Legal
Privacy policy
How this service handles personal data. Last updated 26 September 2026.
Who is responsible
GridCapacity API is an independent data product operated from Belgium. It is not affiliated with, endorsed by, or operated by any transmission or distribution system operator. For anything on this page, including requests to access or delete data, write to hello@gridcapacityapi.com.
What the data is about
The data this service carries describes electricity infrastructure: substations, their available and reserved capacity, the operators that publish those figures, and where each figure came from. It is not data about people.
We do not collect personal data from operators’ publications. Where a publication happens to include a person’s name or contact details — a named contact for connection requests, for instance — that part is not imported. The only personal data this service holds is about its own account holders, below.
If you hold an account
An account exists so you can hold an API key, see your usage and pay for a plan. What is stored is what those three things need and nothing beyond them.
- Name and email address
- To identify the account, address you in the dashboard, and contact you about your keys or billing. The name is optional.
- Password
- None: you sign in with Google. (Where password sign-in is switched on, a password is stored only as an Argon2id hash, never written down itself.)
- Google account identifier
- Only if you sign in with Google. See the section below.
- Session records
- A SHA-256 hash of the session token, and when it was created, last used and expires. Sessions last 30 days. The token itself is not stored.
- API keys
- A SHA-256 hash of the key, its first characters, and the name you gave it. The key itself is shown once and never stored, which is why we cannot recover a lost one.
- Usage counters
- Requests, errors and rate-limited requests per account, per endpoint, per day. Counts only — never the queries you ran or the data you received.
- Billing identifiers
- A Stripe customer and subscription id, your plan and its renewal date.
- Webhook endpoints
- Only if you create one: the URL you gave, its filters, the signing secret we sign deliveries with, and each delivery's status and the HTTP status your server answered. The payloads describe capacity changes, never people.
- Exports
- Only if you create one: what you asked for, its filters, and the file itself until it expires, seven days after it is built. The file holds grid data, never data about you.
- Operator flag and last sign-in
- Whether the account can reach the operator dashboard, and when it last signed in.
There is no advertising, no profiling, no behavioural tracking, and no third-party analytics on this site. Nothing about you is sold or shared for anyone else’s marketing.
Signing in with Google
Accounts are created and signed in with Google: Google hands your browser a signed token, which our API checks against Google’s published keys. The token names a permanent identifier for your Google account, your email address and whether Google has verified it, and your name. We keep the identifier, the address and the name, and nothing else — no contacts, no calendar, no access to anything in your Google account.
The identifier is what the account is keyed on, not the email address. Google documents it as permanent for the life of the account, whereas an email address can be changed by its owner or reassigned to a different person entirely — and that person should not inherit your API keys.
Revoking access at your Google account permissions stops future sign-ins. It does not delete the account here; write to us for that.
Payments
Payments are handled by Stripe. Card numbers are entered on Stripe’s own checkout, never on this site, and never reach our servers. We receive only the identifiers and subscription status listed above. Stripe’s handling of your payment details is covered by Stripe’s privacy policy.
Cookies
One cookie, named gc_session. It holds your sign-in session, is marked httpOnly so no script can read it, and expires after 30 days or when you sign out. It is strictly necessary to keep you signed in, does nothing else, and is not used to track you — which is why this site has no cookie banner rather than why it should have one.
Where the data lives, and for how long
Everything runs on a single rented server in Germany, with Cloudflare in front of it. The database is not reachable from the internet. Payments go to Stripe, and Google receives a sign-in request only at the moment you choose to sign in with Google. Web fonts are loaded from Bunny Fonts, so your browser requests them from that service; we receive nothing from it. There are no other processors.
- Account records
- Kept while the account exists, and deleted on request.
- Sessions
- 30 days, then deleted automatically.
- Revoked API keys
- The hash is kept so a revoked key stays revoked.
- Usage counters
- Aggregated per day; the dashboard shows the last 30.
- Billing events
- The record of what each Stripe notification changed, kept for accounting.
Your rights
Under the GDPR you may ask for a copy of what is held about you, ask for it to be corrected or deleted, object to how it is processed, or complain to a supervisory authority. In Belgium that is the Gegevensbeschermingsautoriteit. Write to hello@gridcapacityapi.com and you will get an answer within 30 days. There is no charge, and you do not need to give a reason for a deletion request.
Changes
If this policy changes in a way that affects you, the date at the top changes and account holders are emailed. Silent rewrites are not a thing we do.
See also the terms of service and how we read sources.