Privacy Policy

Effective date: June 5, 2025

1. Overview

QuoteHub ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights. It applies to Tenants (packaging manufacturers using our platform) and Buyers (their customers using quote widgets).

2. Data We Collect

From Tenants (account holders):

  • Email address and password (authentication)
  • Company name and billing details (processed by Paddle)
  • Pricing configuration: material rates, margin tiers, MOQ settings
  • Branding settings: logo URL, brand color

From Buyers (quote widget users):

  • Name, email address, phone number (submitted at inquiry)
  • Company name and message (optional)
  • Product specifications: material, dimensions, quantity, print options

Automatically collected:

  • Server logs (IP address, browser type, request timestamps)
  • Session tokens stored in browser localStorage

3. How We Use Data

  • Provide and operate the QuoteHub platform
  • Calculate real-time pricing estimates server-side
  • Deliver inquiry notifications to Tenants via email
  • Send confirmation emails to Buyers upon inquiry submission
  • Process subscription billing through Paddle
  • Send OTP verification codes for Buyer re-order authentication
  • Improve and maintain the Service

We do not sell your data to third parties. We do not use Buyer data for advertising.

4. Pricing Data Confidentiality

Tenant pricing internals — including material costs, margin rates, and custom cost slots — are processed exclusively on our servers and are never transmitted to Buyers or included in client-side responses. We treat this data as confidential business information.

5. Third-Party Services

  • Supabase — database and authentication hosting. Data stored in Supabase PostgreSQL with row-level security.
  • Paddle — payment processing and subscription management. Paddle acts as Merchant of Record for billing transactions. See Paddle's Privacy Policy.
  • Resend — transactional email delivery (inquiry notifications, OTP codes, confirmations).
  • Anthropic Claude — AI quote assistant feature (Pro plan). Widget conversation context is sent to Anthropic's API. See Anthropic's Privacy Policy.

6. Data Retention

  • Tenant account data: retained while account is active, deleted 30 days after account termination
  • Buyer inquiry data: retained for the duration of the Tenant's account
  • OTP codes: deleted immediately after verification or on expiry (10 minutes)
  • Buyer session tokens: expire after 24 hours

7. Security

We use industry-standard security measures including encrypted connections (HTTPS), row-level security in our database, and hashed authentication tokens. However, no system is completely secure and we cannot guarantee absolute security.

8. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data in a machine-readable format
  • Withdraw consent where processing is based on consent

To exercise these rights, contact us at support@packos.co.kr.

9. Cookies

We use essential cookies and browser localStorage for authentication sessions. We do not use tracking or advertising cookies.

10. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal data from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify Tenants of material changes via email. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact

Privacy questions or requests: support@packos.co.kr