Sunnova Biometric Notice
Sunnova Energy Corporation (the "Company") uses biometric information in order to verify your identity.
Many laws, including the Illinois Biometric Information Privacy Act, 740 ILCS 14/1, et seq. ("BIPA"), regulate the collection, storage, use, and retention of "biometric identifiers" and "biometric information." "Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. "Biometric information" means any information, regardless of how it is captured, converted, stored, or shared, based on an individual's biometric identifier used to identify an individual.
I understand that I can decline to provide biometric identifiers and biometric information to the Company. I may revoke this consent at any time by notifying the Company in writing or through the Company website at https://www.sunnova.com/legal/access-and-delete-data.
I am aware that I am free to decline or revoke this consent, and doing so will not preclude other Services by the Company and service providers acting on its behalf. However, I understand that if I decline or revoke this consent, the Company will not be able to verify my identity by using biometric information.
Last Updated: July 20, 2022
TABLE OF CONTENTS
Information We Collect
How We Collect Information
Third-Party Data Sources
Cookies and Interest-Based Advertising
How We Use and Disclose the Information We Collect
How we Protect Your Information
Children Under 16
Additional California Consumer Rights
INFORMATION WE COLLECT
We collect information that personally identifies, relates to, describes, or is capable of being associated with you (“Personal Information”), including:
- Personal identifiers and contact information such as name, social security number, driver’s license number, mailing address, garaging address, email addresses, phone numbers, fax numbers;
- Other demographic information such as the type of home you own, whether you rent or own your home, any co-owners or co-tenants of your home, age, gender, and what languages you speak;
- Commercial information such as your utility company, energy you generate and use, your home’s appliances, pool and utility settings, product interest and purchase history, financial account status and balance, and your Sunnova account credentials;
- Banking/financial information such as your credit card, bank account, or other payment information;
- Product information such as information about solar-related equipment in your home, including make, model, serial number, and location in your home, the energy it generates (including power, voltage, current, frequency and flow rates), its settings, schedules, alerts, and system installation and roof diagrams;
- Energy usage such as your past and present energy usage, the amount of energy used in your home (including use generated by appliances and devices), and service obtained from your local utility company.
- Details about your home such as dwelling age, size and type, details about appliances and other energy-related equipment used in the home or building, mapping information, photos and satellite imagery, details about the home or building’s structure for system design, and data regarding solar irradiance.
- Internet and network information such as browsing/search history, IP address, data collected by cookies and similar technologies;
- Geolocation data such as geographic location indicators from mobile, web, and product that are approximate and/or which are not used to locate a particular individual;
- Audio/visual information such as call recordings, chat transcripts, testimonials, pictures or videos you upload to or send through the Website or by using our Services;
- Biometric Information such as a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry used to identify an individual. Our biometric disclosure is found here;
- Professional/employment information such as employer information, income;
- Education information such as education level; and
- Inferences drawn from other Personal Information or data that relate to your preferences, interests, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes, such as credit reports or credit scores.
We also collect certain types of Personal Information that may be considered sensitive under relevant laws such as: social security number, driver’s license and other identification card information, bank account numbers, payment card information, biometric information, and your Sunnova account credentials. We refer to this type of Personal Information as “Sensitive Personal Information” in this Policy. Each type of Sensitive Personal Information may overlap with a category of Personal Information listed above.
The types of Personal Information we collect about you may vary based on how you use the Site and/or Services and your relationship with us.
We retain Personal Information for the length of time needed to carry out the purposes outlined in this Policy and to adhere to our recordkeeping policies, which are informed by applicable laws and industry standards.
Usage Data and Site Activity
We automatically collect information in connection with the actions you take on the Site (“Usage Data”). For example, each time you use the Site, we automatically collect the type of web browser you use, the type of device you use, your operating system and version, your IP address, the pages you view, referring and exit pages, the date and time of your visit, and the number of clicks to, from, and within the Site, and the duration of your visits to the Site. If the data we automatically collect is capable of being associated with you, directly or indirectly, we treat it as Personal Information. If this information is not capable of being individually associated with you, we treat it as Usage Data.
