AgentMClose
VintSnaptitraCitedSitePriceSiblinyLanyardTariffShieldPopSnap

SitePrice Privacy Policy

Last Updated: 30 August 2026

1 Introduction

SitePrice ("we", "us", "our") operates the SitePrice mobile application (the "App"). SitePrice is a quoting and invoicing tool for self-employed tradespeople and small trade businesses, available in the United Kingdom, Ireland, the United States, Canada and Australia. This Privacy Policy explains what information we collect, how we use it, and your rights over it.

SitePrice is a local-first app: your quotes, clients, rates and business details are stored on your own device by default and are not automatically synced to any cloud server. Some optional features (account sign-in, cloud backup, AI quote generation and subscriptions) involve limited data processing, described below.

Two different roles, and it matters which one applies. For a small amount of data about you — your account email, your user ID, your AI usage counter — we are the controller, and this policy is our notice to you. For your clients' details, you are the controller and we are only your processor, and only where that data leaves your device. Section 2.7 explains the split; section 11 sets out the processing terms.

This policy applies to all users of the App.

2 Information We Collect

2.1 Data You Store in the App (Local by Default)

When you use SitePrice, you create data such as quotes and estimates, client records (names, email addresses, phone numbers, addresses), saved rates, job templates, job photos and your business profile. This data is:

  • Stored locally on your device in a SQLite database
  • Never automatically synced or uploaded to any server
  • Under your full control — you can export, back up or delete it at any time

Note that your client records are personal data about other people. See section 2.7.

2.2 AI Quote Generation (Job Notes)

When you ask the App to generate a quote, your job notes — typed or dictated — are sent to our server, which forwards them to Google's Gemini API for processing. This data is:

  • Sent only when you explicitly request an AI quote
  • Processed to produce your quote — we do not retain your job notes on our servers after the quote is returned to you
  • Never used by us to train, fine-tune or evaluate any AI model, and never used to develop our products

Google's use of this content. Google acts as our sub-processor for AI quote generation. What Google itself may do with the content depends on which Gemini API service tier our AI service runs on. Under Google's paid tier terms, prompts and responses are not used to improve Google's products or to train its models. Under Google's free tier, Google's Gemini API Additional Terms permit submitted content and generated responses to be used to provide, improve and develop Google's products and machine-learning technologies, which can include review by human reviewers.

Our commitment to you is that we run SitePrice's AI service on terms under which your content is not used to train or improve AI models. We keep this under review. If that ever ceases to be the case, we will update this policy and tell you in the App before the change takes effect.

Please read section 2.8 before you type a customer's name or address into a job note.

2.3 Optional Account (Firebase Authentication)

You can optionally create an account to enable cloud backup and AI features. Accounts are provided by Google Firebase Authentication and may be email/password based or anonymous. When you use an account, we collect:

  • Your email address (email/password accounts only)
  • A user ID assigned by Firebase

Google Firebase acts as our processor for authentication.

2.4 Optional Cloud Backup

If you choose to back up your data to the cloud, a backup file (JSON) containing your quotes, clients (including their names, email addresses and phone numbers), saved rates and business profile is uploaded to Google Firebase Storage in your private storage area. Cloud backups are:

  • Created only when you explicitly trigger a backup
  • Stored on Google Firebase servers in the London, UK region (europe-west2)
  • Accessible only to your signed-in account
  • Protected by Google's encryption at rest and by TLS in transit. The backup file itself is structured JSON, not separately encrypted by us with a key only you hold — so it is not end-to-end encrypted, and we could in principle be compelled to produce it by a lawful order
  • Retained until you overwrite them with a newer backup, or delete them by deleting your account in the App or by contacting us

A backup contains your clients' personal data. When we hold it, we hold it as your processor — see sections 2.7 and 11.

2.5 Subscriptions and Purchases

Paid subscriptions are sold and billed by Apple (App Store) or Google (Google Play) and managed through RevenueCat. These services process:

  • Purchase history and subscription status
  • Device and app-instance identifiers used to manage entitlements

We never see or store your card or payment details — payments are handled entirely by Apple or Google.

