Privacy Policy
Last updated 15 September 2026
This document is being finalised ahead of public launch. For any question in the meantime, email hello@getquits.uk.
This policy explains how Eben Owen, trading as Quits (“Quits”, “we”) handles personal data when you use our website and application (the “Service”). We are the data controller for the personal data described in section 2. Our address is [trading address — required before public launch]. For any privacy question or to exercise your rights, contact hello@getquits.uk.
This policy is written to meet the UK GDPR and the Data Protection Act 2018. If you are in the EEA, equivalent rights apply under the EU GDPR.
1. Roles: who controls what
For your account and billing data we are the controller. For the client and invoice data you enter (your customers’ names, emails, addresses and the amounts you bill them), you are the controller and we are your processor. We only process it on your instructions to run the Service. The data-processing terms in section 8 apply to that data.
2. What we collect
| Category | Examples |
|---|---|
| Account | Email address, authentication tokens, sign-in timestamps |
| Business profile | Business name, address, contact email, logo, your bank account name, sort code, account number and (optionally) IBAN/BIC |
| Billing | Plan, Stripe customer and subscription identifiers, billing period. Card details are collected and stored by Stripe, not by us. |
| Client & invoice data | Data you enter about your clients and the invoices, line items and payment records you create |
| Technical | IP address, browser type, pages viewed and error logs, collected by our hosting providers to keep the Service secure and working |
We do not use advertising or third-party analytics trackers. We do not sell personal data.
3. Why we use it and our legal bases
- To provide the Service (create your account, store and render your invoices, send invoice emails you trigger): performance of our contract with you.
- To take payment for a paid plan: performance of our contract. Stripe also processes data under its own responsibility to meet legal and anti-fraud obligations.
- To secure and improve the Service (logging, abuse prevention, debugging, rate limiting): our legitimate interest in running a safe, reliable product.
- To send marketing emails: two legal bases, depending on the campaign. Free-plan users may occasionally be sent product news under our legitimate interest in telling existing users about Quits itself, relying on the “soft opt-in” rule in UK PECR. On any plan, if you tick “send me marketing emails” in Settings, that is your explicit consent and we may also send you broader campaigns on that basis. Either way, every marketing email carries a one-click unsubscribe link and you can turn marketing off entirely in Settings at any time. This is separate from service email about your own account and invoices, which we send regardless of these preferences.
- To comply with law (tax, accounting, responding to lawful requests): legal obligation.
- To run the optional AI features (drafting an invoice from your text, reading a receipt you upload): when you choose to use them, that specific text or image is sent to Anthropic for processing and is not used to train their models. Our legitimate interest in offering the feature; don't use it for content you can't share with a processor.
4. Who we share it with
We use the following processors and service providers:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file hosting | EU / UK region |
| Vercel | Application hosting and content delivery | EU / global edge |
| Stripe | Subscription billing and card processing | EU / US (SCCs) |
| Resend | Transactional email delivery | EU / US (SCCs) |
| Anthropic | AI invoice drafting and receipt scanning (opt-in features) | US (SCCs) |
| Sentry | Error monitoring: technical crash reports, not invoice content | EU / US (SCCs) |
We may also disclose data if required by law, to establish or defend legal claims, or as part of a merger or sale of the business (in which case we will tell you).
5. International transfers
We host data in the UK/EU where possible. Where a provider processes data outside the UK or EEA (for example Stripe, Resend or Anthropic in the US), that transfer is covered by the UK International Data Transfer Agreement or Addendum, the EU Standard Contractual Clauses, or an adequacy decision.
6. How long we keep it
- Account and content data: for as long as your account is open.
- After you delete your account: we delete or irreversibly anonymise personal data within 30 days, except where we must keep records to meet legal obligations (for example, billing records kept for up to 6 years for tax purposes).
- Backups: rotated out within 30 days.
- Security logs: typically up to 90 days.
7. Your rights
You have the right to access, correct, delete, restrict or object to processing of your personal data, to data portability and to withdraw consent where processing is based on consent. To exercise any of these, email hello@getquits.uk. You can also access and edit most of your data directly in the app and export or delete your account from Settings.
If you are unhappy with how we handle your data you can complain to the UK Information Commissioner’s Office at ico.org.uk, though we’d appreciate the chance to help first.
8. Data processing terms (for client data you enter)
When we act as your processor:
- we process client data only on your documented instructions, which are given through your use of the Service;
- persons authorised to process the data are bound by confidentiality;
- we apply the technical and organisational security measures in section 9;
- we use the sub-processors listed in section 4; we will give you a way to object to new sub-processors before they start;
- we assist you, taking into account the nature of processing, with data subject requests and with your security, breach-notification and impact-assessment obligations;
- on the end of your account we delete client data in line with section 6 unless law requires retention;
- we make available the information needed to demonstrate compliance and allow reasonable audits;
- we will notify you without undue delay after becoming aware of a personal data breach affecting your client data.
9. Security
We protect data with encryption in transit (HTTPS), access controls and row-level database security so each account can only reach its own data, least-privilege service credentials, security headers, rate limiting on sensitive endpoints and audited hosting providers. Your bank details are stored to display on your invoices; treat the shareable invoice links as semi-public and only send them to the intended recipient. No system is perfectly secure. You are responsible for keeping your own device and email account secure.
10. Cookies
Quits uses only strictly necessary cookies: a secure session cookie to keep you signed in, a cookie that remembers which account you are viewing if someone has shared theirs with you, short-lived cookies used during sign-in and a cookie that remembers you have seen our cookie notice. These are required for the Service to work, so we do not ask for consent to set them. We do not use advertising or analytics cookies and we do not load third-party trackers. You can see the full list any time from the “Cookies” link in the site footer.
11. Children
The Service is for business use and is not directed at anyone under 18.
12. Changes
We may update this policy. If a change is material we will notify you by email or in the app. The “last updated” date above always reflects the current version.
See also our Terms of Service.