1. Who we are

SolarIonix ("we", "us", "our") is a SaaS product for solar installation businesses operating in India. This policy explains what personal data we collect, how we use it, and your rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

2. What we collect

  • Account data — name, email address, phone number, organisation name, role, GSTIN, PAN.
  • Business data — leads, projects, customers, invoices, photos, inventory, location (GPS coordinates from site visits) and business information you enter into SolarIonix.
  • Usage data — pages visited, actions taken, device type, IP address (for security and analytics).
  • Authentication data — if you sign in via Google OAuth, we receive your name, email and profile picture from Google. We do not receive or store your Google password.
  • Payment data — handled by our payment partner; we never see card numbers.

3. How we use it

  • To provide the service you signed up for.
  • To send service-related notifications (login alerts, billing).
  • To improve product reliability and security.
  • To respond to your support requests.

We do not sell, rent or share your customer data with third parties for marketing.

4. Where data lives

Your data is stored in encrypted PostgreSQL on Supabase, hosted in the AWS Mumbai (ap-south-1) region. Backups are encrypted and retained per the table in section 6.

5. Third-party services & sharing

We share data only with sub-processors strictly necessary to operate the service:

  • Supabase — database, authentication, file storage and real-time sync. Data hosted on AWS Mumbai (ap-south-1) region.
  • Firebase Cloud Messaging (FCM) — push notifications on mobile devices. Google processes device tokens; no business data is sent to Google.
  • Google OAuth — optional sign-in method. Google shares only name, email and profile picture.
  • Vercel / Cloudflare — web hosting and CDN for the dashboard at app.solarionix.com.
  • An e-mail/SMS provider for transactional messages.
  • A payment gateway for subscription billing.

6. Retention

  • Active accounts: as long as your subscription is active.
  • Cancelled accounts: 6 months read-only, then permanent deletion.
  • Invoices: 8 years (GST audit requirement under India tax law).
  • Server logs: 30 days.

6A. Data deletion

You may request complete deletion of your account and all associated personal data at any time by emailing apps@softwaller.com. Upon receiving a verified request, we will delete all personal data within 30 days, except where retention is required by law (e.g., GST invoices retained for 8 years under Indian tax law).

7. Your rights

Under the DPDP Act you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your account and associated personal data (subject to legal retention).
  • Export your data in CSV / JSON.
  • Withdraw consent at any time.

To exercise any of these, email apps@softwaller.com. We respond within 30 days.

8. Children

SolarIonix is a B2B product. We do not knowingly collect data from anyone under 18.

9. Changes

We will post any changes to this policy on this page and update the "Last updated" date above. Material changes will be notified by email.

10. Contact

Questions? Email apps@softwaller.com or write to our Data Protection Officer at the address registered on our company profile.