Privacy Policy
Last updated: September 2, 2026
Plain-English Summary
QuoteMate is made by Hansen Dev. To run the app we store your account, business details, customers, quotes, invoices and photos in the cloud (Google Firebase), and we pass job details to a handful of services that generate quotes, send emails and take payments. We never sell your data and we never use it for advertising. This policy sets out exactly what we collect, who touches it and how you can delete it. It is written to meet the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Privacy Policy Summary
Your data, your business
Your quotes, customers and job details belong to you. We use them to run the app for you and for nothing else.
Stored securely in the cloud (Firebase)
Your account data lives in Google Firebase, encrypted in transit and at rest, so it syncs between your devices and survives a lost phone.
Never sold
We do not sell, rent or trade your data, and we do not use it for advertising. It only goes to the services listed in this policy.
Delete any time
Delete your account from Settings, disconnect any integration with one tap, or ask us to erase everything we hold about you.
1. Information We Collect
We collect the information you give us to run your quoting, plus a small amount of technical data needed to keep the app working. Nothing in this section is collected without you signing in.
Account information
- •Your email address and display name, and which sign-in method you used (email and password, Google, or Apple). Sign-in is handled by Firebase Authentication. If you use a password, Firebase stores it in hashed form; we never see it.
- •Your subscription status and trial dates, and where you subscribed (web, App Store or Google Play). We do not hold your card number; see Third-Party Services below.
- •Your referral code and referral earnings if you take part in the referral program.
Business information
- •Business name, ABN, trade, phone, email, address, logo and any brand images you put on your documents
- •Labour rates, markup percentages, quote and invoice numbering, and document preferences
- •Payment details you choose to print on invoices: bank account name, BSB and account number, PayID or BPAY details
Customer and job data you enter
- •Customer names, phone numbers, email addresses and job site addresses
- •Job descriptions, quotes, invoices, materials lists, prices, labour, notes, schedule dates, payments you record, and the status of each job
- •When you search for a customer, the app also looks through the contacts on your phone (with your permission) and shows matches. A phone contact only becomes part of your QuoteMate data when you add it to a quote or your customer list.
Photos, plans, documents and voice you provide
- •Site photos, plan drawings and PDF plans you attach to a job
- •Supplier price lists and invoices you photograph or upload so the app can read prices from them
- •Microphone audio while you dictate a job description or talk to Mate, the in-app assistant, and the transcripts of your Mate conversations
Device and usage data
- •Usage events (for example "quote started", "send sheet opened", "paywall viewed") with the platform they came from. These are written to your own account record, not to a third-party analytics service.
- •A push notification token, a device identifier, the platform and your timezone, if you allow notifications
- •Crash reports containing the error, a stack trace, and device, operating system and app version details
- •A log of the emails we send you and that you send through us (recipient, subject, category, delivery status, opens and clicks)
- •On the web version only, standard Google Analytics data (pages, events, browser type, approximate location from IP address)
Integration tokens
If you connect Google Calendar, Square, Xero or Reece, we store the access token or customer token that service issues to QuoteMate, together with the account or merchant identifier it belongs to. These are held server-side only and are deleted when you disconnect.
2. How We Use Your Information
- •Running the app: creating, storing and syncing your quotes, invoices, jobs, customers and settings between your devices
- •Quote generation: turning your job description, photos and plans into a materials list, quantities and prices, and powering the Mate assistant
- •Sending documents for you: emailing or texting quotes, invoices, payment links and receipts to your customers, and showing them the quote on a web page where they can accept it
- •Integrations you turn on: putting jobs in your Google Calendar, taking payments through Square, sending accepted quotes to Xero, and looking up or ordering products from Reece
- •Billing: starting, checking and cancelling your subscription
- •Keeping you informed: account and billing emails, reminders about unsent quotes and overdue invoices, and push notifications about your jobs. Marketing-style emails carry an unsubscribe link.
- •Support and improvement: answering your questions, fixing crashes, and reviewing usage events and Mate transcripts to find where quotes come out wrong and fix the cause
- •Security: rate limiting, checking payment webhooks are genuine, and detecting abuse
3. Where and How Your Data Is Stored
Google Firebase (Google Cloud)
QuoteMate stores your data in Google Firebase:
- •Firebase Authentication holds your sign-in credentials.
- •Cloud Firestore holds your business settings, customers, quotes, invoices, jobs, usage events, Mate transcripts, push tokens and integration tokens, all under a record keyed to your account.
