Privacy Policy
Last updated: October 8, 2026 · Effective immediately
📋 The short version
- We collect what's needed to run the Service — your email, what you upload, what you generate, and basic usage metadata.
- We do not sell your data. Ever.
- Uploaded documents are sent to OpenAI and Anthropic for AI analysis. Neither provider trains its models on API inputs.
- We keep your quotes and documents for as long as your account is active. Download anything you want to keep for your own records.
- You can request a copy, correction, or deletion of your personal data at oldmanaisolutions@gmail.com.
- Adding past jobs under Historical data is optional. We keep the files we accept until you remove them, and we send only redacted page text to our AI provider to read the prices, never the files, photos or scans. Sharing your de-identified prices with other contractors may not be available to you yet, and when it is, it stays off unless your account owner turns it on.
The full policy below controls in case of any discrepancy with this summary.
1. Who we are
This Privacy Policy describes how Oldman AI Solutions ("we," "us," the "Company"), operating the service known as Oldman Quotes (the "Service"), collects, uses, discloses, and protects personal information you provide in connection with the Service. It applies to the web application at https://quotes.oldmanaisolutions.com, any successor domain, and any related mobile or API access.
The Company is based in Alberta, Canada and is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and the Alberta Personal Information Protection Act (PIPA).
2. What this policy covers
This policy covers personal information processed by the Service. It does not cover:
- data you choose to input about third parties (your customers, subcontractors, suppliers) — you are the "controller" of that data and are responsible for having an appropriate legal basis to share it with us as a processor;
- third-party websites the Service may link to, which have their own privacy practices;
- information collected offline or through any other means.
Historical data you add (section 3.4) usually contains personal information about your clients. You are the organization responsible for that information, and we handle it on your behalf, as your service provider, to store it, read it, show you the results and work out your own learned prices. Combined prices (section 4.1) are a separate use: we make them for our own purposes, and only from prices your account owner chooses to share.
3. Information we collect
3.1 Information you provide directly
- Account information: email address, chosen password hash (if using email-password auth), display name, company name, subscription tier.
- Authentication data: when you sign in with a third-party provider (e.g. Google), we receive your email, name, profile image URL, and a unique provider identifier. We do not receive or store your provider password.
- Payment information: we do not receive or store full credit-card numbers. Stripe (our payment processor) handles card data directly. We store Stripe-issued customer and subscription identifiers, the last four digits of your card, and billing metadata.
- Project inputs: text descriptions you type, documents you upload (PDFs, images, spreadsheets, etc.) including photographs you take through the in-app “Snap a photo” camera capture, quote-template data, company pricing sheets, and any scope or assumption notes you add.
- Voice dictation (optional): where your browser supports it, you can dictate notes instead of typing them. Dictation uses your browser's own built-in speech-recognition service — in Chrome and Edge that means your spoken audio is sent to Google for transcription, under Google's privacy policy rather than ours. We receive only the resulting text, never the audio. If you would rather no audio left your device, type the note instead.
- Generated outputs: quotes, takeoffs, PDF documents, Excel workbooks, and associated metadata produced during your use of the Service.
- Support correspondence: emails, chat messages, and other communications you send us.
3.2 Information collected automatically
- Usage data: pages visited, features used, quotes generated, AI-quote allowance consumed, approximate timestamps.
- Device and connection data: IP address, browser type and version, operating system, screen resolution, language preference, referring URL.
- Cookies and local storage: authentication session tokens, theme preference, feature-flag state. We do not use third-party advertising cookies.
- Error and diagnostic data: stack traces, request identifiers, and runtime metrics captured to diagnose malfunctions and improve reliability.
3.3 Information we do not collect
- Social-security numbers, SIN / SSN, or national identity numbers.
- Government-issued ID documents.
- Biometric data, health information, precise GPS location, or your device contacts.
- Camera or microphone access in the background. We never access either on our own initiative — only when you deliberately use the in-app camera capture or voice dictation described in section 3.1.
- Browsing behavior outside of the Service.
