Privacy Policy
How Quotiv handles personal information across our website, quoting platform, and Shopify app.
- Effective
- 24 August 2026
- Last updated
- 28 August 2026
QUOTIV LIMITED (NZ company number 9444423, NZBN 9429053815293), formerly QuoteMate Limited ("Quotiv", "we", "us"), provides quoting software to businesses. This policy explains how we handle personal information.
In this policy, personal information means information about an identifiable individual. It has the same meaning as "personal data" under the EU GDPR and UK GDPR, and as "personal information" under the Privacy Act 2020 and the California Consumer Privacy Act.
It applies to quotiv.io, the Quotiv application, the Quotiv app for Shopify, public quote and enquiry experiences, and related services (together, the "Services").
We are based in New Zealand and comply with the Privacy Act 2020 ("Privacy Act"). Where we handle information about people in the European Economic Area or United Kingdom, we also comply with the General Data Protection Regulation 2016/679 (EU) ("EU GDPR") and the UK GDPR. Where the California Consumer Privacy Act applies, section 13 sets out additional disclosures.
1. The two roles we play — please read this first
How we handle personal information depends on which of two very different situations applies.
A. Information we control
When you visit quotiv.io, chat with our website assistant, contact us, subscribe to updates, apply for a role, or administer a Quotiv account, we decide why and how that information is used. We are the controller under the EU GDPR and UK GDPR, or the agency under the Privacy Act. This policy governs how we handle that information, and every section applies.
B. Information we process for our business customers
When a business ("Customer") uses Quotiv to build and send quotes, the Customer uploads information about its own customers, such as names, contact details, addresses, quote history and signed acceptance records.
For that information the Customer is the controller and we are the processor under the EU GDPR and UK GDPR, or the agent for our Customer under section 11 of the Privacy Act. The Customer decides why and how the information is used, and the Customer's own privacy notice governs how they handle it. We hold and process it only on the Customer's instructions, and subject to our Terms of Service and our Data Processing Addendum.
If you received a quote from a business using Quotiv and want to access, correct or delete your information, please contact that business directly — they control it, and they can verify who you are. If you contact us, we will refer you to them and assist them in responding.
2. Information we collect
2.1 Information you give us
| What | When |
|---|---|
| Name, work email, phone, company, website, message | Contact, enquiry and demo request forms |
| Identity, login credentials (password stored hashed), business profile, users and roles | Creating and administering a Quotiv account or workspace |
| Catalogue, pricing, templates, billing settings, integration configuration | Setting up your workspace |
| Enquiries, customer records, products, quotes, line items, terms, messages, notes, imported files | Using the Service (this is Customer data — see section 1B) |
| Billing and plan details | Subscribing — payment card data is handled by Shopify or our payment provider. We do not receive or store card numbers. |
| Anything you type into the Quotiv Assistant | Using the on-site chat |
| CV and application details | Applying for a role |
2.2 Information collected automatically
IP address, browser and device type, operating system, referring page, timestamps, feature interactions, diagnostic logs, security events, and cookies or similar storage. We use these to operate and secure the Services, including rate limiting to prevent abuse.
2.3 Information we collect from someone other than you
We may collect personal information about you from a third party, including where:
- a Quotiv account administrator adds you as a user of their workspace and gives us your details, including your name, email address and role, so we can create and administer your access;
- Shopify provides us with staff identity details — Shopify user ID, name, email address, account-owner status and last access — when a Customer installs or uses our app; or
- someone gives us your contact details in an enquiry or support request.
Where we do this, we use the information for the purposes in section 4, the recipients are those in section 6, and you have the rights described in section 12. We are not required by law to collect it. We collect information from a third party on the basis that they are authorised to provide it to us.
2.4 The Quotiv Assistant (our website AI chat)
Our website uses an AI chat assistant. Please note:
- We store your conversations. Messages you send are retained so the assistant can respond helpfully on return visits.
- We create a short summary profile of the conversation to understand what you're interested in. If you volunteer identifying details — your name, email or company — those are stored in that profile.
- Your messages are sent to our AI provider (see section 6) to generate a response.
- Please don't share sensitive or confidential information in the chat. It is a sales and support tool, not a secure channel.
- We use a pseudonymous visitor identifier stored in your browser to recognise you between visits, plus short-lived storage for abuse prevention. It does not contain your name or email.
2.5 Quote acceptance records
When an End Customer accepts a quote, we record on the Customer's behalf: the signer's name and signature (a drawn image or typed name), the acceptance time, IP address, browser information, and any purchase order details provided. This is an evidentiary record of acceptance, held for the Customer.
2.6 Information we do not want
Please do not send us health information, government identifiers, biometric data, or payment card numbers — through the Services, the Assistant, or any form. We don't need them, our systems aren't designed for them, and our Terms of Service prohibits submitting them.
