Privacy Policy
Last updated: July 14, 2026
1. Data We Collect
- Account data: email, name, workspace name.
- Prospect data you upload: names, business emails, company info, tags.
- Usage data: feature interactions, email delivery events (sent, bounced, replied).
- Billing data: handled by Stripe; we store customer/subscription IDs only.
2. How We Use Data
To operate the Service, deliver outbound email on your behalf, triage replies with AI, provide analytics, prevent abuse, and comply with law. We do not sell personal data.
3. Subprocessors
- Lovable Cloud (Supabase) — database, auth, edge functions
- Stripe — payment processing
- Lovable AI Gateway — model inference for AI features
- Lovable Managed Email — transactional email delivery
4. Security
Data is encrypted in transit (TLS) and at rest. Access is scoped per workspace via row-level security. Secrets are stored in an encrypted vault.
5. Retention
We retain workspace data while your account is active and for up to 30 days after cancellation, after which it is deleted from primary systems. Backups age out within 90 days.
6. Your Rights
You may access, export, correct, or delete your data at any time. Contact hello@quotaforge.org for GDPR/CCPA requests.
7. Email Compliance
Every outbound email includes an unsubscribe link and physical sender information as required by CAN-SPAM. Suppression lists are enforced at send time.
8. Cookies
We use only strictly necessary cookies for authentication. We do not use third-party ad trackers.
