← Back to EnergyStackHub

Privacy Policy

Last Updated: March 2026

Your privacy matters. This policy explains what data we collect, how we use it, and your rights. We never sell your personal data to third parties.

Table of Contents

  1. Introduction
  2. Data Controller
  3. Information We Collect
  4. How We Use Your Information
  5. Legal Basis for Processing (GDPR)
  6. Data Sharing and Disclosure
  7. International Data Transfers
  8. Data Retention
  9. Your Privacy Rights
  10. Cookies and Tracking Technologies
  11. Children's Privacy
  12. Security Measures
  13. Changes to This Policy
  14. California-Specific Disclosures (CCPA)
  15. State-Specific Privacy Rights
  16. Contact Us
  17. Dispute Resolution

1. INTRODUCTION

Steeled Inc. ("Company," "we," "us," or "our") operates the EnergyStackHub platform at energystackhub.com (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect your personal and business information when you use the Platform.

By using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, do not use the Platform.

This Privacy Policy is incorporated into and forms part of our Terms of Service.

2. DATA CONTROLLER

Steeled Inc.

Email: energystackhub@polsia.app

For purposes of applicable data protection law, including the EU General Data Protection Regulation ("GDPR"), Steeled Inc. is the data controller responsible for your personal data collected through the Platform.

3. INFORMATION WE COLLECT

We collect the following categories of information:

3.1 Account and Contact Information

When you create an account or contact us, we collect: name, email address, company name, job title, phone number (if provided), and other information you voluntarily submit.

3.2 Commercial Energy Data

To provide energy management services, we collect data you upload or connect including: utility bills and rate information, energy consumption data, facility details (square footage, building type, equipment), utility account identifiers, and energy procurement contracts or proposals.

3.3 Usage and Platform Interaction Data

We automatically collect: pages viewed and features used, search queries and filters applied, AI analysis requests and outputs generated, time spent on features, click patterns and navigation paths, and error logs and performance data.

3.4 Device and Technical Data

We collect: IP address, browser type and version, operating system, device type, referring URLs, session identifiers, and time zone and language settings.

3.5 Payment and Billing Data

For paid subscriptions and per-output purchases: billing name, billing address (country and state), and payment method information (processed and stored by our payment processor; we do not store full card numbers). We retain records of transactions, subscription status, and invoices.

3.6 Communications Data

If you contact us via email or support channels: the content of your communications, attachments you send, and our responses. We may retain this data to resolve disputes, improve support, and fulfill legal obligations.

3.7 Marketplace and Professional Data

For marketplace participants (energy professionals): credentials and certifications (self-reported), service areas, portfolio information, and contact preferences for client lead notifications.

4. HOW WE USE YOUR INFORMATION

4.1 To Provide the Platform

We use your data to operate, maintain, and improve the Platform; authenticate your account; process payments; generate AI analyses and reports; and fulfill your subscription and per-output purchase requests.

4.2 To Improve and Develop the Platform

We use aggregated, de-identified usage data to understand how the Platform is used, identify areas for improvement, train and refine AI models, and develop new features. We do not use personally identifiable information to train AI models without your explicit consent.

4.3 To Communicate With You

We use your contact information to send transactional emails (receipts, account notifications, password resets), platform updates and new feature announcements, and service interruption notices. You may opt out of non-transactional communications at any time.

4.4 For Marketplace Matching

We use your project and energy data to match commercial clients with relevant energy service providers in the marketplace. Contact information shared with matched providers is limited to what is necessary for the lead notification.

4.5 For Safety and Security

We use your data to detect, investigate, and prevent fraudulent activity, abuse, and security threats; enforce our Terms of Service; and comply with legal obligations.

4.6 For Legal and Compliance Purposes

We may use and disclose your data to comply with applicable laws and regulations, respond to lawful requests from governmental authorities, enforce our agreements, and protect the rights, property, or safety of the Company, our users, or others.

