1. Scope and controller
This Privacy Policy applies to scope2quote.com, the Scope2Quote web application, and related beta support and transactional email communications. It does not govern a contractor's independent use of customer information outside Scope2Quote.
Scope2Quote is operated by Aliaksandr Naumionak, an individual based in Lithuania. Aliaksandr Naumionak is the data controller for account, website, support, and service-operation data described in this policy.
A workspace user generally determines why customer and project data is entered into Scope2Quote. For that data, the workspace user is responsible for its own privacy obligations, and Scope2Quote processes the data to provide the service and follow the user's instructions.
2. Information we process
- Account information: name, email address, authentication records, session information, and workspace membership.
- Business information: company name, contact details, pricing settings, templates, and price-book items.
- Customer and project information: names, contact details, project addresses, descriptions, notes, project types, and uploaded photos.
- Estimate and invoice information: draft and finalized line items, pricing, approvals, change requests, customer-link activity, reminders, and delivery status.
- Support and feedback: feedback messages and the application page or workflow connected to them.
- Technical information: session IP address and user agent, security records, timestamps, provider response identifiers, and error diagnostics.
3. How we use information
We use information to:
- create and secure accounts and workspaces;
- store projects, photos, estimates, invoices, and reusable pricing data;
- generate contractor-reviewable AI estimate drafts when requested;
- produce PDFs, secure customer pages, approvals, and change requests;
- send transactional estimates, invoices, and requested reminders;
- operate the beta, investigate failures, prevent abuse, and improve the service;
- comply with legal obligations and protect the rights and safety of users and others.
4. Legal bases for processing
Where the EU General Data Protection Regulation applies, we rely on the following legal bases, depending on the activity:
- Contract: to create an account and provide features requested by a user;
- Legitimate interests: to secure, maintain, troubleshoot, and improve the service, prevent abuse, and understand the performance of our public pages;
- Legal obligations: to comply with applicable law and valid legal requests; and
- Consent: when we specifically ask for it. Consent may be withdrawn at any time without affecting processing that already occurred lawfully.
5. AI processing
When an account user asks Scope2Quote to analyze an estimate, the selected project description, project type, and selected photo content are sent to the OpenAI API to create a structured draft. Scope2Quote requests that the response not be stored as an application response, and OpenAI states that API inputs and outputs are not used to train its models by default. Standard API abuse-monitoring retention may still apply under OpenAI's current policies.
AI output can be incomplete or incorrect. The contractor must review and approve the scope and pricing before anything is sent to a customer.
6. Service providers and disclosures
We use service providers to operate Scope2Quote, including Render for application hosting and managed PostgreSQL, Cloudflare R2 for private object storage, OpenAI for requested AI analysis, and Resend for transactional email delivery. These providers process information on our behalf under their own contractual, security, and privacy terms.
Information may also be disclosed when a workspace user intentionally sends an estimate or invoice, creates a secure customer link, when required by law, to protect the service or its users, or as part of a business reorganization subject to appropriate safeguards. We do not sell personal information.
7. Marketing analytics
On the public homepage and legal pages, we may use Cloudflare Web Analytics to understand page traffic and performance. Cloudflare states that this service does not use cookies, does not track individuals across websites, and does not collect or use visitors' personal data. The analytics beacon is not included on authenticated workspace pages or secure estimate and invoice links.
8. Retention and deletion
We retain account and workspace information while needed to provide the service, preserve finalized business records, resolve disputes, meet legal obligations, and protect the service. Different records may have different retention periods. Revoked or expired share links may remain recorded without preserving their plaintext access token.
Account deletion is not yet self-service during beta. Contact us to request access, correction, export, or deletion. We may need to verify the request and may retain information where required by law or for legitimate security and recordkeeping purposes.
9. Security
Scope2Quote uses tenant isolation, private object storage, hashed bearer tokens for customer links, HTTPS in production, and restricted provider credentials. No system is completely secure, and users should avoid uploading information that is unnecessary for preparing an estimate.
10. Your privacy rights and responsibilities
Workspace users are responsible for having an appropriate basis to add customer information and photos to Scope2Quote and for responding to customer privacy requests relating to their own business.
Depending on the applicable law and circumstances, an individual may have rights to access, correct, delete, restrict, or object to processing of personal data, receive portable data, and withdraw consent. Send a request to the contact address below. We may need to verify identity and will normally respond to a valid GDPR request within one month, subject to extensions and exceptions permitted by law.
You may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (VDAI) or another competent supervisory authority. We encourage you to contact us first so we can try to resolve the concern.
11. Children and international processing
Scope2Quote is a business service and is not directed to children under 18.
Our providers may process information in the United States and other countries outside the European Economic Area. Where required, transfers are supported by an applicable adequacy decision, contractual safeguards such as the European Commission's Standard Contractual Clauses, or another transfer mechanism permitted by law. The mechanism may differ by provider and processing location.
12. Changes and contact
We may update this policy as the beta and its providers change. Material changes will be reflected by a new effective date.
The controller is Aliaksandr Naumionak, Lithuania. Questions and privacy requests can be sent to support@scope2quote.com.