3.4 Historical data you add (optional)
When this feature is available to you, you can add past quotes, estimates, contracts, invoices and supplier bills under Settings, Historical data, or while you set up your account, as PDF, Word, Excel, CSV, photo or zip files. These files can contain your clients' names, addresses, phone numbers and emails, and anything else written in them. We store the files we accept as they are, with their file names and the names of the tabs in a spreadsheet, any of which can name a client. A file taken out of a zip keeps its own name without its folders, with a number added if two names are the same, and the zip itself is removed once its files are stored. A file we refuse, such as a duplicate or a file that fails our safety checks, is not kept. The list in section 3.3 does not cover what is written in these files: a file can contain information of those kinds, such as an identity number or health information, and we store it as it is.
From the readable pages and spreadsheets, our software pulls out only what pricing needs:
- each line item's description, quantity, unit, unit price and amount;
- each document's number, date, type, currency, totals, trade and job type;
- the city and province or state of the job, taken from the job site, or when the document gives none, from the client's billing address or your own address;
- whether you sold the work or bought the materials.
In what we pull out, we keep no client name, street address or full postal code, no customer column from a spreadsheet, and no page text. The original files, which contain all of this, stay stored as described above. Item descriptions are redacted before they are stored, but a name written inside a description can be missed. Photos and scanned pages are stored and listed, but not read. You review what we pulled out before any of it is used for your prices.
4. How we use your information
We process personal information for the following purposes:
- Service delivery: authenticating you, generating AI-powered estimates, storing your quotes and documents, processing payments, sending transactional email (magic links, quote-completion notifications, quote-accepted receipts).
- Service improvement: analyzing aggregated usage patterns to decide which features to prioritize, diagnosing bugs, measuring performance. To check and improve our built-in prices and our setup features, our software reads the line items and prices in contractors' quotes and price books, with the province and currency of each job or company, across all accounts, and combines them into statistics. It does not read the client, the project name or the quote number for this. These reports never name a contractor, client or quote, and an item priced by fewer than 3 contractors shows no figures. For an item priced by 3 or more, a report can show the lowest and highest contractor's typical price, and a built-in price we change because of it can show that range on quote lines.
- Security & fraud prevention: detecting unauthorized access, rate-limiting abuse, investigating security incidents.
- Legal compliance: responding to lawful requests from governmental authorities, complying with tax and corporate record-keeping obligations, enforcing our Terms.
- Communication: notifying you of Service changes, policy updates, and — only with your consent, and never as a primary purpose — occasional product update emails. You may unsubscribe at any time.
Legal bases (for users in PIPEDA / GDPR jurisdictions): we rely on (a) performance of a contract with you, (b) our legitimate interests in operating and securing the Service, (c) your consent (for optional communications), and (d) compliance with legal obligations.
4.1 Learned prices and optional sharing
Your own learned prices. When this feature is available to you, we work out your usual price for an item from your own quotes and the past jobs you reviewed, and your quotes can use it for items your price book does not have (your price book always comes first). The line says so (for example, “Your average over 9 jobs, last 3 years”), and you can leave learned prices out of any job. Your account owner or an admin can leave any past job out of the learned price for an item. Your account owner can turn your own learned prices off: your quotes then stop using them, and we still work them out and show them to you. Your own learned prices are used only in your account.
Sharing, off unless you turn it on. Sharing may not be available to you yet, and until it is, none of your prices are shared. When it is available, your account owner can choose to share your prices to help improve prices for your trade. What is shared is the item, unit, price, date and province, and the kind of record each price came from (for example a paid job, an accepted quote, a price you edited, your price book or a past document you added), never your name, your clients or your documents. Shared prices are combined with other contractors' prices, and a combined price is used only when at least 3 contractors who share have priced the item in that province. Only companies on a paid plan whose account is at least 30 days old are counted. A combined price records how many jobs and how many records of each kind stand behind it. Combined prices can appear in quotes for any user of the Service and can be used to update our built-in prices.
We call combined prices de-identified, not anonymous: no name is attached to them, but when only a few contractors are counted, a combined price can be the same as, or close to, one contractor's own price.
Once sharing is available, the report that compares contractors' prices with our built-in prices (section 4, Service improvement) counts only companies that have turned sharing on.
