Privacy Policy
SunLedger is a product of VC & NB Pty Ltd (ABN 57 621 355 002) ("SunLedger", "we", "us"), a customer-relationship-management platform for solar-energy businesses in Australia. This policy explains what information we collect, how we use and protect it, and the choices you have. It applies to our website and the SunLedger application (together, the "Service").
SunLedger is a business-to-business tool. Our direct customers are solar businesses (each an "Organisation"). Much of the data in the Service is entered by an Organisation about its own customers and leads; for that data the Organisation is the controller and SunLedger acts as a processor on its behalf.
1. Information we collect
Account information
When you create or are invited to an account we collect your name, email address, password (stored only as a secure hash) and your role within your Organisation.
Business data you enter
The Service stores the records your Organisation creates — leads, customers, contact details, addresses, site and roof designs, proposals, quotes, jobs, invoices, notes and messages. You are responsible for having a lawful basis to store information about your own customers in the Service.
Data from services you connect
If you choose to connect a third-party service, we access only what that feature needs:
- Google — Gmail, Google Calendar and Google Drive, to send and read email tied to a deal, create and read calendar events, and export documents to your Drive. See section 4.
- Facebook / Meta Lead Ads — the name, email, phone and answers a person submits through your Facebook lead form, so the lead appears in your CRM. See section 5.
- Xero — to create and sync invoices you raise in SunLedger.
- Nearmap — aerial imagery of a property address, used to design a solar system.
Technical data
We collect standard operational data such as IP address, browser type, and log and session information needed to run and secure the Service.
Cookies
We use a single strictly-necessary cookie to keep you signed in and to secure your session. We do not use advertising or third-party tracking cookies. If we introduce analytics or other non-essential cookies in future, we will ask for your consent first.
2. How we use information
- To provide, maintain and secure the Service and its features;
- To capture and route new leads, send quotes and follow-ups, and move deals through your pipeline;
- To authenticate you and keep each Organisation's data isolated from every other Organisation;
- To send transactional messages (for example a quote link, booking reminder or invoice) on your behalf;
- To provide support and to comply with our legal obligations.
We do not sell your data or your customers' data, we do not use it for advertising, and we do not use it to train generalised AI models.
3. How we share information
We share data only with third-party service providers ("sub-processors") that help us operate the Service, each under contractual confidentiality and security obligations. These providers fall into the following categories:
- Cloud infrastructure — application hosting, database and file storage.
- Messaging — delivery and receipt of the SMS/text messages you send through the Service, and delivery of email SunLedger sends on your behalf (such as a proposal link, booking reminder or invoice). These accounts are held by SunLedger, not by your Organisation, so message content necessarily passes through them.
- Artificial intelligence — SiRe features send the specific record details a task needs (for example a customer's name and system size to draft a proposal note, or an email you ask it to summarise) to an AI provider under contract. That data is not used to train generalised AI models, and SiRe is only ever invoked when you ask it to do something.
- Mapping and aerial imagery — a property address or coordinates are sent to look up imagery and roof data. Message content and contact details are never sent to these providers.
- Integrations you choose to enable — such as accounting, aerial-imagery, rebate-trading and inverter-monitoring services, and Google and Facebook/Meta (see sections 4 and 5), each receiving only the data the integration you turn on requires. Where you sign in with your own account, that provider's own terms and notifications apply to you directly.
We may also disclose information where required by law, or to protect the rights, safety and security of SunLedger, our customers or the public. We never sell personal information.
4. Google user data
When you connect your Google account, SunLedger requests only the scopes needed for the features you use — sending and reading email associated with a deal, reading and writing calendar events, and exporting files to your Drive. We access this data solely to provide those features to you, at your direction, inside the Service.
SunLedger's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not transfer or disclose it except to provide or improve the user-facing features you have enabled, to comply with applicable law, or as part of a merger or acquisition with appropriate notice. We do not allow humans to read your Google data except with your explicit consent for support, where required for security, or where required by law. Google data is never used to train generalised AI or machine-learning models.
You can disconnect Google at any time from your SunLedger settings, or revoke access directly at myaccount.google.com/permissions.
5. Facebook / Meta Lead Ads data
If your Organisation connects a Facebook Page, SunLedger receives the details a person submits through your lead form (typically name, email, phone and any questions you added) so the lead appears in your CRM for follow-up. We only retrieve leads from Pages you explicitly connect, and we store an encrypted access token for that Page. You can disconnect a Page at any time, which stops further lead delivery. People whose data was collected through your form can request deletion via our data deletion page.
6. SMS messages
Messages you send to your customers through the Service, and their replies, are stored against the relevant lead or customer and are visible to your Organisation. Inbound replies are routed strictly to the Organisation that owns the receiving number, by that number, and are never shared across Organisations.
SunLedger provides the number. Unlike integrations you connect with your own account, the SMS gateway account is held by SunLedger, so the content of messages sent and received passes through our systems and our messaging provider's. Both are located in Australia. We do not read message content except where you ask us to help with a support issue, where required for security, or where required by law — and we do not use it for advertising, sell it, or use it to train AI models.
Message content is retained against the lead or customer record for as long as that record exists (see section 8), and deleting the record deletes the messages with it.
7. Data security
Each Organisation's data is isolated at the database level using row-level security, so one Organisation cannot access another's records. Access tokens and other secrets are encrypted at rest. Traffic is encrypted in transit with TLS, passwords are stored only as salted hashes, and file storage uses private buckets with short-lived, signed access. No system is perfectly secure, but we take reasonable steps appropriate to the sensitivity of the data.
8. Data retention & deletion
We keep data for as long as your account is active or as needed to provide the Service. You can delete records within the app at any time. Our standard retention periods are:
- Closed accounts — we delete or de-identify the Organisation's data within 180 days of the account being closed.
- Expired free trials — data is deleted within 60 days if the trial is not converted to a paid plan.
- Encrypted backups — residual copies in our system backups are purged within a further 90 days.
- Security logs — sign-in records (the account, time, IP address and browser) are kept for 12 months and then deleted automatically. We use them only to secure the Service and investigate suspected unauthorised access, never to monitor how individuals work.
- In-app notifications — deleted 60 days after being read, and 180 days regardless.
We may retain some information for longer where we are required to by law (for example, tax and financial records). To request deletion of data collected through a connected service, use our data deletion page, or email us at the address below.
9. Your rights and complaints
Subject to applicable law (including the Australian Privacy Principles), you may request access to, correction of, or deletion of your personal information. If you are an end customer of one of our Organisations, please contact that business directly, as they control that data; we will assist them as their processor.
If you have a privacy complaint, email us at admin@sunledger.com.au and we will respond within a reasonable time. If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. Where your data is stored
The Service and its data are hosted on infrastructure that may process data in Australia and other countries. Where data is transferred internationally, we take steps to ensure it remains protected consistent with this policy and applicable law.
11. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal information from children under 16.
12. Changes to this policy
We may update this policy from time to time. The current version is always the one published here, and material changes will be communicated through the Service where appropriate.
13. Contact us
Questions about this policy or your data? Email admin@sunledger.com.au — we answer every message that reaches that address.
VC & NB Pty Ltd (ABN 57 621 355 002), trading as SunLedger. Victoria, Australia.