Privacy
Privacy Policy
Requotable sends follow-up messages to a contractor's past customers, in that contractor's name. If you received one of those messages, the contractor holds your information — we handle it for them.
This policy describes what the software actually does. Where something is manual, or not built yet, it says so.
- Effective
- July 26, 2026
- Version
- 2026-07-26
01Our role
Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the contractor who hires Requotable is the organization accountable for the personal information of their past customers. In the language used elsewhere, they are the controller. Requotable is a processor: we hold and use that information only to carry out the contractor's instructions.
That distinction matters to you. If you are one of those past customers, you never signed up for Requotable and have no account with us. Your relationship is with the contractor who quoted your job. They are responsible for having a lawful basis to contact you — under CASL, that normally means you personally requested a quote from them. We provide the tooling and require them to warrant that basis in writing (see our Data Processing Agreement), but we do not independently verify how each contact was obtained.
You can raise a request with either of us. We will act on the parts we can act on directly — an opt-out, above all — and pass the rest to the contractor.
02What we process
Contractor business information
For each contractor using the service we store their business name, trade, service area, the email address messages are sent from, an SMS number if they use the SMS channel, a business mailing address and contact phone number (both are printed in the footer of every email — CASL requires it), free-text instructions they want reflected in their messages, and a hashed password for their dashboard login. This is business contact information, not consumer data.
Past-customer information, held for the contractor
The contractor uploads their backlog of unsold quotes as a spreadsheet. For each person on that list we store exactly these fields:
| Field | What it is |
|---|---|
first_name | First name only. We do not store surnames. |
email | Email address, if the contractor has one. |
phone | Phone number, if the contractor has one. |
project_description | The work that was quoted, as the contractor described it. |
quoted_price | The dollar amount quoted. |
quote_date | The date the quote was given. |
status | Where the follow-up stands: not contacted, contacted, in conversation, interested, question, booked, not interested, or opted out. |
opted_out | Whether this person has asked us to stop. |
bounced | Set when mail to the address hard-bounces, so we never try again. |
auto_paused, auto_paused_reason | Set automatically when a conversation trips a safety limit (for example, an auto-responder loop). |
created_at, last_message_at, opening_drafted_at | Timestamps used to pace sending and prevent duplicate messages. |
Messages
We store the full content of every message exchanged— both the messages sent on the contractor's behalf and every reply received — along with the channel (email or SMS), direction, timestamps, delivery status, the provider's message ID, any delivery error, and a one-word classification the model assigns to each reply (for example interested or question_for_contractor) so the contractor knows which conversations need them.
Opt-out records
When someone opts out, we store a normalized form of the email address or phone number they opted out with, plus a short reason (for example, the keyword that triggered it). This is a suppression list. It is deliberately kept separate from the lead record so that suppression survives even if everything else about that person is deleted.
System logs
The dashboard keeps an operational event log — send failures, opt-out events, batch summaries. Log entries reference the contractor and lead involved and can contain a first name or an email address inside the error text. We do not use these logs for anything except operating and debugging the service.
03What we use it for
Past-customer data is used for one purpose only: delivering follow-up messages about that person's own quote, on behalf of the one contractor who uploaded them, and handing any reply back to that contractor. Specifically, we use it to write the message, send it, receive the reply, decide whether the reply is an opt-out, and show the contractor the state of their pipeline.
- We never sell it. There is no data sale, brokerage, or advertising business here of any kind.
- We never share it between contractors.Each contractor's portal only ever queries records belonging to their own account. One exception, described below, works in your favour.
- We do not use it to train AI models.Message text is sent to Google's Gemini API to generate the wording of a reply, on the paid API tier, whose terms do not permit Google to use submitted content to improve its models. We do not train, fine-tune, or build any model of our own on customer data.
- No profiling or scoring beyond the conversation. The only automated judgement made is classifying a reply so the contractor knows whether to call you back. No decision with a legal or similarly significant effect is made automatically.
04Who else touches it
We use the following service providers (sub-processors) to run Requotable. Each is bound by its own terms to process data only as instructed.
| Provider | What it does | Data involved | Where |
|---|---|---|---|
| Supabase | Database. Stores every record described above. | All contractor and customer data. | United States (AWS us-east-1) |
| Vercel | Hosting for the website and the dashboard. Data passes through in transit. | Anything sent to or rendered by the app; request logs. | United States |
| Resend | Sends outbound email and receives replies. | Customer email address, message content, delivery events. | United States (us-east-1) |
| Twilio | Sends and receives SMS. Not yet in use — no contractor is on the SMS channel today. | Customer phone number, message content. | United States |
| Google (Gemini API) | Generates the text of each message. | Customer first name, project description, quoted amount, quote date, and the content of the conversation so far. No email address or phone number is sent. | United States |
We will update this list before adding a new sub-processor, and notify contractors as described in the DPA.
05How long we keep it
Lead and message data is kept for as long as the contractor's account is active. There is no automatic expiry: a quote uploaded today is still in the database a year from now unless someone deletes it.
When a contractor cancels, or asks us to delete their data, we delete their leads, messages and logs within 30 days of the request or the end of the service, whichever is later. On request before that point, we will export their data to them first.
