Privacy Policy
Last updated: July 10, 2026
This Privacy Policy explains how ClearDesk Studio ("we") collects and uses personal data in connection with QuoteRocket (the "Service"). We are the data controller for personal data processed through the Service. Contact: hello@cleardeskstudio.net.
1. Data we collect
- Account data: name, email, authentication identifiers, password hash (via our auth provider).
- Business profile: business name, logo, address, tax/registration ID, default currency, payment terms.
- Customer records you create: customer name, email, phone, address.
- Quotes & invoices you create: line items, totals, PDFs, sent/opened/accepted timestamps.
- Billing data: subscription status, plan, period dates. Card details are handled by Stripe, not stored by us.
- Support & feedback: messages you send us via the in-app feedback form or email.
- Technical logs: IP address, browser info, and error diagnostics for security and troubleshooting.
2. How we use it
- Provide, secure, and maintain the Service.
- Generate quotes, invoices, and PDFs; deliver customer-facing pages and emails you trigger.
- Process subscription payments and prevent fraud.
- Send transactional emails (account, billing, quote/invoice notifications). We do not send marketing emails.
- Respond to support requests and improve the Service.
3. Legal bases (GDPR)
- Contract: to provide the Service you signed up for.
- Legitimate interests: security, fraud prevention, and product improvement.
- Legal obligation: tax, accounting, and other statutory record-keeping (including Danish bookkeeping law).
- Consent: where required (e.g. non-essential cookies).
4. Processors we rely on
We share data with the following processors, who act on our instructions:
- Supabase — database, authentication, file storage, and app hosting infrastructure.
- Stripe — subscription billing and payment processing.
- Email delivery provider used by our platform to send transactional email from our verified sender domain.
- AI provider used to generate draft line items from your job descriptions.
Some processors may be located outside the EU/EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep your data for as long as your account is active. If you delete your account, we delete or anonymise personal data within a reasonable period, except where we must keep records to comply with Danish bookkeeping law (typically 5 years for accounting records) or other legal obligations.
6. Cookies
We use a small number of essential cookies/local storage entries needed for sign-in, security, and to remember your cookie choice. We do not set non-essential (analytics/marketing) cookies by default. You can change your choice via the banner at the bottom of the page or by clearing site data in your browser.
7. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. To exercise these rights, email hello@cleardeskstudio.net. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet) or your local supervisory authority.
8. Security
We use industry-standard measures including encryption in transit, access controls, and row-level security in our database. No system is perfectly secure — please use a strong, unique password.
9. Changes
We may update this policy from time to time. Material changes will be communicated via the app or email. The "Last updated" date above reflects the current version.
ClearDesk Studio · Ringholmvej 1, 2., 2700 Brønshøj, Denmark · CVR 44331543 · VAT DK44331543