Privacy Policy
Last updated: April 13, 2026
1. Introduction
SendEstimates, operated by Apollo Digital Foundry LLC (“we”, “us”, or “our”), respects your privacy. This policy explains what information we collect, how we use it, and your rights regarding your data. This policy applies to all users of the Service, including contractors (account holders) and their clients (quote recipients).
2. Who This Policy Applies To
This policy covers two types of users:
- Account holders (contractors) — users who create accounts, build quotes, and manage their business through the Service.
- Quote recipients (clients) — individuals who receive, view, and accept quotes sent through the Service. Quote recipients do not need to create an account.
3. Information We Collect
From Account Holders
When you create an account and use the Service, we collect:
- Full name and email address
- Password (hashed using bcrypt — never stored in plain text)
- Business name, phone number, and address (optional)
- Business logo (optional)
- Trade/industry selection
- Quote content: line items, pricing, notes, and photos
- Client contact information you enter (names, emails, phone numbers)
- Template data you create
- Subscription and billing information (processed by Stripe)
From Quote Recipients
When you view or accept a quote, we collect:
- IP address at time of viewing and/or signing
- Timestamp of when the quote was viewed and/or accepted
- Full name (typed as electronic signature)
- Drawn signature image (optional)
This data is collected to create a legally valid electronic signature record under the U.S. ESIGN Act and UETA. The contractor who sent you the quote is the “data controller” for your information — we process it on their behalf.
Automatically Collected Information
For all users, we may collect:
- IP addresses (for security, rate limiting, and signature verification)
- Browser type and device information (via standard HTTP headers)
- Pages visited and features used within the Service
4. Legal Basis for Processing
We process your data under the following legal bases:
- Contract performance — to provide the Service you signed up for (account holders)
- Legitimate interest — to operate, secure, and improve the Service; to send transactional notifications; to prevent fraud
- Consent — for optional features like automated follow-up emails (which can be disabled in settings)
- Legal obligation — to comply with applicable laws, regulations, and legal processes
5. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Send quotes to your clients via email and SMS on your behalf
- Send you notifications when quotes are viewed or accepted
- Send automated follow-up reminders to quote recipients (if enabled by the account holder)
- Process subscription payments via Stripe
- Enforce our Terms of Service and prevent abuse
- Improve the Service, fix bugs, and develop new features
- Comply with legal obligations
We do not use your data for advertising, profiling, or any purpose unrelated to providing the Service.
6. Data Processing Relationship
When a contractor enters client information into the Service, the contractor is the “data controller” and SendEstimates is the “data processor” under GDPR terminology. We process client data solely on behalf of the contractor and according to their instructions (e.g., sending quotes, follow-up reminders). Contractors are responsible for ensuring they have the right to share their clients' information with us.
7. Third-Party Services
We use the following third-party services to operate:
- Supabase (database hosting, authentication) — stores account data, quotes, and files. Servers located in the United States. Privacy Policy
- Stripe (payment processing) — handles credit card information. We never see or store your card details. Privacy Policy
- Resend (email delivery) — sends quote emails and notifications. Receives recipient email addresses and email content. Privacy Policy
- Twilio (SMS delivery) — sends quote links via text message. Receives recipient phone numbers and message content. Privacy Policy
- Vercel (application hosting) — hosts the application. Servers located in the United States. Privacy Policy
We only share the minimum data necessary for each service to function. We do not sell or share data with any other third parties.
8. International Data Transfers
Our third-party service providers primarily store and process data in the United States. If you are located outside the United States, your data may be transferred to and processed in the United States. By using the Service, you consent to this transfer. We ensure our service providers maintain appropriate data protection standards.
9. Data Sharing
We do not sell your data. We may share data only:
- With the third-party service providers listed above, to operate the Service
- When required by law, subpoena, or legal process
- To protect our rights, safety, or property, or that of our users
- In connection with a merger, acquisition, or sale of assets (with advance notice)
10. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your data within 30 days, except:
- Signature records and accepted quotes — retained for up to 7 years for legal compliance
- Data required to be retained by applicable law
- Anonymized, aggregated data that can no longer identify you
- Backup copies — purged within 90 days of deletion
11. Your Rights
For Account Holders
You have the right to:
- Access — request a copy of all data we hold about you
- Correction — update inaccurate information via your account settings
- Deletion — request deletion of your account and associated data
- Portability — request your data in a machine-readable format (JSON or CSV)
- Restriction — request we limit how we process your data
- Objection — object to processing based on legitimate interest
- Opt-out — disable automated follow-up emails in your settings at any time
For Quote Recipients
If you received a quote through SendEstimates and want to exercise your data rights (access, deletion, correction), please contact the contractor who sent you the quote directly, as they are the data controller. You may also contact us at contact@sendestimates.com and we will assist in facilitating your request.
To exercise any of these rights, email us at contact@sendestimates.com. We will respond within 30 days.
12. Data Security
We implement industry-standard security measures including:
- Encrypted connections (HTTPS/TLS) for all data in transit
- Passwords hashed using bcrypt with salt
- Row-level security on all database tables
- Rate limiting on API endpoints
- Input validation and sanitization
- CSRF protection on mutation endpoints
- Service role keys restricted to server-side only
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users via email within 72 hours of becoming aware of the breach. We will also notify relevant supervisory authorities as required by applicable law.
14. Cookies and Local Storage
We use the following cookies and browser storage:
- Authentication cookies (essential) — set by Supabase to maintain your login session. These are httpOnly, secure cookies that expire when your session ends or after 7 days of inactivity.
- Service worker cache (essential) — caches static assets for PWA installability. No personal data is cached.
We do not use tracking cookies, analytics cookies, or third-party advertising cookies. We do not participate in any ad networks or cross-site tracking.
15. Children's Privacy
The Service is not intended for children under 18. We do not knowingly collect information from children. If we learn that we have collected data from a child under 18, we will delete it promptly.
16. California Privacy Rights (CCPA)
If you are a California resident, you have the right to: (a) know what personal information we collect and how it is used; (b) request deletion of your personal information; (c) opt out of the sale of your personal information (we do not sell personal information); and (d) not be discriminated against for exercising your rights. Contact us at contact@sendestimates.com to exercise these rights.
17. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes at least 14 days in advance via email. The “Last updated” date at the top of this page indicates when the policy was last revised. Continued use after changes constitutes acceptance.
18. Contact
Questions or concerns about privacy? Contact us at:
Apollo Digital Foundry LLC
Email: contact@sendestimates.com
Washington, United States