GlacierGrid Privacy Policy
GlacierGrid, Inc.
Effective date: 7/31/2026
Last updated: 7/31/2026
GlacierGrid, Inc. ("GlacierGrid," "we," "us") provides energy and facilities monitoring for multi-site operators. This Policy explains what personal information we collect, how we use and share it, how long we keep it, and the choices you have. It covers our websites, applications, and the GlacierGrid Connector for Claude.
1. Information we collect
- Information you provide: contact details (name, email, phone, address), username and password, location data, demographic information, payment information, and communications you send us.
- Information collected automatically: IP address, cookie and device identifiers, mobile advertising identifiers, browser type, operating system, pages visited, timestamps, and link activity.
- Information from other sources: third-party sources that supplement the information you provide, for verification and to improve our services.
- Community and social media: public posts and, where you use social login, publicly available profile information.
- Cookies and tracking: cookies and pixel tags used to remember credentials, analyze usage, and measure page and email engagement.
2. How we use information
Providing and managing the services and your account; service notices; administrative purposes including quality control and identity verification; payment processing and fraud prevention; marketing communications; creating anonymized and aggregated analytics; and research and product development.
3. How we share information
- Service providers (IT, payment processing, customer service) under confidentiality obligations.
- Business partners and affiliates for joint or related offerings.
- Legal compliance in response to lawful requests, court orders, and to protect our rights.
- Business transactions such as a merger, acquisition, or reorganization.
We do not sell your personal information, and we do not otherwise disclose it except as described in this Policy.
3a. Service providers and sub-processors
We use the following providers to operate the GlacierGrid services and the GlacierGrid Connector for Claude. Each processes personal information on our behalf under contract, for the purpose shown. All connector infrastructure is hosted in the United States (Amazon Web Services, US East / Northern Virginia).
- Amazon Web Services — compute, PostgreSQL database, content delivery, and load balancing.
- AWS ElastiCache (Valkey) — authorization state only; no facility data.
- InfluxData (InfluxCloud) — time-series sensor telemetry.
- Google (Firebase) — identity and sign-in.
- Elastic Cloud — operational logs and performance monitoring.
- Anthropic, PBC — operates Claude, the AI assistant. Anthropic receives the facility data returned to answer each question you ask through the connector. See Section 4.
Our current sub-processor list is maintained at glaciergrid.com/subprocessors. With the exception of Anthropic, which receives data only through the connector, all of these providers already supported the core GlacierGrid services before the connector existed.
3b. Business customers and our Data Processing Addendum (DPA)
When we process personal information on behalf of a business customer — for example, data about that customer's sites, devices, and facility users — we act as a processor and the customer is the controller. That processing is governed by a Data Processing Addendum (DPA) between GlacierGrid and the customer, in addition to this Policy. Business customers may request our DPA by contacting privacy@glaciergrid.com.
We add or change sub-processors by notice, not by requiring a new signature: we post the current list at glaciergrid.com/subprocessors, give affected business customers at least 30 days' advance notice of any new sub-processor, and provide an opportunity to object on reasonable data-protection grounds.
4. The GlacierGrid Connector for Claude
The GlacierGrid Connector for Claude is a Model Context Protocol (MCP) connector that lets you ask Claude questions about your own GlacierGrid facilities data in plain language. This section describes how the connector handles data. It applies in addition to the rest of this Policy.
It is read-only. The connector retrieves and reports data from your GlacierGrid account. It does not change setpoints, close alerts, write to, or modify anything in your GlacierGrid systems. It does not grant access to any data your GlacierGrid account could not already reach.
Authentication. You connect the connector to your GlacierGrid account using OAuth. The connector never receives or stores your GlacierGrid password; sign-in is performed by Google Firebase. The connector receives only authorization tokens that link your Claude session to your GlacierGrid account. Access is scoped to the locations your GlacierGrid account already covers.
Data the connector accesses. When you ask Claude a question that uses the connector, it accesses only facility monitoring data associated with your account: HVAC, refrigeration, energy and savings, sensor readings, issues and their notifications, device connectivity, and weather context for your sites. The connector does not access payment information or unrelated personal data, and it does not read Claude's memory, your chat history, or files you upload to Claude.
How data flows. When you submit a question in Claude, Claude sends the connector the parameters needed to answer it, the connector returns the requested facility data to Claude, and Claude composes an answer in your conversation.