HOW WE COLLECT INFORMATION
From You and Your Equipment
We may ask you to provide us with Personal Information when you communicate with us online or offline, including events, surveys, and marketing or promotional programs. You are not required to provide us your Personal Information; however, if you choose not to provide the requested information, you may not be able to use some or all of the features of the Site or Services or we may not be able to fulfill your requested interaction. We may also capture Personal Information when you contact us or through your equipment.
Third-Party Data Sources
We may collect Personal Information from third-party data sources such as marketing agencies, other Sunnova Group customers, fulfillment and account servicing companies, (including sales and/or installation dealers), equipment manufacturers, credit bureaus and/or reporting agencies, analytics firms, map and/or satellite imagery providers, public records, and government agencies
Cookies and Other Automated Tools
We use the following types of cookies:
- Session Cookies: Session cookies keep track of you or your information as you move from page to page within our Sites and are typically deleted once you close your browser.
- Persistent Cookies: Persistent cookies reside on your system and allow us to customize your experience if you leave and later return to our Sites. For example, persistent cookies may allow us to remember your preferences.
- Advertising Cookies: Advertising cookies are used to learn more about you and advertise products/services that might interest you.
We employ software technology that enables us to track certain aspects of a user’s visit to our Sites. This technology helps us better manage content on our Sites by informing us what content is effective, how consumers engage with our Sites, and how consumers arrive at and/or depart from our Sites. The software typically uses two methods to track user activity: (1) “tracking pixels” and (2) “clear gifs.” Tracking pixels are pieces of executable code that are embedded in a web page that track usage activity including which pages are viewed, when they are viewed, and how long the pages are viewed. Clear gifs are tiny graphics with unique identifiers which are embedded in web pages and email messages that track whether a user views a web page or email message. User activity information may be associated with additional information about a user’s session and Personal Information, if provided by the user.
Information from Advertisements
If you arrive at our Sites via an advertisement (e.g., banner ad), we may collect information regarding the advertisement with which you interacted and your interactions (e.g., item clicked, date and time).
Social Media Widgets
The Sites may include social media features, such as the Facebook, YouTube, Pinterest, LinkedIn, Instagram, and Twitter widgets. These features may collect information about your IP address and the pages you visit on our Site as well as other Personal Information. A cookie may be set to ensure that a feature properly functions. The social media features are governed by the privacy policies of the companies that provide them.
HOW WE USE AND DISCLOSE THE INFORMATION WE COLLECT
We use Personal Information for business purposes, such as:
- Account creation, fulfillment, servicing, and customer support: to process applications, create customer accounts, allow customers to create online accounts and profiles, provide goods or services, keep customers informed about the status of their services, respond to questions and addressing customers concerns, deliver updates, upgrades and product improvement information.
- Marketing and market research: to send communications and offers for our or third parties’ products and services, including offers based on consumers’ interests, personal and business characteristics and location; perform analytics for market and consumer research, trend analysis, financial analysis, and anonymization of personal information.
- Collection and credit reporting: to collect on outstanding balances, repossess collateral and update credit reporting agencies.
- Surveys, promotional events, contests: to administer surveys, polls, sweepstakes, contests, loyalty programs and other promotional events and contests.
- Other company communications: to provide consumers with information that may be of interest such as company newsletters, announcements, reminders, and technical service bulletins.
- Website use and analytics: to provide you with access to and use of our Website and Services; analyze consumers’ use of our websites, including the use of third-party web analytics services, which may utilize automated technologies to collect data (such as email and IP addresses).
- Eligibility and Pricing: to determine if consumers are eligible for certain products, services or offers and the pricing related to such offers.
- Product research: to conduct research and analysis for maintaining, protecting, and developing services, increase and maintain the safety of our products and services, and prevent misuse.
- Business operations: to evaluate, develop, and improve business operations, products and services offered; business administration and other normal business activities.
