Privacy Policy

How Quotiv handles personal information across our website, quoting platform, and Shopify app.

Effective
24 August 2026
Last updated
28 August 2026

QUOTIV LIMITED (NZ company number 9444423, NZBN 9429053815293), formerly QuoteMate Limited ("Quotiv", "we", "us"), provides quoting software to businesses. This policy explains how we handle personal information.

In this policy, personal information means information about an identifiable individual. It has the same meaning as "personal data" under the EU GDPR and UK GDPR, and as "personal information" under the Privacy Act 2020 and the California Consumer Privacy Act.

It applies to quotiv.io, the Quotiv application, the Quotiv app for Shopify, public quote and enquiry experiences, and related services (together, the "Services").

We are based in New Zealand and comply with the Privacy Act 2020 ("Privacy Act"). Where we handle information about people in the European Economic Area or United Kingdom, we also comply with the General Data Protection Regulation 2016/679 (EU) ("EU GDPR") and the UK GDPR. Where the California Consumer Privacy Act applies, section 13 sets out additional disclosures.


1. The two roles we play — please read this first

How we handle personal information depends on which of two very different situations applies.

A. Information we control

When you visit quotiv.io, chat with our website assistant, contact us, subscribe to updates, apply for a role, or administer a Quotiv account, we decide why and how that information is used. We are the controller under the EU GDPR and UK GDPR, or the agency under the Privacy Act. This policy governs how we handle that information, and every section applies.

B. Information we process for our business customers

When a business ("Customer") uses Quotiv to build and send quotes, the Customer uploads information about its own customers, such as names, contact details, addresses, quote history and signed acceptance records.

For that information the Customer is the controller and we are the processor under the EU GDPR and UK GDPR, or the agent for our Customer under section 11 of the Privacy Act. The Customer decides why and how the information is used, and the Customer's own privacy notice governs how they handle it. We hold and process it only on the Customer's instructions, and subject to our Terms of Service and our Data Processing Addendum.

If you received a quote from a business using Quotiv and want to access, correct or delete your information, please contact that business directly — they control it, and they can verify who you are. If you contact us, we will refer you to them and assist them in responding.


2. Information we collect

2.1 Information you give us

WhatWhen
Name, work email, phone, company, website, messageContact, enquiry and demo request forms
Identity, login credentials (password stored hashed), business profile, users and rolesCreating and administering a Quotiv account or workspace
Catalogue, pricing, templates, billing settings, integration configurationSetting up your workspace
Enquiries, customer records, products, quotes, line items, terms, messages, notes, imported filesUsing the Service (this is Customer data — see section 1B)
Billing and plan detailsSubscribing — payment card data is handled by Shopify or our payment provider. We do not receive or store card numbers.
Anything you type into the Quotiv AssistantUsing the on-site chat
CV and application detailsApplying for a role

2.2 Information collected automatically

IP address, browser and device type, operating system, referring page, timestamps, feature interactions, diagnostic logs, security events, and cookies or similar storage. We use these to operate and secure the Services, including rate limiting to prevent abuse.

2.3 Information we collect from someone other than you

We may collect personal information about you from a third party, including where:

  • a Quotiv account administrator adds you as a user of their workspace and gives us your details, including your name, email address and role, so we can create and administer your access;
  • Shopify provides us with staff identity details — Shopify user ID, name, email address, account-owner status and last access — when a Customer installs or uses our app; or
  • someone gives us your contact details in an enquiry or support request.

Where we do this, we use the information for the purposes in section 4, the recipients are those in section 6, and you have the rights described in section 12. We are not required by law to collect it. We collect information from a third party on the basis that they are authorised to provide it to us.

2.4 The Quotiv Assistant (our website AI chat)

Our website uses an AI chat assistant. Please note:

  • We store your conversations. Messages you send are retained so the assistant can respond helpfully on return visits.
  • We create a short summary profile of the conversation to understand what you're interested in. If you volunteer identifying details — your name, email or company — those are stored in that profile.
  • Your messages are sent to our AI provider (see section 6) to generate a response.
  • Please don't share sensitive or confidential information in the chat. It is a sales and support tool, not a secure channel.
  • We use a pseudonymous visitor identifier stored in your browser to recognise you between visits, plus short-lived storage for abuse prevention. It does not contain your name or email.

2.5 Quote acceptance records

When an End Customer accepts a quote, we record on the Customer's behalf: the signer's name and signature (a drawn image or typed name), the acceptance time, IP address, browser information, and any purchase order details provided. This is an evidentiary record of acceptance, held for the Customer.

2.6 Information we do not want

Please do not send us health information, government identifiers, biometric data, or payment card numbers — through the Services, the Assistant, or any form. We don't need them, our systems aren't designed for them, and our Terms of Service prohibits submitting them.


