cotiza.io

Back to cotiza.io

Privacy Policy

Effective August 26, 2026

This policy explains what MAVILA Ventures LLC ("we") does with personal data in cotiza.io.

It covers two different relationships, and the difference matters: data about you, our customer, and data about your clients, which you put into the service and we handle on your behalf.

1. Two roles

For data about you and your team — your name, email, role, billing details, how you use the product — we decide why and how it is processed. Under laws such as the GDPR we are the controller.

For data about your clients — the people you quote to — you decide why and how it is processed. We only act on your instructions, which you give by using the product. There we are the processor and you are the controller.

Practically, that means requests from your clients about their data should reach you, not us. If one reaches us directly, we will refer them to you rather than act on it ourselves.

2. What we collect

Directly from you when you sign up and use the service:

  • Account data: name, email address, password (stored only as a hash), organisation name, subdomain, role.
  • Billing data: plan, subscription status, billing history. Payment card details are handled by Stripe and never reach our systems.
  • Content you create: projects, properties, floor plans, quotes, payment schedules, documents and images.
  • Client records you enter: names, contact details, identification numbers, and anything else you choose to store about the people you quote to.
  • Technical data: IP address, browser and device information, pages visited, timestamps, and error diagnostics.
  • Communications: messages you send us for support.

3. Why we use it

We use personal data to:

  • provide the service, including authentication, multi-tenant separation and the features of your plan;
  • process subscriptions and payments, and send billing notices;
  • send transactional email — confirmations, invitations, password resets, quote notifications;
  • keep the service secure: rate limiting, abuse prevention, audit records and error diagnosis;
  • support you when you ask for help;
  • meet legal and accounting obligations.

4. What we do not do

We do not sell personal data, and we do not share it with third parties for their own marketing.

We do not use your content or your clients’ data to train machine-learning models.

We do not run advertising or third-party analytics trackers on the application.

5. Legal bases

Where the GDPR or similar law applies, we rely on: performance of a contract, for providing the service you subscribed to; legitimate interests, for security, error diagnosis and improving the product; legal obligation, for tax and accounting records; and consent, where we specifically ask for it.

Where we act as processor for your clients’ data, the legal basis for that processing is yours to establish, not ours.

6. Service providers

We use a small number of providers to run the service. Each processes data only to provide its function to us:

  • Vercel — application hosting and content delivery (United States).
  • Supabase — database, authentication and file storage (United States).
  • Stripe — subscription billing and payment processing. Card details go directly to Stripe; we never receive or store them.
  • Resend — transactional email, such as confirmations, invitations and password resets.
  • Upstash — rate limiting. Stores request counters keyed by IP address or account, not content.
  • Sentry — error reporting, used to diagnose failures. Configured to record technical context, not the content of your records.

7. International transfers

We are based in the United States and our providers are primarily in the United States. If you are in the European Economic Area, the United Kingdom, or another region with transfer restrictions, using the service involves transferring your data to the United States.

Where required, those transfers rely on the European Commission’s Standard Contractual Clauses or another approved mechanism.

8. Cookies

We use two kinds of cookie, both set by us and neither used for tracking:

  • Session cookies that keep you signed in. Without them, authentication cannot work.
  • A language preference cookie that remembers whether you chose Spanish or English.

9. How long we keep data

We keep your account and content for as long as your organisation exists, including while it is in read-only state, so that nothing is lost if a subscription lapses and later resumes.

After an account is closed we keep data for a limited period so it can be recovered or exported, then delete it. Billing records are kept longer where tax and accounting law requires it.

Security and audit records are kept for a limited period appropriate to their purpose.

10. Security

Data is encrypted in transit. Access between organisations is separated at the database level, so one organisation cannot read another’s records. Passwords are stored as hashes. Administrative access to production systems is restricted.

No system is immune. If a breach affects your personal data and the law requires notification, we will notify you and the relevant authority within the required timeframe.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format.

Much of this you can do yourself in the application. For anything else, write to legal@cotiza.io and we will respond within the period the applicable law sets.

You may also complain to your local data protection authority.

12. Children

The service is for business use and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.

13. Changes

We may update this policy. If a change is material we will notify you at the email address on your account, or in the application, before it takes effect. The effective date above always reflects the current version.

14. Contact

MAVILA Ventures LLC, Delaware, United States.

Privacy questions and rights requests: legal@cotiza.io.