Your Data Is Your Business — We Treat It That Way
QuickEstimate handles sensitive business information every day: client details, project costs, pricing strategies, and financial records. We take that responsibility seriously. Our platform is built from the ground up with security as a core requirement, not an afterthought.
This page explains exactly how we protect your data — from the moment you log in to the way your estimates are stored, transmitted, and backed up. No technical jargon, just clear answers.
Our Security Measures, Explained
Here's a transparent look at the key security layers QuickEstimate has in place to keep your account and business data protected at all times.
Encryption In Transit and At Rest
All data moving between your browser and QuickEstimate's servers is encrypted using industry-standard protocols. Your stored data is equally protected.
- All connections use TLS 1.2 or higher — the same standard used by banks and payment processors
- Data at rest is encrypted using AES-256, one of the strongest encryption algorithms available
- Passwords are never stored in plain text — they are hashed using bcrypt before being saved
- SSL certificates are automatically renewed so there's no lapse in protection
Even in the unlikely event of a breach at the infrastructure level, encrypted data cannot be read without the decryption keys, which are stored separately and securely.
Secure Cloud Infrastructure
QuickEstimate is hosted on enterprise-grade cloud infrastructure with multiple layers of physical and network security built in.
- Hosted on ISO 27001-certified data centres with 24/7 physical security and access controls
- Servers are isolated in a private virtual network — not publicly accessible by default
- Firewalls and intrusion detection systems monitor all traffic in real time
- Regular third-party penetration testing is carried out to identify and fix vulnerabilities
- Automatic security patches are applied to keep server software up to date
Account Access Controls
We give you the tools to control who can access your QuickEstimate account and what they can see or do within it.
- Two-factor authentication (2FA) available for all accounts — strongly recommended for all users
- Role-based permissions let you control what team members can view or edit
- Session timeouts automatically log out inactive users after a set period
- Login activity logs let you review recent sign-ins and flag anything suspicious
- Suspicious login attempts trigger account alerts and optional temporary lockouts
If you ever suspect unauthorised access to your account, you can immediately revoke all active sessions from the Security tab in your account settings.
Automated Backups and Data Recovery
Your data is backed up automatically and continuously so that nothing is ever lost, even in the event of an unexpected system failure.
- Full database backups run daily and are stored in geographically separate locations
- Incremental backups capture changes every hour to minimise potential data loss
- Backups are encrypted and tested regularly to confirm they can be restored successfully
- In the event of data loss, recovery can be completed within a defined recovery time objective (RTO)
Backup retention periods vary by plan. Enterprise plans include extended backup history. See your plan details or contact support for specifics.
Data Privacy and Compliance
QuickEstimate is built to comply with major data protection regulations and to respect your rights over the data you store with us.
- Compliant with GDPR (EU), UK GDPR, and Australian Privacy Act requirements
- We never sell your data or use your business information for advertising purposes
- You own your data — it can be exported in full at any time from your account settings
- On account closure, your data is permanently deleted within 30 days upon request
- Sub-processors and third-party integrations are vetted and listed in our privacy policy
Incident Response and Breach Notification
Despite robust preventive measures, we maintain a clear, tested response plan for security incidents so we can act quickly and communicate transparently.
- A dedicated security incident response team is on call around the clock
- Affected users are notified within 72 hours of a confirmed breach — in line with GDPR requirements
- Notifications include a clear description of what data was affected and what steps to take
- Post-incident reports are published openly to explain what happened and how it was resolved
- We work with independent security researchers through a responsible disclosure programme
Our goal is always to be faster, clearer, and more transparent than required. If something goes wrong, you'll hear from us promptly and honestly.
What We Never Do With Your Data
Some things are non-negotiable. Here is a clear list of data practices QuickEstimate will never engage in:
- We never sell your data to third parties under any circumstances
- We never use your estimates, pricing, or client information for advertising or profiling
- We never share your data with other QuickEstimate customers
- We never access your account or data without your explicit permission, except as required by law
- We never retain your data after account closure beyond the agreed deletion window
- We never store payment card details — all payments are handled by PCI-DSS-compliant processors
Your trust is foundational to our business. These commitments are written into our terms of service, not just our marketing.
Best Practices to Protect Your Own Account
Security is a shared responsibility. Here's what you can do on your end to keep your QuickEstimate account as secure as possible.
Use a Strong, Unique Password
Use a password that is at least 12 characters long and not reused from another site. A password manager makes this easy to manage across all your accounts.
Enable Two-Factor Authentication
2FA ensures that even if your password is compromised, an attacker still cannot access your account without your second device. Enable it in Account Settings today.
Assign Roles Carefully
Only grant team members the level of access they actually need. Use read-only roles for staff who don't need to edit estimates or client records.
Review Login Activity Regularly
Check your login history periodically from the Security tab. If you see a login you don't recognise, change your password and revoke all sessions immediately.
Be Alert to Phishing Emails
QuickEstimate will never ask for your password by email. If you receive a suspicious message claiming to be from us, do not click any links — report it to support.
Log Out on Shared Devices
Always sign out of QuickEstimate when using a shared or public computer. You can also remotely revoke all sessions from your account security settings.
Frequently Asked Questions
Your data is stored in secure data centres located in the UK and EU by default. Enterprise customers can request data residency in specific regions. All data centres are ISO 27001-certified with physical access controls, CCTV, and 24/7 security personnel.
QuickEstimate staff do not routinely access your account data. In limited circumstances — such as investigating a reported bug or responding to a support request you've submitted — a support engineer may access your account with your explicit permission. All such access is logged and auditable.
Yes. QuickEstimate is fully compliant with GDPR and UK GDPR. We act as a data processor on your behalf, and you remain the data controller for the information you store about your clients. Our Data Processing Agreement (DPA) is available on request and outlines our obligations in detail.
If you cancel your QuickEstimate account, your data remains accessible during any remaining paid period. After that, your data is retained for 30 days in case you change your mind, then permanently deleted. You can request immediate deletion at any time by contacting our support team.
QuickEstimate does not store any payment card details on its own servers. All payment processing is handled by Stripe, a PCI DSS Level 1-certified payment processor — the highest level of certification available in the payments industry. Only tokenised references are stored, never raw card data.
We operate a responsible disclosure programme. If you discover a potential security vulnerability in QuickEstimate, please email security@quickestimate.io with a description of the issue. We aim to acknowledge all reports within 24 hours and will keep you updated throughout the investigation process.
Still Have Security Questions?
Our team is happy to answer any questions about how we protect your data.