4.7 Analytics and Research

We use aggregated, anonymized data for internal analytics, industry research, and reporting. No individually identifiable information is included in public reports or research outputs.

5. LEGAL BASIS FOR PROCESSING (GDPR)

For users located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract Performance: Processing necessary to provide the Platform services you have requested and to fulfill our contractual obligations to you.
  • Legitimate Interests: Processing for our legitimate business interests (improving the Platform, preventing fraud, security monitoring), provided those interests are not overridden by your rights.
  • Legal Obligation: Processing required to comply with applicable laws and regulations.
  • Consent: Where we rely on your consent (such as for marketing communications or non-essential cookies), you may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

6. DATA SHARING AND DISCLOSURE

6.1 We Do Not Sell Your Data

We never sell your personal data to third parties. We do not sell, rent, or trade personal information for monetary or other valuable consideration.

6.2 Service Providers

We share data with carefully selected third-party service providers who assist us in operating the Platform, including: cloud hosting and infrastructure providers, payment processors, email service providers, analytics platforms, and customer support tools. These providers are contractually required to handle your data only as instructed by us and in accordance with applicable privacy law.

6.3 Marketplace Lead Sharing

When you request a connection with an energy service provider through the marketplace, we share your contact information and project details with the selected provider to facilitate the introduction. You consent to this sharing by initiating a marketplace connection request.

6.4 Legal Requirements

We may disclose your information if required to do so by law, court order, or other governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.

6.5 Business Transfers

In connection with a merger, acquisition, restructuring, sale of assets, or bankruptcy, your information may be transferred as part of the transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy, and you will have an opportunity to request deletion of your data.

6.6 Aggregated and De-Identified Data

We may share aggregated, de-identified data (data that cannot reasonably be used to identify you) with third parties for research, analytics, or business purposes.

7. INTERNATIONAL DATA TRANSFERS

The Platform is operated from the United States. If you access the Platform from outside the United States, your personal data may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

For EEA, UK, and Swiss users, we rely on the following transfer mechanisms to ensure adequate protection of your personal data: Standard Contractual Clauses (SCCs) approved by the European Commission, and any applicable adequacy decisions. You may contact us at energystackhub@polsia.app to obtain a copy of the relevant transfer mechanisms.

8. DATA RETENTION

We retain your personal data for as long as necessary to provide the Platform, fulfill the purposes described in this policy, and comply with legal obligations. Our general retention periods are:

Data Type Retention Period
Account and contact information Duration of account + 2 years after deletion request
Energy and usage data Duration of account + 1 year
Billing and payment records 7 years (tax and legal compliance)
AI-generated outputs and analyses 90 days after generation, unless saved to account
Support communications 3 years from date of communication
Usage logs (technical) 90 days
Marketing communications consent Until consent withdrawn + 3 years

After retention periods expire, we securely delete or anonymize your data. We may retain de-identified data indefinitely for research and analytics.

9. YOUR PRIVACY RIGHTS

9.1 Rights for All Users

Regardless of your location, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal data (subject to legal obligations)
  • Marketing Opt-Out: Opt out of receiving marketing communications at any time

9.2 Additional Rights for EEA/UK/Swiss Users (GDPR)

  • Data Portability: Receive your data in a structured, machine-readable format
  • Restriction of Processing: Request that we limit how we use your data in certain circumstances
  • Object to Processing: Object to processing based on legitimate interests or for direct marketing
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Lodge a Complaint: File a complaint with your local supervisory authority (Data Protection Authority)

9.3 California Resident Rights (CCPA/CPRA)

California residents have the right to:

  • Know: What personal information we collect, use, disclose, and sell (we do not sell)
  • Delete: Request deletion of personal information we have collected
  • Opt-Out of Sale: We do not sell personal information; no opt-out required
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
  • Correct: Request correction of inaccurate personal information
  • Limit Use of Sensitive Personal Information: Request limits on use of sensitive data

To exercise your rights, contact us at energystackhub@polsia.app. We will respond within 45 days (CCPA) or one month (GDPR), with possible extensions as permitted by law.

