be revoked, and every grant is written to that audit trail. To be exact about the scope of that control: it governs and records the authorisation. It is not at present a technical control that independently prevents access by a platform administrator holding no grant — we say so for the same reason we name the measures below that we do not have.

Two things we do NOT currently offer, so you can plan around them: multi-factor authentication, and customer-managed encryption keys. We also hold no formal security certification such as SOC 2 or ISO 27001.

No online service can be guaranteed completely secure. Because we do not offer multi-factor authentication, the security of your account rests on the strength and secrecy of your password and on your control of the devices and mailbox you use to reach QuoCAD. You are responsible for strong credentials, for protecting your devices, and for limiting who in your workspace can see customer, property and job information. You are responsible, as between you and us, for anything done through valid credentials of your workspace; that allocation does not change what an event is, and if unauthorised access to personal data occurs on our systems we will treat it as a personal data breach and tell you, whether or not valid credentials were used.

11. Children's privacy

QuoCAD is a business tool for contractors. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. You must be at least 18, or the age of majority where you live, to use QuoCAD.

If you believe a child has provided us information, contact us and we will delete it, other than anything we are required to keep for tax, accounting or legal reasons as described in section 9.

12. Policy updates

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date or provide notice in a reasonable way.

Continuing to use QuoCAD after an updated policy becomes effective means the updated policy applies to your use of the service.

If you need the version of this policy that applied on a particular date, contact us and we will provide it.

12a. What this policy is

This policy forms part of your agreement with us and is incorporated into our Terms of Service. It describes our practices: its operational descriptions — retention intervals, security measures, export and deletion behaviour — are descriptions of how the service works rather than warranties or guarantees, and they may change as the service changes, as section 12 explains.

Where this policy and the Terms of Service conflict, the Terms govern — except for the processing of your customers' personal data, where the Data Processing Addendum governs.

Our liability in connection with this policy is subject to the limitations in the Terms of Service, to the extent applicable law allows.

None of that reduces what the law requires us to tell you, or what it entitles you to ask of us.

13. Contact

QuoCAD is operated by Quocad Inc., of 2150 Winston Park Drive, Unit 203, Oakville, Ontario L6H 5V1, Canada. That company is the controller described in section 7a of this policy, and the processor our Data Processing Addendum names.

Questions or requests about this Privacy Policy can be sent to support@quocad.com (phone: (855) 822-7766).