2.6 Device Integrity Checks

To protect our AI service from abuse, the App uses Google Play Integrity and Firebase App Check to verify that requests come from a genuine, unmodified copy of the App. These checks process device integrity signals but do not give us access to your personal files or other apps.

2.7

Your Customers' Personal Data — Who Is Responsible for What

SitePrice is used by tradespeople to run their own businesses. That means the App holds personal data about a second group of people: your customers. Their names, addresses, phone numbers and email addresses sit in your client book and on the quotes and invoices you send. They never signed up to SitePrice, they are not our account holders, and most of them have never heard of us. This section explains who is responsible for what.

2.7.1 You are the controller of your clients' data

You decided to collect your customers' details, you decide what they are used for, and you decide how long to keep them. Under UK and EU data protection law that makes you the controller of that data, and the obligations that go with it are yours, not ours:

  • Telling your customers what you do with their details, and why (a privacy notice — usually a short paragraph on your quote, invoice or website is enough for a sole trader)
  • Keeping the data accurate, secure and no longer than you actually need it
  • Answering requests they make to see, correct or delete their data
  • Reporting a personal data breach affecting their data, where the law requires it

If you are a UK business processing personal data electronically, you may also need to pay the ICO's annual data protection fee and be on its register. It is inexpensive, and it is your responsibility, not ours. Check your position at ico.org.uk. Equivalent obligations exist in Ireland, Australia and Canada.

2.7.2 We are your processor where that data leaves your device

By default your client records stay on your phone and we never see them. They reach us in only two situations:

  • Cloud backup — if you switch it on, the backup file we store contains your client records (section 2.4)
  • AI quote generation — if you type a customer's details into a job note, they are sent with the rest of the note (section 2.8)

In those situations we handle that data only on your instructions and only to deliver the feature you asked for. We do not use it for our own purposes, we do not analyse it, and we do not share it beyond the sub-processors named in section 11. The full processing terms are in section 11 and form part of your agreement with us.

2.7.3 We are the controller of a small amount of data about you

For three things we decide the purpose ourselves, so we are the controller and this policy is our notice to you:

  • Your account email address (if you create an email/password account)
  • Your Firebase user ID
  • Your AI usage counter — how many AI quotes you have generated, used to apply fair-usage limits

2.7.4 If you are a customer of a SitePrice user and want your data removed

Please contact the tradesperson who quoted or invoiced you, not us. They control that data; we do not.

We are not being obstructive in saying so. Your details sit inside an individual tradesperson's own business records. We cannot identify a particular person's record inside a customer's data, we do not index or search it, and we have no lawful basis to go rummaging through a business's client book looking for you. The tradesperson can delete your record in seconds; we cannot do it at all without them.

If the tradesperson needs help — for example to locate or remove data from a cloud backup, or to understand what we hold — they can contact us at the address in section 8 and we will assist them promptly, as section 11 requires us to. If you cannot identify or contact the tradesperson, write to us anyway at the address in section 8 with whatever detail you have and we will do what we reasonably can to help you reach them.

2.8

What You Type Into Job Notes

When you ask SitePrice to draft a quote, the job notes you typed or dictated are sent from your device to our server and on to Google's Gemini API. Whatever is in the note goes with it.

If you type or say your customer's name, address or phone number, that information is sent too. We do not need it to price a job — describe the work, not the person.

Compare these two notes:

  • Everything the AI needs: "Rewire 3-bed semi, 8 double sockets, replace consumer unit, day and a half."
  • Sends a third party someone's personal data for no benefit to you: "Rewire for Mrs Patel at 14 Elm Road, mobile 07700 900123, 8 double sockets, day and a half."

The App does not require your customer's details to build a quote, does not prompt you for them on the AI screen, and does not need them to fill in the client section of the finished document — you attach the client to the quote separately, on your device. Keeping personal details out of job notes is the single easiest thing you can do to reduce your own data protection exposure.

Voice dictation follows the same path: dictation is converted to text and the text is sent. If you say a name or address out loud, it is sent as text.