Two things are kept longer, on purpose:
- Opt-out records are kept indefinitely. A suppression list only works if it outlives the data it suppresses. If we deleted your opt-out, a later re-upload of the same list would start messaging you again. We keep the minimum needed to recognise you: the normalized contact detail and a short reason.
- Backups.Deleted records may persist in our provider's encrypted backups for a short period before those backups age out. They are not restored into service except in a disaster.
Separately, campaigns will not message anyone whose quote is more than 180 days old. That is a CASL consent limit rather than a retention limit — the record still exists; we just will not contact you.
06Your rights under PIPEDA
You have the right to:
- Access — ask what personal information we hold about you and how it has been used and disclosed.
- Correction — have inaccurate or incomplete information corrected.
- Withdraw consent — tell us to stop contacting you, at any time, subject to legal or contractual restrictions and reasonable notice.
- Deletion — ask that your information be deleted. We honour this except for the opt-out record itself, which we keep so that the suppression continues to work.
- Complain — to us, to the contractor, or to the Office of the Privacy Commissioner of Canada.
Email hello@requotable.ai. We will acknowledge within 5 business days and respond substantively within 30 days, the timeframe PIPEDA sets for access requests. Tell us the email address or phone number the message came to; that is how the records are keyed.
Because we are the processor and not the accountable organization, an access, correction or deletion request is normally carried out on the contractor's instruction, and we will tell you which contractor holds your information so you can go to them directly. Two exceptions where we act immediately and without waiting for anyone: opt-out requests, and anything where waiting would leave you being messaged.
07Stopping messages
Any of these works, and none of them requires an account or a login:
- Reply STOPto any email or text. Replies are checked for opt-out language before anything else happens, and a wide range of phrasings is recognised — “unsubscribe”, “remove me”, “take me off”, “stop emailing me”, “don't contact me”, and others.
- Click the unsubscribe link in the footer of any email. It is one click, needs no login, and does not expire.
- Use your mail client's unsubscribe button. Every email carries the standard one-click unsubscribe headers.
- Email hello@requotable.ai and we will do it for you.
Opt-out takes effect immediately. Every send checks the suppression list first, and if that check cannot be completed for any reason the message is not sent. Anything already queued for you but not yet sent is cancelled.
08How we protect it
These are the measures actually in place today, not a wish list:
- Encryption in transit. All traffic to the website, the dashboard, and every provider we call runs over TLS.
- Encryption at rest. The database is encrypted at rest by our hosting provider.
- No direct database access from the browser. Row-level security is enabled on every table with no access policies at all, so the only credential that can read or write anything is a server-side service key that never leaves our backend.
- Authenticated access, scoped per contractor.Both the admin dashboard and the contractor portal require a login. Sessions are carried in a signed, HTTP-only cookie. A contractor session can only reach the portal, and every portal query is filtered to that contractor's own records. Every privileged action re-checks the caller's role on the server rather than trusting the page they came from.
- Hashed passwords. Contractor portal passwords are stored as scrypt hashes, never in plain text. Login attempts are rate-limited.
- Verified webhooks.Inbound email and SMS webhooks are rejected unless the provider's cryptographic signature checks out, so a stranger cannot inject a fake reply.
- Fail-closed sending. Sending stops rather than proceeding when a safety check cannot be completed, and there is a kill switch that halts an in-progress campaign.
- Credential hygiene.No API keys or secrets are stored in our source code; they live in the hosting platform's encrypted environment configuration. Access to the production database and those keys is limited to Requotable's operator.
Requotable is a very small operation. We have not undergone a SOC 2 or ISO 27001 audit, and we do not claim to have. What we have is a small attack surface, a short list of providers, and controls we can point at in the code.
09If there is a breach
PIPEDA requires an organization to report a breach of security safeguards to the Privacy Commissioner and to affected individuals when it creates a real risk of significant harm, as soon as feasible, and to keep records of all breaches regardless of severity.
Our commitments:
- We notify the affected contractor — the accountable organization — without undue delay and in any case within 72 hours of becoming aware of a breach involving their data, with what we know: what happened, when, which data and roughly how many people, and what we are doing about it.
- We assist the contractor with their reporting and notification obligations, and we do not obstruct or delay notification to affected individuals.
- Where we are directly accountable, or where the contractor cannot be reached, we will report and notify ourselves.
- We keep a record of every breach, whether or not it is reportable.
10This website
The Requotable marketing site sets no cookies, runs no analytics, and embeds no third-party trackers. Our host keeps standard server request logs, which include IP addresses, for security and operations.
The dashboard at dashboard.requotable.ai sets two cookies for logged-in users only: a signed session cookie and a light/dark theme preference. Neither is used for tracking or advertising.
When a contractor accepts our DPA, we record who accepted it, when, the IP address it was accepted from, and which version of the document they saw. That is a business record of consent, kept for as long as the agreement matters.
11Contact and changes
Privacy questions, requests, and complaints: hello@requotable.ai. A real person reads that inbox.
If we change this policy in a way that affects how personal information is handled, we will update the effective date and the changelog below, and notify contractors. Material changes to the sub-processor list are notified in advance under the DPA.
Changelog
- July 26, 2026First published.