Legal
Privacy Notice
Last updated: 2026-07-21
Data controller: ACN 699 263 057 Pty Ltd (ABN 77 699 263 057), PO Box 2060, Marmion WA 6020, Australia, trading as Smart Quote AI. Contact: privacy@smart-quote.com.
This Notice explains how we collect, use, store and disclose personal information, and is intended to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and, for visitors from those regions, the EU/UK GDPR, the Swiss FADP and the California CCPA/CPRA.
1. Information We Collect
- Account. Name, email, business name, role.
- Content you create. Clients, jobs, quotes, notes, attachments.
- Address geolocation. Derived from addresses you enter.
- Usage and telemetry. Feature use, request logs, device and browser information, approximate IP-derived location.
- Integration data. Xero organisation, contacts, invoices and other records you choose to sync.
- Payments. Billing metadata from Paddle, not full card details.
2. How We Use It
To operate the Service, authenticate you, provide AI-assisted features, sync with connected apps, send transactional communications, protect the Service from abuse, meet legal obligations, and improve the product.
3. Legal Bases (GDPR/UK GDPR)
- Contract, to provide the Service.
- Legitimate interests, for security, fraud prevention and product improvement.
- Consent, for non-essential cookies and marketing.
- Legal obligation, for tax, accounting and lawful requests.
4. Subprocessors
Paddle (Merchant of Record and billing, UK/EU/global), Lovable Cloud (hosting, database, authentication, global), Google (OAuth and maps, global), Xero (accounting sync, optional, global), the Lovable AI Gateway (LLM inference for AI features), and Microsoft (calendar OAuth, planned, not enabled until connected). We do not sell personal information and do not share it for cross-context behavioural advertising.
5. International Transfers
Personal data may be processed outside Australia, the EEA and the UK. Where data is transferred out of the EEA or UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses with our subprocessors, together with appropriate technical safeguards.
5A. EEA, UK and Swiss Representative
We are established in Australia and do not currently offer goods or services to, or systematically monitor, individuals in the EEA or the UK at a scale that requires appointing a representative under Article 27 of the GDPR or UK GDPR. If our processing later meets those thresholds, we will appoint a representative and publish their contact details in this section within 30 days.
6. Retention
We retain account and content data while your account is active and for up to 12 months after cancellation, except where a longer period is required by law, for example tax records for 7 years under the Corporations Act 2001 and GST Act. Backups are rotated within 35 days.
7. Security
Data is encrypted in transit (TLS) and at rest. Access is scoped by row-level security with least-privilege controls and logged administrative access. Where an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the OAIC under the Notifiable Data Breaches scheme.
8. Your Rights
Under the GDPR/UK GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent; we respond within one month and you may lodge a complaint with a supervisory authority.
Under the Australian Privacy Principles: we comply with all 13 APPs, including open and transparent management, anonymity where practicable, collection limits, permitted use and disclosure, direct-marketing controls, cross-border safeguards, identifier limits, and access and correction.
Under the CCPA/CPRA, California residents may know, access, correct, delete, and opt out of sale or sharing of personal information; we do not sell or share personal information.
Email privacy@smart-quote.com to exercise any right, or complain to the OAIC (oaic.gov.au, 1300 363 992).
9. Notifiable Data Breaches
We follow the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. Eligible breaches are assessed within 30 days and, where notification is required, we notify affected individuals and the OAIC as soon as practicable.
10. Cookies
See our Cookie Policy. You can change your preferences at any time.
11. Changes
We will notify material changes in-app or by email.
