Home

Careers

Log in

Book my demo

Contents

Introduction
1. Who we are and what this policy covers2. Information we collect3. How we use information4. Cookies and tracking technologies5. How we share information6. International data transfers7. How long we keep information8. How we protect information9. Your rights and choices10. Children11. Email communications12. Changes to this policy and how to contact us

Privacy Policy

Version 1.0 · Takes effect · Last updated

This Privacy Policy explains how Solesca Energy, Inc. (“Solesca”, “we”, “us”) collects, uses, shares and protects personal information when you visit solesca.com, use the Solesca platform at app.solesca.com and its related services (together, the “Services”), or otherwise interact with us. It also describes the choices and rights you have.

If you have questions or want to exercise a right described here, email privacy@solesca.com.


1. Who we are and what this policy covers

Solesca Energy, Inc. is a Delaware corporation with its principal office at 4809 N. Ravenswood Ave., Suite 421, Chicago, IL 60640, United States. We provide software for the design, simulation and engineering of solar projects to businesses such as developers, EPCs and engineering firms.

This policy applies to personal information we handle as a controller: information about visitors to our website, about the people who create and use accounts on the platform, and about the business contacts we correspond with.

Much of the data in the platform is content our customers create or upload: site boundaries, equipment selections, project addresses, drawings and similar material (“Customer Content”). Where Customer Content contains personal information about third parties (for example, a landowner’s address), the customer is the controller of that information and we process it only on the customer’s instructions as a processor (or “service provider” under US state law). That relationship is governed by our Data Processing Addendum rather than by this policy. If you are an individual whose information appears in a customer’s project data, please contact that customer first; we will help them respond.

Our Terms of Service govern use of the Services, and our Cookie Policy describes the cookies and similar technologies used on our website.

2. Information we collect

2.1 Information you give us:
  • Account information: your name, email address, organization, role within the organization and password (stored by our authentication provider in hashed form; we never see it). Most accounts are created by invitation from an organization’s owner or administrator, who gives us your email address; you add your name and choose a password when you accept the invitation.
  • Billing information: the billing contact, legal name, address and tax identifier of your organization, and the payment method you provide. Card and bank details are entered directly with our payment processor, Stripe; we store only a reference to the payment method, its type and last digits.
  • Customer Content: the projects, designs, files (for example KML/KMZ boundaries, images and PDFs), site addresses and coordinates, equipment selections and settings you create or upload while using the platform.
  • Support requests: when you contact us through the in-app support drawer or by email, we receive your message, your email address, the page you were on, your browser details and any screenshots you attach.
  • Website forms: when you request a demo or contact us through solesca.com, we receive the name, email address, company and message you enter.
2.2 Information we collect automatically:
  • On the website: your IP address, browser and device type, the pages you view, the site that referred you (including whether you arrived from an AI assistant such as ChatGPT), timestamps, and information from cookies and similar technologies described in our Cookie Policy. Analytics and marketing tools run only with your consent where the law requires it.
  • In the platform: sign-in events, the IP address and browser used to accept our Terms, and logs of account, billing and administrative actions. The platform does not include third-party analytics, session-recording or advertising tools.
  • Email: delivery, bounce and complaint events for the email we send you, and whether a message was opened, reported by our email provider.
2.3 Information we receive from others:
  • Your organization: owners and administrators of an organization account can invite users, assign roles and seats, and remove users. They can see the names, email addresses, roles and activity of the organization’s members.
  • Business data providers: on our website, the Apollo.io visitor tracker may associate a visit with the company it appears to come from and enrich our records with publicly available business contact information. We use HubSpot as our customer relationship management system for demo requests and sales conversations.
  • Payment processor: Stripe tells us whether a payment succeeded, failed or was disputed.

