Privacy Policy
Last updated: 17 August 2026
This Policy explains how Solarcom ("Solarcom", "we", "us") handles personal data when you use solarcom.in and its community forum (the "Service"). For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act") we are the Data Fiduciary, and you are the Data Principal.
Read it alongside our Terms of Service and Cookie Policy.
1. The short version
- We collect what running a public Q&A forum needs, and say so below.
- We do not sell your personal data, we run no advertising, and we embed no third-party analytics or tracking scripts.
- We do keep our own record of what happens on the Service — including pages you open and buttons you press while signed in. It stays with us. See section 2.
- Anything you post — questions, answers, comments, your display name, username and profile details — is public by design, visible to anyone, and indexable by search engines.
- Editing or deleting a post does not erase what it said. We keep the earlier text so moderators can act on reports about it. See section 6.
- Your email address and mobile number are never shown publicly.
2. Data we collect
You give us:
- Account data — name, username, email address, and either a password or a Google sign-in. Passwords are stored only as a salted bcrypt hash; we never hold the plaintext and cannot recover it.
- Profile data (optional) — profile picture, bio, location, company, website and social links. All of it is public, so include only what you are happy for the world to see.
- Mobile number (optional) — kept private, used only to reach you about your account.
- Content — questions, answers, comments, images you attach, likes, bookmarks and reports you submit.
- Correspondence — messages you send us by email or through the contact form, and any reason you give when asking for your account to be deleted.
We receive from Google, if you sign in with Google:
- Your email address, name and profile picture, and confirmation that Google has verified that address. We ask for nothing else, and we get no access to your Gmail, Drive, contacts or any other Google service.
- The sign-in is handled by Firebase Authentication; we verify the token Google issues and then create our own session. We never receive your Google password.
We record as you use the Service:
- Account and security events — sign-ins and failed sign-in attempts, verification codes sent and confirmed, changes to your email, password or account type, and requests to delete your account. Each carries the time, your IP address and a shortened description of your browser.
- Actions on content — questions, answers and comments you post, edit or delete, and likes, dislikes, bookmarks and reports you make.
- Use of the Service — the pages you open and the controls you press, recorded as the page path and the button's own label. We do not record what you type into search boxes or forms, and paths are stored without their query strings for that reason.
- Technical logs — request metadata generated by our servers and hosting provider in the ordinary course of operating and securing the Service.
- Cookies — two strictly necessary cookies only. See the Cookie Policy.
This record is our own. It is not shared with an analytics company, it feeds no advertising profile, and no third-party script collects it in parallel. Our staff can read it.
We do not knowingly collect financial account details, government identifiers, biometric data or health data. Please do not post them.
3. Why we use it, and on what basis
- To provide the Service — create and authenticate your account, publish your content and attribute it to you. Basis: performance of our agreement with you and the consent you give when registering.
- To keep the Service safe — detect and investigate spam, abuse, account takeover and breaches of our Terms, and act on reports. Basis: legitimate use for security, and compliance with law.
- To understand and improve the Service — see which topics and features are used, and where people get stuck. Basis: our legitimate operational interest. We do not use this to build advertising profiles.
- To communicate with you — verification codes, replies to your queries, notifications about activity on your posts, and service or security notices. Basis: performance of our agreement.
- To comply with law — respond to lawful requests and meet obligations under the Information Technology Act, 2000 and rules made under it. Basis: legal obligation.
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects on you.
4. Who we share it with
We do not sell, rent or trade personal data. We share it only with:
- Google (Firebase) — our database, uploaded images and the Google sign-in flow run on Google Cloud Firestore, Cloud Storage and Firebase Authentication. They process this data on our instructions to host the Service.
- Resend — delivers our email: verification codes, notifications and replies. They receive your email address and the contents of that message, and nothing else.
- Authorities — where we are legally required to disclose, or where disclosure is necessary to protect our rights, our users or the public.
- A successor — if the Service is merged, acquired or its assets sold, in which case we will notify you and the acquirer remains bound by this Policy.