- Compliance: to comply with applicable legal requirements, industry standards, contractual obligations, our policies, and take actions that we deem necessary to preserve and enforce our rights and the rights of others.
- Information security and fraud prevention: to operate information security and anti-fraud programs.
We use Sensitive Personal Information as follows:
- Social security numbers, driver’s licenses, and other government identification cards – to provide the Services, service accounts, collect on accounts, and as otherwise required by law.
- Bank account numbers, payment card information – to process payment in connection with providing the Services.
- Sunnova account credentials – to permit access to customers’ online accounts and operate information security and anti-fraud programs.
- Biometric information – to confirm your identity as part of our anti-fraud programs.
We may provide your Personal Information without notice to other businesses (“Service Providers”) to provide services to us or to you on our behalf. Categories of service providers we use include:
- Fulfillment and account servicing vendors, which help us provide products, services and information to you, service your account or benefits, collect survey responses and support our e-commerce services;
- Payment processors, which help us to accept and process the payments for our products and services to you;
- Consumer/credit report services, which help us understand consumer’s eligibility and qualification for certain financing options;
- Marketing and communications vendors, which help us market our products/services to you, conduct promotions, events, surveys and other outreach campaigns;
- Research and development vendors, which help us develop and improve our products and services;
- IT and network administration vendors, which provide services such as data storage and management, website hosting, and data security;
- Professional service firms, which provide accounting, legal and other professional services; and
- General service providers, which help us with day-to-day business operations such as office support services, courier services, facilities management, and document destruction.
Each Service Provider is expected to use reasonable security measures appropriate to the nature of the information involved to protect your Personal Information from unauthorized access, use, or disclosure. Service Providers are prohibited from using Personal Information that we provide to them other than as specified by us.
We may sell your Personal Information with other companies who do not provide services to us (“Third Parties”), including industry associations and advocacy groups, retailers, companies that provide other home services, and other advertisers. In the past twelve months we have sold each of the following categories of Personal Information (except Sensitive Personal Information) to each of the categories of Third Parties identified above: personal identifiers and contact information, other demographic information, commercial information, product information, energy usage, details about your home, and Internet and network information.
Biometric Information Retention Schedule
In circumstances where Sunnova Group retains Biometric Information, we will permanently destroy an individual’s Biometric Data within six (6) months of when the initial purpose for collecting or obtaining such Biometric Data has been satisfied, such as:
- You revoke your consent contained in the Biometric Notice;
- You have not contacted Sunnova Group or used our Services for a 30-month period;
- Your contract with Sunnova has expired and you are no longer a Sunnova customer;
- Sunnova Group no longer uses the Biometric Information.
If any Sunnova Group’s Service Providers require access to Biometric Data in order to fulfill the purpose of collecting such information, we will request that they follow the above destruction schedule.
OTHER IMPORTANT PRIVACY PROVISIONS
Legal Compliance, Business Transfers and Other Disclosures
Notwithstanding anything to the contrary stated herein or on our Website, we may occasionally release information about users of our Website when we deem such release appropriate to comply with law, respond to compulsory process or law enforcement requests, or protect the rights, property or safety of our customers or prospective customers, the public, the Sunnova Group or any third party. Over time, we may reorganize or transfer various assets and lines of business. Notwithstanding anything to the contrary stated herein or on our Website, we reserve the right to disclose or transfer any information we collect in connection with any proposed or actual purchase, sale, lease, merger, foreclosure, liquidation, amalgamation or any other type of acquisition, disposal, transfer, conveyance or financing of all or any portion of the Sunnova Group.
How We Protect Information
The Sunnova Group uses commercially reasonable procedures to protect the Personal Information that we collect from you against loss, theft and misuse, as well as unauthorized access, disclosure, alteration and destruction. We have developed and implemented and continue to maintain and monitor written information security procedures applicable to all records containing Personal Information. Our security procedures are appropriate to the size, scope and type of our business, the resources available to us, the amount of stored data and the need for security and confidentiality of the personal information we store. Our servers are scanned on a regular basis for known vulnerabilities in order to make your visit to our Sites as safe as commercially practicable. We make use of industry standard tools and practices to protect against malware exposure.
