Steeled Inc. ("Company," "we," "us," or "our") operates the EnergyStackHub platform at energystackhub.com (the "Platform"). This Privacy Policy describes how we collect, use, disclose, and protect your personal and business information when you use the Platform.
By using the Platform, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, do not use the Platform.
This Privacy Policy is incorporated into and forms part of our Terms of Service.
Email: energystackhub@polsia.app
For purposes of applicable data protection law, including the EU General Data Protection Regulation ("GDPR"), Steeled Inc. is the data controller responsible for your personal data collected through the Platform.
We collect the following categories of information:
When you create an account or contact us, we collect: name, email address, company name, job title, phone number (if provided), and other information you voluntarily submit.
To provide energy management services, we collect data you upload or connect including: utility bills and rate information, energy consumption data, facility details (square footage, building type, equipment), utility account identifiers, and energy procurement contracts or proposals.
We automatically collect: pages viewed and features used, search queries and filters applied, AI analysis requests and outputs generated, time spent on features, click patterns and navigation paths, and error logs and performance data.
We collect: IP address, browser type and version, operating system, device type, referring URLs, session identifiers, and time zone and language settings.
For paid subscriptions and per-output purchases: billing name, billing address (country and state), and payment method information (processed and stored by our payment processor; we do not store full card numbers). We retain records of transactions, subscription status, and invoices.
If you contact us via email or support channels: the content of your communications, attachments you send, and our responses. We may retain this data to resolve disputes, improve support, and fulfill legal obligations.
For marketplace participants (energy professionals): credentials and certifications (self-reported), service areas, portfolio information, and contact preferences for client lead notifications.
We use your data to operate, maintain, and improve the Platform; authenticate your account; process payments; generate AI analyses and reports; and fulfill your subscription and per-output purchase requests.
We use aggregated, de-identified usage data to understand how the Platform is used, identify areas for improvement, train and refine AI models, and develop new features. We do not use personally identifiable information to train AI models without your explicit consent.
We use your contact information to send transactional emails (receipts, account notifications, password resets), platform updates and new feature announcements, and service interruption notices. You may opt out of non-transactional communications at any time.
We use your project and energy data to match commercial clients with relevant energy service providers in the marketplace. Contact information shared with matched providers is limited to what is necessary for the lead notification.
We use your data to detect, investigate, and prevent fraudulent activity, abuse, and security threats; enforce our Terms of Service; and comply with legal obligations.
We may use and disclose your data to comply with applicable laws and regulations, respond to lawful requests from governmental authorities, enforce our agreements, and protect the rights, property, or safety of the Company, our users, or others.
We use aggregated, anonymized data for internal analytics, industry research, and reporting. No individually identifiable information is included in public reports or research outputs.
For users located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:
We share data with carefully selected third-party service providers who assist us in operating the Platform, including: cloud hosting and infrastructure providers, payment processors, email service providers, analytics platforms, and customer support tools. These providers are contractually required to handle your data only as instructed by us and in accordance with applicable privacy law.
When you request a connection with an energy service provider through the marketplace, we share your contact information and project details with the selected provider to facilitate the introduction. You consent to this sharing by initiating a marketplace connection request.
We may disclose your information if required to do so by law, court order, or other governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Company, our users, or others.
In connection with a merger, acquisition, restructuring, sale of assets, or bankruptcy, your information may be transferred as part of the transaction. We will provide notice before your information is transferred and becomes subject to a different privacy policy, and you will have an opportunity to request deletion of your data.
We may share aggregated, de-identified data (data that cannot reasonably be used to identify you) with third parties for research, analytics, or business purposes.
The Platform is operated from the United States. If you access the Platform from outside the United States, your personal data may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.
For EEA, UK, and Swiss users, we rely on the following transfer mechanisms to ensure adequate protection of your personal data: Standard Contractual Clauses (SCCs) approved by the European Commission, and any applicable adequacy decisions. You may contact us at energystackhub@polsia.app to obtain a copy of the relevant transfer mechanisms.
We retain your personal data for as long as necessary to provide the Platform, fulfill the purposes described in this policy, and comply with legal obligations. Our general retention periods are:
| Data Type | Retention Period |
|---|---|
| Account and contact information | Duration of account + 2 years after deletion request |
| Energy and usage data | Duration of account + 1 year |
| Billing and payment records | 7 years (tax and legal compliance) |
| AI-generated outputs and analyses | 90 days after generation, unless saved to account |
| Support communications | 3 years from date of communication |
| Usage logs (technical) | 90 days |
| Marketing communications consent | Until consent withdrawn + 3 years |
After retention periods expire, we securely delete or anonymize your data. We may retain de-identified data indefinitely for research and analytics.
Regardless of your location, you have the right to:
California residents have the right to:
To exercise your rights, contact us at energystackhub@polsia.app. We will respond within 45 days (CCPA) or one month (GDPR), with possible extensions as permitted by law.
You can control and manage cookies through your browser settings. Note that disabling certain cookies may affect Platform functionality. For more information on managing cookies, visit your browser's help documentation.
Some browsers transmit "Do Not Track" signals. The Platform does not currently respond to these signals, but we do not use tracking technologies for cross-site behavioral advertising.
The Platform is not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at energystackhub@polsia.app. We will promptly delete such information upon verification.
We implement commercially reasonable administrative, technical, and physical security measures to protect your personal data, including:
Despite these measures, no electronic transmission or storage system is 100% secure. We cannot guarantee absolute security of your data. In the event of a breach, we will notify affected users as required by applicable law.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by: posting the updated policy on this page with a new "Last Updated" date; and/or sending notice to your registered email address for significant changes. We encourage you to review this policy periodically. Your continued use of the Platform after changes are posted constitutes acceptance of the updated policy.
In the past 12 months, we have collected the following categories of personal information as defined by the CCPA:
We collect this information for the business purposes described in Section 4 of this policy.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising purposes as defined by the CPRA.
California residents may designate an authorized agent to submit privacy requests on their behalf. To use an authorized agent, contact us at energystackhub@polsia.app with written authorization from the consumer and verification of the agent's identity.
In addition to California, residents of certain other states may have specific privacy rights under applicable state law, including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy legislation. Rights may include access, correction, deletion, portability, and opting out of certain processing activities. To exercise your state-specific rights, contact us at energystackhub@polsia.app. We will respond consistent with applicable law.
Email: energystackhub@polsia.app
For privacy-related questions, requests to exercise your rights, or concerns about how we handle your data, please contact us at the email above. We will respond to all legitimate privacy requests within the timeframes required by applicable law.
If you have a complaint about our privacy practices and are not satisfied with our response, you may have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. For EEA residents, this is the supervisory authority in the EU member state of your habitual residence, place of work, or the location of an alleged infringement. For UK residents, this is the Information Commissioner's Office (ICO). For California residents, you may contact the California Privacy Protection Agency (CPPA).
Privacy disputes are also subject to the dispute resolution provisions in our Terms of Service.