Quote King← Back to home

Legal

Privacy Policy

Effective date: 22 June 2026

QuickRooms Pty Ltd

ABN: 96 697 254 710

1. About This Policy

This Privacy Policy explains how QuickRooms Pty Ltd ("we", "us", "our") collects, holds, uses and discloses personal information in connection with the Quote King platform and the Quote King Mobile application (together, the "Platform").

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in that Act. This policy is written to satisfy APP 1.

By accessing or using the Platform, you consent to the collection, use and disclosure of your information as described in this policy. If you do not agree, please do not use the Platform.

2. What Personal Information We Collect

We collect personal information only where reasonably necessary to provide the Platform. The categories of information we collect include:

2.1 Account and Identity Information

Name, email address, and hashed password (managed by our authentication provider, Clerk). This is collected when you register for an account. If you enable two-factor authentication (2FA), we store an encrypted TOTP secret associated with your account to verify your identity at sign-in.

2.2 Business Information

Business name, trading name, ABN, industry/trade type, phone number, and company logo (uploaded as an image and stored in cloud object storage). This is provided by you during onboarding or via the Settings page.

2.3 Project and Job Data

Client names, client email addresses, project names, project numbers, site addresses, scope-of-works notes (including voice recordings that you dictate — recordings are transcribed and immediately discarded; only the transcript is retained), quote line items, quantities, pricing figures, markup percentages, and any free-text notes you enter about a project.

Note: client data entered by you (e.g. your client's name and email) is stored on your behalf as a data processor. You remain the data controller for your clients' information and are responsible for ensuring you have appropriate authority to share it with us.

2.4 Client-Submitted Photos

When you send a client a photo-upload link, any photos your client submits through that link are stored in cloud object storage and associated with your job record. Photos may contain metadata (e.g. EXIF location data) embedded by the client's device. You are responsible for managing and, where required, deleting your clients' photos. We act as a data processor for client-submitted photos on your behalf.

2.5 Communications and Email Data

Sender email addresses you verify (including the verification codes we send and the time of verification), the list of verified sender addresses associated with your account, quote email templates you write, the content of quote emails sent to clients via the Platform (including scheduled sends), email delivery records logged in our email log, and any communication you send us for support purposes.

2.6 Team Member Data

If you invite colleagues or staff to your account, we collect their name, email address, assigned role, invite acceptance status, and the date the invitation was created and accepted. Invited team members must create their own account and are subject to this Privacy Policy in their own right.

2.7 Payment and Subscription Data

Subscription plan tier, subscription status, Stripe customer and subscription identifiers, seat add-on quantities (Quote Seats and Office Seats), and deposit payment records. Card details are collected directly by Stripe and are never stored on our servers. We receive confirmation of successful payment events from Stripe via webhooks.

2.8 Registration and Marketing Leads

Name, email address, business name, phone number, trade type, and any activation code you provide when expressing interest in the Platform prior to creating an account (including beta and referral programs).

2.9 Settings and Preferences

Default markup percentages, quote email templates (subject and body), sender email address preferences, notification preferences, and company branding settings saved in the Platform. On the mobile application, certain settings are stored locally on your device using AsyncStorage and are not transmitted to our servers unless you explicitly save them.

2.10 AI Features — Data Collected by The King Voice Assistant

When you use AI features (including The King voice assistant, scope extraction, floor-plan upload, dimension extraction, description generation, and audio transcription), we collect or process the following data:

  • Voice and audio recordings — audio you record via the Platform's dictation or voice-memo features. Recordings are transmitted to Google's Gemini AI API for transcription. ⚠ TODO [verify]: Confirm whether raw audio files are stored server-side after transcription, or discarded immediately. Current understanding is that audio is discarded after transcription — only the transcript is retained — but this must be verified against the actual server-side code before this policy is finalised.
  • Transcripts — the text output of audio transcription. Transcripts are stored as part of your job records.
  • Uploaded images — floor-plan images you upload to the web Control Centre for AI dimension extraction. Images are transmitted to Google's Gemini AI API for processing (vision-only prompt; the AI reads printed dimensions, never infers from scale).
  • Job and scope content — scope-of-works text, rate-card identifiers, room and opening descriptions, and other job content submitted to The King for classification, extraction, or description generation. Pricing figures, client personal information and financial data are never sent to the AI model.
  • AI usage metadata — timestamps, AI action types, endpoint names, credit weights consumed, and your IP address. This data is used to enforce monthly usage limits, detect abuse, and generate aggregated analytics. See Section 2.11 for IP address handling.