3 How We Use Your Information

We use the information described above only for the following purposes:

  • Quote generation: to process your job notes through Google's Gemini API to draft line items
  • Cloud backup: to store and restore your backup when you request it
  • Account management: to sign you in and associate your backup and AI usage with your account
  • Billing and subscription management: to unlock paid features against your purchase
  • Security: to verify app integrity, prevent abuse and apply fair-usage limits on AI requests
  • Legal compliance: to comply with legal obligations

The App does not include any third-party analytics or crash-reporting SDKs, and we do not collect usage analytics. We do not sell your data, we do not advertise in the App, and we do not profile you or make automated decisions with legal or similarly significant effects about you.

3.1 Our Legal Bases for Processing (UK GDPR and EU GDPR)

Where we act as controller (see section 2.7.3), we rely on the following legal bases:

  • Performance of a contract — Article 6(1)(b). Creating and running your account; storing and restoring your cloud backup; generating the AI quotes you ask for; providing paid features and managing your subscription entitlement. We cannot give you the service you signed up for without this processing.
  • Legitimate interests — Article 6(1)(f). App and device integrity checks (Google Play Integrity and Firebase App Check), rate limiting and fair-usage counting, and preventing abuse of our AI service. Our legitimate interest is keeping a metered, paid third-party AI service available and affordable for genuine users and protecting it from automated abuse. We have weighed this against your interests: these checks look at the app and the request, not at your business data or your clients' data, so we consider the impact on you minimal. You can object to processing based on legitimate interests — see section 7.5.
  • Legal obligation — Article 6(1)(c). Retaining records of transactions where tax, accounting or consumer law requires it, and responding to valid legal requests.

We do not rely on consent for any of the above, and we do not use your data for marketing. We do not process special category data (Article 9) and ask that you do not put any into the App.

Where we act as your processor — your clients' details in a cloud backup, or in job notes you send for AI drafting — the legal basis for that processing is yours to establish as controller, not ours. We process it only on your documented instructions (section 11).

4 Data Sharing and AI Processing

4.1 AI Processing (Google Gemini)

To draft quotes, your job notes are transmitted via our server to Google's Gemini API. This processing:

  • Happens only when you request an AI quote
  • Is not retained by us — content is processed to produce your quote and is not stored on our servers afterwards
  • Is not used by us to train, fine-tune or evaluate AI models, and is not used to develop our products
  • Is governed, as regards Google's own use of the content, by the Gemini API terms applying to our service tier — see section 2.2, which explains the difference between Google's paid and free tiers and the commitment we make to you

4.2 No Data Sales

We explicitly do NOT:

  • Sell your data, or your clients' data, to anyone
  • Share your job notes, quotes or client details with marketers or advertisers
  • Use your data for purposes other than those stated in this policy
  • Share your contact information without your explicit consent

We do not "sell" or "share" personal information as those terms are defined by the California Consumer Privacy Act, as amended by the CPRA. See section 7.7.

4.3 Service Providers and Sub-processors

We share limited information with the following processors, only as needed to run the App:

  • Google (Firebase Authentication, Firebase Storage for cloud backup, Cloud Functions for our AI proxy, Play Integrity / App Check, and the Gemini API)
  • RevenueCat, Inc. (subscription entitlement management)
  • Apple and Google as the sellers of subscriptions through their stores

All are bound by written terms to protect the data and use it only for the purposes we specify. The full sub-processor list for data you control is in section 11.5.

4.4 Legal Disclosure

We may disclose data where we are legally required to do so by a valid order from a court or regulator, or where necessary to establish, exercise or defend legal claims. Where we are permitted to tell you first, we will.

5 Storage, Retention, Transfers and Security

5.1 Local Storage

By default, all of your data is stored locally on your device in a SQLite database:

  • Quotes, clients, rates, photos and your business profile are retained on your phone
  • Nothing is synced to the cloud automatically
  • Data is protected by your device's native security features (device encryption, screen lock, biometrics)

Because the data is on your device, keeping your device locked and up to date is a meaningful part of protecting your customers' data.

5.2 Cloud Storage (Optional)

If you enable cloud backup, your backup file is stored in Google Firebase Storage in the London, UK region (europe-west2), in a private folder tied to your account. It is retained until you overwrite or delete it (in-app account deletion, or by request).

