Preview Mode

DRAFT — PENDING ATTORNEY REVIEW

This policy has not yet been reviewed by legal counsel. Do not rely on it as a final, enforceable document.

Privacy Policy

Effective Date: April 2026 · Last Updated: April 2026

SunTarget, Inc. (“SunTarget,” “we,” “us,” or “our”) operates the SunTarget platform at suntarget.ai. This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with the Service.

By using the Service, you acknowledge that you have read this Privacy Policy.

1. Who This Policy Covers

This Privacy Policy applies to:

  • Commercial customers — wall-panel manufacturers and commercial real estate professionals who use the commercial solar analysis features
  • Residential customers — solar installation companies who use the residential campaign and walk pack features
  • Visitors — anyone who browses suntarget.ai or the public demo

It does not apply to the personal information of residential homeowners whose addresses are submitted to the Service by our residential customers. That homeowner data is governed by the Data Processing Agreement (DPA) between SunTarget and the applicable residential customer.

2. Information We Collect

2.1 Information You Provide

CategoryExamplesWho Provides It
Account informationName, email address, company name, job title, hashed passwordCommercial and residential customers
Billing informationStripe customer ID (we do not store card numbers)All subscribers
Building dataBuilding addresses, dimensions, BIM/IFC files for commercial analysisCommercial customers
Campaign dataHomeowner address lists uploaded for direct mail campaignsResidential customers
CommunicationsEmails and messages you send to brett@suntarget.aiAny user

2.2 Information Collected Automatically

CategoryExamplesPurpose
Usage dataPages visited, features used, time on siteProduct improvement
Analysis historyBuildings analyzed, report viewsService functionality
Log dataIP address, browser type, referring URLSecurity and debugging
Tracking QR scansIP address, user agent, timestamp for postcards with QR codesCampaign analytics for residential customers

Analytics: We use Plausible Analytics, a privacy-first analytics tool that does not use cookies and does not collect personally identifiable information or share data with third parties.

2.3 Information from Third Parties

SourceInformation ReceivedPurpose
ATTOMProperty data (address, property attributes, estimated value)Residential campaign enrichment
Google Solar APIRoof solar scoreResidential campaign scoring
MapboxGeocoded building coordinates, footprint polygonCommercial analysis
NREL PVWattsSolar energy estimatesCommercial analysis
StripePayment confirmation, subscription statusBilling

3. How We Use Personal Information

We use personal information to:

  • Provide, operate, and improve the Service
  • Process payments and manage subscriptions
  • Respond to support requests and communicate with you about the Service
  • Generate Analysis Outputs (solar analysis reports, financial projections) based on building data you provide
  • Conduct direct mail campaigns on behalf of residential customers (using homeowner data provided by those customers)
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations
  • Send transactional emails (order confirmations, account notices, password resets) — these do not include an unsubscribe option as they are required for Service operation
  • Send product updates and marketing emails (you may unsubscribe at any time)

We do not sell personal information. We do not use personal information for automated decision-making that produces legal effects on individuals.

4. Homeowner Data — Residential Campaigns

When residential customers upload homeowner addresses for direct mail campaigns, SunTarget acts as a data processor on behalf of the residential customer (who is the data controller). In this capacity:

  • We use homeowner addresses solely to fulfill the campaign services contracted by the residential customer (address enrichment, scoring, and postcard printing via Lob)
  • We do not use homeowner addresses for our own marketing or share them with parties other than our sub-processors (ATTOM, Google, Lob)
  • We maintain a suppression list of homeowners who have opted out of future mailings. Opt-out requests may be submitted to brett@suntarget.ai
  • We use census tract median income data (a public dataset from the US Census Bureau) to help residential customers prioritize campaign targets. This data is aggregate and geographic — it is not tied to individual homeowner financial information

Residential customers are responsible for ensuring their use of the campaign service complies with applicable law, including CAN-SPAM, applicable state direct mail regulations, and any state privacy laws governing solicitation.

5. Data Retention

Data CategoryRetention Period
Account and billing recordsDuration of subscription + 7 years (for financial compliance)
Commercial analysis resultsDuration of subscription + 2 years, then deleted on request
Residential campaign homeowner addresses24 months after campaign close, then permanently deleted
Suppression list (opt-outs)Indefinitely (required to honor opt-outs) — stored as hashed identifiers
Security and access logs90 days
Audit logs (admin actions)3 years

You may request deletion of your personal information by submitting a Data Subject Request or contacting brett@suntarget.ai. We will process verified deletion requests within 45 days, subject to retention requirements for legal compliance and fraud prevention.