Purposes of AI data collection: to transcribe your speech; to classify voice commands and take account actions on your behalf; to extract scope items, dimensions and quantities from text or images; to generate quote content; to enforce monthly AI usage limits; and to detect and prevent abusive use of AI endpoints.

Consent: by using any voice or AI feature on the Platform, you consent to your inputs being transmitted to and processed by the third-party AI subprocessors described in section 6.1 and to the collection of AI usage metadata as described above.

Subprocessors: AI inputs are processed by the following third parties (see section 6.1 for full details):

  • Google LLC (Gemini AI) — transcription, scope extraction, dimension extraction, floor-plan reading, command classification, and description generation. Data is processed in the United States. [TODO: confirm Google's API data-retention policy and whether Google uses API inputs to train models — update this section accordingly.]
  • Replit Inc. — cloud hosting and managed AI integration proxy through which Gemini API calls are routed. Data is processed in the United States.
  • Clerk Inc. — authentication; your Clerk user ID is logged alongside AI usage events for per-user quota tracking. Data is processed in the United States.

[TODO: confirm whether any other subprocessors (e.g. third-party vector stores, logging services) receive AI inputs or usage data, and add them here if so.]

2.11 Technical and Usage Data

IP addresses (used for rate limiting and abuse prevention; not stored beyond the request), server request logs (retained for up to 30 days), session tokens, and browser or device type from standard web server logs. On the mobile application, your device may transmit standard Expo/React Native telemetry as described in Expo's privacy policy. We do not currently use cookies for advertising or cross-site tracking.

2.12 SMS Data

Where SMS notifications are enabled for your account (e.g. admin login alerts, client notifications), we pass your mobile phone number and the notification content to our SMS provider, ClickSend, for delivery. We retain a record of sent SMS notifications for operational and billing purposes.

2.13 Certifier and Inspector Contact Details

If you use the certifier email feature, we collect and store the building certifier's or inspector's name, email address, phone number, and company name that you enter in your Settings. This information is stored on our servers and is used solely to pre-populate the certifier email form and to send certifier emails on your instruction. We also store the content and delivery status of certifier emails you send through the Platform.

Note: certifier contact details are business contact information stored by you for professional communication purposes. You are responsible for ensuring you have a lawful basis to store and communicate with the nominated certifier.

2.14 Subtrade Contact Information

If you use the subtrades management feature, we collect and store the names, contact details, trade specialisations, and any notes you enter for your subcontractors and subtrade contacts. This data is stored on our servers and is accessible to authorised team members on your account. You are responsible for obtaining any consents required to store third-party contact information.

2.15 CRM Task Data

When you create tasks in the CRM task management feature, we collect and store the task type, any custom task description, the name of the team member the task is assigned to, the name of the team member who created the task, the client the task relates to (by reference to the client record), and the date the task was created and completed. Task data is visible to all team members on your account.

2.16 Variation Records

When you create and send variation documents through the Platform, we store the variation reference, title, line items, pricing figures, status (proposed, approved or declined), the client's response (if any), and the date and time of any client response. Variation approval links are token-secured and single-use.

2.17 HubSpot Sync Data

If you enable the HubSpot integration, we sync job and client data (including client names, email addresses, phone numbers, project details and quote status) between our Platform and your HubSpot account. We store HubSpot contact and deal identifiers to maintain the sync relationship. The data transmitted to HubSpot is governed by HubSpot's own privacy policy.

2.18 Call Script Data

If you create call script templates in the Platform, we store the script name, content, and associated metadata. Call scripts may contain sales or communication language you have authored and are stored on our servers accessible to your team.

2.19 Price Monitoring URLs

Web URLs you add to the price-monitoring feature so the Platform can check for changes in supplier pricing.

3. How We Collect Personal Information

We collect personal information:

  • Directly from you when you register, complete onboarding, use the Platform, or contact support;
  • From your team members when they accept an invitation and create their own account;
  • From your clients when they submit photos via a token-secured upload link you have sent them;
  • From our authentication provider (Clerk) when you sign in;
  • From Stripe when a payment or subscription event is completed;
  • From HubSpot when you enable and configure the HubSpot integration (contact and deal data);
  • Automatically via server logs and rate-limiting systems when you access the Platform.

We do not collect personal information from third parties except as described above, and we do not buy or source personal information from data brokers.