5.3 Data Security

We implement the following measures:

  • Encryption of data in transit (TLS)
  • Encryption at rest for cloud-stored data, provided by Google Cloud
  • Server-side handling of AI requests so that no API keys are exposed in the App
  • Per-account access controls on cloud backups, enforced by storage security rules
  • App and device integrity verification (Play Integrity / Firebase App Check)
  • Access to production systems restricted to those who need it, under a duty of confidentiality

No system is completely secure and we cannot guarantee absolute security. Cloud backups are not end-to-end encrypted — see section 2.4.

5.4 How Long We Keep Things

WhatHow long we keep it
Account record (email address, Firebase user ID)Until you delete your account
Cloud backup fileUntil it is overwritten by a newer backup, or until you delete it or your account
Job notes, photos and audio sent for AI draftingNot retained by us. Google's retention is governed by its API terms
AI usage counters (fair-usage limits)90 days
Cloud Function error logs30 days
Purchase and subscription recordsHeld by Apple, Google and RevenueCat under their own policies and applicable tax law
Data on your deviceUntil you delete it or uninstall the App — it is yours and we cannot reach it

Where you are the controller (your clients' records), the retention decision is yours. Deleting a client in the App removes them from your device; your next cloud backup will no longer contain them.

5.5 Where Your Data Goes (International Transfers)

Cloud backups and our AI proxy run in Google Cloud's London region (europe-west2), in the United Kingdom.

The Gemini API itself may process your job notes outside the UK and EEA, including in the United States. Where that happens, the transfer is made under Google's Data Processing Addendum, relying on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (and, for EEA users, on the EU Standard Contractual Clauses). This is the main reason section 2.8 asks you to keep your customers' names and addresses out of job notes: what you do not send cannot be transferred.

Apple, Google and RevenueCat process purchase data in accordance with their own published terms and transfer mechanisms.

5.6 If Something Goes Wrong (Personal Data Breach)

If we suffer a personal data breach:

  • We will notify the Information Commissioner's Office within 72 hours of becoming aware of it, where the breach is reportable under UK GDPR Article 33 (and any other supervisory authority where required).
  • We will notify you directly, without undue delay, where the breach is likely to result in a high risk to your rights and freedoms (Article 34).
  • Separately, and importantly: where a breach affects data you control — your clients' details in a backup or an AI request — we will notify you without undue delay whether or not it meets the high-risk threshold, with enough detail for you to meet your own notification obligations as controller. That is your legal duty, not ours, and you cannot discharge it if we do not tell you.

6 Account and Data Deletion

6.1 Deleting Your Account and Cloud Data

You can delete your account and cloud backup directly in the App: Settings → Account → Delete account. This removes your account and any backup stored in Firebase.

If you cannot access the App, email us at hello@agentm.co.uk from the address associated with your account and we will delete your account and cloud data. You can also use our account deletion page.

Deleting your account does not cancel a paid subscription — cancel that in the App Store or Google Play.

6.2 Deleting Local Data

Data stored on your device can be removed at any time using Settings → Clear All Data in the App, or by uninstalling the App, which removes all locally stored information. Export a backup first if you want to keep it.

6.3 Requests From Your Customers

If one of your customers asks you to delete their data, you do it in the App — delete the client record, and any quotes or invoices you are not legally required to keep. Remember that a cloud backup taken before the deletion may still contain them until it is overwritten. If you need help with that, contact us (section 8) and we will assist. See section 2.7.4.

7 Your Rights Over Your Data

The rights below are the UK GDPR rights that apply to data for which we are the controller. Section 7.7 explains the position if you are outside the UK. If you are asking about your clients' data, section 2.7 explains why those requests go to you, not us.

7.1 Right of Access

You have the right to request a copy of your personal data. You can export your data at any time from the App (backup export), or contact us to make a subject access request.

7.2 Right to Erasure

You can delete your data yourself as described in section 6, or ask us to delete any data we hold about you.

7.3 Right to Data Portability

The App can export your data as a structured JSON backup file and as CSV, which you control directly.

7.4 Right to Rectification and Restriction

You can correct your business profile and account details in the App at any time, and you can ask us to correct anything we hold that is wrong, or to limit how we use your data.

