Privacy Policy
Last updated: August 1, 2026
The privacy of your data — and it is your data, not ours — matters to us. This policy sets out what we collect, why we collect it, and what rights you have. We do not sell your data: never have, never will.
What we collect and why
Our guiding principle is to collect only what we need.
Identity and access: when you request a quote or open a portal account we ask for your name, email address, phone number, and company. That lets us reply to you, prepare your quote, and personalise your account.
Billing information: if you buy from us you provide payment details and a billing address. Card details go directly to Stripe, our payment processor, and never reach our servers. We keep a record of the transaction, including the last four digits of the card, for invoicing, accounting, and fraud prevention.
Project information: the drawings, specifications, and project details you send us, so we can quote and prepare your deliverables. We keep these for as long as your account is active and for the period set out under Data retention below.
Website and security logs: we log IP addresses and basic request data to rate-limit abuse, block spam submissions, and investigate security incidents.
What we do not do
We do not sell your personal information to anyone.
We do not use your company name in marketing or publish it as a client reference without your permission.
We do not publish plan-holder lists, and we do not tell other customers who else has bought a takeoff for a project.
When we access or disclose your information
To do the work: our estimators access your project documents to prepare your deliverables. That is the whole point of sending them.
To help with a support request you have made.
To keep the service safe: we review logs and access records to investigate security incidents and abuse.
To meet legal obligations: we disclose information where we are compelled by a valid legal order, or where it is needed for tax or audit purposes — and then only the minimum required.
We use third-party providers to run the service, including Amazon Web Services for file storage and Stripe for payments. They handle data on our instructions.
How we secure your data
All traffic to this site and the portal is encrypted in transit.
Project files are stored in private cloud storage that is not publicly listable. Access happens through short-lived, authenticated links rather than permanent public URLs.
Every uploaded file is scanned for malware before it is stored.
Access to project documents is logged, so we can tell who opened what and when.
Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Email info@qtoexpert.com and we will respond within a reasonable time.
Some records we must keep regardless — completed transactions, invoices, and tax records — for as long as the law requires.
You can unsubscribe from marketing email at any time using the link in the message. Operational email about an active order is not marketing and will still be sent.
Data retention
We keep your account information and project files while your account is active.
If you close your account, we delete your project files from active systems within 60 days, and from backups shortly after, except where we are required to keep records for legal or accounting reasons.
Location of data
QTO Expert LLC is based in New York and our infrastructure is located in the United States. If you use the Services from outside the US, you are transferring your data to the US and consent to it being processed there.
Changes and questions
We may update this policy. When we do, we will revise the date at the top of this page and, for significant changes, notify account holders.
Questions about privacy: email info@qtoexpert.com.