Data Privacy

Data handling and security posture

This page explains the practical controls and product design choices that protect workspace data.
Last updated: July 30, 2026

Tenant separation

QuoteFly is designed so each workspace is scoped by tenant and user membership. Users should only be able to access records tied to their own organization.

Access controls

Account access is role-based. Owners, admins, and members have different capabilities inside the workspace. Team seats and feature access are enforced by plan and membership.

Authentication and billing

Authentication is handled through account credentials and session tokens. Billing is managed through Stripe, and payment card details are not stored inside QuoteFly.

Operational security

We use hosted infrastructure providers to run the application, database, and website. We continue to harden logging, access reviews, and operational controls as the product matures.

AI-assisted features

When a user invokes AI-assisted quoting, QuoteFly may send the prompt and relevant customer, activity, pricing, saved-job, or quote context to OpenAI. AI output is a draft for human review, and prompts plus usage details may be retained in the workspace for operational and quality review.

Retention and export

Customers control the records they add to QuoteFly. The current export paths include PDF quotes and QuickBooks-compatible CSV files. Direct QuickBooks sync remains a staged integration and is not presented as a launch feature.

Reporting a concern

If you believe data has been exposed or mishandled, email support@quotefly.us with “Security” or “Privacy Request” in the subject line and include the affected workspace details.