7.5 Right to Object

You may object to processing we carry out on the basis of legitimate interests (section 3.1) — integrity checks, rate limiting and abuse prevention. Note that if we cannot run those checks we may not be able to offer you the AI features, since they are what protect a metered paid service from abuse.

7.6 Exercising Your Rights

To exercise any of these rights, contact us at the address in section 8. We will respond within one month. We do not charge for this. We may ask you to confirm your identity, which for account holders normally means writing from your account email address.

7.7 If You Are Not in the UK

SitePrice is offered in five countries and your local law travels with you.

  • Ireland and the EU: you have the same rights under the EU GDPR as those set out above. If you are unhappy with how we have handled your data, you can complain to the Irish Data Protection Commission at dataprotection.ie, or to the supervisory authority in your own member state.
  • Australia: we handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You may request access to and correction of your personal information, and you may complain to us first and then to the Office of the Australian Information Commissioner at oaic.gov.au.
  • Canada: we handle personal information in line with PIPEDA and applicable provincial privacy legislation, including Quebec's Law 25. You may request access to and correction of your personal information, and you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca or to your provincial commissioner.
  • United States: we do not sell or share personal information as those terms are defined by the California Consumer Privacy Act as amended by the CPRA, and we do not meet the revenue or data-volume thresholds that make us a "business" subject to that Act. We are saying so plainly rather than staying silent about it. Regardless of whether the CCPA applies to us, any US resident may ask us for a copy of the personal data we hold about them or ask us to delete it, and we will honour that request on the same terms as sections 7.1 and 7.2. We do not discriminate against anyone for exercising a privacy right.

8 Contact Us and Complaints

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Data controller: Agent M sp. z o.o., trading as SitePrice

Company number: KRS 0001259388 (NIP 6793373063, REGON 545441446)

Registered address: ul. Na Zjeździe 11/5P., 30-527 Kraków, Poland

Email: hello@agentm.co.uk

We will respond to your request within one month, in accordance with UK GDPR.

Complaints. If you are not satisfied with our response, you have the right to complain to a data protection authority. In the UK that is the Information Commissioner's Office, ico.org.uk/make-a-complaint. If you are outside the UK, see section 7.7 for your regulator. We would rather you came to us first so we can put it right.

9 Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last Updated" date at the top of this page, and where a change materially affects how we handle your data or your clients' data we will tell you in the App before it takes effect. Your continued use of the App after a change takes effect constitutes acceptance of the updated policy.

10 Laws We Work To

SitePrice is offered in the United Kingdom, Ireland, the United States, Canada and Australia, and we work to the following:

  • United Kingdom: UK General Data Protection Regulation, Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003
  • Ireland and the EU: EU General Data Protection Regulation (2016/679) and the Irish Data Protection Act 2018
  • Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec's Law 25
  • United States: applicable state privacy laws, including the California Consumer Privacy Act as amended by the CPRA — see section 7.7 for our position on its application to us

Where these differ, we apply the standard that gives you the most protection.

11 Processing Terms (UK GDPR Article 28)

This section is a contract, not a description. It applies where you are the controller of personal data (your clients' details) and we process it for you — that is, when you use cloud backup, or when you include a customer's details in a job note sent for AI drafting. It forms part of the agreement between you and us and satisfies UK GDPR Article 28(3) (and EU GDPR Article 28(3) where that applies to you). It does not apply to data for which we are the controller (section 2.7.3).

11.1 Subject Matter and Duration

Subject matter: our processing of personal data contained in your SitePrice records, on your behalf, as part of providing the App's cloud backup and AI quote-drafting features.

Duration: for as long as you use those features and hold an account with us, and thereafter only for as long as any backup file remains stored. Processing ends when you delete the backup or your account (section 11.4(g)).

11.2 Nature and Purpose of the Processing

Nature: collection, transmission, storage, retrieval, deletion and, in the case of AI drafting, disclosure to and processing by a sub-processor for the sole purpose of generating text.

Purpose: (a) storing and restoring a backup of your business records at your request; and (b) drafting quote line items from job notes you submit. We process for no other purpose.

