Privacy
What we hold, and why
Last updated 19 August 2026.
What we collect
- Account data. Your email address, used to sign you in. Nothing else is required to create an account.
- Compliance data you enter. Legal entity details, buyers, products, installation and production data, fuel and electricity figures, and the documents you attach as evidence. This is your data; we process it to compute the figures you asked for.
- Supplier contact details. When you invite a supplier, we hold their name and phone number to build the invitation, and the answers they submit through their one-time link.
- Usage analytics. Aggregate page analytics via Vercel Analytics. No advertising trackers, no third-party ad pixels.
Where it lives
Data is stored in Google Firebase (Firestore and Firebase Authentication) and the application is served by Vercel. Both act as processors; neither is given your data for their own purposes. Transactional email, where configured, is sent through Resend.
Who can see it
- Your compliance data is scoped to your organisation. Other tenants cannot read it.
- A buyer sees a supplier's figures only when that supplier named them — consent is recorded, never assumed. Passport pages are access-coded.
- A supplier's submission is visible to the exporter who invited them, and to nobody else.
- We do not sell data, share it with advertisers, or use it to train models.
Removal and questions
To have your account or your organisation's data removed, or to ask anything about this page, use the contact page. One caveat, stated plainly: regulated calculation records are designed to be immutable — a correction creates a new run rather than editing the old one — so removal means deleting the record set, not silently rewriting history inside it.