Privacy Policy
Effective date: 02/25/26
Introduction This Privacy Policy explains how Peak Rebate ("we," "us," or "our") collects, uses, discloses, and protects personal information when you visit and use our website, applications, and services (collectively, the "Services"). By accessing or using the Services, you agree to the terms of this Privacy Policy.
Peak Rebate provides SMS-based rebate eligibility verification services for licensed HVAC contractors
Information We Collect We collect the following categories of information:
Information you provide directly:
Account registration information (name, email address, username, password)
Message content voluntarily provided by contractors who initiate contact with Peak Rebate to verify Energy Star certification and rebate eligibility.
Profile information (photo, bio, preferences)
Payment and billing information (credit card number, billing address) when you make purchases
Communications and support inquiries (messages, feedback)
Content you submit (reviews, comments, uploads)
Information collected automatically:
Usage data (pages visited, time spent, features used)
Device and connection information (IP address, device type, operating system, browser)
Log data and analytics (clickstream data, referring URL, search queries)
Cookies and similar technologies (see Cookies and Tracking Technologies section)
Information from third parties:
Social media profile information when you link or authenticate via third-party services
Payment processor information necessary to complete transactions
Publicly available information and data from service providers and partners
How We Use Your Information We use personal information for the following purposes:
To provide, maintain, and improve the Services
To process transactions and send related information, such as confirmations and invoices
To communicate with you, including customer service, security alerts, and administrative messages
To personalize content and recommendations
To analyze usage and trends to improve the Services
To detect, investigate, and prevent fraudulent or illegal activity
To comply with legal obligations and enforce our terms and policies
Legal Bases for Processing (for users in the European Economic Area) Where applicable, we rely on the following legal bases to process personal data:
Performance of a contract
Consent
Legitimate interests (e.g., improving services, preventing fraud)
Legal obligations
Sharing and Disclosure of Information We may share personal information with:
Service providers and processors who perform services on our behalf (payment processors, hosting providers, analytics providers)
Affiliates and subsidiaries for internal business purposes
Business partners for joint promotions or integrations, with your consent where required
Law enforcement, regulators, and other third parties as required by law or to protect rights, safety, or property
In connection with a merger, acquisition, or sale of assets (you will be notified and receive choices where required)
Cookies and Tracking Technologies We and our service providers use cookies, web beacons, pixels, and similar technologies to collect information about your interactions with the Services. These technologies help with authentication, security, preferences, analytics, and advertising. You can manage cookie preferences through your browser settings and, where available, the opt-out tools provided by our Services.
Data Retention We retain personal information for as long as necessary to provide the Services, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary depending on the type of data and the purposes for which it was collected.
Security We implement reasonable administrative, technical, and physical safeguards designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. No security measures are perfect or impenetrable; we cannot guarantee absolute security.
Your Rights and Choices Depending on your jurisdiction, you may have rights regarding your personal information, including:
Access: request a copy of personal data we hold about you
Correction: request correction of inaccurate or incomplete data
Deletion: request deletion of your personal data
Portability: request a copy of data in a structured, commonly used format
Restriction or objection: object to or request restriction of certain processing
Withdraw consent: where processing is based on consent, you may withdraw it
To exercise these rights, contact us using the contact details below. We may require verification of your identity and may limit or refuse requests where permitted by law.
Children's Privacy The Services are not intended for children under the age of 13 (or other minimum age required by applicable law). We do not knowingly collect personal information from children under that age. If we learn that we have collected data from a child without parental consent, we will take steps to delete it.
International Data Transfers We store and process information in the United States and other countries. By using the Services, you consent to the transfer of information to countries that may have different data protection laws than your own