1. Strictly necessary storage
PowderQuote uses Django session and security mechanisms needed for login, language choice, CSRF protection and core service operation. These are not used for advertising. Authentication/session cookies may be set where technically necessary to provide the service.
2. Product analytics
In production, PowderQuote uses PostHog EU Cloud for a limited set of product events such as calculator opened, drawing uploaded, area selected, price calculated, quotation-save or PDF requests, registration and checkout events. Persistence, autocapture, pageview/pageleave capture, session recording, surveys, heatmaps, performance capture and automatic exception capture are disabled.
3. Data minimisation
The analytics client filters properties named email, customer email, customer name, filename and source filename. For signed-in users, PowderQuote may send an internal user identifier. Analytics is disabled in Django DEBUG mode.
4. Legal basis
We currently rely on legitimate interests under Article 6(1)(f) GDPR for narrowly scoped cookieless product analytics used to understand service adoption, diagnose product-flow problems and improve PowderQuote. If analytics later uses non-essential cookies, local storage, session replay, advertising identifiers or materially broader tracking, consent requirements and this notice must be reassessed before deployment.
5. Provider
PostHog is an analytics processor and the current client endpoint is PostHog EU Cloud. See the Privacy Policy and Subprocessors page for more information.
6. Changes
This disclosure describes the configuration reviewed on 18 August 2026. Analytics or storage changes must be reviewed before release.