Privacy Policy
Negoti8 turns a quote you upload into a counter-offer email. This page says what we do with the data that passes through, in plain language: what we hold, why we are allowed to, how long we keep it, who else sees it, and what you can make us do about it.
Last updated 16 August 2026
Who is responsible
The controller for this processing is Negoti8 VOF, registered with the Dutch Chamber of Commerce under KVK 42134359.
Blasiusstraat 74AmsterdamThe NetherlandsFor anything on this page, including any request below, write to info@negoti8.app. We answer in Dutch or English. We have not appointed a Data Protection Officer; we are not required to and we would rather say so than imply a function that does not exist.
This policy is written in English while the rest of the site is available in 17 languages. That is a deliberate limit: a translated legal notice that drifts from the original is worse than one language everyone can run through a translator. Ask us in your own language and you will get an answer in it.
Your quote document
This is the part most people want to know about, so it comes first.
- What happens to the file. The PDF or photo you upload is stored briefly by Vercel Blob and its contents are sent to Google (Gemini API) to read the line items and draft your reply. When processing finishes, successfully or not, the file is deleted. We keep no copy of the original document.
- What we keep instead. The extracted line items, quantities and amounts, the market research and the counter-offer we wrote. There is no field anywhere in that structure for your name, your address or your contact details, so none is extracted from the document.
- If you are not signed in. Your quote is tied to a random identifier we mint and store in a first-party cookie. It is not your IP address and not a fingerprint. The quote and everything attached to it are deleted automatically after 7 days unless you sign in and claim it.
- Legal basis. Performance of our agreement with you (Art. 6(1)(b)): you asked us to analyse a document, and this is what analysing it requires.
Google processes the document content under the Gemini API terms. Do not upload a document containing information you would not want read by an automated system: we cannot un-send it once the analysis has started.
The contractor named in your quote
A counter-offer is an email, so it has to be addressed. When we draft one, we store the recipient name and email address taken from your quote alongside it, and they appear on the share page if you send the vendor a link. That is personal data about someone who did not upload anything, which the GDPR calls data not obtained from the data subject (Art. 14).
- It is used for one purpose only: addressing and sending the reply that you asked us to write.
- It is never added to the market-data statistics below, never used for marketing, and never sold.
- It is deleted with the quote it belongs to: after 7 days for a guest quote, or on request for an account.
- Legal basis: our legitimate interest and yours in completing the negotiation you started (Art. 6(1)(f)). A contractor who wants their details removed can write to the address above and we will remove them.
Your account
- Sign-in. You can sign in with Google, or with an emailed magic link. We receive your name, email address and avatar from Google. We never receive your password, and we do not store one: there is no password field in our database.
- What the account holds. Your email address, display name, avatar URL, language, credit balance, your quotes and a Stripe customer reference. Your purchase history is not copied into our database: the account page reads it from Stripe when you open it.
- How long. For as long as the account exists. Ask us to delete it and we delete it, including the quotes attached to it.
- Legal basis. Performance of our agreement (Art. 6(1)(b)). Where a payment is involved, the invoice records that go with it are kept to meet our legal obligation under Dutch tax law (Art. 6(1)(c)), which requires 7 years.
Payments
Credits are sold through Stripe, which acts as its own controller for the payment itself. Your card details are entered on Stripe's systems and never reach ours: we store a Stripe customer reference, what was bought and when. Stripe's handling of your data is described in the Stripe privacy policy.
Anonymised market-price statistics
Negoti8 can only tell you what a fair price is because it has seen a lot of prices. From completed quotes we derive anonymised price observations: a canonical service category, the amounts, a coarse location, the quote date, and a token that is hashed per period and cannot be reversed. That dataset holds no name, email address, user ID, file or raw document text, enforced in the database schema and covered by tests. Observations are published only as cohort benchmarks, and only when a cohort is large enough that no individual can be singled out.
- If you are not signed in, none of your quotes are used. Guests are excluded from this pipeline by default, because we are not prepared to add a stranger's quote to a commercial dataset on the strength of no relationship at all.
- Legal basis: our legitimate interest in building a price reference (Art. 6(1)(f)), not consent. The balancing test behind that is written down and available on request.
- Right to object (Art. 21): the switch below excludes your quotes entirely, for good. Your counter-offers still work exactly as before.
We do not sell personal data. We license anonymised aggregates, and any licensee is contractually barred from attempting to re-identify anyone. We do not attempt it ourselves.
Your switch
Exclude my quotes from market-data and intent
We create anonymized, aggregate pricing statistics from uploaded quotes under our legitimate interest. Turn this on and your quotes are excluded from both the anonymized pricing dataset and the pseudonymous intent layer. Your counter-offers are unaffected.