Turning sharing off stops your prices being counted in any calculation that starts after that, though a calculation already running can still count them. If that leaves fewer than 3 contractors for an item, its combined price usually stops being used at once, and otherwise when combined prices are next worked out, normally within a week. It does not undo combined prices already calculated, built-in prices already updated with them, or quotes already made with them, and because combined prices usually move in limited weekly steps, one can take a few weeks to move fully away from a value your prices helped set. Our Terms of Service (section 11A) set out the license for combined prices already made. We do not pay you or give credits for sharing.
5. AI processing & third-party model providers
This is the most important paragraph in this policy. The Service's core functionality requires sending your inputs to third-party AI model providers for analysis:
- OpenAI, L.L.C. — we send text extracted from uploaded documents, images of document pages (drawings and schedules are analysed visually when text extraction alone is insufficient), text descriptions you provide, related project metadata, and — when you use in-app support chat — your account role, plan, settings summary and recent quote/project titles and totals, to OpenAI's API for analysis. OpenAI returns structured takeoff data, generated scope language, and pricing inferences. Per OpenAI's API data-usage policy (in effect since March 2023), data submitted via the API is not used to train OpenAI's models. OpenAI retains API data for up to thirty (30) days for abuse monitoring, then deletes it. See OpenAI's Privacy Policy.
- Anthropic, PBC — we send the same categories of input (text extracted from uploaded documents, images of document pages, your text descriptions, and related project metadata) to Anthropic's Claude API for analysis. For PDF documents we may also upload the PDF file itself to Anthropic's Files API so the model can read it directly rather than working from extracted text alone. The API returns structured takeoff data, generated scope language, and document-extraction results. Under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models, and the data is processed in the United States. See Anthropic's Privacy Policy.
We select AI providers that publish clear data-handling policies and offer appropriate processor agreements. We do not authorize any AI provider to use your inputs for training general-purpose models.
Historical data files are handled differently. We never send the files themselves, page images, photos, scans or file names to an AI provider. For each readable page, our software first removes what it recognizes as emails, phone numbers, street addresses, postal codes, card and account numbers, the names of the clients and contacts in your client list, and the parts of a document that name the customer or the job site. It does not remove a phone number written as a plain run of digits with no label, and on a line that carries prices it leaves groups of digits alone, such as a card, account or social insurance number or a phone number written with spaces, so that quantities and prices are not lost. Only that redacted text is sent, and a page is not sent at all if our check still finds what looks like an email or a phone number, a known client name, or text left in a part that names the customer or the job site. If we cannot check your pages against your whole client list, for example because it could not be loaded or is very large, no page is sent. The text goes to one of the AI providers named above (today Anthropic, in the United States), which returns the line items it reads. Redaction is automated and can miss a name, number or address written in an unusual way. Spreadsheets are read by our own software, without an AI provider.
Do not submit sensitive data. Because your inputs transit external AI systems, you must not upload or type information subject to special protections (health information, identifying data of third parties collected without consent, confidential legal records, classified information, etc.) into the Service.
6. Other sub-processors & service providers
We rely on the following additional third-party providers. Each is contractually bound to protect your data and use it only for the purposes we direct:
- Supabase, Inc. — authentication, database hosting, and file storage. Your data is stored in Supabase's Canada (Central) region, located in Montreal, Quebec. Data is stored in encrypted Postgres databases with row-level-security policies. Supabase is a US company, so it remains subject to US legal process even though the data itself is held in Canada.
- Vercel, Inc. — application hosting and edge serving. Handles HTTP requests and rendered pages.
- Intuit Inc. (QuickBooks Online) — optional accounting integration, used only if you choose to connect it. When connected, we send your invoices and payments, and the customer records attached to them — including your client's name, email address, phone number and billing address — to Intuit's US-based QuickBooks Online API, and we store an encrypted access token that lets us write to your QuickBooks company file. Because this exports your own customers' information to a third party, only connect it if you are entitled to do so. You can disconnect at any time in Settings → Integrations, which revokes our access at Intuit.
- Stripe, Inc. — payment processing and subscription management. PCI-DSS Level 1 certified. We receive subscription and customer identifiers; Stripe receives your card data directly.
- Resend, Inc. — transactional email delivery (magic-link sign-in, quote notifications, account receipts).
- Functional Software, Inc. (Sentry) — error and performance diagnostics, hosted in the United States. Receives error reports and request context, including the IP address and browser details of the request and an internal account identifier (not your name or email), to help us detect and fix problems. No payment data and no session replay are sent to Sentry.
