1. Product architecture
PowderQuote is a local-first Windows quotation application supported by an online account and licensing service. DXF files, customers, pricing rules, PDF quotations, and quotation history are designed to remain on the user's computer and are not uploaded to the PowderQuote server for quotation processing.
2. Information processed by the online service
The service may process the following information:
- Account email address, optional first name, and optional last name.
- Password hashes generated by the authentication system. Plain-text passwords are not stored.
- Verified-device records, app version, operating-system description, activation status, and last-seen time.
- Trial, license, and entitlement status.
- Paddle customer, transaction, subscription, price, and webhook references required to synchronize billing access.
- Security and operational logs needed to protect and maintain the service.
3. Information stored locally
The desktop application stores quotation-related business data on the user's Windows computer. The user is responsible for local computer security, backups, access control, and lawful handling of customer information entered into the desktop application.
4. Payment processing
Payments are handled by Paddle as merchant of record. Paddle may collect and process payment, tax, invoice, and customer information under its own privacy terms. PowderQuote receives the billing references and status events needed to manage software access; it does not receive full card details.
5. Device identification
PowderQuote Desktop creates a privacy-preserving device fingerprint from local machine characteristics. Raw source values are hashed locally, and the server applies an additional protected hash before storing the device identity. This is used to enforce trial and active-device limits.
6. Retention and deletion
Account, device, license, and subscription records may be retained while the account is active and for a reasonable period afterward for security, accounting, dispute, and legal obligations. Account-deletion procedures will be finalized before public launch. Deleting an online account does not automatically erase data stored locally by the desktop application.
7. Security
The production service is intended to use encrypted HTTPS connections, secure authentication tokens, protected configuration secrets, and access controls. No system can guarantee absolute security, so users should also protect their Windows accounts and maintain backups of important local data.
8. Contact
A privacy contact address will be published before the public launch.