Draft, pending legal review. The practices below are accurate and in force for the pilot. Formal privacy-policy language (data-subject rights, retention specifics, request process) is being finalized with counsel.

What we collect, and when

Your project details and photos first; your contact information (name, email, phone, address) only at the final step, once you choose to continue. We ask for identity last because we only need it last.

Where your contact information lives

Readable contact information is stored only in a separate, encrypted vault, keyed by an opaque token. The rest of the system holds the token, never the values, and access to the vault is restricted and logged.

What providers see

Invited providers see an anonymous packet: your standardized scope and sanitized photos, never your name, email, phone, or exact address. Your contact is shared only after you choose a provider, and only with that provider.

Photos

Every photo is re-encoded on upload to strip embedded location (GPS) and device metadata before anyone, including our concierge, can view it. Only sanitized images are ever stored or shown.

Not sold, not a lead

We do not sell your identity or your project as a lead. Our revenue is provider software subscriptions, not your data.

Still with counsel

Data retention periods, your rights over your data, and the process to request access or deletion will be added here after attorney review.

Privacy questions: hello@getquoteroom.com.