Privacy Policy
No advertising tracking: Polyquote does not use marketing pixels or advertising networks. Technically necessary local storage and connections to the infrastructure providers named below remain unaffected.
1. Controller and scope
Liam Vendel (trading as Polyquote)
Stein 6, 4851 Gampern, Austria
Email: support@polyquote.org
This policy covers website visitors, registered merchant customers, billing contacts and people who contact Polyquote directly. For data entered through a merchant’s widget, that merchant is generally the controller; Polyquote processes the data on its behalf. The widget is enabled for real submissions only after the merchant has provided an HTTPS privacy policy, provider terms and approved embedding domains; those merchant documents are linked directly in the widget.
2. Data processed, purposes and legal bases
- Website and security: IP address, time, URL, browser/device information, status codes and security events; Article 6(1)(f) GDPR (secure and stable operation).
- B2B application and business verification: email, authentication data, company, address, contact and VAT data, relationship to representation, review status and method, and recorded document versions and timestamps. For sole traders and direct contractual contacts, processing is necessary for pre-contractual measures under Article 6(1)(b) GDPR. For employees or other representatives it is based on Article 6(1)(f) GDPR; legitimate interests are verification of B2B eligibility and authority, secure account administration, abuse prevention and legal defence. Verification is data-minimised and based on a public business register, business evidence supplied by the applicant or an existing business relationship. Register data comes from the relevant public register; this information is provided no later than the first communication or through the notice presented when applying.
- Active merchant account: plan, configuration, usage, security and administration data; Article 6(1)(b) GDPR for the contracting party, and Article 6(1)(f) GDPR for its employees or representatives, based on interests in contract performance, secure provision, authorisation management and defence of claims. The current application does not collect bank-account details.
- Price requests: name/company, email, filename, CAD file, material, geometry, pricing and production parameters; processed on the merchant’s behalf under Article 28 GDPR. The merchant’s legal basis is stated in its privacy policy.
- Billing: plan, billing status, invoice number, service period, invoice amount and the company and tax details required for the invoice; Article 6(1)(b) and (c) GDPR.
- Support and email: sender, recipient, subject, message and delivery information; Article 6(1)(b) or (f) GDPR. Legitimate interests under point (f) are responding to and prioritising requests, secure support operation, abuse prevention, and handling or defending potential claims. Data is deleted after the support period below once none of those purposes remains.
Information marked as required for registration, contract and billing is necessary to provide the service. Without it, no account or subscription can be provided. No decision based solely on automated processing produces legal or similarly significant effects; price calculations are non-binding estimates reviewed by the merchant.
3. Local browser storage
For authentication, Supabase stores technically necessary session and refresh tokens in local browser storage. They generally remain until logout, account deletion, automatic invalidation or deletion of browser data. Following an express selection, the website also stores the language preference under pq-lang and colour scheme under pq-theme, in each case until changed or browser data is deleted. Polyquote sets no proprietary marketing, analytics or profiling cookies.
4. Recipients and service providers
- Vercel Inc.: hosting, content delivery, serverless functions and technical logs.
- Supabase Inc.: authentication, database and private CAD file storage in the region configured for the project. The currently unused storage area for former brand images is not public, and new logo uploads are disabled.
- Resend Inc.: account, billing and application notifications exclusively to merchants or their users, as well as incoming support messages; no automated email to merchants’ end customers.
Polyquote self-hosts browser libraries used for the 3D view, CAD import and data transfer. Loading the widget therefore creates no additional connection to a public library CDN. The CAD file is analysed in the browser and transferred to Polyquote’s private file storage for processing the price request.
Where a service provider acts as processor, processing must be protected by an agreement under Article 28 GDPR. Providers may use additional published sub-processors. The relevant agreements, provider roles, data regions and transfer mechanisms must be reviewed before any real personal or CAD data is processed; until then, registration, real widget processing and new paid plans remain technically blocked.
5. Transfers outside the EEA
Individual providers or sub-processors may process data in the United States or other third countries. Transfers take place only on the basis of an adequacy decision, including valid participation in the EU-US Data Privacy Framework, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses; supplementary measures and transfer risks are assessed where required. Information on the safeguard used and a copy or accessible reference may be requested from support@polyquote.org.
6. Retention
- B2B application: The application remains open for acceptance for 30 days. On expiry or rejection, a message containing the intended deletion time is placed in the delivery queue. The non-activated operational authentication/application account is deleted 90 days after that queue entry in limited daily runs, unless the application is renewed or activated or a documented exception applies. A later delivery failure does not move this transparently identified queue timestamp.
- Active merchant account and operational configuration: until controlled account deletion or the end of contract, subject to the evidence and legal duties below.
- Private CAD/model files: after the merchant-configured period of at least one day and no longer than the associated price-request period, 30 days by default, or earlier on account or individual deletion. Incomplete uploads are removed in limited ongoing deletion runs after their short upload authorisation expires.
- Price-request metadata, including contact, pricing and production parameters: after the merchant-configured period of 30 to 2,555 days, 365 days by default, or earlier on account or individual deletion. When the shorter CAD period expires, the price request remains without its model file.
- Support messages: until final handling and thereafter only insofar as required for documented evidence of delivery, security or claims. Completion is recorded using a limited case reference and the message is then scheduled for deletion; further time-limited storage requires a documented purpose code and a specific earlier deletion date. In every case, a maximum of three years from receipt applies. Deletion occurs in limited daily runs.
- Local email-delivery jobs: successfully delivered or aborted jobs for no more than 90 days; jobs that remain open, in processing, failed or require review for no more than 365 days. The period supports controlled delivery, error investigation and prevention of duplicate messages.
- Security and provider logs: only as long as necessary under the documented security and deletion concept and verified provider periods for operation, abuse prevention and incident investigation.
- Invoice and accounting records: normally seven years in accordance with statutory duties.
- Evidence of a non-activated B2B application: after deletion of the operational applicant account, direct user attribution is removed; the data-minimised version/timestamp record is generally intended to be retained for one year after separation to handle potential complaints and legal defence. Records of a contract actually formed may generally be retained for up to seven years after account separation where required by tax, limitation and legal-defence rules. A documented dispute or other legal hold may postpone deletion to the extent required.
- Backups: only where backups are enabled and documented for the actual plan and data type used, until confirmed expiry of the relevant provider or internal rotation plan; deleted data remains blocked from ordinary operation until then. Database backups do not automatically include private CAD files in object storage, and restoration of deleted CAD files is not promised.
7. Security
Measures include encrypted transmission, private file storage, short-lived signed download links, tenant-specific database rules, server-side authentication of privileged operations, signed provider webhooks, input validation and access restriction. No system can guarantee absolute security.
8. Rights
Subject to statutory requirements, data subjects have rights of access, rectification, erasure, restriction, data portability and objection. Consent may be withdrawn at any time for the future. Merchant end customers should primarily address requests to the merchant; Polyquote assists it as processor.
An account-closure request is permanently recorded in the authenticated portal. Before deletion begins, a structured paginated JSON export is available with download links valid for ten minutes for CAD files that still exist. For paid accounts, cancellation at the end of the applicable billing period, outstanding usage and final billing are resolved first. Private files, operational application data and finally the login are then deleted in a controlled and resumable sequence. Billing data required by law, abuse records and time-limited backups remain blocked and retained to the extent required.
9. Complaints and contact
Send requests to support@polyquote.org. You may also lodge a complaint with a data-protection supervisory authority, particularly the Austrian Data Protection Authority; current contact details: www.dsb.gv.at.