Legal / Privacy

Privacy Policy

Effective 7 September 2026

This policy explains what personal data Voltstack collects when you visit https://voltstack.energy, sign up for early access, or use the platform at https://app.voltstack.energy, why we collect it, who processes it for us, how long we keep it, and the rights you have over it.

1. Who we are

Voltstack is operated by Rock Salt Consulting Ltd, a company registered in England and Wales ("we", "us"). We run the public website at https://voltstack.energy and the Voltstack Platform at https://app.voltstack.energy (together, the "Service"), a workspace product for European energy-market analysis.

For your own account, early-access signups, billing and website visits, we are the data controller. For personal data inside a customer organisation's workspace on the Platform (member lists, workspace content, audit trails), the customer organisation is the controller and we act as its processor. This policy covers both and says which is which.

Contact for anything in this policy: hello@voltstack.energy.

2. What we collect

Website visits (we are controller)

Early-access signups (we are controller)

Platform accounts and organisations (we are controller)

Workspace data (your organisation is controller, we are processor)

Product usage measures (we are controller)

We compute a small set of usage measures per customer organisation from its own activity on the Platform: number of seats, number of workspaces and widgets, how recently the organisation was active, and which plan-gated features it has tried to use. We use these to run trials, decide what to build, and shape pricing and account conversations. They are derived from the organisation's activity as a whole, are never sold, and are not shared with other customers.

What we do not collect

The market data shown in the Service (prices, flows, outages, storage levels, forecasts) is public infrastructure data and contains no personal data. We serve no advertising and use no advertising trackers. Error reporting (Sentry) and product analytics (PostHog) are wired into the Platform but switched off; if we turn either on we will update this policy and the processor table below first.

3. Cookies

The Platform sets only the session cookies Clerk needs to keep you signed in. These are strictly necessary and cannot be switched off while using the Platform. The public website sets no cookies of its own. If we add analytics cookies later we will update this section and ask for consent where the law requires it.

4. Why we process it (legal bases)

5. Who processes it for us

We use the following providers to run the Service and share with each only what it needs.

ProviderPurposeApplies to
VercelHosting and cookieless web analytics for the public websiteWebsite
RailwayApplication hosting and PostgreSQL databasesPlatform
ClerkAuthentication, sessions and organisation membershipPlatform
Google, MicrosoftOptional sign-in providers; they release your basic profile to Clerk only when you choose themPlatform
StripePayments, subscriptions and the billing portalPlatform
ResendTransactional email (signup confirmations, account and billing notices)Website, Platform
Google WorkspaceStorage of early-access signups and our own emailWebsite

We do not sell personal data and do not share it with anyone else, except where the law requires it or to protect the Service and its users.

6. International transfers

Several of the providers above are United States companies. Where personal data leaves the EEA or the United Kingdom, we rely on the provider's certification under the EU-US Data Privacy Framework (and its UK extension) where it holds one, and otherwise on Standard Contractual Clauses in our agreement with that provider. Copies of the relevant safeguards are available on request.

7. How long we keep it

8. Security

Tenant isolation is structural: each customer organisation gets its own PostgreSQL database with its own credentials, cross-tenant access is blocked at the database permission layer and covered by automated tests, and stored database credentials are encrypted. Connections use TLS. Access inside an organisation is role-based and every change is written to an append-only audit trail. API routes are rate limited.

No system is perfectly secure. If we learn of a personal data breach affecting you, we will notify affected customers without undue delay and, where we act as processor, within the window agreed in the customer's data processing terms.

9. Your rights

If you are in the EEA or the UK you can ask us for access to, correction of, deletion of, or a copy of your personal data, ask us to restrict or object to its processing, withdraw consent where consent is the basis, and complain to your supervisory authority. Write to hello@voltstack.energy. If your data sits inside a customer organisation's workspace, we may redirect the request to that organisation, since it is the controller, and we will help it answer.

10. Changes

We will post changes here with a new effective date. For material changes we will email account owners before they take effect.