Privacy Policy
Last updated: 27 February 2026
1. Who We Are
Time2Quote ("we", "us", "our") is a SaaS product operated in the United Kingdom. We provide tools that enable businesses to generate and manage customer quotes. For the purposes of UK GDPR and the Data Protection Act 2018, we are the data controller of the personal data you provide to us.
If you have any questions about this policy or how we handle your data, please contact us at privacy@time2quote.co.uk.
2. Data We Collect
We collect and process the following categories of personal data:
- Account data: your name, email address, and password (stored as a secure hash).
- Company data: your company name, address, phone number, logo, and VAT number, which you provide when setting up your profile.
- Quote data: the content of quotes you create, including client names, line items, pricing, and notes.
- Billing data: subscription status and transaction history. Payment card details are processed directly by our payment provider and are never stored by us.
- Usage data: log data, IP addresses, browser type, and pages visited, collected automatically when you use our service.
3. How We Use Your Data
We process your data on the following lawful bases:
- Contract performance: to create and manage your account, process your subscription, and provide the Time2Quote service.
- Legitimate interests: to improve our product, detect and prevent fraud, and ensure the security of our systems.
- Legal obligation: to comply with applicable UK laws, including tax and accounting obligations.
- Consent: to send you marketing communications, where you have opted in. You may withdraw consent at any time.
4. Data Sharing
We do not sell your personal data. We share your data only with trusted third-party service providers who process data on our behalf under data processing agreements, including:
- Supabase: database hosting and authentication (data stored in EU data centres).
- Lemon Squeezy: payment processing and subscription management.
- OpenAI: AI-assisted quote generation. Only quote content you submit for AI generation is shared; no account or billing data is sent.
We may also disclose data where required by law or to protect our legal rights.
5. Data Retention
We retain your account and quote data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or accounting purposes (typically 7 years for financial records under UK law).
6. Your Rights
Under UK GDPR, you have the following rights in relation to your personal data:
- Right of access: to request a copy of the data we hold about you.
- Right to rectification: to ask us to correct inaccurate data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to ask us to limit how we use your data.
- Right to data portability: to receive your data in a machine-readable format.
- Right to object: to object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, email us at privacy@time2quote.co.uk. We will respond within one calendar month. You also have the right to lodge a complaint with the UK's supervisory authority, the Information Commissioner's Office (ICO).
7. Cookies
We use strictly necessary cookies to maintain your authenticated session. We do not use third-party tracking or advertising cookies. No cookie consent banner is required for strictly necessary cookies, but you can disable cookies in your browser settings, which will prevent you from logging in to Time2Quote.
8. Security
We implement appropriate technical and organisational measures to protect your personal data, including encryption in transit (TLS), encrypted storage of passwords, and access controls limiting who within our team can access production data. In the event of a data breach that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and affected users without undue delay.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes by email or by displaying a notice within the application. Continued use of Time2Quote after the effective date of any changes constitutes your acceptance of the revised policy.