QVUNTA
BUILD BETTER, MANAGE SMARTER

Privacy Policy

Last updated 16 August 2026

QVUNTA is project-management software for construction companies. A contracting company (“the Company”) uses QVUNTA to run its projects, record site evidence, control costs and produce formal documents. Its customers (“Clients”) receive a read-only portal.

Who controls your data. Much of the personal data in QVUNTA is entered by a Company about other people — its staff, and its Clients and their contacts. For that data the Company is the controller and QVUNTA is the processor acting on its instructions. QVUNTA is the controller only for the account data needed to operate the service itself. If a Company holds information about you and you want it changed or removed, contact that Company; we will assist them.

1. What we collect, and why

CategoryWhat it isWhy
Identity & accountName, email address, account ID, password (stored hashed by Firebase Authentication), optional profile photoTo sign you in and to attribute actions to a person in audit trails and on documents
Company & membershipCompany name, commercial registration and VAT numbers, address, phone, logo and stamp, your role, membership statusTo separate one company's data from another's, to decide what you may do, and to put a letterhead on generated documents
Client recordsClient name, contact person, email, phone, address, portal accessTo address documents and to give a Client access to their own project
Project contentProjects, tasks, comments, issue reports, material requests, site updates, timeline entriesCore functionality
MessagesMessages between Company staff and Clients, with author and timeProject communication
Photos & filesSite evidence photographs, handover photographs, item images, attachments, signature images, scanned signed copiesEvidence of work done and supporting documents. Photographs may incidentally include people on site
Financial recordsCost items, quotations, purchase orders, deliveries, vendor payments, client receipts, contract values, variation amounts, VAT, company bank account detailsCost control and commercial documents
Audit recordsWho did what, when, what changed, and any stated reasonSo that a contract, certificate or approval can be relied on later
Generated documentsPDFs containing names, signatures, company identifiers and figuresThe service's deliverable
EmailRecipient address, subject, body, PDF attachment, delivery statusTo send a document when you choose to
Notifications & settingsIn-app notifications, theme, language, regionTo run the app the way you set it
What we do not collect. QVUNTA contains no analytics SDK, no crash-reporting SDK, no advertising SDK and no advertising identifier. We do not collect your location. We do not use push-notification tokens. We do not track you across other apps or websites, and we do not sell or share personal data with data brokers or advertisers. Biometric app-unlock, if you enable it, is handled entirely by your device — your fingerprint or face never reaches us.

2. Where it is processed

QVUNTA runs on Google Firebase. These are our only sub-processors:

Sub-processorPurpose
Firebase AuthenticationSign-in and sessions
Cloud FirestorePrimary datastore
Cloud Storage for FirebasePhotographs, attachments, generated PDFs
Cloud FunctionsServer-side logic, document generation
Google Secret ManagerBackend credentials
Gmail APISending a document by email when you ask
Google Sign-InOptional sign-in method

Google processes this data on infrastructure that may be located outside your country, including in the United States, under Google's own terms as our processor. Using QVUNTA means data may be processed internationally in that way.

3. How it is protected

4. How long it is kept

5. Deleting your account

You can delete your QVUNTA account from inside the app: Settings → Delete account. There is a fuller explanation, including what happens if you can no longer sign in, on our account deletion page.

Deleted: your profile (name, email, photo, preferences), your sign-in credentials and Firebase Authentication account, your company and project access, and your device session.

Anonymised: your identity is detached from audit records — the entry keeps what happened and when, and your name and account ID are replaced with a permanent non-identifying marker.

Retained: the Company's own business records — projects, contracts, certificates, variation orders, handovers, financial entries and documents already issued. These are the Company's records rather than yours, and deleting an account does not erase them. Where your name is already printed inside a document that has been issued to a Client or an authority, that document cannot be altered.

If you are the owner of a company, you must first transfer ownership to another active member of that company. This exists so a company is never left with no one able to administer it.

6. Your choices

7. Children

QVUNTA is business software and is not directed at children. We do not knowingly collect data from children.

8. Changes

If this policy changes we will update the date at the top of this page. Material changes affecting how we handle personal data will be signalled in the app.

9. Contact

Questions about this policy or about your data: privacy@qvunta.com. See also our support page.