Legal

Privacy Policy

Last updated: 2026-05-18

Who this applies to

Quotram, Inc. ("Quotram", "we", "us") provides AI-native quoting software to metal-fabrication and contract-manufacturing shops ("Shops"). This policy explains how we handle data when you visit our marketing site, use the Quotram application, or interact with quotes sent through the platform as a Shop's customer.

Data we collect

We collect only what's needed to operate the service. Concretely:

  • Account data: name, email, role, and the Shop you belong to.
  • Shop configuration: machines, rates, materials, branding, and pricing rules you enter to make the cost engine work. This is treated as the Shop's competitive information and is never shared with other Shops.
  • Quote and RFQ content: drawings, parts, customer information, and the quotes you generate. Stored encrypted at rest in Supabase.
  • Usage data: page views, feature usage, and performance metrics via PostHog (product analytics) and Sentry (error monitoring), with sensitive request bodies stripped before transmission.
  • Billing data: subscription status, invoice history, and a payment- method token. We never see or store full card numbers - Stripe handles that directly.

How we use AI

Quotram uses third-party AI APIs (Anthropic Claude for vision and reasoning, Voyage AI for embeddings) to extract drawing fields, draft quote and follow-up emails, and power in-product support. We do not fine-tune any model on customer data, and our agreements with these providers prohibit them from training their models on inputs we send. Inputs are retained only as long as needed for the specific task, plus a short caching window for cost optimization on repeated identical inputs.

Sub-processors

We use the following third parties to operate the service. Each receives only the data needed for its specific function.

  • Anthropic: AI inference (drawing extraction, quote drafting, support)
  • Voyage AI: Embeddings for historical quote similarity search
  • Supabase: Database, authentication, and file storage
  • Vercel: Application hosting and edge delivery
  • Stripe: Subscription billing and payment processing
  • Resend: Transactional email delivery on behalf of shops
  • Inngest: Background job orchestration
  • Upstash: Redis cache for inference results
  • Sentry: Error monitoring
  • PostHog: Product analytics

Data retention

Active Shop data is retained for the life of the subscription. After cancellation, Shop data is retained for 30 days to allow re-activation, then deleted. The customer-facing quote portal token expires by default 60 days after the quote is sent (configurable per Shop). Inference cache entries expire after 90 days. Marketing-funnel data (lead form submissions) is retained for 24 months unless deletion is requested.

Your rights

You can request access, correction, or deletion of your personal data at any time by emailing privacy@quotestream.com. If you're a EU/UK resident or California consumer, you have additional rights under GDPR / CCPA which we honor on the same channel.

Security

All data is encrypted in transit (TLS 1.2+) and at rest. Database access uses Postgres row-level security with shop-scoped policies on every table containing Shop or customer data. Service-role credentials are restricted to server-side code paths and never reachable from the browser. We do not currently hold a SOC 2 audit; we are working toward Type II by month 18 of operation and will update this policy when the audit report is available.

Cookies

We use first-party cookies for session authentication and a small set of third-party cookies for product analytics (PostHog) and error monitoring (Sentry). We do not use advertising cookies and do not sell personal data. Browser settings can disable cookies; the authentication cookie is required to use the application.

Changes

When this policy changes, we'll update the "Last updated" date above and - for material changes - email all Shop owners at least 30 days before the change takes effect.

Contact

Questions: privacy@quotestream.com. Postal: Quotram, Inc., [STREET ADDRESS], [CITY, STATE, ZIP], USA.