Legal

Privacy Policy

How QuoteKita collects, uses, shares, and protects personal data, aligned with the Philippine Data Privacy Act (RA 10173).

Last updated: June 28, 2026

This is a general template, not legal advice. Have a Philippine lawyer review before relying on it.

1. Who is responsible

For data about business owners and their accounts (name, email, billing, dashboard activity), QuoteKita is the personal information controller.

For data submitted by customers through a shop's estimator page (their name, contact details, answers, requested schedule), the business that owns the estimator is the controller. QuoteKita acts as the processor: we host and carry the data on the business's behalf and do not use it for our own marketing.

Data Protection Officer
  • Name: [DPO full name]
  • Email: [dpo@quotekita.com]
  • Address: [Business address, Quezon City, Philippines]

2. What we collect

CategoryExamples
Account dataName, email, password hash, phone, role, 2FA factors.
Business contentServices, prices, photos, brand settings, staff list.
Customer inquiry dataCustomer name, contact, answers, preferred schedule, consent flags.
Usage dataPages visited, actions taken, device, browser, IP, timestamps.
CookiesSession, preferences, and optional analytics — see Cookie Policy.

3. Why we use it and our legal basis

  • Contract: to provide the service you signed up for, including processing your account, plan, and payments.
  • Legitimate interests: to secure the platform, prevent fraud and abuse, debug issues, and improve features.
  • Consent: for optional marketing, optional analytics cookies, and any feature that asks before turning on.
  • Legal obligation: to comply with tax, accounting, and law-enforcement requests under Philippine law.

4. How we share

We do not sell personal data. We share it only with:

  • Service providers acting as our sub-processors under written data processing agreements, for example [Supabase] (hosting and database), [Resend] (email), and [your payment provider].
  • The relevant business, when a customer submits an estimator request to that business.
  • Authorities, when required by a valid Philippine legal process.

Some processing may take place outside the Philippines (for example our hosting provider's regional servers). Where this happens we put in place safeguards consistent with the Data Privacy Act.

5. Your rights under the Data Privacy Act

As a data subject under RA 10173, you have the right to be:

  • Informed about how your data is processed.
  • Granted access to your data.
  • To object to processing, including for marketing.
  • To have your data rectified if it is wrong.
  • To request erasure or blocking when allowed.
  • To data portability in a common machine-readable format.
  • To claim damages for unlawful processing.
  • To file a complaint with the National Privacy Commission (privacy.gov.ph).

To exercise these rights, contact our DPO using the details above.

6. How long we keep data

We keep personal data only as long as needed for the purposes above and to meet legal requirements. Defaults:

  • Active account data: while your account is active and for [12 months] after closure.
  • Customer inquiries on a shop's estimator: [24 months] from last activity, or sooner on request.
  • Billing and tax records: [10 years] as required by Philippine law.
  • Security logs: [12 months].

7. How we protect data

We apply organisational, physical, and technical safeguards appropriate to the risk: role-based access controls, encryption in transit (TLS), per-tenant row-level isolation in the database, and audit logging of sensitive actions.

In the event of a personal data breach that meets the thresholds of the Data Privacy Act, we will notify affected data subjects and the National Privacy Commission within the timelines required by NPC rules.

8. Children

QuoteKita is not directed at children under 18. We do not knowingly collect personal data from minors. If you believe a minor has submitted information to us, contact our DPO and we will remove it.

9. Changes to this Policy

We may update this Policy. The "Last updated" date at the top reflects the current version. For material changes we will notify account owners through the app or by email.

Questions about this page?

  • Email [privacy@quotekita.com]
  • Data Protection Officer: [DPO name] · [dpo@quotekita.com]
  • [Business address, Quezon City, Philippines]