MyCO2 Suite
  • Features
  • CBAM
  • For Agents
  • Data
  • Docs
  • FAQs
  • Pricing
Sign inGet API key

Privacy Policy

Last updated: 6 August 2026

  1. Who we are
  2. What we collect
  3. Why we use it & our legal basis
  4. Cookies
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. Your rights
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact & complaints

1. Who we are

MyCO2 Suite (“MyCO2 Suite”, “we”, “us”) provides a carbon-intelligence API and related dashboard (the “Service”). For the personal data described in this policy, we act as the data controller. This policy explains what we collect, why, and the rights you have. Contact us any time at admin@myco2suite.io.

2. What we collect

We collect only what we need to run the Service. We do not use third-party advertising or analytics trackers, and we do not sell personal data.

  • Account details — the email address you sign up with. You can sign in with a one-time “magic link” (passwordless), or with GitHub or Google — in which case we receive your email address and basic profile (such as your name) from that provider to create your account. We never store a password.
  • API keys — we store only a hashed form of your key, never the plaintext, plus a short non-secret preview.
  • Usage records — for each API request: the endpoint called, a timestamp, your account/key, and the resulting CO₂e figure, so we can meter your plan and show your dashboard analytics.
  • Request metadata — limited inputs you send (for example an industry code, a country, or a spend amount) are logged to operate and improve factor resolution and the Service. The API is not intended to receive personal data: you are responsible for ensuring you have the right and a lawful basis to submit any input, and you must not send personal data, special-category data or secrets in request payloads.
  • Technical data — your IP address and browser user-agent, captured with requests for security, rate-limiting and abuse prevention.
  • Billing data — if you subscribe, our payment processor (Stripe) collects and holds your card details; we never see or store full card numbers. We store your Stripe customer reference, plan, and subscription status.
  • Pay-per-call payment data (x402) — if you access the Service by paying per call in USDC (the x402 protocol), we record the paying blockchain wallet address, the on-chain transaction reference, the amount and the endpoint called, so we can verify and reconcile payments. We do not receive a name, email or other contact details for pay-per-call payers.

3. Why we use it & our legal basis

Under the UK GDPR we rely on the following bases:

  • Performance of a contract — to create your account, issue API keys, deliver the Service, and provide support.
  • Legitimate interests — to secure the Service, prevent abuse, enforce rate limits and quotas, and improve factor resolution and reliability. We balance these against your rights.
  • Legal obligation — to keep billing and tax records for the period required by law.
  • Consent — we currently send only essential service emails (such as your sign-in link). If we ever introduce marketing emails, we will ask for your consent first and you can withdraw it at any time.

4. Cookies

We use only strictly necessary cookies — there are no advertising or analytics cookies. Specifically: a Supabase authentication cookie that keeps you signed in to the dashboard, and (while the site is in private pre-launch) a cookie that remembers you have entered the preview password. Because these are essential to provide the Service you have asked for, they do not require consent.

For traffic measurement we use Cloudflare Web Analytics, which is privacy-first and cookieless — it records aggregate visits, page views, approximate country and referrers without setting any cookie or tracking you across sites, so it likewise requires no consent.

5. Who we share it with

We share personal data only with the service providers (“sub-processors”) that help us run the Service, each under a data-processing agreement:

  • Supabase — database and authentication (hosted in the EU / Ireland).
  • Vercel — application hosting and delivery.
  • Stripe — payment processing for paid plans.
  • Resend — sending transactional emails (such as your sign-in link).
  • GitHub and Google — optional single sign-on (“Continue with GitHub / Google”); they provide us your email and basic profile only if you choose to use them to sign in.
  • Coinbase (CDP) — settling x402 pay-per-call payments; processes the paying wallet address and the transaction on the Base network.
  • Cloudflare — privacy-first, cookieless website analytics: aggregate visit and page-view counts, approximate country (derived from your IP without storing it) and referring sites. No cookies and no cross-site tracking.

We may also disclose data where required by law, or to protect our rights, users or the Service. We do not sell or rent personal data to anyone.

6. International transfers

Your database and authentication data are hosted in the EU (Ireland). Some of our sub-processors (for example Stripe, Vercel, Resend, GitHub, Google, Coinbase and Cloudflare) may process data outside the UK/EEA. Where they do, the transfer is protected by an appropriate safeguard — such as a UK/EU adequacy decision or Standard Contractual Clauses (with the UK Addendum) — so your data receives an equivalent level of protection.

7. How long we keep it

We keep account and usage data for as long as your account is active, and for a reasonable period afterwards to meet legal, security and operational needs. Billing records are retained for the period required by tax law (in the UK, this is typically six years). When data is no longer needed, we delete or anonymise it. You can ask us to delete your account at any time (see below).

8. Your rights

Under the UK GDPR you have the right to: access a copy of your data; correct inaccurate data; erase your data; restrict or object to certain processing; and receive your data in a portable format. You can exercise the most common of these directly — rotate or revoke your API key and update your email from the dashboard — or contact us at admin@myco2suite.io for anything else. We will respond within the timeframes the law requires (usually one month).

9. Security

We protect your data with measures appropriate to its sensitivity: encryption in transit (HTTPS), row-level access controls on our database, API keys stored only as hashes, secrets held server-side only, and rate-limiting against abuse. No system is perfectly secure, but we work to protect your data and will notify you and the relevant regulator of a breach where the law requires.

10. Children

The Service is intended for businesses and developers and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the Service evolves or the law changes. We will post the updated version here with a new “last updated” date, and for material changes we will notify you by email or a dashboard notice.

12. Contact & complaints

For any privacy question or to exercise your rights, contact admin@myco2suite.io. If you are in the UK and are unhappy with how we have handled your data, you may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. Governing jurisdiction for this policy: England and Wales.

MyCO2 Suite
  • Documentation
  • Data
  • Pricing
  • For Agents
  • llms.txt
  • Privacy
  • Terms
© 2026 MyCO2 Suite. All rights reserved.