Privacy Policy

Last updated: 26 June 2026

1. Who we are

Radiant ("Radiant", "we", "us") provides a software platform at radiantsolar.io for commercial solar installers to manage companies, proposals, customer relationships, and Google Business Profile optimisation. This policy explains what personal data we collect, how we use it, and your rights. Contact: sam@radiantsolar.io.

2. Scope

This policy covers the Radiant platform, our websites at radiantsolar.io, installer landing pages we host, and related features including OpenLead (our Google Business Profile and company-generation toolset).

3. Information we collect

  • Account data: name, email, company, role, and authentication details.
  • Customer and company data you process: contact details and project information for the companies, contacts, and deals you manage in the platform.
  • Google Business Profile data: where you connect your Google account, we access your Google Business Profile through Google APIs to provide optimisation features (details in section 5).
  • Usage data: log data, device and browser information, and analytics on landing pages we host on your behalf (including a hashed identifier derived from IP address; we do not store raw IP addresses for landing-page analytics).
  • Communications: messages and review requests sent through the platform.

4. How we use information

  • To provide and operate the platform and its features.
  • To generate proposals, manage pipelines, host installer landing pages, and surface analytics.
  • To provide OpenLead features: assess Google Business Profile health and, where you authorise it, update your profile and manage reviews.
  • To send transactional and review-request emails on your behalf.
  • To secure, maintain, and improve the service.
  • To comply with legal obligations.

Legal bases under UK GDPR: performance of a contract, our legitimate interests in operating and improving the service, your consent (for example, connecting your Google account), and legal obligation.

5. Google user data (Business Profile and Calendar)

Google Business Profile. Where you choose to connect your Google account for OpenLead, Radiant requests the https://www.googleapis.com/auth/business.manage scope. With your authorisation we access and, where you direct, update your Google Business Profile, including business information (name, address, contact details, hours, categories, attributes), photo metadata, reviews, posts, and profile insights. We use this data solely to provide the OpenLead features you have requested, such as scoring your profile's completeness, recommending improvements, applying fixes you approve, and helping you respond to reviews.

Google Calendar. Where you choose to connect your Google account for calendar sync, Radiant requests the https://www.googleapis.com/auth/calendar scope together with the openid and email scopes. The openid and email scopes are used only to identify which Google account you connected. The calendar scope is used solely to create, update and delete meeting and site-visit booking events on your own Google Calendar from within Radiant, and to read your events so we can reflect your availability inside the platform. Radiant does not use your Google Calendar data for any other purpose.

Storage and security. When you connect Google Calendar, Radiant stores an OAuth refresh token so it can perform the actions above on your behalf. The refresh token is stored securely and encrypted at rest in our backend. Short-lived Google access tokens are not persisted; they are held only in memory long enough to make the API call. Tokens are deleted when you disconnect the calendar in Radiant (Settings → Integrations → Disconnect), when you request deletion by emailing sam@radiantsolar.io, or when you revoke Radiant's access from your Google Account permissions page at https://myaccount.google.com/permissions.

Sharing. Radiant does not sell Google user data and does not transfer it to third parties except as needed to provide the feature you have requested (for example, sending the API request to Google itself), to comply with applicable law, or as part of a merger or acquisition subject to equivalent protections. We do not use Google user data to develop, improve, or train generalised machine-learning models.

Limited Use. Radiant's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Other calendar providers. Microsoft 365/Outlook Calendar and Calendly connections are handled in the same way as Google Calendar: we store the provider's refresh token securely (encrypted at rest), use it only to create, update, delete and read your booking events for the purpose of calendar sync inside Radiant, and delete the stored tokens when you disconnect the integration or request deletion.

We also use the Google Places API to retrieve publicly available information about your business listing to produce a public health snapshot. This uses public data and does not require access to your Google account.

Privacy queries relating to any of the above can be sent to sam@radiantsolar.io.

6. Sharing and subprocessors

  • Supabase (application hosting, database, authentication), Lovable (application hosting), Airtable (data storage), Google (Business Profile and Places APIs, Maps), OpenSolar (solar design and project integration), Resend (transactional email), and Stripe (payments).

We require each to protect data and use it only to provide their service to us. We do not sell personal data.

7. International transfers

Some providers may process data outside the UK and EEA. Where they do, we rely on appropriate safeguards such as the UK International Data Transfer Agreement or equivalent.

8. Retention

We keep personal data for as long as your account is active and as needed to provide the service, then delete or anonymise it within a reasonable period, unless we must retain it to meet legal obligations.

9. Security

We use industry-standard measures including encryption in transit, access controls, and role-based permissions. No system is perfectly secure, but we work to protect your data.

10. Your rights

Under UK GDPR you may request access, correction, deletion, restriction, portability, or object to processing. To exercise these rights, contact sam@radiantsolar.io. You may also complain to the Information Commissioner's Office at ico.org.uk.

11. Controllers and processors

For data about your own account, Radiant is the controller. For customer and company data you load into the platform, you are the controller and Radiant acts as your processor, handling that data on your instructions under our terms.

12. Changes

We may update this policy and will revise the date above. Material changes will be notified through the platform.

13. Contact

Radiant. Email: sam@radiantsolar.io.