TidyQuote

Privacy Policy

Effective: September 24, 2026

This policy explains what data the TidyQuote app (“the app”), the quote approval pages and this website process, why, and for how long. The service is operated by Eric Z (“we”). Contact: candy66861@gmail.com.

In short: there is no account and no sign-up. Your clients, price lists, costs and photos stay on your iPhone. We only receive a copy of a quote when you choose to send it as an approval link. We do not track you across apps or websites, we do not show ads, and we do not sell personal information.

1. Data that stays on your device

Everything you enter — client names, phone numbers, email and street addresses, property details, photos, price lists, wages and other costs, profit figures, notes and drafts — is stored only on your device, in the app's local database. Automatic backups are saved on the device and, if you turn it on, in a folder of your own iCloud Drive (handled by Apple under its terms). We cannot see this data.

PDFs, images and text you export are shared only through the share sheet to the apps you pick (for example Messages, Mail or WhatsApp).

2. Approval links (only when you create one)

When you send a quote as an approval link, the app uploads a snapshot of that quote so your client can open it in a browser:

Not uploaded: photos, your clients' phone numbers and email addresses, your internal costs and profit, and the reasons you changed a price.

To manage your links the app registers an anonymous installation ID and a secret key (we store only a hash of the key). No name, email or Apple ID is involved.

3. Data your client enters on the approval page

If your client approves, requests changes or declines, we store what they enter: their name, handwritten signature (as a vector drawing), selected optional items, messages and, for change requests, optional contact details, together with the time. To count views and prevent abuse we store a daily salted hash of the IP address and browser type — never the raw IP address. The approval page sets no cookies and loads no third-party scripts.

For this client data, you (the cleaning business) are the controller and we act as your processor: we process it only to show the quote, record the response and send the status back to your app. Clients who want to exercise their rights should contact the business that sent the quote; we will help that business respond.

4. Anonymous usage data

The app sends anonymous usage events (for example “quote created”, “quote sent by link”, “paywall viewed”) with a random device identifier generated by the app, app and iOS version, device model, language and region. Events never contain client names, addresses, free text or exact amounts — amounts and differences are only sent as ranges. We use them to understand which features work and to fix problems.

You can turn this off at any time in Settings → Privacy → “Send anonymous usage data”. In the EU/EEA, the UK and Switzerland it is off until you agree on first launch.

5. Diagnostics and support

The app keeps technical logs on your device (they do not contain client data, amounts or credentials). If you contact support, we may ask the app to upload the logs from a specific time window, identified by the anonymous device ID; they are deleted after 7 days.

If you send feedback in the app, we receive your message, optional contact details you choose to give, the app and iOS version, device model, language and a few technical values, and we give you a ticket number. If you attach diagnostics while anonymous usage data is on, the ticket also carries the app's random device identifier so we can fetch the matching logs.

Crash reports: the app uses Firebase Crashlytics (Google LLC, USA) as our processor. If the app crashes, it sends a crash report — stack trace, app and iOS version, device model, free disk space and memory state, and a random Crashlytics installation ID — the next time it starts. Crash reports contain no client data, amounts or free text, are not linked to your identity, and are kept for 90 days.

6. Purchases

Purchases and subscriptions are processed by Apple. We do not receive your payment details, name or Apple ID. The app checks your purchase status on the device using Apple's StoreKit. When a purchase succeeds, the anonymous usage data (section 4, if it is on) includes a purchase event: which product (lifetime, monthly or yearly), whether it started a free trial, the screen it was bought from and the App Store country — never your Apple ID, payment details or amounts, and not linked to you.

7. Where data is stored and who processes it

Server data (approval links, client responses, feedback, usage events, logs) is stored in a database operated by Cloudflare, Inc. (USA) on our behalf (Cloudflare Workers and D1), and may be processed in data centers outside your country. Cloudflare acts as our processor under its data processing terms, including the EU Standard Contractual Clauses. We use no other processors for this data; crash reports are processed by Google as described in section 5.

We do not sell or share personal information for cross-context behavioral advertising, and we do not use data for tracking as defined by Apple.

8. How long we keep data

DataRetention
Quote snapshot and client responsesUntil 60 days after the quote's validity date (the link then expires), then deleted 120 days later — or earlier when you revoke the link or delete your server data
Logo and stamp imagesDeleted 24 hours after no active link uses them
Anonymous installation recordUntil you delete your server data in the app
Feedback tickets180 days after the ticket is closed — or at once when you delete your server data (tickets sent after the app first created a link; for older ones, write to us)
Usage eventsDetails 90 days; daily totals (no identifiers) 400 days
Uploaded diagnostic logs7 days

9. Your choices and rights

Depending on where you live (for example under the GDPR/UK GDPR, the California CCPA/CPRA, Japan's APPI or Korea's PIPA) you may have the right to access, correct, delete or port your data, to restrict or object to processing, and to complain to a data protection authority. Because we do not know who you are, we may need your installation ID (Settings → Help) to find your data. Write to candy66861@gmail.com; we answer within 30 days.

Legal bases (GDPR): performance of a contract for approval links and support; legitimate interests for security, abuse prevention and aggregated counts; consent for anonymous usage data where required.

10. Children

TidyQuote is a business tool and is not directed at children. We do not knowingly collect data from children under 16.

11. Changes

If we change this policy, we will post the new version here with a new effective date and, for significant changes, tell you in the app.

12. Contact

Eric Z · candy66861@gmail.com