- Vercel Web Analytics & Speed Insights — cookieless, aggregated page-view and performance telemetry (part of our Vercel hosting). No cross-site tracking or advertising. Quote share links are stripped of their access token before any telemetry is sent, so a client's quote link is never recorded here.
- Google LLC (Google Workspace / Gmail) — our own support and operations mailbox. When you contact support, escalate an issue, or request account deletion, the contents of that request (including your email address and anything you write in it) are delivered to and stored in our Google-hosted inbox.
This list may change as we add or replace providers. Material changes will be reflected in an updated version of this Policy.
7. Disclosure of personal information
We do not sell, rent, or trade your personal information. We disclose it only in these circumstances:
- To sub-processors named in sections 5 and 6, as necessary to operate the Service;
- With your consent, where you explicitly direct us to (e.g. generating a client-facing share link containing your quote);
- For legal reasons — to comply with a lawful subpoena, court order, or government request; to enforce our Terms; to protect our rights, property, or safety or that of our users or the public; to investigate fraud or security incidents;
- In a corporate transaction — if we are acquired, merged, or sell substantially all of our assets, personal information may be transferred as part of that transaction. We will notify you and, where required by law, seek your consent.
8. International data transfers
The Service is operated from Alberta, Canada, and your account data, uploaded documents and quotes are stored in Canada: our database and file-storage provider (Supabase) hosts them in its Canada (Central) region in Montreal, Quebec.
Some processing still happens in the United States. Our hosting provider (Vercel) serves the application from US and global edge locations, and our AI providers (OpenAI and Anthropic), our email provider (Resend), our error-monitoring provider (Sentry), our accounting integration (Intuit, if you connect it) and our payment processor (Stripe) are US-based. When you generate a quote, the relevant document text and images are sent to the AI providers in the United States for the duration of that request; when you send a quote, the email passes through Resend. By using the Service, you understand and consent to that processing in the United States and other jurisdictions.
While your information is outside Canada it is subject to the laws of the country it is in, and may be accessible to the courts, law enforcement and national-security authorities of that country under their own legal processes. Storing the data in Canada does not remove that exposure for the US-based providers above, and Supabase itself is a US company. We cannot contract that risk away, and we tell you about it rather than leaving it implied.
Historical data files you add are stored in Canada with your other uploads. The redacted page text described in section 5 is sent to our AI provider in the United States, which may keep it for a limited time under its own terms (section 5).
For users in the European Economic Area, the United Kingdom, or Switzerland, transfers of personal data outside those regions rely on standard contractual clauses approved by the European Commission or equivalent mechanisms our sub-processors have implemented.
9. Security
We implement reasonable technical and organizational measures to protect personal information, including:
- TLS encryption for data in transit;
- Encryption at rest for database storage and file storage;
- Row-level security policies limiting each user's access to only their own records;
- Principle of least privilege for internal service credentials;
- Hashed authentication secrets (passwords are never stored in plaintext; service tokens are rotated periodically);
- Regular review of sub-processor security posture.
No system is perfectly secure. You are responsible for keeping your own credentials confidential. If you suspect unauthorized account access, notify us at oldmanaisolutions@gmail.com immediately. We will notify affected users of a confirmed data breach within the timelines required by applicable law.
10. Retention
Our retention periods align with the Service's data-lifecycle commitments in our Terms:
- Quotes, generated documents, and uploaded source documents: retained for as long as your account remains active. We recommend downloading copies of anything you want to keep for your own records.
- Account records (email, subscription metadata): retained for the life of the account plus approximately seven (7) years for tax and regulatory compliance, then deleted or anonymized.
- Payment records: retained as required by applicable financial regulations (generally about 7 years).
- Error logs and diagnostic data: retained for up to ninety (90) days.
- Audit / security logs (records of quote views, client responses, and administrative actions): retained for the life of the account, and removed when the account is deleted. These are the evidence trail behind a signed acceptance, so we do not expire them on a fixed clock while the account is active. Separately, our internal change log of edits to records is kept for at least a year, with personal information such as names and emails masked, and is not removed when an account is deleted.