3. Shopify

3.1 What we receive

When a Customer installs the Quotiv app for Shopify, we receive only the information the Customer and Shopify permit:

  • Store: name, shop domain, contact email, country, currency, time zone, plan, installation status, permissions
  • Shopify staff identity: user ID, name, email, account-owner status, last access
  • Products: identifiers, titles, descriptions, SKUs, prices, images, status, locations, shipping information
  • Customer identifiers: names, emails, phone numbers, billing and shipping addresses, where authorised

3.2 Permissions we request

Currently: customer read and write, product read, location read, shipping read, and draft order write. These support catalogue sync, quote workflows, and creating Shopify customers and draft orders. We do not modify your theme code through the Shopify Asset API.

3.3 Billing

Shopify manages billing for app subscriptions. We receive subscription and billing-status information, not payment card details.

3.4 Uninstalling, and Shopify's redaction webhooks

We handle Shopify's three mandatory webhooks: customer data request, customer redaction, and shop redaction. Generated customer-data-request records expire after 30 days.

Following uninstall, Shopify-linked data is deleted in response to the shop redaction request, with a 30-day purge as additional cleanup. Customers should export any data they need before uninstalling — see section 9.


4. How we use information, and our legal basis

We use information to:

  • provide, operate, maintain, personalise and improve the Services;
  • authenticate users, connect integrations, and enforce workspace roles and permissions;
  • manage enquiries, sync catalogues, generate and deliver quotes, record acceptance, and create Shopify records;
  • respond to contact requests, provide support, and send transactional communications;
  • provide AI-assisted search, product matching, catalogue mapping, quote generation, recommendations, analytics and website assistance;
  • understand website and product usage, where you have consented to analytics;
  • protect the Services, detect abuse, enforce limits, investigate incidents and prevent fraud; and
  • comply with law, enforce our agreements, and protect legal rights.
PurposeLegal basis (EU GDPR / UK GDPR)
Providing and administering your accountPerformance of a contract
Responding to enquiries and demo requestsLegitimate interests; steps prior to a contract
Billing and collecting feesPerformance of a contract; legal obligation
Operating the Quotiv AssistantLegitimate interests (helping visitors; understanding demand)
Analytics and measuring marketingConsent
Marketing emailsConsent, or legitimate interests for existing customers about similar services
Security, fraud and abuse preventionLegitimate interests; legal obligation
Complying with law and enforcing our termsLegal obligation; legitimate interests

Under the Privacy Act we collect personal information for these lawful purposes connected with our functions.

Marketing. We send marketing only where you have consented, or where you are an existing customer and the message concerns a similar service. Every marketing email has an unsubscribe link, or you can contact us using the details in section 16 to unsubscribe, and we act on unsubscribes promptly. Unsubscribing does not stop essential service messages such as billing notices or security alerts.


5. AI-assisted features

We use AI service providers for quote drafting, catalogue interpretation, product matching, analytics and website assistance. When AI features are invoked, the relevant instructions, conversation and minimum necessary content may be sent to those providers (named in section 6).

  • Please avoid submitting unnecessary personal information to AI-assisted features.
  • Please review generated output before you use it. AI output can be inaccurate or incomplete, and Customers are responsible for checking every price, quantity, total and term before issuing a quote.
  • We do not make automated decisions producing legal or similarly significant effects about you based solely on automated processing.

6. Who we share information with

We do not sell Customer or End Customer personal information, and we do not use it for cross-context behavioural advertising.

We share information with:

  • the Customer whose workspace collected or controls it, and that Customer's authorised users;
  • Shopify, to operate the integration, manage subscriptions, respond to platform events, and write authorised records;
  • the service providers below;
  • professional advisers, and where required by law, to enforce our terms, or to protect the rights and safety of any person; and
  • a counterparty in a merger, financing, acquisition, reorganisation or asset sale, with confidentiality protections. We will notify you before your information becomes subject to a different privacy policy.
ProviderPurposeLocation
VercelWebsite and application hostingUnited States / global edge
NeonDatabase hosting (marketing site)Australia
RailwayDatabase hosting (product application)United States
OpenAIQuote generation and embeddings within the productUnited States
AnthropicQuote prompt generation; the website AssistantUnited States
GoogleAnalytics (with consent); email delivery via Google Workspace; Preferred Sources button on article pagesUnited States / global
ShopifyApp distribution, integration and subscription billingCanada / United States
StripePayment processingUnited States

We engage each provider under data protection terms and obligations. The current list of sub-processors used in the product is maintained in our Data Processing Addendum.

We may also disclose personal information where it is required by law.


7. Cookies and analytics

We use:

  • Strictly necessary cookies and browser storage — sign-in, session security, consent choices, the Assistant's pseudonymous visitor identifier, and short-lived abuse-prevention settings. These are required for the Services to function.
  • Analytics cookies — Google Analytics 4 on the marketing site, for aggregate usage understanding. Analytics storage is off by default and is enabled only after you accept analytics cookies. We use Google Consent Mode v2, so analytics storage stays disabled until you allow it.
  • Google "Preferred Sources" button — our blog posts and Knowledge Base articles embed a button, provided and rendered by Google, that lets you add Quotiv as a preferred source in your own Google account. Displaying it loads a script and a frame from Google, and Google may read or set its own cookies in that frame. It is not analytics and it does not track what you read. If you never click it, nothing is added to your Google account. It appears only on article pages.