How we count visitors
There are two layers and they work differently.
- A first-party page counter, always on. Each page view records the path, your country as our host reports it, and a visitor token that is a salted hash of your IP address and browser user-agent. The salt is scoped to the calendar day, so the token rotates every midnight and cannot be linked across days or back to you. It sets no cookie and reads nothing from your device, which is why it does not sit behind the consent banner. Legal basis: our legitimate interest in knowing whether anyone is using the site (Art. 6(1)(f)).
- PostHog product analytics, only with your consent. Loaded only if you accept analytics cookies. These events are pseudonymous rather than anonymous, and we would rather be precise than flattering: they are keyed to a random identifier, and if you later sign in we link that identifier to your account so repeat use is countable. Withdraw consent in the cookie banner and it stops.
Advertising
Only if you accept advertising cookies: Google AdSense may serve ads, and we record a pseudonymous in-market signal against an anonymous advertising identifier, never your name, email address or user ID. That signal expires and is deleted automatically, and is used to make ads more relevant and to build cohort audiences that are suppressed below a minimum size. The market-data switch above also turns this layer off.
Cookies
- Strictly necessary, always on: your sign-in session, the guest identifier that lets you see your own quote, your language choice and your consent choices. No consent needed, because the site cannot work without them.
- Analytics, off until you turn them on (PostHog).
- Advertising, off until you turn them on (Google AdSense).
The banner sets both optional categories to off by default, and you can change your mind at any time. These choices are separate from the market-data switch above, which is about a different thing and is governed by objection rather than consent.
- Service email. Sign-in links, your result when it is ready, and a small number of messages about a quote you uploaded. Legal basis: performance of our agreement (Art. 6(1)(b)).
- The mailing list. If you hand over your address for a guide or a tip sheet, we store the address, your language and your country, and we send a confirmation email first. Nothing else is sent until you click the link in it. Legal basis: your consent (Art. 6(1)(a)), withdrawable with the unsubscribe link in every message.
- Who sends it. Resend, acting as our processor.
Who else handles your data
These are our processors and the counterparties involved in running Negoti8. We do not sell personal data to anyone.
- Vercel (United States): hosting, and the temporary storage your uploaded file passes through.
- Neon: the database holding accounts, quotes and results.
- Google (United States): sign-in, the Gemini API that reads your quote, and AdSense if you consent to advertising cookies.
- Stripe (United States and Ireland): payments.
- Resend (United States): sending email.
- PostHog: product analytics, only with your consent.
Transfers outside the EEA
Several of the services above are based in the United States, so your data can be processed there. Those transfers rely on the European Commission's standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework. You can ask us for the details of any specific transfer.
How long we keep things
- Uploaded file: deleted as soon as processing ends, whether it succeeded or failed.
- Guest quote and its results: 7 days, then deleted automatically along with the contractor details attached to it.
- Account, quotes and results: until you ask us to delete them.
- Invoice and payment records: 7 years, because Dutch tax law says so.
- Page-counter rows: the visitor token rotates daily, so rows stop being attributable to anyone after a day.
- Advertising signals: expire and are purged automatically.
- Anonymised price observations: kept indefinitely. They are no longer personal data, which is the point of anonymising them.
Your rights
Write to info@negoti8.app to exercise any of these. We answer within one month, free of charge.
- Access a copy of what we hold about you (Art. 15).
- Rectification of anything wrong (Art. 16).
- Erasure of your account and its data (Art. 17).
- Restriction of processing while a dispute is open (Art. 18).
- Portability of the data you gave us, in a machine readable file (Art. 20).
- Objection to anything we do on legitimate interest, including the market-data pipeline, which has its own switch above (Art. 21).
- Withdrawal of consent at any time, for cookies and for the mailing list. It does not affect what happened before you withdrew it.
You can also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or to the authority in your own EU country. We would rather you came to us first, but it is your right either way.
Automated processing
An AI model reads your quote and drafts a reply. It produces a suggestion that you read, edit and choose whether to send: nothing is decided about you, no profile is built, and there is no automated decision with a legal or similarly significant effect in the sense of Art. 22. The prices it cites can be wrong, which is why every counter offer is shown to you before it goes anywhere.
Security and breaches
Data is encrypted in transit and at rest with our hosting and database providers, access to production is limited to the two founders, and uploaded files sit in private storage that is not publicly listable. No system is perfect. If a breach happens that puts you at risk, we notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the law requires it.
Children
Negoti8 is for adults negotiating quotes and is not directed at children under 16. We do not knowingly collect their data.
Changes to this policy
When the product changes, this page changes with it, and the date at the top moves. If a change materially affects what we do with data you have already given us, we tell you rather than relying on you rereading this page.