Privacy Policy
Quick Docket

Last updated: 01/09/2026

1. Who We Are

This Privacy Policy explains how Quick Docket (“Quick Docket”, “we”, “us”, “our”), collects and uses personal data. It applies to our marketing website and to the Quick Docket application (together, the “Service”).

2. Scope of This Policy

Quick Docket is a business-to-business tool. Our business customers (“Customers”) may upload their own data, including personal data about their staff or contacts, into the application in the course of using it (“Customer Data”). In relation to Customer Data, Customer is the data controller and Quick Docket acts only as a data processor, under the terms of our Data Processing Agreement — that relationship is not covered by this Policy.

This Policy instead covers personal data that Quick Docket collects and controls directly: about visitors to our website, and about individuals who register for or use an Account (“Account Holders” and “Authorized Users”).

3. Personal Data We Collect

3.1 Website visitors

When you visit our marketing website, we collect limited, aggregated analytics data via Umami — a privacy-focused analytics tool that does not use tracking cookies and does not track individuals across different websites. This may include page views, referring pages, general device/browser type, and an approximate location derived from IP address. We cannot identify you individually from this data.

3.2 Account Holders and Authorized Users

When you or your organisation registers for the Service, we collect:

  • name
  • work email address
  • job title (if provided)
  • password (stored in hashed form)
  • records of login activity and IP address for security purposes

3.3 Billing contacts

If you are responsible for billing, we collect your name and email address for invoicing purposes. Payment card details are collected and processed directly by our payment processor, Stripe — we do not receive or store full card details ourselves.

3.4 Support and correspondence

If you contact us for support or otherwise, we keep a record of that correspondence and any personal data included in it.

4. Cookies

We use a small number of essential cookies, strictly necessary to operate the Service:

  1. a login/session cookie, used to keep you signed in
  2. an application settings cookie, used to remember your preferences within the app

These cookies do not track you across other websites and are not used for advertising. As noted above, our website analytics (Umami) does not rely on tracking cookies. We do not use any marketing or advertising cookies.

5. How We Use Personal Data, and Our Legal Basis

  1. To provide, maintain, and secure the Service — necessary to perform our contract with Customer.
  2. To process payments and maintain billing records — necessary to perform our contract, and to comply with our legal obligations (e.g. tax records).
  3. To monitor and improve the performance and security of the Service and our website, including via analytics — our legitimate interest in operating a secure, reliable Service.
  4. To respond to support requests and other correspondence — necessary to perform our contract, or our legitimate interest in providing good support.

We do not use personal data for marketing profiling, and we do not sell personal data to third parties.

6. Who We Share Data With

We share personal data only with the following categories of recipient, each acting under appropriate contractual safeguards:

  1. Stripe — to process payments.
  2. Hetzner Online GmbH — our hosting provider, based in Germany, where our servers and databases are located.
  3. Amazon Web Services (AWS) — we use Amazon S3 to store encrypted backups of the Service. These backups are stored in the AWS Ireland (EU) region. The backups are encrypted and are not stored in a readable form.
  4. Umami — our website analytics provider, as described in Section 3.1.
  5. Microsoft — we use Microsoft 365 for business email and related services. Personal data may be processed through Microsoft 365 when we communicate with users, customers, or other business contacts.
  6. Sentry — we use Sentry to monitor and diagnose errors and other technical issues in the Service. Sentry may process technical information associated with errors, such as IP addresses, user identifiers, request information, and error or diagnostic data.

We do not otherwise share personal data with third parties, except where required by law or to protect our legal rights.

7. International Transfers

Our infrastructure and service providers are, with one exception, hosted within the EU or UK. Our payment processor, Stripe, may process data outside the UK/EEA; where this occurs, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised under UK and EU data protection law.

8. Data Retention

We retain Account Holder and Authorized User data for as long as the relevant Account remains active. Following cancellation or termination of a subscription, data is retained and deleted in line with the timelines set out in our Terms of Service — in summary, available for export for a limited period after cancellation, with any residual copies in backups or caches deleted within 90 days. Billing records may be retained for longer where required by law (e.g. tax rules).

9. Your Rights

Depending on your location, you have rights under UK GDPR and/or the EU GDPR in respect of your personal data, including the right to:

  1. access the personal data we hold about you
  2. request correction of inaccurate data
  3. request erasure of your data, subject to any legal or contractual retention requirements
  4. object to, or request restriction of, certain processing
  5. request a portable copy of your data
  6. lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in Ireland, the Data Protection Commission (DPC).

To exercise any of these rights, please contact us using the details in Section 13.

10. Children

The Service is a business tool intended for use by working professionals and is not directed at, or intended for use by, children. We do not knowingly collect personal data from children.

11. Security

We maintain reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, or misuse, including access controls and regular backups. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice, such as by email or a notice on our website, before the change takes effect.

13. Contact

Quick Docket