Confirm the operating legal entity, jurisdiction, retention obligations, analytics configuration, subprocessors, international transfers and final effective date.
1. Scope
This policy is intended to explain how Quoinvo handles information when people use its contractor-business application, website and related support.
2. Information the product is designed to process
- Account identity such as email, display name, provider identifiers and sign-in state.
- Business workspace details, active membership role, plan and company profile.
- Customer contact, billing and shipping information entered by the user.
- Quotes, invoices, payments, expenses, saved items, jobs, activity and document settings.
- Logos, receipts and supported work or item photos when the user uploads them.
- Subscription verification records, including a one-way hash of a Google Play purchase token rather than the raw token.
- Technical and support information needed to operate, secure and troubleshoot the service.
3. How information is used
Information is used to authenticate users, enforce business membership, provide requested application functions, generate documents, synchronize data, verify entitlements, protect the service and respond to support requests.
4. Storage and access
Operational data is organized below a business workspace in Firebase. Security rules check authenticated active membership and role. Quoinvo does not rely on hidden client configuration or a browser-only Premium flag for authorization.
5. Service providers
The inspected architecture uses Google Firebase services and Google Play for Android subscription handling. IONOS is intended to host the public website and support-domain services. Owner/legal review: confirm the final provider list and required disclosures before publication.
6. Retention and deletion
No retention period is published yet. The current app explicitly notes that safe deletion must account for required financial records and a planned 30-day recovery period. Do not interpret that planned recovery period as a finalized retention policy. See the account deletion page.
7. Choices and rights
Users may contact support@quoinvo.com to request access, correction or deletion. Identity and authority to act for a business may need to be verified.
8. Security
Quoinvo uses authenticated access, business-scoped data paths, role-aware rules and server-verified entitlements. No system can guarantee absolute security.
9. Children
Owner/legal review: confirm the intended age restriction and jurisdiction-specific wording.
10. Contact
Privacy questions can be sent to support@quoinvo.com until a dedicated privacy address is established.
