SmartBatt Energy Solutions
S
SmartBatt Energy Solutions

Privacy Policy

SmartBatt Platform & SmartBatt mobile app

Applies to the website and Client / Operations / Asset Owner / Channel Partner portals at www.smartbattenergy.com and to the SmartBatt app for Android.

Version 1.0  |  Effective 30 August 2026www.smartbattenergy.com  ·  info@smartbattenergy.com

1. Who we are

This Privacy Policy is issued by SmartBatt Energy Solutions LLP ("SmartBatt", "we", "us", "our"), a limited liability partnership registered under the LLP Act, 2008, PAN AFMFS1799B, with its principal place of business at F-10 Shree Ganesh Industrial House, Waman Tukaram Patil Marg, Chembur, Mumbai 400071, India.

We act as the Data Fiduciary for personal data processed through the SmartBatt platform and the SmartBatt mobile app, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules made thereunder.

2. Scope

The SmartBatt platform and app are business tools provided to registered users of organisations that SmartBatt has an energy-services relationship with (clients, asset owners, channel partners) and to SmartBatt's own personnel. They are not consumer products and are not directed at the general public or at children. You must be at least 18 years old and authorised by your organisation to use them.

3. Data we collect

3.1 Account and identity data

When you sign in, we receive your name and email address from Google (we use Google Sign-In for authentication; we never see or store your Google password), and we hold the organisation, role and access permissions assigned to your account by an administrator.

3.2 Device telemetry data

For battery energy storage systems (BESS) assigned to your account, we process real-time and historical operational data — state of charge, load / grid / battery power, voltages, currents, runtime estimates, fault and connection status. This data relates to equipment, not to you personally, but it is shown to you through your account.

3.3 Usage and diagnostic data

We use PostHog for product analytics on both the website and the app. It records: pages / screens visited, taps and clicks on interface elements (button and link labels — not the text you type into fields), app open / update / background events, and a small number of named actions (for example creating a deployment or submitting an enquiry). It also receives standard technical context: browser or app version, device model, operating-system version, language, time zone, screen size, network type, a randomly generated device / installation identifier, and your IP address, from which PostHog may derive an approximate (city-level) location. On the website, unhandled application errors are also captured to help us diagnose faults.

When you are signed in, these analytics events are linked to your account (your user identifier and email address). We do not record your screen or session (there is no screen or session recording), and we do not use this data for advertising or build advertising profiles.

Cookies and similar storage. On the website we use first-party cookies and local storage that are necessary to keep you signed in and secure, plus first-party analytics cookies as described above. We do not use third-party advertising or cross-site tracking cookies. You can block or delete cookies in your browser, though sign-in and some features may then stop working. The mobile app does not use cookies; it stores your session token in the device's encrypted storage.

3.4 Location — Wi-Fi setup

The Android app requests the precise location permission because Android requires an app to hold that permission in order to read nearby Wi-Fi network names and connect a phone to a specific Wi-Fi network. When the permission is used for the "Wi-Fi Setup" flow (connecting a SmartBatt unit to a venue's Wi-Fi), your geographic location is not recorded, stored or transmitted — only the surrounding Wi-Fi network names are read, on your device. You can decline the permission; the Wi-Fi Setup feature will then be unavailable.

3.5 Location — attendance check-in (SmartBatt staff)

SmartBatt operations personnel who use the labour-attendance features record attendance by checking in and out at a work location. At the moment you perform a check-in or check-out, the platform captures your device's current location (latitude and longitude) so that the attendance record shows where it was marked. This capture happens only at the moment of that action— there is no continuous or background location tracking. The coordinates are stored against your staff attendance record and are visible to authorised SmartBatt administrators; they may be converted to a readable street address for display using the OpenStreetMap Nominatim service. This feature is for SmartBatt's own field staff and is not part of the client, asset-owner or channel-partner experience.