- •Firebase Storage holds your logo, brand images, site photos and plan PDFs. These files are served from unguessable links so they can appear in the quotes, emails and PDFs you send to customers.
- •Cloud Functions run our server-side code (quote generation, email sending, payments, integrations) in the United States (us-central1).
Access rules: Firestore and Storage security rules only allow your own signed-in account to read or write the records under your account (uploading files also requires a verified email address). Our server code and the admin tools we use for support can also read them.
Encryption: all traffic between the app, our servers and the services below uses HTTPS/TLS. Google encrypts Firebase data at rest.
On your device: the app keeps a local copy of your quotes, settings and customers so it opens quickly and works with a poor signal. This copy is cleared when you sign out or delete your account. Integration tokens and our service API keys are never stored on your device.
Overseas disclosure: Google, Anthropic, OpenAI, ElevenLabs, Stripe, Sentry, Expo and Brevo are based outside Australia, mainly in the United States and Europe. By using QuoteMate you agree that the data described in this policy is processed by them there.
4. Google Calendar (optional)
QuoteMate can put your scheduled jobs into your Google Calendar. This is optional and stays off until you connect it yourself. If you never connect it, QuoteMate does not touch your Google Calendar at all.
What we ask for
When you go to Settings → Google Calendar and tap Connect, Google asks you to let QuoteMate "view and edit events on your calendars" (the https://www.googleapis.com/auth/calendar.events scope). QuoteMate asks for no other calendar permission.
What we use it for
When you schedule a job in QuoteMate, a server function creates a matching event in your primary Google Calendar. When you reschedule the job, it updates that event. When you clear the schedule, it deletes the event. Sync is one-way, from QuoteMate to your calendar. Nothing you do in Google Calendar changes anything in QuoteMate.
What we access
QuoteMate only reads back the events it created itself, so it can update or delete them later. It does not read, store or analyse any other events on your calendar.
What we store and where
So the connection keeps working without asking you to sign in every time, QuoteMate stores:
- •An OAuth refresh token for the Google account you connected
- •The email address of that Google account
- •The ID of each calendar event QuoteMate creates, so it can find that event again to update or delete it
These are stored server-side in Firestore (Google Cloud). None of it is stored on your device.
Sharing
Your Google data is never sold, shared with third parties or used for advertising. It is never used to develop, improve or train generalised artificial intelligence or machine learning models.
Disconnecting
Go to Settings → Google Calendar → Disconnect. QuoteMate calls Google's token revocation endpoint and deletes the stored refresh token. You can also remove QuoteMate's access at any time from your Google Account at https://myaccount.google.com/permissions.
QuoteMate's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
5. Third-Party Services
These are the services that receive your data, what each one receives and why. Each is bound by its own privacy policy. We do not send your data to any service not listed here.
Google Firebase and Google Cloud
Sign-in, database, file storage and our server code, as described in section 3. Receives everything in section 1.
Language-model providers: Anthropic (Claude) and Google (Gemini)
Quote generation and the Mate assistant run on Anthropic's Claude models, with Google's Gemini models used for some tasks and as a fallback when Claude is unavailable. Depending on the feature, they receive:
- •Your job description, and the site photos, plan drawings, PDF plans, supplier price lists or invoices you attach, to work out materials, quantities and prices
- •Product names, to search the web for prices from suppliers we cannot look up directly
- •Your Mate conversation, your business profile, and the customer, quote and contact details Mate needs for what you asked it to do
- •The quote or invoice details when the app drafts an email to your customer for you
All of these calls go through our servers; the providers' API keys are never on your device. The data is processed to provide the feature, subject to each provider's privacy policy and API data terms.
Voice providers: ElevenLabs, OpenAI and Google
When you talk to Mate by voice, your microphone audio streams to a voice service that transcribes it, runs the conversation and speaks the reply. Our server picks the service for each session from ElevenLabs (conversational agent), OpenAI (Realtime) or Google (Gemini Live). The service receives your voice, the conversation history and the same business, customer and quote details as text Mate. Nothing streams until you start a voice session.
Apple and Google speech recognition (dictation)
The voice-to-text button on the job description screen uses your phone's built-in speech recognition (Apple on iOS, Google on Android). Audio is handled by that platform service under its own terms; only the resulting text reaches QuoteMate.
