Privacy Policy
This policy explains what personal data Voltstack collects when you visit https://voltstack.energy, sign up for early access, or use the platform at https://app.voltstack.energy, why we collect it, who processes it for us, how long we keep it, and the rights you have over it.
1. Who we are
Voltstack is operated by Rock Salt Consulting Ltd, a company registered in England and Wales ("we", "us"). We run the public website at https://voltstack.energy and the Voltstack Platform at https://app.voltstack.energy (together, the "Service"), a workspace product for European energy-market analysis.
For your own account, early-access signups, billing and website visits, we are the data controller. For personal data inside a customer organisation's workspace on the Platform (member lists, workspace content, audit trails), the customer organisation is the controller and we act as its processor. This policy covers both and says which is which.
Contact for anything in this policy: hello@voltstack.energy.
2. What we collect
Website visits (we are controller)
- Standard server logs: IP address, browser type, pages requested and timestamps, kept by our hosting provider for security and troubleshooting.
- Aggregate page-view statistics through Vercel Web Analytics. It sets no cookies and does not build a profile of individual visitors.
- Alert and briefing settings you configure on the public dashboard (thresholds, an optional delivery webhook URL) are stored in your own browser. When an alert fires, the Service forwards the alert text to the webhook you supplied and stores nothing.
Early-access signups (we are controller)
- What you enter in the early-access form: email address, company, role, markets of interest, location, and your consent tick.
- Context we attach: the time of signup, the page you came from and any campaign tag in its URL.
- Where it goes: a signup spreadsheet in our Google Workspace, and a confirmation email to you sent through Resend. The form is rate limited by IP address; those counters live in memory and are not written anywhere.
Platform accounts and organisations (we are controller)
- Name, email address and, where provided, a profile picture, collected at sign-up through our authentication provider, Clerk. If you sign in with Google or Microsoft, we receive the basic profile those providers release (name, email address, avatar) and nothing else. We never see your Google or Microsoft password.
- Your organisation's name and identifier, and your role in it (admin, editor, viewer).
- Billing linkage: a Stripe customer identifier and your plan and subscription status. Card details go directly to Stripe and never reach our systems.
- Service emails about your account, trial or subscription, sent through Resend.
Workspace data (your organisation is controller, we are processor)
- Workspace names, layouts, widget configurations and their version history, attributed to the user who created or saved them.
- Your organisation's member list: user identifier, email address and role.
- An append-only audit trail of actions inside your organisation (who did what and when), including the IP address each request came from.
Product usage measures (we are controller)
We compute a small set of usage measures per customer organisation from its own activity on the Platform: number of seats, number of workspaces and widgets, how recently the organisation was active, and which plan-gated features it has tried to use. We use these to run trials, decide what to build, and shape pricing and account conversations. They are derived from the organisation's activity as a whole, are never sold, and are not shared with other customers.
What we do not collect
The market data shown in the Service (prices, flows, outages, storage levels, forecasts) is public infrastructure data and contains no personal data. We serve no advertising and use no advertising trackers. Error reporting (Sentry) and product analytics (PostHog) are wired into the Platform but switched off; if we turn either on we will update this policy and the processor table below first.
3. Cookies
The Platform sets only the session cookies Clerk needs to keep you signed in. These are strictly necessary and cannot be switched off while using the Platform. The public website sets no cookies of its own. If we add analytics cookies later we will update this section and ask for consent where the law requires it.
4. Why we process it (legal bases)
- To provide the Service you or your organisation signed up for: performance of a contract (GDPR Art. 6(1)(b)).
- To bill for paid plans and keep the records tax law requires: performance of a contract and legal obligation (Art. 6(1)(b) and (c)).
- To keep a multi-tenant system secure (audit trails, rate limiting, abuse prevention): our legitimate interest (Art. 6(1)(f)).
- To send early-access communications after you sign up for them: your consent (Art. 6(1)(a)), which you can withdraw at any time by emailing us.
- To send service emails about your account, trial or subscription: performance of a contract. These are not marketing emails. If we ever want to send marketing email we will ask first.
5. Who processes it for us
We use the following providers to run the Service and share with each only what it needs.
| Provider | Purpose | Applies to |
|---|---|---|
| Vercel | Hosting and cookieless web analytics for the public website | Website |
| Railway | Application hosting and PostgreSQL databases | Platform |
| Clerk | Authentication, sessions and organisation membership | Platform |
| Google, Microsoft | Optional sign-in providers; they release your basic profile to Clerk only when you choose them | Platform |
| Stripe | Payments, subscriptions and the billing portal | Platform |
| Resend | Transactional email (signup confirmations, account and billing notices) | Website, Platform |
| Google Workspace | Storage of early-access signups and our own email | Website |
We do not sell personal data and do not share it with anyone else, except where the law requires it or to protect the Service and its users.
6. International transfers
Several of the providers above are United States companies. Where personal data leaves the EEA or the United Kingdom, we rely on the provider's certification under the EU-US Data Privacy Framework (and its UK extension) where it holds one, and otherwise on Standard Contractual Clauses in our agreement with that provider. Copies of the relevant safeguards are available on request.
7. How long we keep it
- Early-access signups: until you ask us to delete them or until we close the early-access programme, whichever comes first.
- Account and organisation data: for the life of the account or organisation.
- Workspace data, member lists and the audit trail: for the life of the organisation's tenancy. The audit trail is append-only by design while the tenancy is active.
- Billing records: for as long as tax and accounting law requires.
- Deletion: when an organisation is deleted its tenancy is suspended and cut off from access immediately, and its database is permanently deleted within 30 days of a written request from an organisation admin. Backup copies may persist for a short period after deletion and are then overwritten.
8. Security
Tenant isolation is structural: each customer organisation gets its own PostgreSQL database with its own credentials, cross-tenant access is blocked at the database permission layer and covered by automated tests, and stored database credentials are encrypted. Connections use TLS. Access inside an organisation is role-based and every change is written to an append-only audit trail. API routes are rate limited.
No system is perfectly secure. If we learn of a personal data breach affecting you, we will notify affected customers without undue delay and, where we act as processor, within the window agreed in the customer's data processing terms.
9. Your rights
If you are in the EEA or the UK you can ask us for access to, correction of, deletion of, or a copy of your personal data, ask us to restrict or object to its processing, withdraw consent where consent is the basis, and complain to your supervisory authority. Write to hello@voltstack.energy. If your data sits inside a customer organisation's workspace, we may redirect the request to that organisation, since it is the controller, and we will help it answer.
10. Changes
We will post changes here with a new effective date. For material changes we will email account owners before they take effect.