Privacy (draft)
Effective date: [TODO: Effective date]
This privacy notice is a draft and is not in force. It cannot be published until the operator supplies their real business details. Still missing: Legal business name, Trading name, Business address, Support email, Contact method, Governing law, Refund period (days), Refund eligibility, Digital product delivery policy, Effective date. While anything is missing, live payments are blocked by the server.
This page describes what actually happens to your data, including the parts that do involve a server. It is written to be accurate rather than reassuring.
Your quote stays in your browser unless you save it
Everything you type into the calculator — your name, business name, email, the client and campaign, notes, deliverables, rates, payment terms — is held in your browser and used there. Without an account there is no copy anywhere else.
Saved drafts and branding live in your browser's localStorage, on your device. Clearing site data removes them, and we cannot recover them for you.
Accounts, and what an account stores
An account is optional. You can calculate, save a local draft, share a link, print, preview the watermarked PDF and buy the branded export without ever signing in.
Signing in on its own uploads nothing. A quote is stored only when you press Save to account on that specific quote. There is no background sync, and an existing local draft is never uploaded because you signed in.
When you do save a quote, what is stored is:
- The quote itself: your deliverables, rates, usage-rights selections and payment terms.
- The quote metadata you filled in: your name, business name and email if you entered them, the client and campaign names, and your notes.
- The title and status you gave it, and the times it was saved.
- The identifier of the account that saved it.
What is not stored, ever: your logo, the PDF, your branding colours and header/footer text, and your card details.
Each saved quote is readable only by the account that saved it. That is enforced by the database itself, not only by our code. Deleting a quote removes it immediately and permanently — there is no backup and we cannot restore it.
Signing in
Sign-in is by one-time email link. There is no password, so there is none for us to store or for anyone to steal. Your email address is used to send that link and to identify your account, and for nothing else — we send no marketing.
Authentication and quote storage are provided by Supabase, acting as our processor, under its own privacy terms at supabase.com/privacy.
Share links
A share link encodes the quote into the part of the URL after the #. Browsers never send that portion to a web server, so opening a share link does not transmit the quote to us. Your email address is deliberately excluded from share links. Anyone you send the link to can read everything else in it, so treat it as you would the quote itself.
Your logo and PDFs
An uploaded logo is re-encoded and stored in your browser only. The PDF is drawn on your device. Neither the logo nor the PDF is uploaded.
Payments, which do involve servers
If you buy a branded export, payment is processed by Stripe. You are redirected to Stripe's hosted checkout, and your card details are entered on Stripe's systems — we never see or store them.
Our server is involved in exactly two moments, and it is honest to say so: it asks Stripe to create a checkout session, and it later asks Stripe whether a given session was paid. In those exchanges our server handles the Stripe checkout session identifier, the fixed price and currency, and three constant product labels. It does not receive your quote, your name or email, the client or campaign name, your notes, any amounts from your quote, your logo, or the PDF.
Stripe processes payment data as an independent controller under its own privacy policy at stripe.com/privacy.
What is stored on your device
- Your saved quote draft, if you choose to save one.
- Your branding: logo, accent colour, header and footer lines.
- The identifier of your most recent checkout session, so a page refresh can re-check a completed payment without charging you again. This is not a password and grants no access on its own.
- If you sign in, the session cookies that keep you signed in. Signing out removes them.
There are no analytics, no advertising pixels and no third-party trackers. We set no cookies of our own, which is why you are not being asked to accept any.
Server logs
Requests to the payment endpoints are served by our hosting provider, which keeps operational logs (such as IP address, timestamp and request path) for reliability and abuse prevention. Those logs do not contain quote content.
Who is responsible for your data
Data controller: [TODO: Legal business name], trading as [TODO: Trading name], of [TODO: Business address].
Privacy enquiries: [TODO: Support email]. How to reach us and how quickly: [TODO: Contact method].