Brevo (email delivery)
All email leaves through Brevo: account and billing emails to you, reminders, and the quotes, invoices, payment links and receipts you send to customers. Brevo receives the recipient address, subject and content, and reports delivery, bounces, opens and clicks back to us. Customer-facing emails show your business name as the sender and route replies to your email address.
Expo push service (notifications)
If you allow notifications, Expo's push service relays them to Apple and Google. It receives your push token and the notification text (for example that a quote was accepted or an invoice was paid).
Sentry (crash reporting)
When the app crashes, Sentry receives the error, a stack trace, and device, operating system and app version details. Sentry's default personal-data collection is switched off, performance tracing is off and no screen recording is used.
Stripe, Apple App Store and Google Play (subscriptions)
On the web, subscriptions are billed by Stripe. You enter card details on Stripe's own checkout; we send Stripe your QuoteMate user ID so the payment can be matched to your account, and Stripe tells us the subscription status. On iOS and Android, subscriptions are billed by Apple or Google through in-app purchase; we receive purchase receipts from them to confirm your plan. We never see your card number.
Square (optional, take payments)
If you connect your Square account (Settings → Square), Square asks you to grant QuoteMate permission to read your merchant profile and to create and read payments, including in-person payments. We then:
- •Store your Square access token, merchant ID and location ID server-side so you do not have to reconnect each time
- •Send Square the invoice number, job name and amount when you create a payment link (and, where tap to pay is enabled for your account, when you take an in-person payment). Your customer pays through Square, so their card details go to Square, not to us.
- •Record the resulting payment against the invoice in your account. QuoteMate's platform fee is deducted from the payment by Square.
- •Revoke the token with Square and delete it when you tap Disconnect
Xero (optional, accounting)
If you connect Xero (Settings → Xero), QuoteMate asks for permission to manage quotes and invoices, contacts and payments and to read your organisation settings. When a customer accepts a quote, we send Xero the quote lines and the customer's name, email, phone and job address so it can create or match the contact and create the quote in Xero. Tokens are stored server-side and are revoked with Xero and deleted when you disconnect.
Reece (optional, plumbing supplies)
If you link your Reece trade account, we store the customer token Reece issues, server-side only, and use it to search products, fetch your prices and check branch stock. Product searches send only the material name. If you place an order through the app, Reece also receives the order lines and, for delivery, the contact name and delivery address you enter. Disconnecting deletes the stored token.
Bunnings pricing
To price materials, our server looks up products on bunnings.com.au using only the product search term. No account is linked and no customer, business or quote data is sent.
Google Analytics (web version only)
The web version at quotemateapp.au/app loads Google Analytics, the same property as the marketing site. See section 8. The iOS and Android apps do not include Google Analytics or any third-party analytics SDK.
6. Device Permissions
QuoteMate asks for these permissions only when you use the feature that needs them. Every one is optional; the app keeps working without it. QuoteMate does not ask for your location.
Camera and Photo Library
Purpose: Take or pick site photos, plans, supplier price lists and invoices for a job, and capture your logo
What we do: Photos and plans you attach are uploaded to your account in Firebase Storage and, when you ask for a materials list, sent to the language-model providers in section 5. We only access the photos you pick.
Optional: You can type a job description instead
Microphone and Speech Recognition
Purpose: Dictate a job description, and talk to Mate by voice
What we do: Dictation uses your phone's speech recognition. Voice chat with Mate streams audio to the voice provider for that session (section 5). The microphone is only live while you are dictating or in a voice session.
Optional: You can type to Mate and type job descriptions instead
Contacts
Purpose: Fill in customer details from your phone's address book when you search for a customer
What we do: Contacts are read on the device to show matches. Only a contact you add to a quote or your customer list is saved to your account. We do not upload your address book.
Optional: You can type customer details in by hand
Notifications
Purpose: Tell you when a customer opens, accepts or declines a quote or pays an invoice, and remind you about expiring quotes, overdue invoices and unfinished drafts
What we do: Store a push token for your device in your account. Customer and payment events are delivered whenever notifications are on; reminders are also held back during quiet hours in your timezone and capped at one a day.
Optional: Turn notifications off in your device settings at any time
7. Data Sharing & Disclosure
We do not sell, rent or trade your data, and we do not share it with advertisers.