4. Why We Collect Personal Information — Purposes of Collection

We collect and use personal information to:

  • Create and manage your account and authenticate your identity (including 2FA verification);
  • Provide, operate and improve the Platform;
  • Generate quotes, scope-of-works documents, variations and deposit payment links on your behalf;
  • Send transactional emails (verification codes, team invitations, quote emails to your clients, certifier emails to nominated certifiers, variation approval links, support confirmations);
  • Schedule and dispatch future-dated quote emails at your instruction;
  • Send SMS notifications where enabled (admin alerts, client communications);
  • Facilitate team collaboration by linking invited members to your account and enabling task assignment;
  • Store and display client-submitted project photos within your job records;
  • Enable the certifier email feature: sending client details and photo links to your nominated certifier;
  • Store and manage your subtrade and subcontractor contact records;
  • Sync job and client data with HubSpot where you have enabled that integration;
  • Process subscription, seat add-on and deposit payments via Stripe;
  • Respond to your support requests;
  • Comply with our legal obligations;
  • Detect and prevent fraud, abuse and security incidents;
  • Analyse aggregated, de-identified usage patterns to improve the Platform (see section 5).

5. Aggregated Data and Analytics

We intend to use data collected on the Platform for analytical and product improvement purposes. We do not use, sell or share any individual's personal information for these purposes. Any analysis we undertake is performed on de-identified or aggregated data from which no individual can reasonably be identified.

Examples of aggregated insights we may derive include: average quote values by trade type, most common scope items, platform feature usage rates, and regional pricing trends — none of which are linked to any identifiable person or business.

6. Disclosure of Personal Information

We may disclose personal information to the following third parties, solely to enable us to provide the Platform:

6.1 Authorised Third-Party Service Providers (Our Processors)

These parties receive data from us to deliver their services on our behalf. We do not authorise them to use your data for their own purposes.

  • Clerk — identity and authentication management (United States). Stores account credentials and manages sign-in sessions. Data is encrypted in transit and at rest.
  • Stripe — payment processing for subscriptions, seat add-ons and deposit links (United States). Stripe is PCI DSS Level 1 certified. We share Stripe customer identifiers and subscription metadata.
  • Resend — transactional email delivery including quote emails, certifier emails, verification codes and team invitations (United States). Email content and recipient addresses are passed to Resend for delivery.
  • ClickSend — SMS notification delivery where enabled (Australia / United States). Phone numbers and message content are passed to ClickSend for delivery.
  • Google (Gemini AI) — AI-powered scope extraction and description generation (United States). Scope text and rate-card identifiers only; no personal or pricing data is shared.
  • Replit — cloud infrastructure, hosting and object storage for uploaded files including company logos, client-submitted project photos, and audio transcriptions (United States).

6.2 Third-Party Recipients Nominated by You

Certain Platform features transmit your clients' personal information to third parties that you nominate and control — not third-party processors we have engaged. In these cases, we act as a technical conduit only; you are the data controller for those disclosures and are solely responsible for compliance with the Privacy Act 1988 (Cth) and all other applicable laws.

  • Certifiers and Building Inspectors — when you use the certifier email feature, the Platform sends an email to the certifier email address you have configured in your Settings. That email may include your client's name, phone number, site address, project name, and a token-secured link to a gallery of the client's project photos. You must obtain your client's consent before using this feature to share their personal information with any certifier.
  • Your Clients — when you send a quote, variation approval link or photo upload link, the Platform delivers that email to the client email address you nominate. The content of those emails is authored or approved by you.

6.3 HubSpot (Where Integration Is Enabled by You)

If you enable the HubSpot CRM integration, we sync client and job data (client names, email addresses, phone numbers, project details, and quote status) with your HubSpot account. HubSpot is an independent data controller for data held in your HubSpot account. Their handling of synced data is governed by HubSpot's Privacy Policy (hubspot.com/legal/privacy-policy). We are not responsible for HubSpot's privacy practices. By enabling the HubSpot integration, you represent that you have a lawful basis to transfer your clients' data to HubSpot.

6.4 Overseas Disclosure

All third-party service providers listed in section 6.1 are based in or process data in the United States. HubSpot (where enabled) may also process data in the United States and other jurisdictions. By using the Platform you consent to the disclosure of your personal information to these overseas recipients. We take reasonable steps to ensure these recipients handle your information in a manner consistent with the APPs, however, APP 8.1 obligations to take reasonable steps to ensure overseas recipients comply with the APPs are satisfied by your consent.

6.5 Disclosure Within Your Team

Personal information visible within your account (job records, client names, quote details, CRM tasks, client notes, variation records) is accessible to all team members you have invited to your account, in accordance with their assigned role. You acknowledge and consent to this disclosure when you invite a team member.

6.6 Other Disclosures

We may also disclose personal information: (a) where required or authorised by law; (b) to enforce our Terms of Service; (c) to protect the safety of any person; or (d) in connection with a merger, acquisition or sale of our business (in which case we will notify you).

