MyCO2 Suite (“MyCO2 Suite”, “we”, “us”) provides a carbon-intelligence API and related dashboard (the “Service”). For the personal data described in this policy, we act as the data controller. This policy explains what we collect, why, and the rights you have. Contact us any time at admin@myco2suite.io.
We collect only what we need to run the Service. We do not use third-party advertising or analytics trackers, and we do not sell personal data.
Under the UK GDPR we rely on the following bases:
We use only strictly necessary cookies — there are no advertising or analytics cookies. Specifically: a Supabase authentication cookie that keeps you signed in to the dashboard, and (while the site is in private pre-launch) a cookie that remembers you have entered the preview password. Because these are essential to provide the Service you have asked for, they do not require consent.
For traffic measurement we use Cloudflare Web Analytics, which is privacy-first and cookieless — it records aggregate visits, page views, approximate country and referrers without setting any cookie or tracking you across sites, so it likewise requires no consent.
We share personal data only with the service providers (“sub-processors”) that help us run the Service, each under a data-processing agreement:
We may also disclose data where required by law, or to protect our rights, users or the Service. We do not sell or rent personal data to anyone.
Your database and authentication data are hosted in the EU (Ireland). Some of our sub-processors (for example Stripe, Vercel, Resend, GitHub, Google, Coinbase and Cloudflare) may process data outside the UK/EEA. Where they do, the transfer is protected by an appropriate safeguard — such as a UK/EU adequacy decision or Standard Contractual Clauses (with the UK Addendum) — so your data receives an equivalent level of protection.
We keep account and usage data for as long as your account is active, and for a reasonable period afterwards to meet legal, security and operational needs. Billing records are retained for the period required by tax law (in the UK, this is typically six years). When data is no longer needed, we delete or anonymise it. You can ask us to delete your account at any time (see below).
Under the UK GDPR you have the right to: access a copy of your data; correct inaccurate data; erase your data; restrict or object to certain processing; and receive your data in a portable format. You can exercise the most common of these directly — rotate or revoke your API key and update your email from the dashboard — or contact us at admin@myco2suite.io for anything else. We will respond within the timeframes the law requires (usually one month).
We protect your data with measures appropriate to its sensitivity: encryption in transit (HTTPS), row-level access controls on our database, API keys stored only as hashes, secrets held server-side only, and rate-limiting against abuse. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a breach where the law requires.
The Service is intended for businesses and developers and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with data, contact us and we will delete it.
We may update this policy as the Service evolves or the law changes. We will post the updated version here with a new “last updated” date, and for material changes we will notify you by email or a dashboard notice.
For any privacy question or to exercise your rights, contact admin@myco2suite.io. If you are in the UK and are unhappy with how we have handled your data, you may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. Governing jurisdiction for this policy: England and Wales.