Anthropic's role. Anthropic operates Claude. Once your request and the connector's response reach Claude, Anthropic's own privacy policy governs how that data is handled, retained, and whether it is used to train models. Your use of Claude is subject to Anthropic's terms and privacy policy at https://www.anthropic.com/legal/privacy. GlacierGrid does not control Anthropic's handling of data once it reaches Claude.
What the connector stores.
- Tool outputs (your facility data) are not stored. The connector has no database of its own, writes no files, and caches no results. Data is returned to Claude to answer your question and then discarded. For reliability, a short-lived in-memory buffer holds recent responses so a dropped connection can be recovered mid-answer; it never touches disk and is discarded when your session ends, at most four hours later and typically within about 30 minutes.
- Authorization credentials. Access tokens are retained for 1 hour, refresh tokens for 30 days, and client registrations for 90 days (refreshed on use), held only as authorization state, separate from any facility data.
- Request logs. We log operational metadata about each request — which tool was called, the site or device identifiers, and the time range requested — with a row count and byte size of the response. We do not log the response contents, and the logs contain no personal contact information. Logs are retained for 7 days, then deleted.
Third-party sharing. The connector shares your facility data only with Anthropic, to deliver the answer to your own request. It introduces exactly one new recipient of your data, Anthropic, and no new storage location.
Your control. You can disconnect the connector at any time in Claude's connector settings, which revokes its access to your GlacierGrid account.
5. Data retention
We retain personal information for as long as you use the GlacierGrid services or as necessary to fulfill the purposes for which it was collected, and to comply with our legal obligations. We retain core account information for 2 years after your account is closed, unless a longer period is required by law. Connector retention periods: request logs 7 days; access tokens 1 hour; refresh tokens 30 days; client registrations 90 days; and the in-memory response buffer at most 4 hours. Facility data returned through the connector is not stored by us.
6. Security
We take reasonable steps designed to protect personal information, though no method of transmission or storage is completely secure. Keep your password confidential and report any suspected compromise to support@glaciergrid.com.
7. Your rights and choices
Subject to applicable law, you may request access to, correction of, or deletion of your personal information; opt out of marketing email (unsubscribe link or privacy@glaciergrid.com) and SMS; and withdraw consent for new processing. California and other state residents have additional rights as described below. We do not recognize Do Not Track signals.
8. Children
We do not knowingly collect information from children under 13 (or 16 in certain jurisdictions) and will delete such information promptly if discovered.
9. California privacy rights (CCPA, as amended by the CPRA)
This section applies to California residents.
Categories of personal information we collect. In the past 12 months we have collected: identifiers; California customer records; commercial information; internet or other electronic network activity; geolocation data; and inferences. The specific data points are in Section 1. We do not collect characteristics of protected classifications (such as race, religion, or health).
Sources, purposes, and disclosures. We collect this information from the sources in Section 1, use it for the purposes in Section 2, and have disclosed it for business purposes to the recipients in Sections 3 and 3a.
Sensitive personal information. We collect account log-in credentials (your username in combination with your password), which the CCPA treats as sensitive personal information. We use it solely to provide and secure the services, which is a purpose for which the CCPA does not require us to offer a right to limit. Location collected through our mobile app is approximate, not precise geolocation, and is not sensitive personal information. We do not use sensitive personal information to infer characteristics about you.
Sale or sharing. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We use HubSpot as our marketing and website-analytics platform under a service-provider agreement. We do not sell or share the personal information of consumers we know to be under 16.
Your rights. You have the right to know and access, delete, correct, opt out of the sale or sharing of your personal information, limit the use of your sensitive personal information, and non-discrimination for exercising these rights.
How to exercise your rights. Submit a request by emailing privacy@glaciergrid.com or through our online privacy request form at glaciergrid.com/privacy-request. We will verify your request before responding. You may use an authorized agent, with proof of authorization. GlacierGrid operates primarily online with a direct relationship with its users, so a toll-free number is not required.
Retention. We retain each category of personal information as described in Section 5.
9a. Other US state privacy rights
GlacierGrid has users in all 50 states. If you live in a state with a comprehensive consumer privacy law — including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, and other states as their laws take effect — you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. To exercise any of these rights, contact privacy@glaciergrid.com. If we deny your request, you may appeal by replying to our decision; we will respond within the period your state's law requires.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date, and where required by law we will provide additional notice.
11. Contact us
GlacierGrid, Inc.
2515 Waco Street, Richmond, VA 23294
Privacy inquiries: privacy@glaciergrid.com
General support: support@glaciergrid.com
Phone: +1 (833) 865-0773