6. How We Share Information

We share personal information only in the following circumstances:

Service Providers (Sub-processors)

We share personal information with third-party vendors who help us operate the Service:

  • Neon — database hosting (PostgreSQL)
  • Vercel — application hosting and edge computing
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Lob — postcard printing and mailing (residential customers only)
  • ATTOM Data Solutions — property data (residential customers only)
  • Mapbox — geocoding and building footprints (commercial customers only)
  • NREL — solar energy calculations (commercial customers only)
  • Sentry — error monitoring

All sub-processors are contractually required to use personal information only for the purposes of providing their services to SunTarget and to maintain appropriate security measures.

Legal Requirements

We may disclose personal information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, prevent fraud, or protect the safety of users or others.

Business Transfers

In the event of a merger, acquisition, or sale of assets, personal information may be transferred to the acquiring party. We will notify you before your information is transferred and subject to a different privacy policy.

With Your Consent

We may share information for other purposes with your explicit consent.

7. Data Security

We implement technical and organizational security measures including:

  • Passwords stored using bcrypt hashing (never plaintext)
  • Session tokens stored in HTTP-only, Secure, SameSite cookies
  • All data transmitted over HTTPS/TLS
  • Neon PostgreSQL database with access restricted to application credentials
  • Admin access protected by mandatory two-factor authentication (TOTP)
  • Per-request cryptographic nonces for Content Security Policy enforcement
  • Audit logging for all administrative actions

No security system is impenetrable. We cannot guarantee that personal information will never be accessed, disclosed, altered, or destroyed by a breach. In the event of a data breach affecting your personal information, we will notify you as required by applicable law.

8. Your Privacy Rights

Depending on your location and applicable law, you may have the following rights:

RightDescriptionHow to Exercise
AccessRequest a copy of personal information we hold about youDSR form or email brett@suntarget.ai
CorrectionRequest correction of inaccurate personal informationDSR form or email brett@suntarget.ai
DeletionRequest deletion of your personal informationDSR form or email brett@suntarget.ai
Data portabilityRequest your data in a portable formatDSR form or email brett@suntarget.ai
Opt-out of marketingUnsubscribe from marketing emailsUnsubscribe link in email
Homeowner opt-outOpt out of future direct mail campaignsEmail brett@suntarget.ai with subject “Mail Opt-Out”

We do not respond to Do Not Track signals as no industry standard has been established.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information.

Categories of Personal Information We Collect

  • Identifiers — name, email address, phone number, account credentials
  • Property data — street address, roof characteristics, building dimensions
  • Geolocation — latitude/longitude derived from property addresses
  • Commercial information — order history, payment records, service usage

How We Use This Information

  • Solar analysis and energy production modeling
  • Direct mail generation for marketing campaigns
  • Financial modeling (IRR, payback period, savings estimates)

We Do Not Sell Personal Information

SunTarget does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration as defined under the CCPA.

Your CCPA Rights

  • Right to know — request what personal information we have collected, used, disclosed, or sold in the preceding 12 months
  • Right to delete — request deletion of your personal information, subject to certain legal exceptions
  • Right to correct — request correction of inaccurate personal information we maintain about you
  • Right to non-discrimination — we will not deny service, charge different prices, or provide a different quality of service because you exercised your CCPA rights

How to Exercise Your California Privacy Rights

Submit a request through our Data Subject Request form or email us at brett@suntarget.ai with the subject line “California Privacy Request.” We will respond to verifiable requests within 45 days. We may need to verify your identity via the email address associated with your account before processing your request.

9. Cookies and Tracking

The SunTarget platform does not use third-party advertising cookies. Our analytics provider (Plausible) is cookieless and does not track users across sites.

We use a session cookie (HTTP-only) to keep you logged in during your browser session. This cookie is essential for Service operation and cannot be disabled if you wish to use the Service.

QR codes on postcards generated by the residential campaign feature link to tracking URLs that log scan events (IP address, user agent, timestamp). These are used solely to provide campaign scan analytics to the residential customer who ordered the campaign.

10. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, please contact us at brett@suntarget.ai.

11. International Data Transfers

The Service is hosted in the United States. If you access the Service from outside the United States, your personal information may be transferred to and processed in the United States, where privacy laws may differ from those in your country. By using the Service, you consent to this transfer.

For customers based in the European Economic Area (EEA) or United Kingdom who use the Service to process EU/UK personal data, a Data Processing Agreement (DPA) is available upon request.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or in-app notice at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact

  • Privacy inquiries: brett@suntarget.ai
  • Subject line for privacy requests: “Privacy Request”
  • Subject line for homeowner opt-out: “Mail Opt-Out”
  • Data Subject Request form: /privacy/request
  • Response commitment: 5 business days for general inquiries; 45 days for formal data subject requests

SunTarget, Inc. | suntarget.ai