- Oldman Chat history (your past conversations with the in-app support chat): retained for the life of the account, so you can read them again on any device. Only you can see your chats in the app. Nobody else on your team can, including the account owner. You can delete a past chat at any time, and your chats are deleted when your login or the account is deleted.
- Historical data files: files we accept are kept until you remove them (Settings, Historical data) or your account is deleted. We never remove them because of their age, including files older than the 3 years we normally read. Removing a file removes it from storage and deletes the line items we read from it. Price suggestions are then recalculated without it, though a record of earlier suggestions is kept with your account, and your own learned prices are recalculated without it the next time we work them out. Prices you accepted into your price book stay there until you change them. Our change log keeps a copy of some of what we read (each document's date, number, city and totals, and the short name of each suggested item, which can contain a word from an item description) for at least a year, including after a file is removed or your account is deleted.
- Learned prices: the price records we collect from your quotes, price book and reviewed past jobs to work out learned prices are kept with your account and deleted with it. Your own learned prices are kept only in their current form, recalculated as your data changes, and deleted with your account. Combined prices from sharing, including earlier versions, are kept after a contributor leaves or deletes their account, because no contractor's name or account is attached to them.
- Sharing choices: a record of each time your account owner turned a learned price switch on or off, and the policy version shown, kept for the life of the account and deleted with it, except that our change log keeps a copy for at least a year.
You can request early deletion of your account and associated data — see section 11.
11. Your rights
11.1 Universal rights (available to all users)
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate information.
- Deletion: request deletion of your account and associated personal data. (Retention of payment and audit records required by law will continue for the applicable statutory period.)
- Withdraw consent: withdraw consent for optional processing (e.g. product update emails). Withdrawing consent to essential processing will require closing your account.
- Export: receive a copy of your data in a structured, commonly-used format.
To exercise any of these rights, email oldmanaisolutions@gmail.com from the address associated with your account. We will respond within thirty (30) days or the period required by applicable law, whichever is shorter.
If you are a client of a contractor who uses the Service: documents the contractor adds as historical data are under the contractor's control, so please make your request to them. If you contact us, we will pass your request to the contractor and help them respond.
11.2 Additional rights for EU / UK / Swiss residents (GDPR)
If you are located in the EEA, the UK, or Switzerland, you have additional rights to: (a) restrict processing, (b) object to processing based on legitimate interests, (c) not be subject to solely automated decision-making that produces legal or similarly significant effects (note: AI-generated quotes are advisory; they are not binding legal decisions), (d) lodge a complaint with your local supervisory authority.
11.3 Additional rights for California residents (CCPA / CPRA)
If you are a California resident, you have the right to know what categories of personal information we collect, the purposes for which we use it, and to whom we disclose it (see sections 3–7 above). You have the right to request deletion (section 11.1) and the right to opt out of "sale" or "sharing" of personal information. We do not sell or share your personal information within the meaning of California law, so no opt-out is required. You have the right to non-discrimination for exercising your CCPA rights.
12. Cookies and tracking technologies
We use a small set of strictly necessary cookies and local-storage entries:
- Authentication cookies — required to keep you signed in.
- Theme preference (light / dark / system).
- Feature-flag state (which experimental features you have seen).
We do not use third-party advertising cookies. We do not use cross-site behavioural tracking. Disabling strictly-necessary cookies will prevent the Service from functioning.
13. Children's privacy
The Service is intended for professional contractors and is not directed to anyone under the age of eighteen (18). We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it promptly.
14. Do Not Track signals
Browsers may send a Do Not Track (DNT) signal. Because there is no industry consensus on how to interpret DNT, we currently do not respond to DNT signals. We do not engage in cross-site behavioural tracking regardless of DNT.
15. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page and, where practicable, by in-app or email notice. Continued use of the Service after an update takes effect constitutes acceptance of the revised Policy.
16. How to contact us
If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, please contact:
Oldman AI Solutions
Attn: Privacy Officer
Alberta, Canada
Email: oldmanaisolutions@gmail.com
If you are a Canadian resident and we have not resolved your concern to your satisfaction, you have the right to contact the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, if you reside in Alberta, the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca).
By using Oldman Quotes you acknowledge that you have read and understood this Privacy Policy. This Policy is incorporated by reference into our Terms of Service.