3.6 Local network / Wi-Fi Setup data

During Wi-Fi Setup the app communicates directly with a SmartBatt unit's local configuration page over the local network. Wi-Fi credentials you enter for the venue network are sent to that local device to configure it. A venue's Wi-Fi network name (and, where you choose to save it, its password) may be stored on our platform so that future setups at the same venue are faster; this is visible only to authorised SmartBatt operations users and the relevant client account.

3.7 Support requests

If you raise a help ticket from the app, we receive the message you write and your account email so we can respond.

4. How we use data

  • To authenticate you and enforce the access permissions set by your organisation.
  • To provide the monitoring, reporting, deployment, billing and (where enabled) unit-control and Wi-Fi-setup features.
  • To relay configuration and control commands you initiate to the relevant hardware via the manufacturer's cloud service.
  • To operate, secure, debug and improve the platform and app.
  • To respond to your support requests and to communicate service-related notices.
  • To comply with legal obligations and enforce our terms.

Our lawful bases under the DPDP Act are performance of the service you and your organisation have signed up for, our legitimate business interests in operating and improving that service, and compliance with law.

5. Sharing and processors

We do not sell personal data. We share it only with service providers that process it on our instructions to run the service:

  • Supabase — database, authentication and backend hosting.
  • Google — sign-in / identity.
  • Deye Cloud — the inverter manufacturer's cloud, used to fetch unit telemetry and deliver control commands you initiate.
  • PostHog — product analytics.
  • Vercel — hosting of the web platform and its API.
  • OpenStreetMap Foundation (Nominatim) — converting attendance check-in coordinates to a readable address (see section 3.5).

We may also disclose data where required by law, to protect our rights or the safety of users, or in connection with a corporate transaction. Some providers may process data outside India; where they do, we rely on contractual safeguards.

6. Android permissions

PermissionWhy the app needs it
INTERNET, ACCESS_NETWORK_STATECommunicate with the SmartBatt backend.
ACCESS_WIFI_STATE, CHANGE_WIFI_STATE, CHANGE_NETWORK_STATEList nearby Wi-Fi networks and connect the phone to a SmartBatt unit's network during Wi-Fi Setup.
ACCESS_FINE_LOCATIONTwo uses: (a) reading nearby Wi-Fi network names during Wi-Fi Setup, where location is not recorded (section 3.4); and (b) for SmartBatt field staff, capturing the check-in / check-out point in the attendance features (section 3.5). No background location tracking.

7. Retention

  • Account and identity data: for the duration of your relationship with SmartBatt and up to 7 years afterwards, in line with Indian tax and audit requirements.
  • Device telemetry and operational data: for the operational life of the relevant BESS units and up to 3 years afterwards.
  • Attendance records (including check-in coordinates): for the period required for payroll, contractor settlement and statutory records.
  • Analytics data: per our analytics provider's configured retention.

We delete or anonymise data when it is no longer needed for these purposes, subject to any legal hold or retention obligation.

8. Security

Data is encrypted in transit (HTTPS/TLS). Access to data within the platform is enforced by row-level security and role-based permissions. Session tokens on the mobile app are held in the device's encrypted storage. No system is perfectly secure, but we work to protect your data and will notify affected users and the Data Protection Board as required if a reportable breach occurs.

9. Your rights

Subject to the DPDP Act, you may request access to, correction of, completion of, or erasure of your personal data; withdraw consent where processing relies on it; and nominate another person to exercise these rights on your behalf in the event of death or incapacity. Because accounts are provisioned by your organisation, some requests may be actioned through your organisation's administrator.

To exercise a right or raise a grievance, contact our Grievance Officer at info@smartbattenergy.com with the subject line "Privacy Request". We will respond within the timelines prescribed by law.

10. Children

The platform and app are not intended for anyone under 18 and we do not knowingly collect data from children.

11. Changes

We may update this policy from time to time. Material changes will be notified in the app or by email. The "Effective" date above shows when this version took effect.

12. Contact

SmartBatt Energy Solutions LLP, F-10 Shree Ganesh Industrial House, Waman Tukaram Patil Marg, Chembur, Mumbai 400071, India. Email: info@smartbattenergy.com.