Privacy Policy

Version 1.0 · Last updated 15 August 2026 · Effective immediately for new accounts

Who we are and what this covers

Kwota is a sales quota, commission, and forecasting tool operated by Kwota (“Kwota”, “we”, “us”) from Michigan, United States. This policy explains what personal information we handle, why, and what rights you have over it.

It applies to our website at usekwota.com, the Kwota web application, and our email communications.

The short version. We collect what the product needs to work: your account details and the sales data you or your employer put into it. We never sell it, never share it with advertisers, and never use it to train AI models. You can export it or ask us to delete it at any time.

Two different relationships: our customers and their people

This distinction matters, because most people in Kwota did not sign up for it — their employer did.

When your organization is the customer

If your company subscribes to Kwota, your company decides what sales data goes in, who can see it, and how long it stays. In data-protection terms your company is the controller and Kwota is the processor. We handle that data on your company’s instructions, not for our own purposes.

When you were invited by your employer

If a manager invited you, your quota, pipeline, and commission information belongs to your employer’s account. We will help you with access or correction requests, but for deletion of company sales records we will direct you to your employer, because that data is theirs to control. We will tell you plainly when that is the case rather than ignoring the request.

When we are the controller

For our own website visitors, account signups, billing records, support conversations, and product analytics, Kwota is the controller and this policy governs directly.

What we collect

CategoryExamplesWhere it comes from
AccountName, work email, company name, role, password hash, last login timeYou, or the colleague who invited you
Sales dataOpportunities, amounts, close dates, stages, notes, commit promises, quotas, commission plans, forecast snapshots, quarter historyEntered by you, or synced from Salesforce
SalesforceOpportunity records owned by the connecting user, plus OAuth tokens and your Salesforce user ID and emailSalesforce, only if you connect it
BillingSubscription plan, seat count, status, Stripe customer IDStripe
UsagePages viewed, features used, device and browser type, approximate location from IP, session recordings of app usageCollected automatically
SupportEmails you send us and our repliesYou

We do not collect payment card numbers. Card details go directly to Stripe and never touch our servers.

We do not intentionally collect special category data — health, biometrics, race, religion, political views, or similar. Please do not put that kind of information into free-text fields such as deal notes.

Why we use it, and our legal basis

PurposeLegal basis (UK/EU)
Providing the product: accounts, pipeline, attainment and commission calculations, Salesforce syncPerformance of a contract
Service emails: invitations, password resets, billing notices, security alertsPerformance of a contract
Taking payment and keeping financial recordsContract, and legal obligation
Product analytics and session recordings to improve KwotaLegitimate interests, balanced against your privacy
Security, fraud prevention, abuse investigationLegitimate interests
Responding to support requestsLegitimate interests
Marketing emails to people who ask for themConsent, withdrawable at any time

We do not carry out automated decision-making that produces legal or similarly significant effects. Kwota calculates figures from plans your employer configures; it does not make employment decisions.

What we never do

Who can see what, inside your organization

Kwota enforces access by role at the database level, not merely by hiding things in the interface:

If you are a rep, assume your manager can see your Kwota pipeline and compensation figures. That is how the product is designed to work.

Sub-processors

We use a small number of vendors to run Kwota. Each has access only to what its function requires, and each is bound by a data processing agreement.

ProviderPurposeLocation
SupabaseDatabase, authentication, server functionsUnited States
NetlifyWebsite and application hostingUnited States
StripeSubscription billing and paymentsUnited States
ResendTransactional emailUnited States
PostHogProduct analytics and session recordingUnited States
SalesforceCRM sync, only where a user connects itPer your Salesforce agreement

If we add or replace a sub-processor that handles customer data, we will update this list and email account admins at least 30 days beforehand, so you have time to object.

International transfers

Kwota and its sub-processors operate in the United States. If you are in the United Kingdom, European Economic Area, or Switzerland, your information will be transferred to and stored in the US.

Where required, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with the technical measures described below, to protect those transfers.

How long we keep it

DataRetention
Account and sales dataFor as long as the account is active
After cancellation30 days, then permanently deleted
BackupsPurged on the normal backup cycle, no more than 30 days after deletion
Billing and invoice records7 years, to meet tax and accounting obligations
Product analytics12 months
Session recordings30 days
Support emails2 years
Salesforce tokensDeleted immediately when you disconnect

Security

What we do:

What we do not claim. Kwota is not currently SOC 2 certified and has not undergone a third-party penetration test. We will not imply otherwise to win a deal. If your procurement process requires either, tell us and we will give you an honest account of where we are.

If something goes wrong

If we become aware of a breach affecting your personal information, we will notify affected account admins without undue delay and in any case within 72 hours of becoming aware, describing what happened, what data was involved, and what we are doing about it.

Your rights

Wherever you live, we will honour these requests:

Email privacy@usekwota.com. We respond within 30 days and will not charge you or make the service worse because you asked.

If you are in California

You have the right to know what we collect and why, to delete it, to correct it, and to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we do not process it for cross-context behavioural advertising. We will not discriminate against you for exercising any right.

If you are in the UK or EEA

You may complain to your supervisory authority — the ICO in the UK, or your national data protection authority in the EEA. We would rather you came to us first.

Cookies and tracking

We use only what the product needs:

TypeWhat for
EssentialKeeping you signed in and maintaining your session. The app also uses browser local storage for your session and theme preference.
AnalyticsPostHog, to understand which features are used and where people get stuck. Includes session recordings of in-app activity.

We use no advertising cookies and no cross-site tracking. We do not currently respond to Do Not Track signals, as there is no agreed standard for them.

Children

Kwota is a business tool, not directed at children, and not intended for anyone under 16. We do not knowingly collect information from children. If you believe a child has provided us information, email us and we will delete it.

Changes to this policy

If we make a material change, we will email account admins before it takes effect, not merely update the date at the top. The version history is available on request.

Contact us

Privacy questions and rights requests: privacy@usekwota.com
Everything else: hello@usekwota.com

We are a small company. A person reads these, and you will get a real answer.