Privacy Policy

This page explains what information BEQ receives, stores, generates, and shares when you create an account, build quotations, make payments, or use the website. It describes the product as it runs today and is not legal advice.

Last updated: October 8, 2026.

1. Who this applies to

This policy applies to visitors to https://beq.ae, registered BEQ users, and the data flows below: registration, sign-in, email verification, quota and entitlement checks, quotations/PDFs, account administration, payments, contact messages, and advertising conversion tracking.

2. Information you provide when creating an account

Creating a public BEQ account uses your name, email address, and a password. The password is stored as a bcrypt-hashed password hash; the plaintext password is not stored.

If you created a public account, BEQ also stores email-verification fields: a bcrypt-hashed verification code, expiry timestamp, verification-sent timestamp, failed-attempt count, and verification requirement flag. Verification codes are single-use, expire after 10 minutes, and are invalidated after 5 failed attempts.

3. Information you store inside BEQ

When you use the quotation builder, you may save data scoped to your user account:

  • Company profile: company name, address, city, country, phone, email, website, TRN/trade-license fields, bank name/account/IBAN, payment terms, quote validity days, defaults, and related notes.
  • Clients: company name, contact name, phone, email, address, city, country, TRN, notes, creation time, and links to tenant quotes.
  • Products/services: item names, optional codes, categories, units, cost prices, descriptions, notes, active status, creation/update timestamps.
  • Price history: previous and new prices for items, with their change timestamps.
  • Quotes/estimates: quote numbers/revisions, client references, project name/location, dates, validity, reference/name, notes, payment terms, exclusions, terms, profit method/value, VAT settings, totals, visibility toggles, per-quote design snapshots, and revision metadata.
  • Quote line items: names, descriptions, categories, units, quantities, unit costs, line totals, other costs, and visibility flags.
  • Labor and overhead details: labor descriptions, method/quantity/rate/days/amount/total, and overhead categories/labels/methods/values/amounts.
  • Design and settings: currency, VAT rate, default markup, quote prefix/starting number, validity, text defaults, colors, fonts, template style, item style, heading/right-column title, signature name/title, stamp, and saved branding.

4. Uploaded assets

Users can upload company assets used in quotations: a company logo, a banner image for the quotation header, and a signature/stamp image. Logos are stored as data in the database or in upload storage. Banners and stamps are stored under the configured upload directory, keyed by the authenticated user, and served through application routes. Upload files are validated by type, extension, size, and magic bytes before being used.

Admin users can also upload replacement Home/public video assets; those files are stored under the configured upload directory and referenced in site settings.

5. PDF quotation generation and download entitlements

PDFs are generated on the server from quotation, client, settings, branding, and design data. The generated PDF is served inline for preview or download.

BEQ tracks a free PDF entitlement per account: exactly one customer-facing quotation PDF download may be consumed for the life of the account. The app records that the free download was used, when it was used, and which quote consumed it. Admin/subscription entitlement fields can grant or remove PDF download access.

6. Authentication and sessions

BEQ uses email-and-password authentication managed by NextAuth. A successful login or a completed email-verification mail links a session to the account. Session tokens are server-trusted NextAuth/AUTH_SECRET-based JWTs with a 30-day max age, stored in the expected session-token cookie: `__Secure-authjs.session-token` over secure requests or `authjs.session-token` otherwise. Session cookies are used only to keep one logged-in session associated with your account.

Administrators and the owner can view and manage user records in the admin panel; those records are limited to operational fields such as email, name, role, subscription status/plan/end date, and whether the free PDF allowance has been used. Admin account deletion also removes the account and its related account data through the app schema.

7. Email communications

BEQ sends account and contact emails only when required by the relevant action:

  • Account verification: to the account email, a 6-digit code is sent by the configured email service.
  • Contact Us: the submitted name, email, optional phone/contact field, subject, and message are delivered to the fixed BEQ inbox at info@beq.ae.

Public registration and verification-email requests are rate-limited to reduce abuse. Verification codes are not stored plaintext.

8. Payments and subscription information

Payments are processed through Ziina for paid subscriptions. Before redirecting you to Ziina, BEQ records a payment attempt for your account. That record may contain: the plan name, amount, currency, detected country, Ziina payment intent ID, status, success/cancel/ failure return URLs, creation/update timestamps, and completion timestamp.

