PRIVACY POLICY - KINGDOM SUN Effective Date: 03/22/2026 Last Updated: 03/22/2026 Kingdom Sun operates kingdom-sun.com and kingdom-sun.app. This policy explains how we collect, use, and protect your information. ================================================================================ 1. INFORMATION WE COLLECT ================================================================================ YOU PROVIDE: - Contact info: Name, email, phone, address, ZIP code - Design choices: Frame size, solar configuration, stain color, siding, installation package, pricing - Optional notes WE COLLECT AUTOMATICALLY: - Visitor ID (cookie, 30 days) to identify returning visitors across sessions (may require consent depending on your location — see Section 4) - Session ID (browser session storage, per-tab) to track configurator progress within a single visit — cleared when you close the tab - Usage data: ZIP entries, configuration changes, step completions - Technical data: IP address, browser, device, referrer - Geographic data: City, state, country (from IP geolocation and ZIP code) - Marketing data: UTM parameters, referrer THIRD-PARTY ANALYTICS: - Google Analytics 4 (via Google Tag Manager) collects anonymous behavioral data and may set cookies (_ga, _gid) for analytics purposes - Google Ads conversion tracking may set cookies (_gcl_au) for advertising measurement - These third-party cookies are subject to your consent preferences where required by law SOLAR CALCULATIONS: - We share your ZIP code with OpenWeather (geocoding) and NREL PVWatts API for solar production estimates (no contact info shared) ================================================================================ 2. HOW WE USE YOUR INFORMATION ================================================================================ - Process inquiries and create custom designs - Communicate with you about your project - Improve the configurator experience - Analyze marketing effectiveness - Plan service area expansion WE DO NOT SELL YOUR INFORMATION. ================================================================================ 3. HOW WE SHARE YOUR INFORMATION ================================================================================ SERVICE PROVIDERS: - Resend: Email notifications - Google Sheets: Lead management - Supabase: Database hosting - Google (Tag Manager, Analytics 4, Ads): Anonymous behavioral analytics and advertising conversion measurement - Vercel: Website hosting and IP-based geolocation - OpenWeather: ZIP code geocoding for solar calculations - NREL PVWatts: Solar production estimates (ZIP/coordinates only) LEGAL REQUIREMENTS: We may disclose information if required by law or to protect our rights, prevent fraud, or ensure safety. ================================================================================ 4. COOKIES & STORAGE ================================================================================ ESSENTIAL COOKIES (always active): - ks_consent: Stores your cookie preferences (365 days) - ks_geo_region: Determines which privacy regulations apply to your visit (24 hours) ANALYTICS COOKIES (may require consent): - ks_visitor_id: Identifies returning visitors across sessions (30 days) - _ga, _gid: Set by Google Analytics for usage analysis (up to 2 years) MARKETING COOKIES (may require consent): - _gcl_au: Set by Google Ads for conversion tracking (90 days) BROWSER SESSION STORAGE (not cookies — cleared when you close the tab): - Session ID, configurator progress, form data, UTM parameters CONSENT BY LOCATION: - EU/EEA/UK visitors: Analytics and marketing cookies require your explicit opt-in consent before being set (GDPR) - California visitors: Analytics and marketing cookies are active by default; you can opt out at any time (CCPA) - All other visitors: Cookies are active by default You can manage your cookie preferences at any time using the "Cookie Settings" link in the page footer. OPT OUT: You can also disable cookies in your browser settings or use private/incognito mode. ================================================================================ 5. DATA RETENTION ================================================================================ - Lead data: Retained indefinitely for ongoing service - Analytics data (including IP addresses): Retained indefinitely for product improvement Request deletion anytime (see Section 7). ================================================================================ 6. SECURITY ================================================================================ We use database security policies, API authentication, HTTPS encryption, and access controls. No system is 100% secure. ================================================================================ 7. YOUR RIGHTS ================================================================================ You can request to: - Access your data - Correct inaccurate information - Delete your data - Opt out of communications - Receive data in portable format - Withdraw cookie consent at any time via the "Cookie Settings" link EU/EEA/UK RESIDENTS (GDPR): You have additional rights under the General Data Protection Regulation, including: - Right to withdraw consent at any time (this does not affect processing before withdrawal) - Right to data portability - Right to restrict processing - Right to lodge a complaint with your local data protection supervisory authority CALIFORNIA RESIDENTS (CCPA): You have additional rights under the California Consumer Privacy Act: - Right to know what personal information is collected, used, and shared - Right to delete personal information - Right to opt out of the sale or sharing of personal information - We do not sell personal information. You can opt out of cross-context behavioral advertising (sharing) by clicking "Do Not Sell or Share My Info" in the cookie consent banner or "Cookie Settings" in the page footer. - Right to non-discrimination for exercising your rights CONTACT US: kingdomsunVT@gmail.com ================================================================================ 8. ADDITIONAL INFORMATION ================================================================================ CHILDREN: Services not directed to users under 18. CHANGES: We may update this policy. Continued use means acceptance. THIRD-PARTY LINKS: We're not responsible for other sites' privacy practices. CONTACT: Kingdom Sun West Glover, VT Email: kingdomsunVT@gmail.com Phone: 802.472.1113 (6am – noon, M-F)