Privacy · your data

How QuoteRail handles your data and your retail workspace.

Plain language on what we collect when you wire QuoteRail into your trade-in flow, how long we keep it, and the third parties we hand it to. No legalese for the sake of it.

Last updated: August 18, 2026

01

The service

QuoteRailis a trade-in pricing and routing tool for wireless retailers. We run the live wholesale-direct stream, score incoming trade-ins against your condition grades, and route each device to the buyer lane with the highest net-after-fee payout. The product runs in your browser on top of a per-workspace tenant — your data is yours, scoped to that tenant, and never pooled with other retailers' rows.

This page covers what that means for the data we touch. The companion agreement at /terms covers the rules we operate under.

02

What we collect

Workspace + account data
The email you sign up with, the workspace name you pick, the seat assignments, and the auth/session tokens that keep you signed in. We store the minimum we need to bill you and authenticate the session.
Quote + routing rows
Every (device, condition, serial) tuple a quote is built from, the MarketObservation rows the quote pulled from, the buyer lane it routed to, and the timestamp. Stored so finance and ops can replay any quote and audit why a device went where it went.
Stream reads (read-only)
We read from the live resale-market stream — Back Market, Decluttr, Swappa, and any warehouse opponent you wire in. We do NOT write tenant-derived rows back into that stream; your quotes stay in your tenant.
Support + billing correspondence
Anything you send us through the contact form, email, or chat support. We retain it for as long as your workspace is active plus a wind-down window so we can resolve disputes about historical quotes.
03

How long we keep it

Quote and routing rows stay for the life of the workspace plus 24 months after cancellation — long enough for finance to close the books on a contested trade-in, short enough that we're not warehousing forever. Workspace + account data is deleted within 30 days of account erasure. Support correspondence rolls off after 36 months. Backups cycle out on a 90-day rotation, so true deletion completes no later than that window after the primary row is removed.

04

Third parties we share with

Auth + session
Our auth provider runs the sign-in flow and stores hashed credentials and session tokens — credentials never touch our database.
Email delivery
Transactional mail (sign-up confirmation, password reset, quote receipts) is routed through our deliverability partner. No marketing email is sent to anyone who has not opted in.
Resale-market stream
We READ from Back Market, Decluttr, Swappa, and wired-in warehouse opponents. We do NOT push tenant rows or per-retailer observations back upstream — the stream sees none of your quote decisions.
Hosting + storage
Application runtime, database, and object storage sit on a single cloud provider with at-rest encryption and TLS in transit. Backups are encrypted and stored in the same region as your primary tenant.
05

Acceptable use

QuoteRail exists to price and route trade-ins on behalf of a single retail tenant. You agree not to use it to scrape or republish the underlying resale- market stream, not to inject quotes that you did not actually build against a real trade-in, and not to share workspace credentials across teams that should be sitting on separate seats. We will suspend a workspace that is abusing the stream or the routing surface, and we will surface what we found before we do.

Privacy question we did not cover?

Reach the team