11.3 Types of Personal Data and Categories of Data Subject

Types of personal data: names; postal addresses (including job-site addresses); email addresses; telephone numbers; job and quote descriptions; quote, invoice and payment status records; and any other personal data you choose to enter into a client record, quote, invoice or job note.

Categories of data subject: your customers and prospective customers, and any individual you name in a client record, quote, invoice or job note (for example a site contact, a landlord, a letting agent or a main contractor's staff).

Special category data: the App is not designed for it and you should not enter it. If you do, you remain solely responsible for having an Article 9 condition for it.

11.4 Our Obligations as Processor

We will:

  • (a) Process only on your documented instructions, including in relation to transfers of personal data outside the UK or EEA (see section 11.6 for your standing instruction), unless we are required to do otherwise by law — in which case we will tell you before processing, unless the law prohibits us from doing so.
  • (b) Ensure confidentiality. Everyone we authorise to process the data is bound by a duty of confidentiality, whether contractual or statutory, and that includes any contractor or temporary staff.
  • (c) Take the security measures required by Article 32, as described in section 5.3 — encryption in transit and at rest, per-account access controls, integrity verification, restricted production access, and measures to restore availability.
  • (d) Not engage another processor without authorisation. You give general written authorisation for the sub-processors listed in section 11.5. We will give you at least 30 days' notice in the App or by email before adding or replacing a sub-processor, and you may object; if you object, you may stop using the affected feature or terminate your account, and we will refund any unused prepaid subscription period to the extent the store permits. Every sub-processor is engaged under written terms imposing data protection obligations equivalent to those in this section, and we remain fully liable to you for their performance.
  • (e) Assist you with data subject requests. Taking into account the nature of the processing, we will help you by appropriate technical and organisational measures to respond to requests from your customers to exercise their rights. Because your records are structured on your device and you can act on them yourself, this normally means helping you deal with a stored backup or confirming what we hold. We will do so promptly and, unless the request is manifestly excessive or repetitive, without charge.
  • (f) Assist you with Articles 32 to 36. We will assist you, taking into account the nature of the processing and the information available to us, in meeting your obligations on security, breach notification to the regulator and to affected individuals, data protection impact assessments and prior consultation. See section 5.6 for the breach notification commitment.
  • (g) Delete the data at the end of the service. At your choice, we will delete or return the personal data when you stop using the relevant feature, and delete existing copies, unless we are required by law to keep it. Deleting your account in the App deletes your cloud backup, and that is the practical route to exercising this right. Job notes sent for AI drafting are not retained by us at all.
  • (h) Make available the information you need and allow audits. We will make available to you all information necessary to demonstrate compliance with the obligations in this section, and allow for and contribute to audits and inspections conducted by you or an auditor you appoint. Given the scale of the service, we will normally satisfy this by answering your questions in writing and providing our sub-processors' published security and compliance documentation; if that is genuinely not sufficient, we will agree a proportionate alternative with you. We will immediately inform you if, in our opinion, an instruction from you infringes data protection law.

11.5 Sub-processors

You give general written authorisation for the following sub-processors:

Sub-processorWhat it doesWhere it processes
Google LLC / Google Cloud EMEA Limited Firebase Authentication; Firebase Storage (cloud backup); Cloud Functions (AI proxy); Play Integrity and App Check; the Gemini API (AI drafting) Backup and proxy in the UK (europe-west2). The Gemini API may process outside the UK/EEA, including the US — see section 5.5
RevenueCat, Inc. Subscription entitlement management United States

RevenueCat processes purchase and entitlement identifiers and does not receive your clients' details.

11.6 Your Standing Instruction

By using cloud backup and AI quote drafting, you instruct us to process the personal data described in section 11.3 as set out in this Privacy Policy — including transferring it to the sub-processors in section 11.5 and, for AI drafting, transferring it outside the UK and EEA under the safeguards described in section 5.5 — for the sole purpose of providing those features to you. This is your complete set of documented instructions. If you need us to process differently, ask us in writing first; we may not be able to agree.

11.7 Precedence

If anything else in this policy or in our Terms of Service conflicts with this section 11 in respect of data you control, this section 11 prevails.

Kept with the app’s source code and published here unchanged.

How AgentM handles data across all its products