Privacy Policy
Effective date: August 9, 2026 · Previous versions: August 6, 2026 · June 27, 2026
This Privacy Policy explains how Qoat, LLC ("Qoat", "we", "us") collects, uses, and protects information in connection with the Qoat operational alignment platform and the qoat.ai website (the "Service"). Questions: align@qoat.ai.
1. Information we collect
- Account & access-request information — name, email address, and company name you provide when requesting access or when an administrator creates your account.
- Organization & CRM data you enter — organizations, contacts, opportunities, and notes you add to the platform.
- Assessment data — responses, scores, and the analysis derived from them (drift, continuity, findings).
- Authentication data — a securely hashed (bcrypt) password and single-use, time-limited setup/reset tokens. We never store passwords in plain text.
- Photographs — images uploaded to document work or to accompany a quote request. See Photographs below, which covers them in full.
- Technical & usage data — server logs, IP addresses, and error/diagnostic reports used to operate, secure, and troubleshoot the Service.
2. Whose information this covers
Two kinds of people appear in this policy, and the difference matters.
- Our customers. Businesses that use Qoat, and the people at those businesses who hold accounts. We decide how their information is handled, and this policy governs it.
- Our customers' customers. When a business uses Qoat to run its own service delivery, information about its customers — names, addresses, and photographs of the properties it services — is entered into Qoat by that business. We hold and protect that information on that business's behalf and under its instructions. We do not use it for our own purposes, we do not sell it, and we do not use it to market anything to anyone.
If a property was serviced by a business that uses Qoat and you want to know what we hold about it, contact that business first — it is their record. You can also write to align@qoat.ai and we will work with them to answer you.
3. What we do not collect
- No payment or financial card data. We do not collect or store credit-card or bank-account information. Payments for invoiced professional-services engagements are processed by Square (see Service providers below); your card details go to Square, not to Qoat.
- No advertising or cross-site tracking cookies. The Service does not use third-party advertising trackers.
4. How we use information
- To provide, maintain, and improve the Service.
- To authenticate users and secure accounts.
- To send transactional email (e.g., welcome, password setup/reset). We do not send marketing email without consent.
- To monitor, debug, and protect the Service against abuse.
5. Photographs
Businesses using Qoat upload photographs to document work: the condition of a property before and after a job, and issues found on site. Some photographs are also submitted by people requesting a quote.
- Location data is removed from every photograph we display. Phone cameras embed precise GPS coordinates in photo files. Every version of a photograph shown in the platform or in a customer report has that data stripped out, along with the rest of the camera metadata.
- The originally uploaded file is kept unchanged, including its metadata. It is the archival record of what was actually submitted, and altering it would defeat the purpose of keeping evidence at all. It is never displayed in a browser and is reachable only by authorized staff.
- Photographs are not analyzed, profiled, or used to train anything. We do not run facial recognition or any other biometric process on them.
- Access is restricted. Photographs are visible to authorized Qoat staff and to the business that uploaded them. They are not public, are not indexed by search engines, and are not shared with anyone else except as described in this policy.
- Photographs should document property, not people. Businesses using Qoat are responsible for the photographs they upload and are instructed not to photograph people, identifying documents, or personal belongings beyond what documents the work.
6. Customer reports and link tracking
When a job is complete, the business can publish a Service Report — the property, the date, and the photographs documenting the work — and send its customer a private link to it.
- The link contains a long random code. It is not listed anywhere, is marked so search engines do not index it, and can be revoked by the business at any time.
- We record when the link is opened, and how many times. The business uses this to know whether their customer received and read the report. We record the fact and time of the view; we do not build a profile of the viewer or track them anywhere else.
- A published report is a fixed record. If something needs correcting, the business publishes a new report rather than altering one a customer has already seen.
7. Cookies & local storage
The platform stores your authentication token in your browser's local storage to keep you signed in; this is not a tracking cookie. The marketing site loads web fonts from Google Fonts, which may expose your IP address to Google when the page loads.
8. Service providers (sub-processors)
We share data with a limited set of vendors strictly to operate the Service:
- Railway — application hosting and PostgreSQL database.
- Resend — delivery of transactional email.
- Cloudflare — DNS for qoat.ai, and (via Cloudflare R2) storage of uploaded photographs.
- Sentry — error monitoring (configured to minimize personal data).
- Google Workspace — our business email (e.g., align@qoat.ai).
- Square — payment processing for invoiced professional-services engagements. Square receives the billing details needed to process your payment; Qoat does not receive your card or bank-account numbers.
9. Data retention
We do not delete work records on a timer. Evidence that supports a claim about completed work keeps its value for as long as the claim might be questioned, and a dispute can surface long after a job. Photographs older than a year are moved to lower-cost storage, which may add a short delay when retrieving a full-resolution original; thumbnails and report pages continue to load normally.
- Job photographs and Service Reports — kept while the business's account is active.
- Quote-request photographs — up to 24 months, unless the request became a customer record.
- Report view records — up to 24 months.
- Customer and account records — while the account is active, plus 90 days after closure, so a departing business has time to export its data.
- Invoices and payment records — 7 years, to meet tax and accounting obligations.
- Records of agreement to these terms — for the life of the account plus 7 years; their whole purpose is to show what was agreed and when.
- Audit logs — up to 24 months, except our records of deletions, which we keep for longer as proof that we acted on the request.
- Backups — our hosting provider keeps database backups on a rolling basis. Information you delete remains in those backups until they age out.
Deletion is an action, not a schedule. If a business asks us to delete a customer's records, we delete them and record that we did. If you are that customer, ask the business you dealt with, or write to align@qoat.ai and we will work with them.
10. Security
We protect data with encryption in transit (TLS), hashed credentials (bcrypt), role-based access controls, per-organization data scoping, rate-limiting on authentication endpoints, and regular database backups. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
11. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information. To make a request, contact align@qoat.ai.
If your information reached us through a business that uses Qoat — for example, a company that cleaned or serviced your property — that business controls the record. Ask them first; if you come to us, we will pass the request on and work with them to complete it.
12. International data transfers
Our providers may process data in the United States and other countries.
13. Children
The Service is intended for business use and is not directed to children under 16. We do not knowingly collect information from children.
14. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the effective date and, where appropriate, by notice. The current version is maintained under version control.
15. Contact
Qoat, LLC · align@qoat.ai