Privacy Policy
Last updated 19 July 2026
UniQuote is made by Multifacture (“we”, “us”), based in the United Kingdom. This policy explains what we collect, why, and your rights. Questions: contact@multifacture.co.uk.
Who’s who
Workshops (“merchants”) use UniQuote to run their own storefronts. For a workshop’s customers, the workshop is the data controller of its customer data and we act as its processor — we host that data so the workshop can do its job. For merchant and team accounts themselves, we are the controller.
What we collect
- Account details — workshop name, your name, email, and a password we store only as a secure hash. Team-member and buyer accounts: name, email, hashed password; buyers may add a delivery address.
- Quotes and orders — the details a customer submits to a workshop: name, email, the job’s specification, and any design files uploaded (stored so the workshop can make the part).
- Workshop network activity — jobs, messages and shipment references passed between connected workshops. A customer’s contact details are never shared down the chain.
- Integration credentials — if a workshop connects Stripe, Shopify, Xero, QuickBooks, Etsy, OctoPrint or an AI provider, those tokens are stored encrypted at rest (AES-256) and used only to provide that integration.
- Payment information: we never see card numbers. Card payments are processed by Stripe on the workshop’s own Stripe account; subscription billing for workshops runs on our Stripe account. We hold references (customer/subscription ids), not card data.
- Cookies — strictly functional session cookies (staying signed in, cart contents). No advertising or cross-site tracking cookies.
What we use it for
Running the service: quoting, orders, production, emails about your quotes/orders/account (we send no marketing you didn’t ask for), support, keeping the platform secure (rate limiting, abuse prevention), and — where a workshop switched it on — syncing its own sales into its own accounting package. We do not sell personal data. Ever.
Who helps us run it
Carefully-chosen processors: our UK/EU hosting provider (the servers), our email delivery provider (transactional emails), and Stripe (payments and subscriptions). Where a workshop connects a third-party service (Shopify, Xero, QuickBooks, Etsy, an AI provider), data flows to that service only because and while the workshop chose to connect it, under that provider’s own terms.
Keeping and deleting data
We keep data while the account it belongs to is active. Workshops can delete quotes, team members and integrations themselves; closing an account removes the workshop’s data (business records a workshop must legally retain — invoices, for instance — are theirs to export first via the built-in exports). Disconnecting an integration deletes its stored tokens.
Your rights (UK GDPR)
You can ask for a copy of your data, ask us to correct or delete it, object to processing, and complain to the ICO (ico.org.uk) if you’re unhappy with our answer. If you’re a customer of a workshop, the quickest route is the workshop itself (the controller); we’ll help them comply. Email contact@multifacture.co.uk and we’ll respond within a month.
Security
HTTPS everywhere, hashed passwords, encrypted integration credentials, login throttling and lockouts, per-workshop data isolation, and permission-scoped team logins. No system is perfect; if we ever discover a breach affecting you, we’ll tell you and the ICO as the law requires.
Changes
If this policy changes materially we’ll note it here with a new date, and email account holders about significant changes.