Privacy Policy
How we collect, use, and protect your personal information when you use Quote My Build.
Last updated: 24 January 2026
1. Introduction
Quote My Build ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services at quotemybuild.co.uk (the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.
2. Data Controller
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, we are the data controller. Our contact details are:
- Business Name: Quote My Build
- Location: Plymouth, Devon, United Kingdom
- Email: info@quotemybuild.co.uk
3. Information We Collect
3.1 Account Information
When you register for an account, we collect:
- Full name
- Email address
- Password (stored in encrypted form)
- Authentication provider information (if you sign in via Google or Facebook)
3.2 Company Information
When you set up a company profile, we collect:
- Company name
- Business address (address lines, city, county, postcode)
- Company logo (if uploaded)
- Brand colours and display preferences
3.3 Client Information
When you create projects for your clients, you may store:
- Client name
- Client address
- Client email address
- Client telephone and mobile numbers
Important: You are responsible for ensuring you have appropriate consent from your clients to store their personal data on our Service.
3.4 Project and Business Data
We collect data you input while using the Service, including:
- Project names, descriptions, and notes
- Quotations, invoices, and pricing information
- Schedules and calendar events
- Material prices and trade rates
- Receipt images and extracted data (supplier names, amounts, dates)
3.5 Contact Form Submissions
When you contact us via our website, we collect:
- Name and email address
- Company name and phone number (if provided)
- Your message content
- Marketing consent preferences
3.6 Technical Data
We automatically collect certain technical information when you use our Service:
- IP address
- Browser type and version
- Device information
- Pages visited and time spent
- Referring website
4. How We Use Your Information
We use your information for the following purposes:
- Service Provision: To create and manage your account, provide the quoting, invoicing, scheduling, and project management features, and deliver the Service you have requested.
- Communication: To send you service-related emails (account verification, password resets, important updates) and respond to your enquiries.
- Third-Party Integrations: To connect with Google Calendar (with your explicit consent) for schedule synchronisation.
- Document Processing: To process uploaded receipt images using optical character recognition (OCR) to extract relevant data.
- Improvement: To analyse usage patterns and improve our Service, fix bugs, and develop new features.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Security: To detect, prevent, and address technical issues, fraud, and security threats.
5. Legal Basis for Processing
Under UK GDPR, we process your personal data on the following legal bases:
- Contract: Processing necessary to perform our contract with you (providing the Service).
- Legitimate Interests: Processing necessary for our legitimate business interests (improving the Service, security, fraud prevention), where those interests are not overridden by your rights.
- Consent: Where you have given explicit consent (e.g., marketing communications, Google Calendar integration).
- Legal Obligation: Processing necessary to comply with legal obligations.
6. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
6.1 Service Providers
We use trusted third-party services to operate our platform:
- Hosting: Our servers are hosted in secure data centres.
- Email: We use email service providers to send transactional and marketing emails.
- Authentication: Google and Facebook for social login (if you choose to use these).
- Calendar Integration: Google Calendar API for schedule synchronisation.
6.2 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency).
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
7. Data Retention
We retain your personal data for as long as:
- Your account remains active
- Necessary to provide you with the Service
- Required to comply with our legal obligations
- Necessary to resolve disputes and enforce our agreements
When you delete your account, we will delete or anonymise your personal data within 30 days, except where we are required to retain it for legal, accounting, or reporting purposes.
8. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (HTTPS/TLS)
- Secure password hashing
- Regular security assessments
- Access controls limiting who can access your data
- Secure file storage for uploaded documents
However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal data, we cannot guarantee its absolute security.
9. Your Rights
Under UK GDPR, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data ("right to be forgotten").
- Restriction: Request restriction of processing in certain circumstances.
- Portability: Request transfer of your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent.
To exercise these rights, please contact us at info@quotemybuild.co.uk. We will respond within one month.
10. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Essential Cookies: Maintain your session, remember your preferences, and ensure security (CSRF protection).
- Functional Cookies: Remember your login state and settings.
You can control cookies through your browser settings. However, disabling essential cookies may prevent you from using certain features of the Service.
11. Third-Party Links
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies before providing any personal information.
12. Children's Privacy
Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
13. International Data Transfers
Your data is primarily stored and processed in the United Kingdom. If we transfer data outside the UK, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) to protect your information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
15. Complaints
If you have concerns about how we handle your personal data, please contact us first at info@quotemybuild.co.uk. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
16. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
- Email: info@quotemybuild.co.uk
- Address: Plymouth, Devon, United Kingdom