Privacy Policy
What we collect, why, who else handles it, and how you can ask for a copy or deletion. Effective May 29, 2026.
1. Who this is from
This Privacy Policy is from Affordable Photovoltaic Energy LLC, doing business as Ape Solar ("Ape Solar", "we", "us"). It covers apesolar.com and the services connected to it: shopping, the system builder, your account, and the email we send you about orders or projects.
2. What we collect
Sources of the information below: from you (when you sign in, place an order, place a deposit, or contact us), from third-party services you use to sign in (Google OAuth), from our service providers (Stripe sends us payment-status and address data), and automatically when you visit the site (analytics and server logs).
Account information you give us: your email address, your name if you provide it, and the OAuth profile data (your name, email, and Google profile picture) if you sign in with Google. Magic-link sign-in only stores your email.
Order information you give us: shipping address, billing address, phone number (when collected), and what you ordered. Credit card numbers go directly to Stripe; we never see or store them.
Project information you give us during the deposit flow: your name, email, ZIP, the system you designed, and your utility provider if you tell us.
Communication you send us: contact form submissions, emails to contact@apesolar.com, and any phone calls you make to 850-530-1872 (which we may take notes on).
Automatic information about your visit: anonymous page-view and traffic-source data via Vercel Web Analytics (cookieless), and Core Web Vitals (LCP, CLS, INP) via Vercel Speed Insights. Standard web server logs may capture your IP address and user agent for security and abuse prevention.
Conversion-flow information via PostHog: which buttons you click in the cart, the system builder, and the kit checkout. When you submit a form that asks for your email (an emailed quote, a deposit, or a kit checkout), we pass your email and name to PostHog so the events on that browser tie together in one user view. We use this to understand which steps people complete and which they drop on, so we can fix what is broken.
We do not collect sensitive personal information as defined under CCPA/CPRA (such as government IDs, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, biometric data, or health information).
3. How we use it
We use the information you give us to: fulfill orders, schedule and manage Pro Install projects, communicate with you about your account or your project, send transactional email (order confirmations, receipts, project updates), and answer your questions. We use automatic information to keep the site fast and to spot abuse.
We may use aggregated, de-identified information (for example, "this many people built an off-grid system this month") to improve the site. Aggregated information cannot be tied back to you.
4. The third parties that handle your data
Supabase (database and authentication). Stores your account, your saved system builds, your orders, and your project status. Located in the United States.
Stripe (payments). Handles checkout and card processing for the $500 deposit, the cart, and DIY kit purchases. We receive a Stripe customer ID and order metadata, never the full card number.
Vercel (hosting and analytics). Hosts the site and provides anonymous Vercel Web Analytics and Speed Insights.
PostHog (product analytics). Records conversion events on the cart, the system builder, and the kit checkout. Receives your email and name when you submit a form that asks for them, so events tied to one browser show up in one view. United States. PostHog does not sell data and is a service provider to us.
Resend (transactional email). Sends order confirmations, project notifications, and similar service email from us to you.
Google (OAuth sign-in). If you sign in with Google, Google authenticates you and shares your name, email, and profile picture with us. If you sign in with the email magic link, Google is not involved.
Each of these companies has its own privacy practices. We pick partners that handle data responsibly, but we cannot guarantee their conduct.
5. We do not sell your data
We do not sell your personal information. We do not share it for cross-context advertising. We do not run ad-tracking pixels on the site. The only third parties that receive your data are the service providers in section 4, who need it to do their job for us.
We respect the Global Privacy Control (GPC) browser signal as an opt-out of sale or sharing, even though we do not currently sell or share personal information. If your browser sends GPC, we treat that as a standing opt-out for as long as the signal is on.
California residents have an additional right under the California "Shine the Light" law to request a list of third parties to which we have disclosed personal information for those parties' direct marketing purposes during the prior calendar year. We do not share personal information for third-party direct marketing, so the answer to that question is currently "none." The request right exists regardless; email contact@apesolar.com to make one.
6. Cookies and local storage
apesolar.com does not use advertising cookies. The site uses local storage and one product-analytics cookie. Local storage holds your sign-in session (Supabase Auth keeps it in localStorage so you stay signed in across page loads) and your shopping cart (we save the items you added to localStorage so they are still there when you come back). PostHog sets a first-party cookie to tie the events on your browser into one user view so the funnels make sense. Clearing your browser data signs you out, empties your cart, and resets the PostHog session on that device.
Vercel Web Analytics and Speed Insights are cookieless and do not collect personal information.
7. What you can ask for
You can ask us for a copy of the personal information we hold about you, ask us to correct any of it that is wrong, or ask us to delete it. You can also ask us to stop sending you marketing email at any time (transactional email tied to an active order or project we still need to send to you).
To make a request, email contact@apesolar.com from the email address on your account. We will acknowledge your request within 10 business days and substantively respond within 45 calendar days, extendable by another 45 days for complex requests with notice to you. There is no charge.
Before we send you a copy of your data or delete anything, we will verify your identity using information already in your account (the email on file, and if needed, confirmation of recent order or sign-in activity). We will not ask for more documentation than is needed for the request.
You may also have an authorized agent submit a request on your behalf. We will ask for written authorization from you, signed by you, and we will confirm the request with you directly before acting on it.
8. Children
apesolar.com is for adults buying or planning solar for a home or other property they have authority over. We do not knowingly collect personal information from anyone under 13. If you believe a child has given us personal information, email us and we will delete it.
9. Security
We use TLS (HTTPS) for traffic to and from the site. Your account, orders, and project records sit in Supabase. Payments run through Stripe. These are reputable providers with their own security programs. No site is perfectly secure, and we cannot guarantee your information will never be exposed; we will tell you promptly if anything you gave us is involved in a breach we become aware of.
10. How long we keep it
Account data: as long as your account is open. If you ask us to delete it, we remove your profile and order links; we may keep a basic record of past orders (date, total, products) for our tax and accounting records.
Order and project records: 7 years, which is what our accountants and the IRS expect for a small business.
Server logs and analytics: 90 days for logs; analytics retention follows Vercel's defaults.
11. Changes to this Policy
We will update this Privacy Policy from time to time. When we do, we will change the effective date at the top of this page. If we make a material change to how we use your information, we will tell you by email or by a notice on the site before the change takes effect for you.
You can request a paper copy of this Privacy Policy at any time by emailing contact@apesolar.com.
Questions? Email contact@apesolar.com or call 850-530-1872.
Related
Terms of Use — the rules of the road for buying and using the site.
Pro Install Service Agreement — the contract attached to the $500 Pro Install deposit.