Estiquote
Estimator Find builders Pricing Contact Get started free
Estimator Find builders Pricing Contact Get started free
Contents
  • 1. Who we are
  • 2. Data we collect
  • 3. How we use it
  • 4. Legal basis
  • 5. Who we share with
  • 6. How long we keep it
  • 7. Cookies
  • 8. Your rights
  • 9. Security
  • 10. Children
  • 11. Changes
  • 12. Contact & complaints
Legal

Privacy Policy

๐Ÿ“… Effective date: 1 May 2025
๐Ÿข Controller: SSH Ltd
๐Ÿ‡ฌ๐Ÿ‡ง Regulation: UK GDPR
This Privacy Policy explains what personal data Estiquote collects, how we use it, who we share it with, and what rights you have. We are committed to handling your data responsibly and in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Section 01

Who We Are

Data controller: SSH Ltd, trading as Estiquote.

SSH Ltd is registered in England and Wales and is registered with the Information Commissioner's Office (ICO) as a data controller. Our ICO registration number will be provided on request.

Contact for data matters: estiquoteofficial@gmail.com

Section 02

Data We Collect

2.1 Homeowner users
DataWhen collectedWhy
NameAccount registrationTo personalise your account
Email addressAccount registrationAccount access, notifications, billing
PostcodeRegistration or estimator useRegional pricing, postcode-level estimates (Pro)
Project dataEstimator useTo generate and save your estimates
Subscription planPaymentTo enforce plan features and billing
Stripe customer IDFirst paymentBilling management, subscription records
IP addressPlatform useSecurity, fraud prevention, analytics
Browser / device typePlatform useCompatibility and analytics
2.2 Builder / trade users
DataWhen collectedWhy
Business nameListing registrationPublished on your builder profile
Contact nameListing registrationInternal verification and communication
Email addressListing registrationAccount access, enquiry delivery, billing
Phone numberListing registrationPublished on profile; homeowner enquiries
Business postcodeListing registrationMap pin placement, search radius
Trade categoriesListing registrationSearch matching and profile display
Business descriptionListing registrationPublished on your profile
Insurance detailsVerification processVerification only โ€” not published
Trade qualificationsVerification processVerification only โ€” certificate numbers not published
Stripe customer IDFirst paymentBilling management
2.3 Enquiry data

When a homeowner submits an enquiry to a builder via the platform, we collect and forward the homeowner's name, email, phone number, postcode, and project description to the relevant builder. This data is processed via Formspree and is shared with the builder for the sole purpose of responding to the enquiry.

2.4 Data we do NOT collect
  • Full payment card numbers (processed exclusively by Stripe)
  • Precise GPS location (we use postcode-level location only)
  • Government ID or passport numbers
  • Sensitive personal data as defined under UK GDPR Article 9
Section 03

How We Use Your Data

PurposeData usedLegal basis
Providing the estimator toolPostcode, project inputsContract performance
Managing your accountName, email, planContract performance
Processing subscription paymentsEmail, Stripe IDContract performance
Delivering builder enquiriesHomeowner contact detailsContract performance / consent
Verifying builder listingsInsurance, qualificationsContract performance
Sending service emailsEmail addressContract performance
Sending material price alerts (Pro)Email addressContract performance
Security and fraud preventionIP address, usage dataLegitimate interests
Platform analytics and improvementUsage data, device dataLegitimate interests
Legal complianceAs requiredLegal obligation

We do not use your data for automated decision-making that produces legal or similarly significant effects on you. We do not use your data for targeted advertising on third-party platforms.

Section 04

Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases for processing your personal data:

  • Contract performance (Article 6(1)(b)): Processing necessary to provide the services you have signed up for, including generating estimates, managing subscriptions, and delivering enquiries.
  • Legitimate interests (Article 6(1)(f)): Security monitoring, fraud prevention, platform analytics, and improving the quality of our service. We have assessed these interests and determined they do not override your rights.
  • Legal obligation (Article 6(1)(c)): Where we are required by law to process or retain data, for example for tax and accounting purposes.
  • Consent (Article 6(1)(a)): Where you have explicitly opted in, for example to receive marketing emails. You may withdraw consent at any time.
Section 05

Who We Share Your Data With

We do not sell your personal data. We share data only with the following third parties, for the purposes described:

Third partyPurposeData shared
StripePayment processing and subscription managementEmail, billing address, subscription data
FormspreeProcessing form submissions (contact, signup, enquiries)Form submission content
Builder businessesDelivering homeowner enquiries to the relevant builderName, email, phone, postcode, project description
NetlifyWebsite hosting and serverless functionsAccess logs, IP addresses
OpenStreetMapMap tile deliveryApproximate location (postcode area)

All third-party processors are contractually required to process data only in accordance with our instructions and applicable data protection law. We carry out due diligence on all processors before use.

