Privacy Policy

Effective: September 2026

This Privacy Policy explains how Carbonlyt collects, uses, and protects information in connection with the Carbonlyt platform (app.carbonlyt.com) and our public website (carbonlyt.com).

1. Who this policy applies to

This policy applies to visitors to our public website, people who submit a demo request, and individuals invited by a customer organization to use the Carbonlyt platform ("Users"). Carbonlyt does not offer self-service sign-up — every account is created by invitation from an authorized administrator at a customer organization.

2.1 Demo request information

When you submit a demo request on carbonlyt.com, we collect your name, work email address, company name, an optional message, your browser locale, and the submission timestamp. This is sent by email (via Resend) to our sales inbox (contact@carbonlyt.com) so our team can respond. We do not currently store demo request submissions in our own database — the email itself is the record.

2.2 Account information

When an organization invites you to use Carbonlyt, we (and our authentication provider, Supabase) store your email address, first and last name (if you choose to provide them), your assigned role, your organization association, your preferred interface language, an invitation record, and your last platform access time.

2.3 Authentication and security data

Account authentication (passwords, session tokens, login verification) is handled by Supabase Auth. Carbonlyt's own application code does not store or have direct access to your password.

2.4 Organization-provided business and sustainability data

Authorized users may enter operational data used for carbon accounting and sustainability reporting — for example, fuel, energy and water use, waste records, business travel, employee commuting (aggregate figures such as distance and commute type, not employee names), purchased goods and services, logistics activity, and related site/department/reporting-period metadata. This data belongs to your organization; see our Terms of Service for details on ownership and how we process it.

2.5 What we don't collect

We do not currently run analytics or tracking scripts, advertising cookies, behavioral tracking, or payment/billing collection on the public website.

3. How we use information

To respond to demo requests and communicate with prospective customers; to provide, maintain, and secure the platform; to authenticate users and enforce role-based access; to generate the reports and calculations your organization requests from data it enters; and to send service-related notices such as password reset and invitation emails. We do not sell personal information, and we do not use customer data to train third-party AI models.

4. Service providers we use

Carbonlyt relies on Supabase (authentication and database hosting), Resend (transactional and demo-request email delivery), and Vercel (application hosting and infrastructure) to operate the platform. We share only the minimum information each needs to perform its function, and we do not currently use any other analytics, advertising, or data-processing subprocessors.

5. Data retention

Demo request emails are retained in our sales inbox as part of normal business email practices; we don't keep a separate database record of them. Account and organization data is retained while your organization has an active relationship with Carbonlyt, plus a reasonable period afterward for legitimate business or record-keeping purposes. We do not currently offer automated self-service data deletion — contact contact@carbonlyt.com and we will handle the request manually.

6. Cookies

The Carbonlyt platform uses only the cookies strictly necessary to keep you signed in, set by Supabase Auth. We do not use advertising, analytics, or tracking cookies on the marketing website or the authenticated platform today. If this changes, we will update this policy.

7. Security

We rely on our infrastructure providers' security practices (Supabase and Vercel) and follow reasonable practices in how we build the platform, including role-based access control and server-side session verification on sensitive actions. No method of transmission or storage is completely secure.

8. International data processing

Our infrastructure providers may process and store data in multiple regions depending on their own hosting configuration.

9. Your privacy rights

Depending on applicable law and your location, you may have rights regarding your personal information, such as accessing, correcting, or requesting deletion of it, or objecting to certain processing. Contact contact@carbonlyt.com to make a request. If you are a User of a customer organization, your organization's administrator may also be able to assist with requests about data entered on your behalf.

10. Children's privacy

Carbonlyt is a business product not directed at children, and we do not knowingly collect information from anyone under 18.

11. Changes to this policy

We may update this policy as our practices evolve. Material changes will be reflected on this page.

12. Contact

contact@carbonlyt.com