Privacy Policy
What Quotewright actually collects, from whom, why, and where it goes. Last updated August 06, 2026.
This notice replaces an earlier version of this page that was a generic template and, in one place, directly contradicted what this product does: it said "We do not collect any information from third parties." That was wrong. Quotewright's entire function is reading correspondence from third parties — people who send a request for quotation (an "RFQ") to one of our customers — and using it to draft a quote. This page now describes that, and everything else, as accurately as we can.
Table of contents
- Who this is about — two different kinds of people
- What we collect, and from whom
- Why we process this information
- Where it goes — the systems that touch your data
- Connecting an AI assistant (MCP)
- How long we keep information
- How we try to keep information safe
- Your rights, and how to exercise them
- Cookies
- Children
- Changes to this notice
- Contact us
1. Who this is about — two different kinds of people
Most privacy notices are written for one kind of person: someone who visits the website and maybe signs up. Quotewright has two, and they are treated differently:
- Console users. People at one of our customer firms who sign in to the Quotewright console (at
quotewright.seamuk.com) to review, approve or send quotes, manage settings, or connect an AI assistant. These people create an account and see this page. - RFQ senders. Anyone who emails a request for quotation to a mailbox our pipeline monitors on a customer's behalf. These people are third parties in the fullest sense — they never visit this website, never create an account, and never see this notice at the point their information is collected. Their name, email address, company details and the full text of their correspondence are read and processed automatically so a quote can be drafted in reply. This is the core of the product, and it is exactly the third-party collection the old version of this page denied.
If you are an RFQ sender and want to know more about how your message was handled, see "Your rights" below, or contact the company you emailed directly — they are the ones you have a relationship with; we process the data on their behalf.
2. What we collect, and from whom
From console users
- Name and email address, and a password (or, if you sign in with Google, the identity Google gives us — see "Social sign-in").
- Which firm ("tenant") your account is linked to, and whether you're an admin.
- Actions you take in the console — approving a quote, recording an outcome, resolving an ambiguous match, revoking a connected AI assistant — recorded so the system and other users on your team can see what happened and when.
From RFQ senders (third parties)
- Name, email address, and any company, phone or contact details included in the message.
- The full text of the RFQ email thread — every message, not just the latest one — read so the system can work out what is being requested, including earlier back-and-forth about specification, quantity or price.
- Any attachments sent with the RFQ (for example, a specification sheet), read to extract the requested items. We do not currently keep a permanent, separate copy of attachment files after the request is processed — the information extracted from them (product, spec, quantity) is what ends up stored on the resulting quote record.
Automatically, from anyone who uses this website or the console
- Standard web server information (IP address, browser, device) collected by our hosting provider (Netlify) as part of serving any page.
- If you connect an AI assistant to your account, a record of each call it makes — see "Connecting an AI assistant" below for exactly what that does and does not include.
Social sign-in
If you choose to sign in with Google, we receive the identity Google confirms for you (name and email) via Supabase Auth's own sign-in flow. We never see or store your Google password.
3. Why we process this information
- To produce a quotation. The whole point of reading an RFQ thread is to match what was asked for against a catalogue and agreed prices, and draft a reply.
- To remember a customer. We keep a record of who has asked for quotes before (their contact details, what they've asked for, preferences noticed over time) so that a repeat request from the same person or company is faster and more consistent — the system doesn't have to relearn the same customer from scratch.
- To run the console. Signing in, permission checks, letting a team see and act on quotes together, and letting an account holder see and revoke what's connected to their account.
- To let a customer connect their own AI assistant to their own data, if they choose to — see below.
We have not yet documented a formal legal basis (for example, under GDPR or KVKK) for each of the above — that is exactly the kind of legal judgement this page is [TO BE COMPLETED] pending a lawyer's review, not something we are asserting here.
4. Where it goes — the systems that touch your data
Quotewright is built on several outside services, each doing one job. None of these are Quotewright-owned infrastructure — your data passes through all of the ones relevant to how you use the product:
| Provider | What it does with the data |
|---|---|
| Supabase | Hosts the database — accounts, quotes, customer records, catalogue and prices — and handles sign-in. |
| n8n Cloud | Runs the automated pipeline that watches the RFQ inbox, reads incoming email threads, and drives the quoting process end-to-end. |
| Anthropic (Claude) | The AI model that reads the RFQ text and attachment content and drafts the matching quote. The text of the RFQ — and, transiently, catalogue and pricing information needed to answer it — passes through Anthropic's API to do this. |
| Google / Gmail | The inbox an RFQ arrives in, and where the drafted reply sits until a human reviews and sends it. |
| Railway | Hosts the server that turns an approved quote into a branded PDF, and the server that lets a customer's AI assistant connect to their own data (see below). |
| Netlify | Hosts this website and the quote console. |
All of the above operate outside Türkiye. We have not yet confirmed and recorded the specific data-processing region for each provider, or what transfer safeguard (if any) applies to each one [TO BE COMPLETED — cross-border transfer register]. We chose each provider for the job it does, not to route around any particular country's rules, but we are not yet in a position to make a compliance claim about the transfers this creates.
