Privacy Policy
This Privacy Policy describes how GridPay Inc. ("GridPay," "we," "us") collects, uses, shares, and retains information when you use gridpay.com, gridpay.app, our mobile experiences, and related energy services (the "Service"). GridPay is a Texas-focused smart-home energy company. We help homeowners connect authorized meter, battery, solar, and thermostat data, participate in energy programs, and manage subscriptions and rewards.
If you do not agree with this policy, do not use the Service. Our Terms of Service govern use of the Service.
1. Data we collect
We collect information you provide, information from devices and accounts you authorize, and information generated when you use the Service.
1.1 Account and identity
- Name, email address, and phone number.
- Login credentials and session data handled by our authentication provider, Clerk. We do not store your password ourselves.
- Home or service address, and communications you send us (support email, in-product messages).
1.2 Smart Meter Texas and premises data
With your authorization, we connect to Smart Meter Texas to retrieve data for the electric service identifier (ESIID) you enroll. That data includes meter identity and 15-minute interval consumption and export (kilowatt-hours), and related read timestamps. We use it to show your usage, verify exports, calculate rewards, and support retail-plan comparisons you request. You can disconnect the meter in GridPay. Authorization is also controlled through Smart Meter Texas and your utility processes.
1.3 Batteries, solar inverters, and other smart devices
If you connect equipment, we receive the data that manufacturer’s API makes available under the permissions you grant, which may include:
- Tesla Powerwall and Tesla energy sites (Tesla Fleet API): site and battery telemetry such as charge level, backup reserve, grid import and export, solar production, and, if you enable control, commands that change charge, discharge, or reserve settings.
- Solar inverters, including SolarEdge and Enphase, when you connect those accounts: production and site telemetry those APIs provide.
- Other batteries or panels you choose to connect: the telemetry and control scope shown at the time you connect.
We store the tokens needed to call those APIs on your behalf. Device tokens are encrypted at rest (AES-256-GCM). Remote commands run only for features you turn on. You can disconnect a device in GridPay and revoke access in the manufacturer’s account.
1.4 Google Nest thermostats (Smart Device Management API)
If you connect a Google Nest thermostat, you sign in with Google and grant the Smart Device Management scope https://www.googleapis.com/auth/sdm.service. GridPay then calls Google’s Smart Device Management API from our servers using tokens we store encrypted. We access thermostat data and, when you enable scheduling or control, we send thermostat commands. Specifically, we use:
- Traits we read: Temperature (ambient temperature), Humidity, ThermostatMode (for example heat, cool, heat-cool, or off), ThermostatHvac (whether the system is heating or cooling), ThermostatTemperatureSetpoint (heat and cool setpoints), ThermostatEco (eco mode and eco setpoints), Fan (fan timer state), Connectivity (online or offline), and Info (the custom device name).
- Commands we may send when you enable control: set heat setpoint, set cool setpoint, set a heat-cool range, set HVAC mode, set fan timer, and set eco mode.
Why: we use this Nest data to schedule heating and cooling for energy savings and for demand-response or grid programs you join. We use it to show thermostat status in GridPay and to apply the schedule or event you authorized.
What we do not do with Nest data: we do not sell Nest data. We do not use Nest data for advertising, retargeting, or ads profiling. We do not use it to train ads models. We do not allow humans to read Nest data except with your consent, for security, to comply with law, or as aggregated internal operations data that does not identify you. We do not transfer Nest data to others except service providers who process it solely to provide the energy features you asked for, or where the law requires.
How to revoke Nest access: disconnect Nest in GridPay (Devices), and remove GridPay in your Google Account under Data & privacy → Third-party apps & services. Either step stops new collection. You can also email founder@gridpay.com.
1.5 Payments
Subscriptions are billed by Stripe. Stripe collects payment card or bank details. GridPay receives limited billing data such as Stripe customer id, subscription status, plan, and the last four digits or brand of a card when Stripe provides them. We do not store full card numbers on GridPay servers.
1.6 Retail electricity enrollment (PowerHQ / EnergyBot)
If you ask GridPay to shop or enroll a retail electricity plan, we share the information needed to request quotes and complete that enrollment with our referral partner, Blitz Ventures Inc. dba PowerHQ (EnergyBot), and with the retail electric provider you select. That information can include your name, contact details, service address, ESIID, and usage. We share it because you asked us to start enrollment, not for third-party advertising.
1.7 Wallets and rewards
GridPay may create a smart wallet (ZeroDev) so we can record GridPay Token (GPT) rewards associated with your account. We process the wallet address, reward balances, and transaction identifiers. Transfers recorded on Arbitrum are public and cannot be deleted by GridPay. GPT is a utility reward, not a bank deposit.
1.8 Analytics, logs, and cookies
We use PostHog for product analytics (pages and features used, a distinct id, browser and device type, and coarse location derived from IP). We use Sentry to diagnose crashes and errors. Server logs include IP address, user agent, and request timestamps. See Cookies below. This legal page does not load analytics scripts.
2. How we use information
- Create and secure your account (Clerk) and provide the Service.
- Read authorized meter, solar, battery, and thermostat data and, when you enable it, send device commands for energy scheduling and programs you join.
- Calculate and display usage, exports, and rewards, including GPT associated with verified exports.
- Bill subscriptions through Stripe and prevent fraud.
- Start a retail-plan quote or enrollment you request (PowerHQ / EnergyBot).
- Send transactional messages about your account, devices, billing, and rewards.
