Your privacy matters to us. This policy explains how DIY Off-Grid Advisor collects, uses, and protects your data when you use our web platform. We are committed to full transparency and compliance with the Australian Privacy Act 1988, GDPR (EU) 2016/679, and UK GDPR.
1. Who We Are
DIY Off-Grid Advisor is a web-based platform operated by an individual based in Melbourne, Victoria, Australia. We provide tools, calculators, educational content, and community features to help people design off-grid solar and electrical systems.
Contact: info@diyoffgridadvisor.com
This policy applies to all users of www.diyoffgridadvisor.com and any associated subdomains. It covers how we collect, use, store, and protect your personal data.
2. What Data We Collect
Account Data
When you create an account, we collect your email address and optional display name. We use a passwordless sign-in system — a one-time code is sent to your email to verify your identity. No passwords are stored.
User-Generated Content
Data you enter into the platform — including system configurations, load profiles, location data, build journal entries, community questions and answers, and price submissions — is stored in our database and associated with your account.
Location Data
If you choose to use location-based features (solar forecasting, regional pricing), we may request access to your approximate location via your browser. This is always optional — you can enter a location manually instead. Location data is used solely to calculate solar irradiance and sun hours for your region.
Local Storage & Browser Data
We use browser local storage to save your preferences, session state, and temporary system data. This data stays on your device and is not transmitted to our servers unless you are signed in and choose to sync.
Usage Data
We may collect basic usage logs (pages visited, features used, error events) to improve the platform. This data is not linked to personally identifiable information unless you are signed in.
Profile Photos
If you upload a profile photo or system photo, it is stored securely via our infrastructure provider. You can delete uploaded photos at any time from your profile settings.
3. How We Use Your Data
We use your data to:
- Provide and operate the platform and its features
- Authenticate your identity and maintain your session
- Save and sync your system designs, load profiles, and preferences
- Calculate solar forecasts and system sizing recommendations
- Display community content (questions, answers, builds) you have submitted
- Send transactional emails (sign-in codes, account notifications)
- Improve the platform based on usage patterns and feedback
- Respond to support requests
We do not sell your data, use it for advertising, or share it with third parties for marketing purposes.
4. Legal Basis for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:
Contract Performance
Processing your account data and user-generated content is necessary to provide the service you have signed up for (Art. 6(1)(b) GDPR).
Legitimate Interests
We process usage data and error logs to improve platform stability and security. This is in our legitimate interest and does not override your rights (Art. 6(1)(f) GDPR).
Consent
Where we request optional data (such as location access), we rely on your explicit consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time.
5. Third-Party Data Processors
We use the following third-party services to operate the platform. Each acts as a data processor under our instruction and does not use your data for their own purposes.
Supabase (Backend & Auth)
Your account credentials, user-generated content, and system data are stored via Supabase's secure infrastructure. Data is encrypted at rest (AES-256) and in transit (TLS/HTTPS). Supabase is SOC 2 Type II certified. Supabase Privacy Policy →
Vercel (Hosting)
The platform is hosted on Vercel. Vercel may process request metadata (IP address, browser type) for CDN and security purposes. Vercel Privacy Policy →
Stripe (Payments — coming soon)
When paid plans launch, payment processing will be handled by Stripe. We will never store your card details — all payment data is handled directly by Stripe. Stripe Privacy Policy →
6. Data Retention
Active accounts: Your data is retained for as long as your account is active.
Deleted accounts: When you delete your account, your personal data (email, display name, profile photo) is permanently deleted within 30 days. User-generated community content (questions, answers) may be retained in anonymised form to preserve the integrity of community discussions.
Guest / unauthenticated users: Data stored in your browser's local storage is never transmitted to our servers. It remains on your device until you clear your browser data.
Backups: Encrypted database backups may retain data for up to 90 days after deletion for disaster recovery purposes.
7. Your Rights
Depending on your location, you have the following rights regarding your personal data. To exercise any of these rights, contact us at info@diyoffgridadvisor.com. We will respond within 30 days.
Right of Access
AU · EU · UKRequest a copy of all personal data we hold about you.
Right to Rectification
AU · EU · UKRequest correction of inaccurate or incomplete data.
Right to Erasure
EU · UKRequest deletion of your personal data ('right to be forgotten').
Right to Portability
EU · UKReceive your data in a structured, machine-readable format.
Right to Object
EU · UKObject to processing based on legitimate interests.
Right to Restrict Processing
EU · UKRequest that we limit how we use your data.
Right to Withdraw Consent
AU · EU · UKWithdraw consent at any time where processing is consent-based.
Right to Complain
AU · EU · UKLodge a complaint with your local data protection authority.
Australian users: You also have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your data.
EU/EEA users: You may lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at edpb.europa.eu.
8. International Data Transfers
Our infrastructure providers (Supabase, Vercel) may store and process data in data centres located in the United States and other countries. Where data is transferred outside the EEA or UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Providers certified under recognised frameworks (SOC 2, ISO 27001)
10. Security
We take reasonable technical and organisational measures to protect your data, including:
- All data in transit is encrypted via HTTPS/TLS
- All data at rest is encrypted via AES-256 (Supabase)
- Passwordless authentication — no passwords stored
- Row-level security (RLS) policies ensure users can only access their own data
- Access to production systems is restricted to authorised personnel only
No system is 100% secure. If you discover a security vulnerability, please report it responsibly to info@diyoffgridadvisor.com.
11. Children's Privacy
This platform is not directed at children under the age of 13 (or 16 in the EU/UK). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you by email. Your continued use of the platform after any changes constitutes your acceptance of the updated policy.
13. Contact & Data Requests
For any privacy-related questions, data access requests, or deletion requests:
Email: info@diyoffgridadvisor.com
Location: Melbourne, Victoria, Australia
Response time: We aim to respond to all data requests within 30 days.
Questions about this policy?
info@diyoffgridadvisor.com© 2026 DIY Off-Grid Advisor. All rights reserved.