3. How we use information

3.1 Purposes:
  • Providing the Services: creating and securing accounts, running simulations and designs, storing Customer Content, generating deliverables, and providing the features your organization has purchased.
  • Billing: issuing invoices, collecting payment, retrying failed payments, and keeping the financial records the law requires.
  • Support: responding to your requests. Support requests submitted in the platform are relayed to a Solesca staff channel in Slack, together with your email address and any screenshots, so that the right person can respond. When a support engineer needs to view your account to resolve an issue, that access is signed, time-limited and logged.
  • Improving the Services: understanding how the platform is used, fixing defects, and developing new features. We may use de-identified or aggregated data, including data derived from usage patterns and Customer Content, to improve the Services and to develop and train the models behind them. We do not use identifiable Customer Content or project data for model training without the customer’s permission, and an organization can opt out of having its de-identified data used for training by emailing privacy@solesca.com. Our ARGUS roof-obstruction feature analyzes satellite imagery of the site being designed; it does not analyze personal information.
  • Security and integrity: detecting and preventing fraud, abuse, and unauthorized access; monitoring and logging administrative actions; and enforcing our Terms.
  • Communications: sending operational messages about your account, invoices, security, and changes to our terms and policies; and, for business contacts, sending information about Solesca products and events, which you can opt out of at any time.
  • Legal compliance: meeting our legal, tax and regulatory obligations and responding to lawful requests from authorities.
3.2 Legal bases (EEA, UK and Switzerland):

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Services and billing to the organization you represent, and responding to your requests); legitimate interests (securing and improving the Services, understanding how our website is used, and marketing to business contacts, in each case balanced against your interests and rights); consent (non-essential cookies on our website and any marketing that requires it; you can withdraw consent at any time); and legal obligation (financial record-keeping and responding to lawful requests).

4. Cookies and tracking technologies

Our website uses cookies and similar technologies for analytics and to measure whether our advertising leads to demo requests. Our Cookie Policy lists each cookie, its purpose and how long it lasts.

If you visit from the European Economic Area, the United Kingdom or Switzerland, analytics and marketing tools do not load until you accept them in the cookie banner, and you can change your choice at any time through the “Cookie settings” link in the site footer. We honor the Global Privacy Control browser signal as a request to disable marketing cookies.

The platform itself uses only the cookies and local storage needed to keep you signed in and remember your preferences. It does not use analytics, session-recording or advertising cookies.

5. How we share information

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information only as described here.

  • Subprocessors: service providers that process personal information on our behalf to run the Services: Amazon Web Services (hosting, storage, authentication, email delivery), Stripe (payments), Google Maps Platform (geocoding of site addresses and map imagery) and Slack (relaying support requests to our staff). Our current list, with what each provider receives, is at /legal/subprocessors.
  • Project-data providers: services that receive site coordinates or design parameters, but no personal information, to run simulations and provide terrain and imagery, such as DNV (SolarFarmer energy simulation), GPXZ (elevation data), the European Commission’s PVGIS service (horizon profiles) and satellite-imagery providers. Where an organization connects its own Nearmap subscription, Nearmap receives tile requests under that organization’s own agreement.
  • Website and marketing tools: Google Analytics and Google Ads conversion measurement, the Apollo.io visitor tracker (which loads a LiveIntent identity script), HubSpot (demo requests and CRM), Calendly (scheduling, on Calendly’s own site) and Google Fonts (which serves font files from Google’s servers). These apply to solesca.com, not to the platform.
  • Your organization: the owners and administrators of the organization account you belong to, as described above.
  • Legal and safety: when we believe disclosure is required by law or legal process, or is necessary to protect the rights, property or safety of Solesca, our customers or others.
  • Business transfers: in connection with a merger, acquisition, financing or sale of all or part of our business, in which case we will require the recipient to honor this policy.

6. International data transfers

We are based in the United States and store customer data in Amazon Web Services facilities in the US East (Ohio) region, with backups kept in the United States. If you use the Services from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your country.

For personal information transferred from the European Economic Area, the United Kingdom or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum and Swiss requirements where applicable. Customers that are controllers can enter into these clauses with us through our Data Processing Addendum.

