Could a customer see my margin if I send a quote link?
A no-login quote link is a second way for your costs to reach a customer. We built it on the same stripping as the PDF, then the client asked us to remove it.
You send customers a PDF of the quote. Somebody suggests sending a link instead, so they can open it without logging in. Before you agree, the question to ask is whether the link could show them something the PDF never would: what the job costs you, and what you make on it.
In a bespoke pricing system that is a real question. A quotation holds two prices for everything. There is the price the customer sees, and underneath it the internal cost, the gross profit on each feature, the margin percentage, and the working that shows which rates went into both.
The emailed document has been carefully stripped of all that over months of use. A public link is a second way for the same data to leave the system, and the second way starts from nothing. That is the real risk in a share link, and it is not the secret web address.
What was actually going on
The danger was not the link. It was a second “remove the internal figures” step, written separately from the first. Two such steps drift apart. Not immediately, but about four months in, when somebody adds a cost figure to a line, removes it from the export they were told about, and not from the page they did not know about.
What we changed
We built the public page from the same preparation step that the PDF and spreadsheet exports use, not by reading the quotation straight from the database. That step already leaves out internal financials and internal notes, because it feeds something that goes to customers, and every field it shows is one somebody has already decided a customer may see. When a new internal field is added and correctly kept out of the export, the link keeps it out too, without anyone remembering that a second route exists.
The share page also shows the 3D preview of each item, which needs the raw dimensions and feature choices, plus enough of the catalogue to name the things being quoted. That is extra exposure, so it is held in two ways. It only covers the things this quote actually uses, so a link cannot reach the catalogue. And every lookup is filtered by the owning company as well. That second check is redundant today, and stays, because on a boundary between companies it is the check that survives the day somebody adds a route where the identifiers are not already trusted.
Sharing is two pieces of state, not one: the secret address, and a separate switch saying whether sharing is on. Turn it off and the link stops working, but the same link works again when you turn it back on. Regenerate it and every copy of the old link is broken for good. “Pause this while we revise the price” and “that link went to the wrong person, kill it” are different intentions and should not be the same button. A link opens only if the address matches, sharing is on and the quotation has not been deleted, all checked together.
A link always shows the current version of the quote. Revise it and everyone holding the link sees the revision. For this business that was the point, but it had to be stated, because the customer holding the link cannot tell which kind they have. A snapshot would be a different feature.
What it did not fix
The share link was built, it worked, and on the review call the client asked for it to be taken out of the flow.
Their reason was operational and completely reasonable. They send their customers a document in their own format, with their terms, their guarantees and their letterhead, and it is what the customer’s own purchasing process expects to receive. A second thing, a link to a web page showing the same quote differently, added nothing. It created a question the salesperson then had to answer, and confusion in a sales conversation costs more than a preview is worth.
So the most carefully protected part of the product was switched off because it did not match how the business communicates. The engineering was not wrong. The assumption under it was: that a customer wants a richer view, when what they want is the document they are used to, in the format their accounts department files.
We would build it the same way again, and we would find that out sooner by asking how they currently send quotes before designing a new way to send them.
The pattern, for anyone who shares prices with customers
If you add a second way to send out data you already send one way, it should borrow the first one’s removal of internal figures, not copy it. Ask whether a change to one route would automatically change the other.
Ask whether you can pause a link without destroying it, and separately whether you can kill one outright. And before hardening any channel, confirm anybody wants it. A perfectly protected feature nobody uses is still a feature nobody uses.
Where this ends up
The share link, the exporter it borrows its removal of internal figures from, and the internal cost it is careful never to print all sit in Sazinga Quote, where the price the customer sees and the working behind it are different things by design.