1. Scope
This policy describes privacy-relevant behavior observed in the Solar Equb application source. Items requiring an approved backend or legal decision remain visibly marked rather than invented.
2. Account and profile data
The inspected application uses Firebase phone OTP authentication. Profile records can include account/user identifiers, phone number, display name, preferred language, account status and legal-consent version records.
The current profile creation flow explicitly stores no KYC document payload. Any future identity-verification process must be documented here before deployment.
3. Equb and product activity
The app stores operational records required to provide the service, including selected solar packages, groups, invitations, membership, agreements, contribution schedules and obligations, payment state, cycles, allocations, orders, installation, handover, warranty and support activity.
4. Notifications and device information
The application uses Firebase Cloud Messaging and stores push-notification tokens and related device/platform information so operational notifications can be delivered and managed.
5. Firebase services
The inspected source uses Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Messaging, Cloud Storage and App Check. These services process data necessary for authentication, application records, notifications, uploads and backend-controlled workflows.
6. Analytics
[TO BE VERIFIED FROM BACKEND / RELEASE CONFIGURATION]
The website does not claim analytics behavior that could not be conclusively established from the inspected source snapshot.
7. Support content and uploads
Support flows can include tickets, messages and attachments. Users should submit only information necessary to resolve the support request and should not send passwords, OTP codes or unrelated sensitive documents.
8. Payment information
The codebase models payment and contribution state, receipts, callbacks and reconciliation. The inspected source snapshot does not contain an approved production payment provider configuration; it contains a non-production sandbox adapter. Definitive provider-specific privacy disclosures must be added when a production provider is approved.
9. Data retention and deletion
The app includes an authenticated deletion-request workflow. The exact retention periods, deletion completion timeline, legal holds and records that may need to be retained are not finalized in the inspected source.
[TO BE VERIFIED FROM BACKEND / LEGAL REVIEW]
10. Data sharing and processors
Firebase/Google services are used as infrastructure processors for the functions described above. Any additional production vendors, payment providers, support processors or other recipients must be listed after they are approved and configured.
[ADDITIONAL PROCESSORS TO BE VERIFIED]
11. Security
The application includes Firebase security rules, App Check integration and backend-controlled operations. This policy does not make an absolute security guarantee. No internet-connected system can honestly promise perfect security.
12. Your choices and requests
Users can request account deletion through the authenticated app flow. A website deletion request channel is also available when its backend endpoint is configured.
Other statutory rights, response deadlines and identity-verification requirements depend on the approved legal basis and applicable jurisdiction: [TO BE VERIFIED BY LEGAL REVIEW].
13. Contact
Approved privacy contact: [SUPPORT_EMAIL NOT CONFIGURED]
