Privacy
Privacy statement
SunMeasure is built to need as little of your data as possible. No account, no tracking cookies, and the scan itself runs on your phone. Here is exactly what is processed and why.
Last updated: June 2026
1. Who is responsible
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Marc EisenhardtHohe Straße 6/1
71116 Gärtringen
Germany
Email: [email protected]
2. The short version
- You can use SunMeasure without creating an account or giving us your name.
- We set no advertising or tracking cookies and run no third-party analytics.
- The camera scan is processed on your own device. We do not receive or store your camera video.
- We only process what is technically necessary to serve the site, compute your result and, where applicable, deliver a paid report.
3. Visiting the website (server log files)
When you open SunMeasure, your browser automatically sends technical information to our hosting provider so the page can be delivered. This is stored temporarily in server log files and typically includes the requesting IP address, the date and time of the request, the page or file requested, the referring page, and your browser and operating system identifiers.
This data is processed to deliver the website reliably and to protect it against misuse and attacks. The legal basis is our legitimate interest in a secure and functional website (Art. 6(1)(f) GDPR). Log data is kept only as long as necessary for these purposes and then deleted or anonymised.
4. The sun scan and your result
The core measurement runs in your browser. Your phone uses the camera and motion sensors to map the obstructions (trees, roofs, ridges) around you. This processing happens locally on your device, and the raw camera video is not transmitted to us or stored by us.
To calculate the solar result, the app needs the approximate location of the spot (its coordinates) and the computed shadow horizon. This information is sent to our backend, which combines it with public solar-irradiance data to generate your report (for example as a PDF). The legal basis is the performance of the service you requested (Art. 6(1)(b) GDPR) and our legitimate interest in providing the measurement (Art. 6(1)(f) GDPR). Location data is used only to produce the result you asked for and is not used to track you.
To retrieve regional solar-irradiance values, the coordinates of the spot may be sent to external data services such as PVGIS (EU Joint Research Centre) and comparable providers. Only the location needed for the calculation is transmitted; no information identifying you personally is sent.
5. Web fonts
This site uses the Fraunces, IBM Plex and Space Grotesk typefaces, which are loaded from Google Fonts (Google Ireland Limited / Google LLC). When a page loads, your browser connects to Google's servers and your IP address is transmitted to Google so the fonts can be delivered. The legal basis is our legitimate interest in a consistent and well-presented website (Art. 6(1)(f) GDPR). Google may process this data on servers in the USA. You can find more information in Google's privacy policy at https://policies.google.com/privacy.
6. Local storage on your device
To remember your language preference, we store a single value (your chosen language) in your browser's local storage. This stays on your device, is not sent to us, and is not used to identify or track you. You can clear it at any time through your browser settings. We do not use cookies for advertising or analytics.
7. Paid reports and payments
If you purchase a paid report, the payment is handled by an external payment provider (a merchant of record) that processes the transaction and issues your invoice. The data you enter for payment is processed by that provider under its own privacy policy; we do not receive or store your full card details. The legal basis for processing the data needed to fulfil your order is Art. 6(1)(b) GDPR, and tax and commercial-law retention obligations may apply to invoice data (Art. 6(1)(c) GDPR).
8. Contacting us
If you contact us by email, we process the information you provide (such as your email address and the content of your message) in order to handle your request. The legal basis is our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR) and, where your request relates to a contract, Art. 6(1)(b) GDPR. We delete this data once it is no longer required and no retention obligations apply.
9. Sharing with third parties
We do not sell your data. Data is only shared with the service providers needed to run SunMeasure, such as our hosting provider, the font provider and, for paid reports, the payment provider. These providers act on our behalf or under their own responsibility as described above, and only to the extent necessary.
10. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or deleted, to restrict its processing, to data portability, and to object to processing carried out on the basis of our legitimate interests. Where processing is based on consent, you can withdraw that consent at any time with effect for the future.
To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or place of the alleged infringement.
11. Changes to this statement
We may update this privacy statement when the service or the legal requirements change. The current version is always available on this page.