7. How long we keep information

  • Account information and Customer Content: for as long as the account or organization is active. When an organization asks us to delete its data, or an account is closed, we delete the associated data within about 30 days, except where we must keep it for the reasons below.
  • Backups: deleted data may persist in encrypted backups for up to 30 days before it is overwritten.
  • Billing records: invoices, payments and related records for as long as tax and accounting law require, typically seven years.
  • Security and audit logs: logs of sign-ins, administrative actions and support access are kept for as long as needed to investigate incidents and demonstrate compliance.
  • Marketing preferences: if you opt out of marketing email, we keep your email address on a suppression list so that we continue to honor your choice.
  • Website analytics: for the periods stated in our Cookie Policy.

8. How we protect information

Customer data is encrypted at rest with AES-256 and in transit with TLS 1.2 or newer. Administrative access to our infrastructure requires multi-factor authentication and is logged. Our container images, dependencies and cloud environment are scanned continuously for vulnerabilities. When a support engineer needs to see a customer’s account, that access runs through a signed, time-limited mechanism and every session is recorded. More detail is available on our security overview, and full documentation is available to customers under NDA.

No system is completely secure. If we learn of a breach affecting your personal information, we will notify you and any relevant authorities as the law requires. You are responsible for keeping your account credentials confidential.

9. Your rights and choices

9.1 Everyone:

You can update your name and email address in your account settings, and organization owners and administrators can manage members and billing details. You can opt out of marketing email through the link in any marketing message, in your account settings, or by emailing privacy@solesca.com. Operational messages about your account, invoices, security and changes to our terms are part of the Services and cannot be opted out of while you hold an account.

9.2 European Economic Area, United Kingdom and Switzerland:

You have the right to request access to the personal information we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your local supervisory authority (in the United Kingdom, the Information Commissioner’s Office). To exercise these rights, contact privacy@solesca.com; we respond within one month.

9.3 United States:

Depending on the state you live in, you may have the right to know what personal information we collect and how we use and share it, to access and receive a copy of it, to correct inaccurate information, to delete it, to opt out of the sale of personal information, of sharing for targeted advertising and of certain profiling, and to not be discriminated against for exercising these rights. We do not sell personal information or share it for targeted advertising. We treat the Global Privacy Control signal as an opt-out for marketing cookies on our website.

To exercise these rights, email privacy@solesca.com. We will confirm receipt within ten business days and respond within 45 days, extending once by a further 45 days if necessary. If we deny your request, you may appeal by replying to our response; we will explain the outcome of the appeal and, where required, how to contact your state attorney general.

9.4 Verification and authorized agents:

To protect your information, we verify requests by confirming control of the email address associated with your account or, for website visitors, by asking for information that matches our records. An authorized agent may submit a request on your behalf if they provide your written authorization or other proof of authority, and we may still confirm the request with you directly.

If your personal information is contained in a customer’s Customer Content, we will refer your request to that customer and assist them, as described in our Data Processing Addendum.

10. Children

The Services are business tools intended for adults. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact privacy@solesca.com and we will delete it.

11. Email communications

We send two kinds of email. Operational email covers invoices and payment notices, security alerts, support replies, and notices about changes to our terms and policies. These are part of providing the Services and do not include an unsubscribe link. Marketing email covers product news, events and similar content for business contacts; every marketing message includes an unsubscribe link, and you can also opt out in your account settings or by emailing us. When you opt out, we add your address to a suppression list within ten business days.

Marketing and operational email are sent through separate systems so that an unsubscribe from marketing never stops an invoice or a security notice from reaching you.

12. Changes to this policy and how to contact us

12.1 Changes:

We may update this policy as our Services, our providers or the law change. We post every revision, with a summary of what changed, at /legal/updates and update the “last updated” date above. For changes that materially affect how we use your personal information, we will notify account holders by email before the change takes effect.

12.2 Contact:

Privacy questions and requests: privacy@solesca.com. Legal notices: legal@solesca.com. Post: Solesca Energy, Inc., 4809 N. Ravenswood Ave., Suite 421, Chicago, IL 60640, United States.


LEGAL

Terms of Service

Legal

CONTACT

Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60659

SOCIAL

Book a demo



Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60659


© 2026 Solesca Energy, Inc.