Your data is disclosed only:
- •To the service providers in section 5, to the extent each one needs to do its job
- •To your customers, when you send them something. A quote, invoice, receipt or payment link you send shows your business details and the document contents. If you email it through the app, it goes via Brevo; if you text or share it, it goes through your phone's messaging or share sheet. A customer who opens a quote link sees the quote on a web page and can accept it there, and we record when they open it and when they accept.
- •To integrations you connect (Google Calendar, Square, Xero, Reece), as described above, and only while they are connected
- •Where the law requires it, for example a court order or a lawful request from a regulator
- •If QuoteMate changes hands. If the business is sold or merged, your data would pass to the new owner under this policy, and we would tell you first.
Hansen Dev staff can see your data when you ask for support, when reviewing crashes, and when reviewing Mate transcripts and usage events to improve quoting accuracy.
8. Analytics, Crash Reporting & Cookies
- •Usage events (all platforms): the app records which features you use as events in your own account record in Firestore. We use them to see where people get stuck. They are not sent to an analytics company.
- •Google Analytics (web version and marketing site only): sets cookies to measure visits, sign-ups and which page brought you here. Block or clear it with your browser's cookie controls.
- •Crash reporting: Sentry, as described in section 5.
- •Email tracking: emails sent through Brevo record delivery, opens and clicks so we can see what arrives and stop sending to addresses that bounce.
- •Mate transcript review: every Mate conversation is saved under your account and we review transcripts to find where quotes go wrong. This is on by default.
- •Cookies: the iOS and Android apps use no cookies. The web version uses browser storage to keep you signed in and the Google Analytics cookies above. No advertising cookies or trackers are used in the app.
9. Data Security
What we do to protect your data:
- Encryption: HTTPS/TLS for every connection; Google encrypts stored data at rest
- Per-account access rules: Firestore and Storage rules restrict your records to your own signed-in account
- Secrets stay on the server: API keys for the language-model, voice, email and payment services, and the tokens for your integrations, live only in our Cloud Functions and Firestore, never in the app on your device
- Verified webhooks and rate limits: payment notifications from Stripe and Square are signature-checked before we act on them, and our endpoints are rate limited
- Device security: the local copy on your phone is protected by your device's own lock (PIN, password, biometrics)
No system is perfectly secure. If we become aware of a data breach that is likely to cause you serious harm, we will notify you and the OAIC as the Privacy Act requires.
10. Data Retention & Deletion
How long we keep it
We keep your data for as long as your account exists so your quotes, invoices and customer history stay available to you. Payment and subscription records are kept as long as tax and accounting law requires.
Deleting individual items
You can delete quotes, invoices, customers and photos from inside the app at any time.
Disconnecting integrations
Disconnecting Google Calendar, Square or Xero revokes the token with that service and deletes it from our servers. Disconnecting Reece deletes the stored token.
Deleting your account
Go to Settings → Account → Delete Account. This removes your sign-in straight away and clears the app's data on that device. To have the records held under your account on our servers (quotes, customers, photos, usage events, Mate transcripts, integration tokens) removed as well, contact us using the details in section 14 and we will delete them. We keep only what the law requires us to keep, such as payment records and our log of emails sent.
11. Your Rights
Under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles you can:
Access your data
Everything you have entered is visible in the app, and every quote and invoice can be exported as a PDF. Ask us for a copy of anything else we hold about you.
Correct it
Edit your business details, customers and documents in the app, or ask us to correct anything you cannot change yourself.
Delete it
Delete items in the app, delete your account, or ask us to erase your records, as set out in section 10.
Opt out of messages
Marketing and re-engagement emails carry an unsubscribe link. Push notifications can be switched off in your device settings. Account, billing and security emails still go out because the service needs them.
Manage permissions
Revoke camera, photo, microphone, contacts or notification access at any time in your device settings. The app keeps working without them.
Complain
Contact us first and we will respond within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at www.oaic.gov.au.
12. Children's Privacy
QuoteMate is a business tool for tradies and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has created an account, contact us and we will delete it.
13. Changes to This Policy
We update this policy when the app changes what it collects or who it shares with. When we do, we will:
- •Post the new policy on this page
- •Update the "Last updated" date at the top
- •Email account holders about significant changes, such as a new service that receives your data
Continuing to use QuoteMate after a change means you accept the updated policy.
14. Contact Us
If you have any questions about this privacy policy or QuoteMate's privacy practices, please contact us:
QuoteMate is an open-source project maintained by Hansen Dev. The source code is publicly available, so you can verify our privacy claims yourself.