3. Shopify
3.1 What we receive
When a Customer installs the Quotiv app for Shopify, we receive only the information the Customer and Shopify permit:
- Store: name, shop domain, contact email, country, currency, time zone, plan, installation status, permissions
- Shopify staff identity: user ID, name, email, account-owner status, last access
- Products: identifiers, titles, descriptions, SKUs, prices, images, status, locations, shipping information
- Customer identifiers: names, emails, phone numbers, billing and shipping addresses, where authorised
3.2 Permissions we request
Currently: customer read and write, product read, location read, shipping read, and draft order write. These support catalogue sync, quote workflows, and creating Shopify customers and draft orders. We do not modify your theme code through the Shopify Asset API.
3.3 Billing
Shopify manages billing for app subscriptions. We receive subscription and billing-status information, not payment card details.
3.4 Uninstalling, and Shopify's redaction webhooks
We handle Shopify's three mandatory webhooks: customer data request, customer redaction, and shop redaction. Generated customer-data-request records expire after 30 days.
Following uninstall, Shopify-linked data is deleted in response to the shop redaction request, with a 30-day purge as additional cleanup. Customers should export any data they need before uninstalling — see section 9.
4. How we use information, and our legal basis
We use information to:
- provide, operate, maintain, personalise and improve the Services;
- authenticate users, connect integrations, and enforce workspace roles and permissions;
- manage enquiries, sync catalogues, generate and deliver quotes, record acceptance, and create Shopify records;
- respond to contact requests, provide support, and send transactional communications;
- provide AI-assisted search, product matching, catalogue mapping, quote generation, recommendations, analytics and website assistance;
- understand website and product usage, where you have consented to analytics;
- protect the Services, detect abuse, enforce limits, investigate incidents and prevent fraud; and
- comply with law, enforce our agreements, and protect legal rights.
| Purpose | Legal basis (EU GDPR / UK GDPR) |
|---|---|
| Providing and administering your account | Performance of a contract |
| Responding to enquiries and demo requests | Legitimate interests; steps prior to a contract |
| Billing and collecting fees | Performance of a contract; legal obligation |
| Operating the Quotiv Assistant | Legitimate interests (helping visitors; understanding demand) |
| Analytics and measuring marketing | Consent |
| Marketing emails | Consent, or legitimate interests for existing customers about similar services |
| Security, fraud and abuse prevention | Legitimate interests; legal obligation |
| Complying with law and enforcing our terms | Legal obligation; legitimate interests |
Under the Privacy Act we collect personal information for these lawful purposes connected with our functions.
Marketing. We send marketing only where you have consented, or where you are an existing customer and the message concerns a similar service. Every marketing email has an unsubscribe link, or you can contact us using the details in section 16 to unsubscribe, and we act on unsubscribes promptly. Unsubscribing does not stop essential service messages such as billing notices or security alerts.
5. AI-assisted features
We use AI service providers for quote drafting, catalogue interpretation, product matching, analytics and website assistance. When AI features are invoked, the relevant instructions, conversation and minimum necessary content may be sent to those providers (named in section 6).
- Please avoid submitting unnecessary personal information to AI-assisted features.
- Please review generated output before you use it. AI output can be inaccurate or incomplete, and Customers are responsible for checking every price, quantity, total and term before issuing a quote.
- We do not make automated decisions producing legal or similarly significant effects about you based solely on automated processing.
6. Who we share information with
We do not sell Customer or End Customer personal information, and we do not use it for cross-context behavioural advertising.
We share information with:
- the Customer whose workspace collected or controls it, and that Customer's authorised users;
- Shopify, to operate the integration, manage subscriptions, respond to platform events, and write authorised records;
- the service providers below;
- professional advisers, and where required by law, to enforce our terms, or to protect the rights and safety of any person; and
- a counterparty in a merger, financing, acquisition, reorganisation or asset sale, with confidentiality protections. We will notify you before your information becomes subject to a different privacy policy.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Website and application hosting | United States / global edge |
| Neon | Database hosting (marketing site) | Australia |
| Railway | Database hosting (product application) | United States |
| OpenAI | Quote generation and embeddings within the product | United States |
| Anthropic | Quote prompt generation; the website Assistant | United States |
| Analytics (with consent); email delivery via Google Workspace; Preferred Sources button on article pages | United States / global | |
| Shopify | App distribution, integration and subscription billing | Canada / United States |
| Stripe | Payment processing | United States |
We engage each provider under data protection terms and obligations. The current list of sub-processors used in the product is maintained in our Data Processing Addendum.
We may also disclose personal information where it is required by law.
7. Cookies and analytics
We use:
- Strictly necessary cookies and browser storage — sign-in, session security, consent choices, the Assistant's pseudonymous visitor identifier, and short-lived abuse-prevention settings. These are required for the Services to function.
- Analytics cookies — Google Analytics 4 on the marketing site, for aggregate usage understanding. Analytics storage is off by default and is enabled only after you accept analytics cookies. We use Google Consent Mode v2, so analytics storage stays disabled until you allow it.
- Google "Preferred Sources" button — our blog posts and Knowledge Base articles embed a button, provided and rendered by Google, that lets you add Quotiv as a preferred source in your own Google account. Displaying it loads a script and a frame from Google, and Google may read or set its own cookies in that frame. It is not analytics and it does not track what you read. If you never click it, nothing is added to your Google account. It appears only on article pages.