- Understand product usage (PostHog) and fix errors (Sentry).
- Comply with law, enforce our terms, and protect customers, GridPay, and the public.
We do not sell personal information. We do not use Google Nest data or Smart Meter Texas interval data for advertising.
3. Google API Services disclosure
GridPay's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Policy: https://developers.google.com/terms/api-services-user-data-policy.
Limited Use means, in substance, that we use Google user data only to provide or improve user-facing energy features that are prominent in GridPay, only transfer it as needed to provide those features, for security, to comply with law, or as part of a merger with notice, and we do not use it for serving advertisements or to determine creditworthiness. The Nest data we access and why we access it are described in section 1.4.
4. Sharing and subprocessors
We share information with service providers who process it on our instructions, with partners you ask us to contact, and when the law requires. Current categories:
| Recipient | Role |
|---|---|
| Clerk | Account authentication and session management. |
| Stripe | Subscription payments and billing status. |
| Smart Meter Texas | Authorized interval meter reads for your ESIID. |
| Tesla | Powerwall and energy-site data and commands you authorize. |
| Google (Smart Device Management) | Nest thermostat data and commands you authorize. |
| SolarEdge, Enphase, and similar device makers | Inverter or device data when you connect them. |
| Blitz Ventures Inc. dba PowerHQ / EnergyBot, and the retail provider you pick | Quote and enrollment data when you ask to enroll a retail plan. |
| ZeroDev and the Arbitrum network | Smart wallet and public on-chain reward records. |
| PostHog | Product analytics. |
| Sentry | Error diagnostics. |
| Postmark or our then-current email provider | Transactional email. |
| Vercel, Railway, and Neon (PostgreSQL) | Website hosting, API hosting, and database. |
We may also share information if we reasonably believe it is required by law, legal process, or to protect rights, safety, and security, or as part of a merger or sale of GridPay with notice where required. We do not sell personal information for money and we do not share it for cross-context behavioral advertising.
5. Retention and deletion
We keep personal information only as long as we need it for the purposes above.
- Account data is kept while your account is open and for a limited time afterward to finish deletion, resolve disputes, and meet tax, accounting, and legal duties. Billing records may be kept for up to seven years.
- Meter intervals and device telemetry are kept while the device or meter stays connected and as needed to support rewards, disputes, and audit. We delete or de-identify them when we complete a deletion request, except where a law requires us to keep a record.
- OAuth and device tokens are deleted when you disconnect the integration or when we complete deletion.
- Server logs and diagnostics are kept for a shorter operational period, generally not more than 24 months, then deleted or de-identified.
- On-chain wallet records are public and permanent. We cannot delete data that has been written to a blockchain.
How to request deletion. Email founder@gridpay.com from the email on your account with the subject “Delete my GridPay account,” or use the delete-account control in the product where it is shown. We will verify the request and delete or de-identify personal information we control, except records we must keep for legal reasons and data that is technically immutable (including blockchain records). Disconnecting Nest, Tesla, Smart Meter Texas, or another device stops further collection from that source. Revoking Google access is described in section 1.4.
You may also opt out of product analytics by emailing founder@gridpay.com with the subject “Opt out of analytics.”
6. Security
We use HTTPS in transit, encrypt stored device credentials with AES-256-GCM, and limit access to personal information to people and vendors who need it to operate the Service. No method of transmission or storage is completely secure. Please use a unique password and protect your email account, because that account can reset access to GridPay.
7. Children
The Service is not directed to children. You must be at least 18 to create an account. We do not knowingly collect personal information from children under 13, or from anyone under 18. If you believe a child has provided personal information, email founder@gridpay.com and we will delete it.
8. Your rights, including Texas and CCPA-style rights
Depending on where you live, including under the Texas Data Privacy and Security Act and the California Consumer Privacy Act as amended, you may have the right to:
- Know and access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete personal information, subject to legal exceptions described above.
- Opt out of the sale or sharing of personal information. GridPay does not sell personal information and does not share it for cross-context behavioral advertising.
- Appeal a refusal of a privacy request.
- Not be discriminated against for exercising these rights.
We honor these rights whether or not a statute’s revenue or volume threshold currently applies to GridPay. Submit a request to founder@gridpay.com with the subject “Privacy request.” We will verify you (typically using the account email) and respond within 45 days, or tell you if we need more time. You may use an authorized agent where the law allows it; we may still ask you to confirm the agent’s authority. To appeal, reply to our decision or email founder@gridpay.com with the subject “Privacy appeal.”
We process information in the United States. If you access the Service from elsewhere, you understand your information will be processed in the United States.
9. Cookies and similar technologies
- Necessary. Clerk and GridPay use cookies or similar storage to keep you signed in and to protect the Service. Stripe may set cookies during checkout.
- Analytics. PostHog may set a cookie or local storage key to recognize a browser across visits so we can measure product use. This is not used for advertising.
You can block or delete cookies in your browser. Blocking necessary cookies can sign you out. This Privacy Policy and the Terms of Service pages are static documents and do not set analytics cookies.
10. Changes
We will post changes on this page and update the “Last updated” date above. If a change materially reduces your rights, we will provide a more prominent notice, such as email to the address on your account. Continued use after the update means you accept the revised policy.
11. Contact
GridPay Inc.
Email: founder@gridpay.com
Web: https://gridpay.com
Privacy requests, deletion requests, Nest or other device questions, and appeals all go to that address.