Pokitquote Ltd ("we", "us", "our") operates the Pokitquote mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use the App and related services. We are committed to transparency, accountability, and full compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Data (Use and Access) Act 2026.
We are the data controller for the personal information described in this policy.
Information We Collect
a. Information You Provide Directly
- Account Details: Name, email address, business name, and phone number provided during registration.
- Workflow Data: Quotes, financial estimates, project metrics, and invoice data you generate.
- Client Management Records: Third-party customer data you enter (e.g., client names, project addresses, contact details).
- Media Uploads: Architectural photographs, asset images, receipts, and documents uploaded for OCR, tracking, or PokitCam rendering.
- Subscription Data: Records processed via Apple App Store or Google Play Store (we do not store raw payment card details).
- Merchant Payment Data: Transaction records processed by Stripe when you collect client payments in-app (we do not store full card credentials).
b. Information from QuickBooks Integration
With your explicit OAuth consent, we access and synchronise:
- Customer databases and contacts.
- Invoices, estimates, ledger balances, and payment history.
- Inventory items, chart of accounts, tax rates, and transaction histories.
This data supports syncing, reconciliation, and quote-to-invoice workflows.
c. Automatically Collected Information
- Device telemetry (hardware model, OS version, device identifiers).
- Usage analytics (interactions with templates, exports, and AI features).
- Stability diagnostics (crash reports and performance data).
d. AI Feature Data (PokitMate, PokitCam, Receipt Scanner)
We transmit relevant prompts, job descriptions, receipt scans, or photographs to Google Gemini API (commercial tier) for processing.
Retention: Temporary inputs are subject to Google's maximum 55-day transient cache for stability, abuse prevention, and state management.
Protections: Google acts as our sub-processor under a Data Processing Agreement and is contractually prohibited from using your inputs to train public models.
Outputs: Generated results (e.g., PokitCam images or extracted text) are downloaded and stored in our Firebase infrastructure.
e. Backend Storage (Firebase)
All persistent data is hosted in Google Firebase (eur3 European multi-region – Belgium and Netherlands). This includes account records, quotes, invoices, and media assets in Firebase Storage. No secondary external databases are used. Firebase Analytics and Crashlytics are configured to collect only essential, aggregated, and anonymised data for stability and service improvement.
Lawful Basis for Processing
We rely on the following bases under Article 6 UK GDPR:
- Contractual Necessity: To deliver the App's core functions (quoting, invoicing, AI tools) you request via our Terms of Service.
- Legitimate Interests: To maintain App stability, security, fraud prevention, and product improvement (balanced against your rights).
- Legal Obligation: To comply with UK tax, accounting (e.g., Making Tax Digital), and Companies Act requirements.
- Explicit Consent: For optional features such as QuickBooks linking or marketing communications (you may withdraw consent anytime).
We do not engage in solely automated decision-making that produces legal or similarly significant effects without human oversight.
How We Use Your Information
We use your data to:
- Provide, maintain, and improve core App features.
- Enable QuickBooks syncing and reconciliation.
- Process AI-generated outputs.
- Manage subscriptions and payments.
- Send service-related communications and support responses.
- Ensure security, debug issues, and prevent fraud.
- Fulfil statutory tax and regulatory obligations.
Sharing Your Information
We share data only with the following processors under strict agreements:
- Intuit (QuickBooks): For authorised syncing.
- Stripe: For in-app payment collection.
- Google (Firebase & Gemini API): As backend host and AI sub-processor (eur3 region).
- Apple & Google: For app store subscriptions and licensing.
- Legal Authorities: Only when required by UK law or to protect safety and rights.
We maintain Data Processing Agreements with all processors and do not sell, rent, or trade personal data.
Data Security
We implement appropriate technical and organisational measures, including:
- Encryption of data in transit and at rest.
- Strict access controls and authentication.
- Regular security reviews and monitoring.
- Secure Firebase configuration with regional restrictions.
In the event of a personal data breach, we will notify the ICO and affected users where required by law.
Data Storage, Retention & Deletion
All data is stored in the EEA (eur3).
- Media Assets (Photos, PokitCam Outputs): Retained for the life of your account; permanently deleted upon your request or account closure.
- Financial & Tax Records: Retained for a minimum of 6 years from the end of the relevant financial year to meet UK legal obligations (Companies Act 2006 and HMRC rules), then securely purged or anonymised.
- Other Account Data: Retained during active use and deleted within 30 days of account closure (subject to legal holds).
You may delete your account directly within the App settings. You may also request deletion of your data at any time by contacting us, subject to statutory retention obligations.
International Data Transfers
All processing by Firebase and Gemini occurs within the EEA. These transfers benefit from the UK's adequacy decision for the EU/EEA, so no additional safeguards are required.
Your Rights Under UK GDPR
You have the following rights:
To exercise these rights, email support@pokitquote.com. We respond within one month (free of charge, unless requests are manifestly unfounded or excessive). You also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Cookies and Tracking Technologies
We do not use traditional advertising cookies. We use essential Firebase tools (Crashlytics and Analytics) for stability, crash reporting, and aggregated, anonymised usage insights. These support service improvement without cross-app tracking or profiling for marketing.
Children's Privacy
The App is designed for adult tradespeople and business users and is not intended for children under 16. We do not knowingly collect data from children under 13 (or under 16 where the App could be considered an information society service). If we become aware that a child has provided data, we will delete it promptly. Parents/guardians should contact us if they believe their child has created an account.
Changes to This Privacy Policy
We may update this policy to reflect changes in our practices or legal requirements. Material changes will be notified via an in-App banner or email. The "Last Updated" date indicates the current version. Continued use after changes constitutes acceptance of the updated policy.
Contact Us
Privacy Questions or Requests?
Reach out to our team directly — we're happy to help.
support@pokitquote.com