These providers may store or process data on servers outside India. Where that happens we rely on the provider's contractual safeguards and transfer data only to jurisdictions not restricted by the Central Government under the DPDP Act.
5. Public content and search engines
The forum is a public archive. Your posts and profile can be read without an account, indexed by search engines, and copied or quoted by others. Deleting content from Solarcom does not remove copies already cached or republished elsewhere, and we cannot control third-party caches.
6. Edits and deletions are recorded
When you edit a question, answer or comment, we keep the previous text alongside the new one. When you delete a comment or answer, we keep what it said. Both records show who made the change and when, and are visible to our moderation staff — not to other members.
This exists for one reason: a post that is reported for abuse and then quietly rewritten or removed would otherwise leave the report describing something nobody can read, and there would be no way to act on it fairly. It is not used for any other purpose.
7. How long we keep it
- Account and profile data — while your account is open, and for a short period afterwards to handle disputes and prevent abuse.
- Content — indefinitely, as part of the public archive, unless removed under section 8.
- Activity records — page views and clicks are kept for up to 12 months. Security events such as sign-ins and verification are kept longer where needed to investigate abuse, then deleted or anonymised.
- Edit and deletion history — kept while the underlying account and discussion exist, so a report can still be assessed after the fact.
- Session tokens — the refresh token record is destroyed the moment it is used or when you sign out.
- Verification codes — stored as a hash, valid for ten minutes, and destroyed once used or expired.
We keep data longer only where a law requires it or where it is needed for an ongoing legal claim.
8. Your rights
Under the DPDP Act you may, in respect of your personal data:
- Access a summary of the data we process and who we have shared it with.
- Correct or complete inaccurate data — most of it yourself under Settings, or email us and we will make the change.
- Erase data that is no longer needed for the purpose it was collected for. You can ask us to delete your account from Settings → Security; we review each request and confirm by email before anything is removed. Because the forum is a shared public record, we may retain or anonymise posts rather than delete them where removing one side of a conversation would render the rest unintelligible.
- Withdraw consent at any time. Withdrawing consent for processing that is essential to the Service means we can no longer provide you an account.
- Nominate another individual to exercise your rights in the event of your death or incapacity.
- Complain to us, and thereafter to the Data Protection Board of India.
To exercise any of these, email hello@solarcom.in from the address on your account. We will respond within the period required by law. We may ask you to verify your identity before acting, and we may decline requests that are manifestly unfounded, repetitive, or that would infringe another person's rights.
You are responsible for the accuracy of the data you give us, and for not filing false or frivolous complaints — the DPDP Act imposes duties on Data Principals too.
9. Security
We apply reasonable technical and organisational safeguards, including:
- passwords stored as salted bcrypt hashes, never in plaintext;
- verification codes stored as hashes, expiring in ten minutes, limited in attempts and rate-limited between sends;
- short-lived, HTTP-only session cookies that JavaScript cannot read, with single-use refresh tokens that are destroyed and reissued on every renewal;
- encryption in transit (HTTPS), and no direct client access to our database — every read and write passes through our own API;
- sanitisation of user-submitted content before it is displayed, to prevent script injection;
- staff and member accounts kept entirely separate, so an administrator's access cannot be reached through the public site;
- rate limiting on sensitive operations such as sign-in, registration and code sending.
No system is perfectly secure. If we become aware of a personal data breach we will notify the Data Protection Board of India and affected users as required by the DPDP Act.
10. Children
The Service is not intended for children under 13, and we do not knowingly collect their personal data. We do not carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child has provided us personal data, contact us and we will delete it.
11. Contact and grievances
- Privacy queries: hello@solarcom.in
- Grievance Officer: hello@solarcom.in
We acknowledge grievances within 24 hours and aim to resolve them within 15 days. If you remain dissatisfied you may escalate to the Data Protection Board of India.
12. Changes to this Policy
We may update this Policy. The "Last updated" date above always reflects the current version, and we will give reasonable notice of material changes through the Service or by email.
Questions about this policy? Email hello@solarcom.in.
