Legal

Privacy Policy

Last updated: 16 July 2026

This Privacy Policy explains how Queezy (“we”, “us”, “our”) collects, uses and protects personal data across our mobile app, our website queezy.co.uk, and our waiting list. We comply with the UK GDPR and the Data Protection Act 2018.

Our role: controller and processor

  • We are the data controller for your own account information (your name, email, business details, billing and usage) and for website/waiting-list data.
  • For the details of your customers that you enter into the app (your clients' names, addresses, contact details and the quotes/jobs you create for them), you are the controller and we act as your processor — we process that data only to provide the service to you, under the terms of our Data Processing Addendum.

What we collect

  • Account & business — your name, email, password (stored only as a secure hash), business name, trade, phone, address, VAT details and logo.
  • Your clients' data — names, phone numbers, emails and addresses you add, and the quotes, job details and photos you create (processed on your behalf).
  • Billing — subscription tier, status and payment records. Payments are handled by Stripe; we never see or store your card number.
  • Waiting-list & contact — name, business name, trade, email, optional quotes-per-month, and any message you send us.
  • Technical — a push-notification token (if you enable notifications); security and abuse-prevention logs; and, only if you consent, privacy-friendly aggregate analytics (see Cookie Policy).

How we use it & our legal bases

  • To provide the app — create your account, store your quotes/clients, send quote emails and notifications. Basis: performance of a contract.
  • Billing — manage your subscription and keep required records. Basis: contract and legal obligation.
  • Security & anti-abuse — protect accounts and our systems. Basis: legitimate interests.
  • Waiting-list updates & analytics — tell you when we launch, and understand site usage. Basis: consent (withdrawable at any time).

Who we share it with (sub-processors)

We use a small number of trusted providers to run the service. Core data is stored in the EU by design.

  • Neon (database) & Render (hosting) — EU.
  • Cloudflare — storage (files), edge, website hosting and cookie-free analytics — EU data.
  • Stripe — payments (US; safeguarded by Standard Contractual Clauses).
  • Resend — transactional & waiting-list email (US; SCCs).
  • Expo, Apple, Google — push-notification delivery and app distribution (US; SCCs / Data Privacy Framework).

We never sell your data. Where a provider is outside the UK/EEA, appropriate transfer safeguards are in place.

Cookies & analytics

We are consent-first: no analytics or non-essential storage runs until you accept on our cookie banner. Our analytics (Cloudflare Web Analytics) is cookie-free and aggregate. Full details, and how to change your choice, are in our Cookie Policy.

How long we keep it

  • Account & client data — for as long as your account is open. If you delete your account in-app, your subscription is cancelled and your account and all data are permanently erased at your subscription's expiry date (you keep access until then).
  • Billing/tax records — minimal records may be retained where the law requires (e.g. tax).
  • Waiting-list — until launch and a reasonable period after, or until you unsubscribe.
  • Logs — kept only as long as needed for security and diagnostics.

Your rights

Under UK GDPR you have the right to:

  • Access and portability — get a copy of your data (in the app: Settings → export your data, once available, or email us).
  • Rectification — correct your details in the app at any time.
  • Erasure — delete your account and all data yourself in the app (Settings → Delete account), or email us.
  • Restrict or object to processing, and withdraw consent (e.g. unsubscribe or decline analytics) at any time.

To exercise any right, email [email protected]. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Security

Data is encrypted in transit (TLS) and at rest, and core data is hosted in the EU. Passwords and security tokens are stored only as strong hashes, access is scoped per account, and we minimise what we log. No method is 100% secure, but we take appropriate technical and organisational measures to protect your data.

Children

Queezy is a business tool for tradespeople and is not directed at children. We do not knowingly collect data from children.

Changes & contact

We may update this policy as Queezy develops; the “last updated” date shows the current version. Questions? Email [email protected].