10. COOKIES AND TRACKING TECHNOLOGIES

10.1 Types of Cookies We Use

  • Essential Cookies: Required for the Platform to function (authentication, session management). Cannot be disabled.
  • Analytics Cookies: Used to understand how the Platform is used (page views, feature usage). May be disabled via browser settings or cookie preference center.
  • Preference Cookies: Remember your settings and preferences. May be disabled, though this may affect functionality.

10.2 Managing Cookies

You can control and manage cookies through your browser settings. Note that disabling certain cookies may affect Platform functionality. For more information on managing cookies, visit your browser's help documentation.

10.3 Do Not Track

Some browsers transmit "Do Not Track" signals. The Platform does not currently respond to these signals, but we do not use tracking technologies for cross-site behavioral advertising.

11. CHILDREN'S PRIVACY

The Platform is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at energystackhub@polsia.app. We will promptly delete such information upon verification.

12. SECURITY MEASURES

We implement commercially reasonable administrative, technical, and physical security measures to protect your personal data, including:

  • Encryption of data in transit (TLS/HTTPS) and at rest
  • Access controls limiting data access to authorized personnel on a need-to-know basis
  • Regular security assessments and vulnerability testing
  • Employee training on data privacy and security practices
  • Incident response procedures for detecting and responding to security events

Despite these measures, no electronic transmission or storage system is 100% secure. We cannot guarantee absolute security of your data. In the event of a breach, we will notify affected users as required by applicable law.

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by: posting the updated policy on this page with a new "Last Updated" date; and/or sending notice to your registered email address for significant changes. We encourage you to review this policy periodically. Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy.

14. CALIFORNIA-SPECIFIC DISCLOSURES (CCPA/CPRA)

14.1 Categories of Personal Information Collected

In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:

  • Identifiers (name, email address, account credentials, IP address)
  • Commercial information (transaction history, subscription status)
  • Internet or network activity information (usage logs, feature interactions)
  • Professional or employment-related information (job title, company name)
  • Energy consumption and facility data (commercial energy data you provide)

14.2 Business Purposes for Collection

We collect this information for the business purposes described in Section 4 of this policy.

14.3 No Sale or Sharing for Cross-Context Behavioral Advertising

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising purposes as defined by the CPRA.

14.4 Authorized Agent

California residents may designate an authorized agent to submit privacy requests on their behalf. To use an authorized agent, contact us at energystackhub@polsia.app with written authorization from the consumer and verification of the agent's identity.

15. STATE-SPECIFIC PRIVACY RIGHTS

In addition to California, residents of certain other states may have specific privacy rights under applicable state law, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy legislation. Rights may include access, correction, deletion, portability, and opting out of certain processing activities. To exercise your state-specific rights, contact us at energystackhub@polsia.app. We will respond consistent with applicable law.

16. CONTACT US

Steeled Inc.

Email: energystackhub@polsia.app

For privacy-related questions, requests to exercise your rights, or concerns about how we handle your data, please contact us at the email above. We will respond to all legitimate privacy requests within the timeframes required by applicable law.

17. DISPUTE RESOLUTION

If you have a complaint about our privacy practices and are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. For EEA residents, this is the supervisory authority in the EU member state of your habitual residence, place of work, or the location of an alleged infringement. For UK residents, this is the Information Commissioner's Office (ICO). For California residents, you may contact the California Privacy Protection Agency (CPPA).

Privacy disputes are also subject to the dispute resolution provisions in our Terms of Service.

Terms of Service Privacy Policy AI Disclaimer

© 2026 Steeled Inc. All rights reserved. EnergyStackHub is a product of Steeled Inc., a Delaware Corporation.

Contact: energystackhub@polsia.app