You can decline analytics without losing access to the public site, and you can change or withdraw your choice at any time through our cookie banner or by clearing cookies in your browser.

Google Analytics is not loaded on public signed-quote token URLs, so viewing or accepting a quote is not tracked by analytics.

Reference: Google Privacy Policy.


8. International transfers

We are based in New Zealand and our providers operate internationally, so your information may be stored or processed outside your country, including in the United States.

  • From the EEA / UK: New Zealand has an adequacy decision from the European Commission, so transfers to us do not require additional safeguards. Where our providers are outside the EEA, UK or an adequate country, we rely on Standard Contractual Clauses (with the UK Addendum where applicable) or another lawful transfer mechanism.
  • From New Zealand: where we disclose personal information to an overseas recipient, we comply with IPP 12, ensuring the recipient is subject to comparable safeguards.

9. Retention and deletion

We keep personal information only as long as reasonably necessary for the Services, security, business records, dispute resolution and legal compliance. How long depends on the type of information, the Customer's instructions, account status, and applicable law.

CategoryRetention
Account recordsDuration of the account, then 12 months
Billing and tax records7 years (NZ tax law)
Contact and demo enquiries24 months from last contact
Assistant conversations and visitor profiles12 months from last activity
Analytics dataPer the Google Analytics retention setting — 14 months
Server and security logs90 days
Job applications12 months unless you ask us to keep them
Shopify customer-data-request records30 days

Customer data. Information held in the product on a Customer's behalf is retained per the Customer's instructions and the Data Processing Addendum, not this schedule. On termination, Customers may export data using the Service's export functionality — except where the app was installed through Shopify and is uninstalled, in which case Shopify's shop redaction process governs and deletion may occur sooner (section 3.4). Export before uninstalling.

Residual records. Where deletion would compromise accounting, security or transaction records, we may retain non-identifying records instead: identifying content is removed or replaced and use is restricted. Residual copies are removed through normal backup-expiration cycles.


10. Security

We use administrative, technical and organisational safeguards appropriate to the risk, including encrypted connections (TLS) and encryption at rest, hashed passwords, access controls and role-based permissions, encryption of Shopify credentials and sensitive secrets, server-side session revocation, rate limiting, monitoring, and least-privilege access to production systems.

No system guarantees absolute security.


11. If something goes wrong — notifiable privacy breach notification

If we become aware of a privacy breach that has caused, or is likely to cause, serious harm to affected individuals, a notifiable privacy breach occurs. We will notify the Office of the Privacy Commissioner and affected individuals as soon as practicable, as required by the Privacy Act, and any other regulator as required.

Where we act as processor for a Customer, we notify the Customer without undue delay so they can meet their own obligations, and we support Customers and Shopify in responding.


12. Your rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you (Privacy Act IPP 6; GDPR Art. 15);
  • correct it (IPP 7; GDPR Art. 16);
  • delete it (GDPR Art. 17);
  • restrict or object to processing, including objecting to direct marketing (GDPR Arts. 18, 21);
  • portability — receive it in a machine-readable format (GDPR Art. 20); and
  • withdraw consent at any time, without affecting processing already carried out.

If your information was submitted through a Customer's store, enquiry experience or quote, contact that Customer first — they control the relationship and can verify your request. We support Customers and Shopify in responding to verified requests.

Customers, account users and website visitors may contact us directly using the details in section 16. We will respond within 20 working days (Privacy Act) or one month (GDPR), and we will verify your identity first. There is no fee unless a request is manifestly unfounded or excessive.


13. California residents

Where the CCPA/CPRA applies:

  • We do not sell or share personal information as those terms are defined, and we have not in the preceding 12 months. We do not use personal information for cross-context behavioural advertising.
  • Categories collected in the last 12 months: identifiers, commercial information, internet activity, approximate geolocation, and professional information. Sources, purposes and recipients are in sections 2, 4 and 6.
  • You have rights to know, delete, correct, and to non-discrimination. Submit requests using section 16; an authorised agent may act for you with proof of authority.
  • Where we process Customer data, we act as a service provider and do not retain, use or disclose it except to perform the services.

14. Children

The Services are for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.


15. Changes to this policy

We may update this policy to reflect changes to the Services, our practices, or legal requirements. Material changes will be notified by email or prominent notice at least 30 days before they take effect. Other updates are posted with a revised effective date. The "last updated" date above always reflects the current version.


16. Contact, Privacy Officer and complaints

For privacy questions, requests or complaints, you can contact us using any of the following:

  • Email: our Privacy Officer at privacy@quotiv.io, with "Privacy request" in the subject
  • Contact form: quotiv.io/contact
  • Post: QUOTIV LIMITED, Attention: Privacy Officer, 93a Hetherington Road, Ranui, Auckland 0612, New Zealand

Please include the relevant Shopify store or Quotiv workspace where applicable.

If you are not satisfied with our response, you may complain to:

  • New Zealand — Office of the Privacy Commissioner, privacy.org.nz, 0800 803 909
  • EEA / UK — your local supervisory authority, or the UK Information Commissioner's Office