Children Under 16
The Sunnova Group cares about protecting the privacy of children. We will not specifically market to or knowingly collect Personal Information from children under 16. If a child under 16 submits Personal Information to us and we learn that the Personal Information is the information of a child under 16, we will take reasonable steps to delete the information as soon as possible. If you are under 16, please do not register for any of our services or provide us any information about yourself (such as your name, email address or phone number).
ADDITIONAL CALIFORNIA CONSUMER RIGHTS
If you are a resident of California, you may have additional rights to access and control your Personal Information, including a right to request that we disclose the Personal Information we collect, use, disclose, and/or sell. Exemptions may apply.
Right to Opt-Out from the Sale of Personal Information
As a California resident, you have the right to direct us not to sell your Personal Information to Third Parties. We will process verified requests within 15 business days, subject to any applicable exceptions and extensions permitted by law.
Right to Know
You have the right to request twice per 12-month period that we provide you (i) the categories or specific pieces of Personal Information we collected about you; (ii) the categories of sources from which your Personal Information was collected; (iii) the business or commercial purpose for which we collected your Personal Information; (iv) the categories of Third Parties with whom we shared your Personal Information; and (v) the categories of Third Parties to whom we sold your Personal Information. We are not permitted to provide access to specific pieces of Personal Information if the Personal Information is sensitive or creates a high risk of potential harm from disclosure to an unauthorized person such as financial information, social security numbers, and driver’s license numbers.
Right to Deletion
You have the right to request that we delete any Personal Information we have collected about you. Please understand that we are not required to honor a deletion request if a legal exemption applies such as if we need the information to complete a requested or reasonably anticipated transaction, prevent security incidents or fraud, enable internal uses that are reasonably aligned with your expectations, or comply with legal obligations.
Submitting a Request
If you are a California resident and would like to exercise your rights under the California Consumer Privacy Act, you may submit a request though our online California Consumer Privacy Act request form. You may also submit a request by phone by contacting us at 1-866-786-6682. After you submit your request, we may contact you to obtain additional information necessary to verify your identity. For example, we may require you to verify certain information in our files or submit a signed declaration under penalty of perjury verifying your identity. We will not process Right to Know or Deletion requests without verifying your identity, so please respond promptly. If you do not timely respond to our requests for information, we may deny your request.
We will process Opt-Out of Sale requests within 15 business days of receipt. We will process verified Right to Know and Deletion requests within 45 calendar days of receipt, subject to any applicable exemptions and extensions permitted by law up to 90 calendar days. If you request specific Personal Information and that information creates a high risk of potential harm from disclosure to an unauthorized person, we will withhold that information and replace it with a category identifier. For example, if we withhold a social security number, we will inform you that we have a social security number on file. If you have an online account with us, we will provide the response to your request via the online account, otherwise, we will give you the option to choose between mail and electronic delivery. We will retain a copy of your Deletion request for at least two years as required by law.
If you are an authorized agent submitting a request for a California resident, you must provide a copy of a lawful power of attorney or written authorization from the consumer (along with proof of your identity). If you make a request as an authorized agent, you will receive additional instructions from us after submitting the request. We may contact you or the consumer on whose behalf you claim to act to verify your authorization.
Do Not Track
Do Not Track is a web browser privacy preference that causes the web browser to broadcast a signal to websites requesting that a user’s activity not be tracked. Currently, our Website and Services do not respond to “do not track” signals.
Energy Usage Data
Additionally, pursuant to California Civil Code Section 1798.98, if you are a customer of an electrical or gas corporation operating for profit in California or of a local publicly owned electric utility, we cannot disclose information we obtain about your energy usage without your consent.
20 Greenway Plaza, Suite 540
Houston, Texas 77046