We do not sell personal information to anyone, and we do not use RFQ or customer data for advertising.
5. Connecting an AI assistant (MCP)
A console user can optionally connect their own AI assistant — Claude Desktop, Claude Code, and others we may add — directly to their firm's own data, so they can ask it questions like "what did we quote this customer last time?" This is opt-in, per account, and works as follows:
- Read-only. The connection can look things up — search the catalogue, check a price, review quote history — and nothing else. It cannot send, edit or delete a quote.
- Scoped to your own firm's data only. The same access rules that protect the console protect this connection; it can never see another customer's catalogue, prices, quotes or customer list.
- Logged, without duplicating the sensitive part. Every call the assistant makes is recorded — which tool was called, when, whether it succeeded, and which fields the call filtered on (for example, that it searched by customer name) — but never the actual value of a price, a cost, or a customer's name. The log is there to answer "what did the AI read?", not to become a second, less-protected copy of your price book.
- Visible and revocable. You can see every assistant currently connected to your account — and when it was last used — on the console's Connections page, and revoke any of them at any time.
6. How long we keep information
- MCP access-log entries, and the record of a connection you've revoked, are automatically deleted after 90 days by a scheduled job. A connection that is still active is not deleted — it is current state, not a log entry.
- Quotes and customer records currently have no automatic deletion schedule. We want to be direct about this rather than imply a retention policy that doesn't exist: once a quote or customer record is created, it stays until someone deletes it by hand. The console gives an account holder three ways to do that for a customer's own data — forgetting the customer record only, anonymising their past quotes as well (the commercial numbers stay for reporting, but the customer's name and stored correspondence are removed), or deleting the customer and every one of their quotes outright. None of these currently reach every place a copy might exist — for example, the original Gmail thread, or n8n's own execution history — see "Your rights".
Setting a general retention period for quotes and customer records — rather than leaving deletion to a manual request — is on our list to fix, not a considered decision we're standing behind today.
7. How we try to keep information safe
- Each customer firm's data is isolated from every other customer firm's at the database level (row-level security) — one firm's console login, or their connected AI assistant, cannot read another firm's catalogue, prices or quotes.
- Where a password is used, it's handled by Supabase Auth directly; we don't store it ourselves.
- A human reviews every quote before it is sent. The system drafts a reply; it does not send on its own.
- No electronic system is unbreakable, and we don't claim ours is. If we become aware of a security incident affecting your data, we will tell you.
8. Your rights, and how to exercise them
Whichever law applies to you, you can ask us to tell you what we hold about you, correct it, get a copy of it, or delete it. In practice:
- If you have a console account, some of this is already self-service — the Customers page lets an admin forget, anonymise or delete a customer's data (see "How long we keep information"), and the Connections page lets you see and revoke any AI assistant connected to your account.
- If you sent an RFQ and never created an account, you can contact the company you emailed directly, or email us at alp.sisman@gmail.com and we will help route the request. Because we act on our customers' behalf for this data, we may need to confirm the request with them before acting on it.
- A dedicated privacy contact / data protection officer, and which specific authority you could complain to, are [TO BE COMPLETED] — both depend on the legal entity details in section 12, which have not been finalised yet.
We will respond to any request we can identify and verify, and we will say so plainly if there is a copy of your data we cannot currently reach end-to-end (see the retention section above) rather than claim otherwise.
9. Cookies
This website uses a small number of cookies. What they are, and how to control them, is covered in our separate Cookie Policy; a cookie-consent banner and preference control are available on every page of this site.
10. Children
Quotewright is a business tool for firms that send and receive commercial quotations. It is not directed at, and we do not knowingly collect information from, anyone under 18. If you believe a minor's information has reached us, contact us at the address below and we will remove it.
11. Changes to this notice
We will update this notice as our systems change — new processors, new data we collect, or a change to how long we keep something — and update the "Last updated" date above when we do. Given the gaps flagged throughout this page, we expect to revise it again once it has had legal review and once the legal-entity details below are confirmed.
12. Contact us
If you have questions about this notice, email us at alp.sisman@gmail.com.
Seam Studio operates Quotewright.
London / İstanbul
Legal entity name, registration number and registered address: [TO BE COMPLETED]
See also our Terms & Conditions and Cookie Policy.