We may disclose your data to law enforcement or regulatory authorities if required to do so by law, or to protect the rights and safety of Estiquote users.

Section 06

How Long We Keep Your Data

Data typeRetention periodReason
Account data (homeowner)Duration of account + 2 yearsService continuity, legal claims
Account data (builder)Duration of subscription + 2 yearsService continuity, legal claims
Saved project estimatesUntil deleted by user or account closureUser-controlled
Billing records7 years from transaction dateHMRC / tax law requirement
Enquiry data6 months from submissionDispute resolution
Security logs (IP addresses)90 daysSecurity and fraud prevention
Verification documentsDuration of listing + 1 yearRegulatory compliance

After the applicable retention period, data is securely deleted or anonymised. You may request early deletion of your data subject to our legal retention obligations โ€” see Section 8.

Section 07

Cookies & Local Storage

Estiquote uses browser local storage (not traditional cookies) to store your session data, saved estimates, and plan status on your device. This data does not leave your browser unless you are logged in, in which case it is synchronised with our database.

โ„น๏ธ No advertising cookies
Estiquote does not use advertising cookies, tracking pixels, or third-party analytics cookies. We do not share browsing data with advertising networks. The only third-party scripts loaded on Estiquote are: Google Fonts (typography), Leaflet.js (maps), and Stripe.js (payment forms). Each of these may set their own cookies governed by their respective privacy policies.

Stripe may set cookies for fraud detection and session management when you visit a payment page. These are necessary for secure payment processing and cannot be disabled without breaking the payment flow. For more information, see Stripe's Privacy Policy.

Section 08

Your Rights

Under UK GDPR, you have the following rights in respect of your personal data:

๐Ÿ‘ Right of access
Request a copy of all personal data we hold about you (a Subject Access Request).
โœ๏ธ Right to rectification
Ask us to correct inaccurate or incomplete personal data.
๐Ÿ—‘ Right to erasure
Request deletion of your data where we no longer have a lawful basis to hold it.
โธ Right to restriction
Ask us to pause processing of your data in certain circumstances.
๐Ÿ“ฆ Right to portability
Receive your data in a structured, machine-readable format.
๐Ÿšซ Right to object
Object to processing based on legitimate interests, including profiling.
๐Ÿ”• Withdraw consent
Where processing is based on consent, you may withdraw it at any time.
๐Ÿค– Automated decisions
Not to be subject to solely automated decisions with legal effect. We do not make such decisions.

To exercise any of these rights, contact us at estiquoteofficial@gmail.com. We will respond within 30 days. We may need to verify your identity before processing your request.

If you are unhappy with how we have handled your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

Section 09

Security

We take the security of your personal data seriously. Our security measures include:

  • All data transmitted between your browser and Estiquote is encrypted using TLS (HTTPS).
  • Payment data is processed exclusively by Stripe, which is PCI DSS Level 1 certified. We do not store full card numbers.
  • Access to user data is restricted to authorised personnel only.
  • We use Netlify's secure hosting infrastructure with automatic SSL certificate management.
  • Passwords are never stored in plain text.

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you and the ICO within 72 hours of becoming aware of the breach, as required by UK GDPR Article 33.

Section 10

Children

Estiquote is intended for use by adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a child under 18, we will delete it promptly. If you believe we have inadvertently collected data from a child, please contact us at estiquoteofficial@gmail.com.

Section 11

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 14 days before the new policy takes effect. The current version is always available at estiquote.co.uk/privacy.html.

Section 12

Contact & Complaints

For all data protection queries, Subject Access Requests, or complaints:

  • Email: estiquoteofficial@gmail.com
  • Contact form: estiquote.co.uk/contact.html
  • Data controller: SSH Ltd, trading as Estiquote
  • Supervisory authority: Information Commissioner's Office โ€” ico.org.uk ยท 0303 123 1113
Estiquote
A trading brand of SSH Ltd
Registered in England and Wales
Privacy Policy
Effective: 1 May 2025
Terms of Service ยท Contact
Estiquote
ยฉ 2025 Estiquote Ltd ยท Privacy ยท Terms ยท Contact