The current checkout flow never receives or stores full card details in BEQ. Ziina returns a hosted payment page URL where the actual payment is completed by the customer.

BEQ also stores subscription status and plan fields, trial/start/end dates where available, and subscription IDs that may exist in the database for compatibility. The active payment provider in current code is Ziina; the presence of legacy-named database fields does not mean Stripe is used by this application.

9. Contact form

If you use the public contact form, we collect the name, email address, optional contact field, subject, and message you submit. The selected receiving mailbox is fixed server-side toinfo@beq.ae. The form is throttled per client address to help prevent abuse.

10. Cookies and browser storage

BEQ uses the authentication session cookie described above. When account verification finishes, the app sets the same NextAuth session cookie without requiring a password re-entry. The conversion tracking flag for a successful registration is stored in sessionStoragefor that browser session.

The Google Ads tag may set cookies according to Google’s own behavior. There is no separate BEQ cookie preference center at this time.

11. Analytics and advertising

The project loads the Google Ads tag on public pages. It is used for advertising measurement. Client-side conversion events are limited to successful registration (`sign_up` with an event category/label for registration completion).

BEQ does not claim a more extensive analytics implementation than this. If Google Ads cookies are disabled in the browser, the conversion call may not forward, but it is designed not to break registration or navigation.

12. Location/country detection

For pricing, BEQ decides between the UAE AED table and the default USD table based on the request IP address. This is done server-side using embedded public network-range data. The implementation states that IP addresses are not logged or sent to a third party solely for this purpose.

13. Where data is stored and processed

BEQ’s application state is stored through Prisma against the configured database. Local development sources are prepared for SQLite; production is expected to use PostgreSQL through `DATABASE_URL`. Uploaded company assets and admin-uploaded videos are stored under the configured upload directory.

The application runtime is a Next.js app deployed through a Docker setup on Railway. Requests are processed by the BEQ server. Outbound calls are limited to payment verification via Ziina, transactional email via Resend, Google tag/script/addons, and the configured database.

14. Third parties that may receive information

  • Resend: receives your contact-form submission or verification code request so it can deliver email. It receives the email address, subject, body text, and configured sender/reply-to information.
  • Ziina: receives payment intent creation and verification requests with plan/currency/amount/country and return URLs, plus the customer’s payment details on Ziina’s hosted payment page.
  • Google Ads / Google Tag Manager web setup: receives page-load/tag traffic and the one registration conversion event described above.
  • Railway / configured database provider: receives the hosted application traffic and database records needed to operate BEQ.

15. No selling of personal data

BEQ does not sell personal data, and it does not advertise a data broker or ad-reseller integration. Third-party processing is limited to the operational services above.

16. Imports and CSV/Excel data

If you upload Excel or CSV files for price-library imports or quantity imports, BEQ parses those rows server-side or in the app workspace to match names/items, preview updates, and write the accepted rows into your account. Import files are not publicly shared.

17. Data retention and deletion

We retain your account and related records while the account exists and as needed to provide the service and fulfill payment/entitlement records. Administrators can delete an account through the owner/admin area; the app schema cascades that deletion to company, settings, clients, items, price history, quotes, and payment-intent records belonging to that user.

If you need help deleting or correcting account information, contactinfo@beq.ae.

18. Security

  • Passwords are bcrypt-hashed.
  • Email-verification codes are bcrypt-hashed, single-use, 10-minute expiry, and protected by attempt limits.
  • Public registration/resend/contact endpoints are rate-limited.
  • Routes are server-guarded by Auth.js sessions and user-scoped queries.
  • Payment success is confirmed by server verification against Ziina.
  • Uploaded images are type/size/extension/magic-byte checked before being stored or used.
  • HSTS, strict origin referrer policy, and nosniff response headers are configured.

19. Your choices

  • You may sign out at any time; sign-out clears the active session cookie in the usual NextAuth behavior.
  • You can upload/replace or remove company branding where the account settings UI provides that action.
  • You can edit or remove your clients, items, settings, and quotes inside the account where those actions are provided.
  • For payment-provider card data, choose your own card/payment details carefully on Ziina’s hosted page.
  • For Google Ads cookies, use your browser’s cookie controls or Google’s ad preferences where available.

20. Updates

If BEQ’s data flows change, this page should be updated. The latest revision date appears near the top.

21. Contact

Questions, correction requests, deletion assistance, or concerns about this Privacy Policy can be sent to info@beq.ae.