You can decline analytics without losing access to the public site, and you can change or withdraw your choice at any time through our cookie banner or by clearing cookies in your browser.
Google Analytics is not loaded on public signed-quote token URLs, so viewing or accepting a quote is not tracked by analytics.
Reference: Google Privacy Policy.
8. International transfers
We are based in New Zealand and our providers operate internationally, so your information may be stored or processed outside your country, including in the United States.
- From the EEA / UK: New Zealand has an adequacy decision from the European Commission, so transfers to us do not require additional safeguards. Where our providers are outside the EEA, UK or an adequate country, we rely on Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism.
- From New Zealand: where we disclose personal information to an overseas recipient, we comply with IPP 12, ensuring the recipient is subject to comparable safeguards.
9. Retention and deletion
We keep personal information only as long as reasonably necessary for the Services, security, business records, dispute resolution and legal compliance. How long depends on the type of information, the Customer's instructions, account status, and applicable law.
| Category | Retention |
|---|---|
| Account records | Duration of the account, then 12 months |
| Billing and tax records | 7 years (NZ tax law) |
| Contact and demo enquiries | 24 months from last contact |
| Assistant conversations and visitor profiles | 12 months from last activity |
| Analytics data | Per the Google Analytics retention setting — 14 months |
| Server and security logs | 90 days |
| Job applications | 12 months unless you ask us to keep them |
| Shopify customer-data-request records | 30 days |
Customer data. Information held in the product on a Customer's behalf is retained per the Customer's instructions and the Data Processing Addendum, not this schedule. On termination, Customers may export data using the Service's export functionality — except where the app was installed through Shopify and is uninstalled, in which case Shopify's shop redaction process governs and deletion may occur sooner (section 3.4). Export before uninstalling.
Residual records. Where deletion would compromise accounting, security or transaction records, we may retain non-identifying records instead: identifying content is removed or replaced and use is restricted. Residual copies are removed through normal backup-expiration cycles.
10. Security
We use administrative, technical and organisational safeguards appropriate to the risk, including encrypted connections (TLS) and encryption at rest, hashed passwords, access controls and role-based permissions, encryption of Shopify credentials and sensitive secrets, server-side session revocation, rate limiting, monitoring, and least-privilege access to production systems.
No system guarantees absolute security.
11. If something goes wrong — notifiable privacy breach notification
If we become aware of a privacy breach that has caused, or is likely to cause, serious harm to affected individuals, a notifiable privacy breach occurs. We will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by the Privacy Act, and any other regulator as required.
Where we act as processor for a Customer, we notify the Customer without undue delay so they can meet their own obligations, and we support Customers and Shopify in responding.
12. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you (Privacy Act IPP 6; GDPR Art. 15);
- correct it (IPP 7; GDPR Art. 16);
- delete it (GDPR Art. 17);
- restrict or object to processing, including objecting to direct marketing (GDPR Arts. 18, 21);
- portability — receive it in a machine-readable format (GDPR Art. 20); and
- withdraw consent at any time, without affecting processing already carried out.
If your information was submitted through a Customer's store, enquiry experience or quote, contact that Customer first — they control the relationship and can verify your request. We support Customers and Shopify in responding to verified requests.
Customers, account users and website visitors may contact us directly using the details in section 16. We will respond within 20 working days (Privacy Act) or one month (GDPR), and we will verify your identity first. There is no fee unless a request is manifestly unfounded or excessive.
13. California residents
Where the CCPA/CPRA applies:
- We do not sell or share personal information as those terms are defined, and we have not in the preceding 12 months. We do not use personal information for cross-context behavioural advertising.
- Categories collected in the last 12 months: identifiers, commercial information, internet activity, approximate geolocation, and professional information. Sources, purposes and recipients are in sections 2, 4 and 6.
- You have rights to know, delete, correct, and to non-discrimination. Submit requests using section 16; an authorised agent may act for you with proof of authority.
- Where we process Customer data, we act as a service provider and do not retain, use or disclose it except to perform the services.
14. Children
The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
15. Changes to this policy
We may update this policy to reflect changes to the Services, our practices, or legal requirements. Material changes will be notified by email or prominent notice at least 30 days before they take effect. Other updates are posted with a revised effective date. The "last updated" date above always reflects the current version.
16. Contact, Privacy Officer and complaints
For privacy questions, requests or complaints, you can contact us using any of the following:
- Email: our Privacy Officer at privacy@quotiv.io, with "Privacy request" in the subject
- Contact form: quotiv.io/contact
- Post: QUOTIV LIMITED, Attention: Privacy Officer, 93a Hetherington Road, Ranui, Auckland 0612, New Zealand
Please include the relevant Shopify store or Quotiv workspace where applicable.
If you are not satisfied with our response, you may complain to:
- New Zealand — Office of the Privacy Commissioner, privacy.org.nz, 0800 803 909
- EEA / UK — your local supervisory authority, or the UK Information Commissioner's Office
Related documents