Privacy Policy
ThermSuite, LLC ("ThermSuite," "we," "us," or "our") is an enterprise service for institutional natural gas market participants. We collect only what you submit to us and a limited set of operational data needed to run our site and services. This Policy explains what we collect, how we use it, and the choices you have.
1. Information we collect
We limit collection of personal information to what is reasonably necessary and proportionate to the purposes described in this Policy.
Information you provide. When you request a demo, contact us, or subscribe to Notes, we collect what you submit — typically your name, work email address, company, role, and any optional context about your inquiry — and use it to respond to your request and manage our relationship with you.
Subscription information. When you subscribe to Notes (our editorial section), we store your email address through our membership platform (Ghost) to deliver content and manage your preferences.
Analytics information. We use a self-hosted instance of Umami, an open-source, cookieless analytics tool, to measure aggregate site usage. For each pageview we collect the URL and referrer, derived browser/operating-system/device information, screen size, language, and approximate location (country, region, and city) inferred from the IP address at the time of the request. Umami sets no cookies and does not store IP addresses or raw user-agent strings. To estimate unique visitors, Umami generates a server-side, regularly-rotating salted hash from the IP, user-agent, and our site identifier; this hash cannot be reversed to identify you and is reset on a rolling basis. Because we self-host Umami, analytics data is stored on infrastructure we control and is not shared with any third-party analytics provider.
Information automatically collected. Standard web server logs may include IP address, user agent, requested URL, and timestamp. We retain these logs for operational and security purposes for up to 90 days, except where a longer period is required by law or to investigate an incident.
Sensitive personal information. We do not knowingly collect "sensitive personal information" as defined under California Civil Code §1798.140(ae) or analogous state laws (including government identifiers, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, contents of private communications, genetic or biometric data for identification, health data, sex life or sexual orientation, and neural data). If you include such information in a free-text field, we treat it as ordinary contact information and process it only to respond to your inquiry.
2. How we use information
We use the information we collect to:
- Respond to your inquiries and demo requests.
- Deliver the editorial content you have subscribed to receive.
- Operate, secure, and improve our website and services.
- Comply with applicable legal obligations and enforce our terms.
We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under state privacy laws, and have not done so in the preceding 12 months. We do not use third-party advertising platforms, behavioral tracking pixels, or cross-site retargeting.
3. Cookies, tracking, and browser signals
Our marketing website uses no advertising cookies, remarketing pixels, or cross-site trackers. Our self-hosted analytics tool (Umami) is cookieless. Our membership platform (Ghost) sets strictly-necessary first-party cookies for Notes subscriber authentication and session management (e.g., ghost-members-ssr); these are operational cookies and are not used for advertising or cross-site tracking.
Global Privacy Control (GPC). If your browser transmits a GPC signal, we treat it as a valid opt-out request for any sale, sharing, or targeted advertising — and will continue to honor it if our practices change.
Do Not Track. Because there is no consistent industry standard for "Do Not Track" signals, we do not respond to them separately.
4. How we share information
- Service providers. We use a small set of providers for hosting, email delivery, and membership management. They process information on our behalf under written contracts that restrict their use to the services they provide. A current subprocessor list is available on request to contact@thermsuite.com.
- Legal compliance. We may disclose information when we believe in good faith that it is required by law, court order, or regulatory authority, or necessary to address suspected fraud, security incidents, or violations of our terms.
- Business transfers. If ThermSuite is involved in a merger, acquisition, financing, or asset sale, your information may be transferred as part of that transaction, subject to this Policy and applicable law.
5. Data retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, maintain our business relationship with you, comply with applicable law, and defend legal claims. Demo and contact inquiries are typically retained while we manage the relationship and for a reasonable follow-up period; Notes subscriber records are retained while you remain subscribed; server logs are retained on a short-term operational basis.
You may request deletion at any time by contacting contact@thermsuite.com; see Section 7.
6. Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, access controls, and audit logging. Our infrastructure is privately hosted with Tailscale-based access patterns for institutional deployments, and we align our internal controls with the SOC 2 framework. No system is perfectly secure, and we cannot guarantee absolute security. Suspected security issues may be reported to security@thermsuite.com.
7. Your privacy rights
Depending on where you live, and subject to applicable exemptions — notably the business-to-business and employee-data exemptions available under most state privacy laws — you may have rights under applicable privacy laws to:
- Know or access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete personal information we have collected.
- Receive a portable copy of your personal information.
- Opt out of the sale or sharing of personal information, targeted advertising, and certain forms of profiling. ThermSuite does not engage in these activities.
- Limit the use of sensitive personal information (California). As noted in Section 1, we do not knowingly collect sensitive personal information.
- Non-discrimination for exercising your privacy rights.
Submitting requests. Email contact@thermsuite.com or write to the postal address in Section 12. We will respond within the timeframe required by applicable law (typically 45 days). We may verify your identity before responding.
Authorized agents and appeals. Where required by applicable law, you may use an authorized agent to submit a request on your behalf, and may appeal a denied request by contacting us with a message clearly identifying it as a privacy-rights appeal.
California residents. Under the California Consumer Privacy Act, you have the rights described above. The categories we collect, the sources, the purposes, and the categories of recipients are described in Sections 1, 2, and 4. We do not sell or share personal information as those terms are defined in the CCPA and have not done so in the preceding 12 months. Under California's "Shine the Light" law (Civ. Code §1798.83), we do not disclose personal information to third parties for their own direct marketing purposes.
Residents of other states. If you live in another state with a comprehensive consumer privacy law, you may have similar rights. Most of these laws exempt information collected from individuals acting as representatives of a business, which covers most of the data we collect.
European Economic Area and United Kingdom. ThermSuite is directed to users in the United States. We do not target services to individuals in the EEA, UK, or Switzerland, and do not monitor behavior in those regions. To the extent any EEA or UK data protection rights apply to you, contact contact@thermsuite.com.
8. Children's privacy
Our website and services are not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it promptly.
9. Automated decision-making and profiling
We do not use your personal information to make automated decisions that produce legal or similarly significant effects, and we do not engage in profiling as defined under the Colorado Privacy Act, Connecticut Data Privacy Act, or analogous state laws. We do not use personal information collected through our website to train generative AI models, and we do not sell or otherwise provide it to third parties for AI model training. Routine analytics and CRM tools we use for sales and marketing do not result in significant automated decisions.
10. Data brokers
ThermSuite is not a data broker as defined by the California Delete Act or analogous state laws. We do not buy personal information from third parties for the purpose of selling it, and we are not registered with the California Privacy Protection Agency as a data broker.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will provide notice of material changes by posting them on our website or, where appropriate, by email to subscribers, at least 30 days before they take effect; non-material updates take effect on posting.
12. Contact
Privacy inquiries:
- Email: contact@thermsuite.com
- Mail: ThermSuite, LLC
Attn: Privacy
405 W 36th Ave, Ste 104
Anchorage, AK 99503
Security disclosures: security@thermsuite.com
If you have an unresolved privacy concern, you may also contact your state attorney general or, in California, the California Privacy Protection Agency.