Privacy Policy
Effective January 1, 2026 · Last updated September 3, 2026
This Privacy Policy describes how VexTech Technologies, LLC, a wholly owned subsidiary of 148FPS, LLC, a Texas limited liability company, doing business as Quotra Shop (“Quotra,” “we,” “us,” or “our”), collects, uses, shares, and protects personal data when you use our website at www.quotrashop.com and the Quotra Shop platform (collectively, the “Service”). This Policy also explains your rights regarding your personal data under applicable law, including the Texas Data Privacy and Security Act (“TDPSA”).
By using the Service, you acknowledge that you have read and understood this Privacy Policy.
1. Who We Are
Quotra Shop is a software-as-a-service platform operated by VexTech Technologies, LLC, a company organized under the laws of the State of Texas. Our principal place of business is in Texas.
2. Personal Data We Collect
We collect only the personal data reasonably necessary to provide and improve the Service. The categories of personal data we collect are as follows:
2.1 Account Information. When you create an account, we collect your name, email address, business name, and Employer Identification Number (EIN).
2.2 Business and Customer Data. You may enter business-related content into the Service, including quotes, jobs, invoices, product listings, and customer records (“User Content”). You control what User Content you enter, and we process it solely to provide the Service to you.
2.3 Payment Information. Stripe, Inc. processes subscription payments entirely. When you enter payment credentials (such as a credit or debit card number), that information is transmitted directly to Stripe. We do not receive, process, store, or have access to your payment card numbers or bank account details. We receive only a transaction confirmation and basic billing metadata (such as the last four digits of your card and transaction status) from Stripe.
2.4 Usage and Diagnostic Data. We automatically collect basic usage logs and diagnostic data, including IP address, browser type, device information, pages visited, and timestamps. This data helps us maintain, secure, and improve the Service.
2.5 Analytics Data. We use Google Analytics to understand how visitors interact with our website. Google Analytics collects information such as your IP address (anonymized where supported), browser type, referring pages, pages visited, and time spent on pages. Google Analytics places its own cookies on your device for this purpose. You can learn more about how Google uses data at https://policies.google.com/privacy and opt out of Google Analytics by installing the Google Analytics Opt-Out Browser Add-On at https://tools.google.com/dlpage/gaoptout.
3. How We Use Your Data
We use the personal data we collect for the following purposes:
- To provide, operate, and maintain the Service, including processing your subscription and delivering the features of your selected plan;
- To authenticate your identity and manage your account;
- To send transactional communications, such as account confirmations, invoices, subscription notices, and service-related alerts;
- To monitor, diagnose, and resolve technical issues;
- To analyze usage trends and improve the Service;
- To comply with legal obligations, enforce our terms of service, and protect the rights, safety, and property of Quotra, our users, and the public.
We do not use your personal data for targeted advertising. We do not sell your personal data to third parties. We do not engage in profiling that produces legal or similarly significant effects.
4. How We Share Your Data
We share personal data only as described below. We do not sell personal data.
4.1 Sub-Processors. We use a limited set of trusted third-party service providers (“sub-processors”) to operate the Service. Each sub-processor receives only the data necessary to perform its specific function:
- Stripe, Inc. — Payment processing. Stripe receives payment credentials directly from you. We receive only transaction confirmations and billing metadata from Stripe.
- Resend — Transactional email delivery. Resend receives recipient email addresses and message content necessary to deliver account-related emails on our behalf.
- Cloudflare R2 — File storage. Files you upload to the Service are stored on Cloudflare R2 infrastructure.
- Meilisearch — Product search indexing. Meilisearch indexes product data you enter into the Service to power search functionality within your account.
- Google Analytics — Website analytics. Google Analytics receives anonymized usage data as described in Section 2.5.
4.2 Error Diagnostics. Error and crash diagnostics are captured by our self-hosted infrastructure. No third-party error-tracking processor is used.
4.3 Legal Requirements. We may disclose personal data if required by law, regulation, legal process, or governmental request; or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others; to investigate fraud; or to respond to a lawful request from a public authority.
4.4 Business Transfers. In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or part of our assets, we may transfer personal data as part of that transaction. We will notify you of any such change in ownership or control of your personal data.
5. Cookies and Tracking Technologies
5.1 Session Cookie. We use a session cookie to keep you signed in to the Service. This cookie is essential to the Service and cannot be disabled without losing access to your account.
5.2 Google Analytics Cookies. If Google Analytics is enabled, Google places cookies on your device to collect usage data as described in Section 2.5. You may opt out of Google Analytics tracking as described in that section.
5.3 No Sale via Cookies. We do not use cookies to sell your personal data or to deliver targeted advertising.
6. Data Isolation and Security
6.1 Tenant Isolation. Every record in the Service is scoped to your business and isolated from other tenants by PostgreSQL row-level security, enforced at the database layer. No other customer can access your data through the Service.