We do not sell personal information to any third party.

7. Direct Marketing

We may use your name and email address to send you information about Platform updates, new features, and offers. You may opt out of marketing communications at any time by clicking "Unsubscribe" in any marketing email or by contacting us at info@quickrooms.au. Opting out of marketing does not affect transactional emails (e.g. verification codes, team invitations, quote confirmations).

All marketing communications are sent in accordance with the Spam Act 2003 (Cth).

8. Data Retention

We retain personal information for as long as your account is active or as needed to provide the Platform. When you delete your account:

  • Account and business information is deleted within 30 days;
  • Job and project data (including client names, scope notes and quote records) is deleted within 30 days;
  • Client-submitted photos stored in object storage are deleted within 30 days of account deletion or earlier if you delete individual job records;
  • Team member invitation records associated with your account are deleted within 30 days;
  • Sender verification records are deleted within 30 days;
  • CRM task records, client notes and variation records are deleted within 30 days;
  • Certifier contact details and certifier email logs are deleted within 30 days;
  • Subtrade contact records are deleted within 30 days;
  • HubSpot sync mapping records are deleted within 30 days (data already synced to HubSpot is governed by HubSpot's retention policies);
  • Call script records are deleted within 30 days;
  • Email logs (quote emails, certifier emails, photo request emails) are retained for 12 months for operational purposes then deleted;
  • Payment records are retained for 7 years to meet Australian taxation and financial record-keeping obligations under the Corporations Act 2001 (Cth) and ATO requirements;
  • Server logs are retained for up to 30 days then deleted.

AI usage logs (ai_usage_events records — endpoint, action type, credit weight, timestamp, IP) are retained for 12 months for abuse-detection and usage-reporting purposes, then deleted.

Monthly AI credit counters (voiceQuotesUsed, aiCreditsUsed) are reset at the start of each billing cycle and do not constitute personal information.

⚠ TODO [verify]: Confirm whether raw audio recordings are stored server-side after transcription or discarded immediately. Current understanding is that audio is discarded on the server after the transcript is returned — only the transcript is retained as part of the job record. Verify this against the actual /api/transcribe and /api/extract-scope route code before finalising this policy. If audio is stored, add a specific retention period here.

Voice recordings you make via the dictation feature are transcribed in real time and immediately deleted — we do not retain audio files.

If you are a team member on another user's account and that account owner deletes their account, your own personal Quote King account is not deleted; only your access to the owner's data is removed.

9. Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Measures include:

  • Encryption in transit (TLS/HTTPS) for all Platform communications;
  • Encrypted storage for sensitive credentials including 2FA secrets;
  • Role-based access controls on all API endpoints;
  • Per-IP and per-address rate limiting on authentication and email-sending endpoints;
  • Token-based access control for client photo upload links and certifier photo gallery links (HMAC-signed, time-limited);
  • Optional two-factor authentication (TOTP) for account holders;
  • Invite tokens are single-use UUIDs consumed on acceptance;
  • Variation approval links are single-use and token-secured.

No method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security. If you become aware of a security issue, please contact us immediately at info@quickrooms.au.

10. Mobile Application

The Quote King Mobile application stores certain settings and draft data locally on your iOS device using AsyncStorage. This locally stored data is subject to Apple's device security controls and is not backed up to our servers unless you explicitly sync it. If you uninstall the app, locally stored data is permanently deleted from your device. Data you save to jobs via the mobile app is transmitted to our API and stored on our servers subject to the same retention rules described in section 8.

11. Accessing and Correcting Your Information

Under APP 12 and APP 13, you have the right to request access to the personal information we hold about you and to ask us to correct any inaccuracies. To make a request, contact us at info@quickrooms.au with the subject line "Privacy Access Request".

We will respond within 30 days. We may need to verify your identity before providing access. We will not charge a fee for making a request, though we may charge a reasonable fee to cover the cost of providing access in some circumstances.

You may update most of your account and business information directly within the Platform's Settings page at any time.

12. Complaints

If you believe we have breached the APPs or this policy, please contact us first at info@quickrooms.au so we can try to resolve the matter. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice on the Platform or emailing your registered address at least 14 days before the change takes effect. Continued use of the Platform after that date constitutes acceptance of the updated policy.

The current version of this policy is always available at quoteking.au/privacy.

14. Contact Us

For privacy-related enquiries, access requests or complaints:

QuickRooms Pty Ltd

Email: info@quickrooms.au

Website: quoteking.au

Australia