6.2 Security Measures. We implement reasonable administrative, technical, and physical safeguards designed to protect personal data from unauthorized access, disclosure, alteration, and destruction. These include: (i) encryption of data in transit using TLS; (ii) encryption of data at rest; (iii) role-based access controls limiting internal access to personal data to personnel who require it for their job function; and (iv) regular review of our security practices.
6.3 No Guarantee. While we take commercially reasonable steps to protect your data, no transmission or storage method is completely secure, and we cannot guarantee absolute security.
7. Data Retention
7.1 Active Accounts. We retain your personal data for as long as your account remains active and as reasonably necessary to provide the Service to you.
7.2 After Cancellation. When you cancel your account, we retain your personal data for ninety (90) days after cancellation to allow for account reactivation or data export. After this period, we will permanently delete your personal data from our active systems, except where retention is required by law or necessary to resolve disputes or enforce our agreements.
7.3 Backup Systems. Residual copies of personal data may persist in encrypted backup systems for a limited period consistent with our backup retention cycle, after which they are automatically overwritten.
8. Your Privacy Rights
Under the Texas Data Privacy and Security Act and other applicable laws, you have the following rights regarding your personal data:
8.1 Right to Access. You have the right to confirm whether we are processing your personal data and to access that data.
8.2 Right to Correction. You have the right to request correction of inaccurate personal data we hold about you.
8.3 Right to Deletion. You have the right to request deletion of personal data you have provided to us or that we have collected about you.
8.4 Right to Data Portability. You have the right to obtain a copy of your personal data in a portable, readily usable format (such as CSV or JSON).
8.5 Right to Opt Out. You have the right to opt out of: (i) the sale of your personal data; (ii) targeted advertising; and (iii) profiling that produces legal or similarly significant effects. We do not currently engage in any of these activities.
8.6 Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge different prices, or provide a different quality of service because you exercised a right under this Policy.
8.7 Universal Opt-Out Signals. We recognize and honor Global Privacy Control (GPC) signals and other universal opt-out mechanisms recognized under applicable law. When we detect a GPC signal from your browser, we treat it as a valid opt-out request for the sale of personal data and targeted advertising.
8.8 How to Exercise Your Rights. To exercise any of the rights described above, contact us at privacy@quotrashop.com. We will respond to your request within forty-five (45) days of receipt. If we require additional time, we will notify you of the extension and the reason within the initial 45-day period. The total response period will not exceed ninety (90) days.
8.9 Appeals. If we decline your request, we will inform you of the reasons and provide instructions for how to appeal. You may appeal by contacting us at privacy@quotrashop.com with the subject line “Privacy Rights Appeal.” We will respond to your appeal within sixty (60) days. If your appeal is denied, you may contact the Texas Attorney General to submit a complaint at https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint.
9. Sensitive Data
We treat Employer Identification Numbers (EINs) as sensitive business identifiers. We collect EINs only when reasonably necessary to provide Service features that require business identification. We do not sell, share for advertising purposes, or otherwise disclose EINs to third parties except as required by law. Access to EINs within our systems is restricted to authorized personnel on a need-to-know basis.
We do not knowingly collect sensitive personal data as defined by the TDPSA (such as racial or ethnic origin, religious beliefs, health data, biometric data, precise geolocation, or sexual orientation).
10. Children’s Privacy
The Service is designed for use by businesses and is not directed at individuals under the age of eighteen (18). We do not knowingly collect personal data from children under thirteen (13). If we learn that we have collected personal data from a child under 13, we will promptly delete that data. If you believe a child under 13 has provided us with personal data, please contact us at privacy@quotrashop.com.
11. Breach Notification
If a security breach involves your personal data, we will notify affected users in accordance with the Texas Identity Theft Enforcement and Protection Act (Tex. Bus. & Com. Code Chapter 521) and any other applicable breach notification laws. We will provide notification without unreasonable delay and in no event later than sixty (60) days after we determine that a breach has occurred.
12. International Users
The Service is currently offered to users in the United States. If you access the Service from outside the United States, you understand that your personal data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
If we expand the Service to users in the European Economic Area or the United Kingdom in the future, we will update this Policy to include applicable disclosures under the General Data Protection Regulation (GDPR) and the UK GDPR, including lawful bases for processing, international transfer mechanisms, and region-specific rights.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will notify you by posting the updated Policy on this page and updating the “Last Updated” date above. Where required by law, we will provide additional notice (such as by email). Your continued use of the Service after any update constitutes your acceptance of the revised Policy.
14. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the State of Texas, without regard to its conflict-of-law principles.
15. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at: