Privacy Policy

Last updated

This policy sets out the personal data that Podee collects when you connect a Tesla vehicle, the purposes for which it is processed, the periods for which it is retained, and the rights available to you in respect of it. It constitutes the information we are required to provide to you under Articles 13 and 14 of the UK GDPR.

Where you configure it to do so, Podee processes precise location data. Connecting a vehicle and configuring it to send us location data causes us to receive that vehicle's location and the history of its movements. Data of that nature is capable of revealing a great deal about the individuals who travel in the vehicle. This policy sets out what we do with it, and our Acceptable Use Policy sets out what you may not do with it.

1. The controller

[TODO: Podee Ltd] (trading as Podee) is the controller of the personal data described in this policy. We are registered in England and Wales under company number [TODO: Companies House number], and our registered office is at [TODO: registered office address, including postcode]. We are registered with the Information Commissioner's Office under registration [TODO: ICO registration number].

Any enquiry concerning this policy, including any request to exercise your rights, should be addressed to privacy@podee.app. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the UK GDPR.

2. Personal data we collect

Account data

Your Tesla account identifier, which is the only identifier under which your data is held with us. There is no registration form, and we do not ask you to choose a password: you sign in through Tesla's own OAuth 2.0 process, your account with us is created the first time you do so, and we neither receive nor store your Tesla password.

Your name, your email address and the address of your Tesla profile picture are fetched from Tesla each time you open the service and are displayed to you in your browser. We do not store them, save that your email address is stored if you set up billing, as to which see Billing data below.

Signing in issues us with an access token and a refresh token, which we hold in order to make requests to the Tesla Fleet API on your behalf. They are encrypted before they are written to our database, under a key held by the service rather than by the database, so that they cannot be read from the stored data alone; seeSecurity below. They are disclosed to no one. Signing out of Podee is the only thing that deletes them. Closing the tab or closing your browser does not sign you out, and nothing else removes them: if you stop using Podee without signing out, they remain in our database indefinitely. Withdrawing Podee's authorisation in your Tesla account stops them working, and stops any further vehicle data reaching us, but does not of itself delete them. To do both, withdraw the authorisation in your Tesla account and sign out of Podee.

Vehicle and location data

When you authorise Podee against your Tesla account, we receive vehicle data through the Tesla Fleet API. Depending upon the vehicle and the signals you have configured, that data comprises one or more of the following, which are currently the only signals we collect:

Each reading is stored against the vehicle identification number (VIN) of the vehicle it came from. We also record, once a day, which vehicles your Tesla account gives you access to, keeping for each of them the VIN, Tesla's own identifiers for the vehicle, and the type of access you hold. The name and colour you have given a vehicle are read from Tesla each time you open the service and shown to you, but are not stored.

Commands you send to a vehicle

Where you use the service to send a command to a vehicle — locking or unlocking it, starting climate control, sounding the horn, setting a navigation destination, and others — we record which command was sent, the vehicle it was sent to, and when. That record is what your usage is billed from, and it amounts to a history of the actions you have taken on the vehicle. We keep the name of the command only: anything accompanying it, such as a navigation destination, is passed to Tesla and is not retained by us.

Usage and technical data

The requests you make to the service, recorded in our server logs against your Tesla account identifier, together with the volume of commands and telemetry signals your account consumes. That consumption is also the measure by which charges are metered.

Each request is logged by the service with the address of the page or endpoint requested and anything appended to it, the date and time, the outcome of the request, the IP address it came from, and the browser and operating system your device reports. An IP address is personal data: it indicates your approximate location, and it links together the requests made from a single connection. We rely upon this data for the purposes of operating and securing the service set out in section 4, and it is retained as described in section 8.

Error reports

When the service fails in your browser, it sends a report of the fault to Sentry, our error tracking provider, so that we are able to diagnose and correct it. Each report contains the error and the point in our code at which it arose, the address of the page you were on, and a short trail of what immediately preceded it: the pages you moved between, the requests the service made to our servers, anything written to the browser console, and the elements you clicked. It records the browser, operating system and device you are using, and your language and time zone.

We send Sentry nothing that identifies you, your account or your vehicle. A report carries no name, no email address, no Tesla account identifier, no vehicle identification number, no location or telemetry reading, no Tesla token, no cookie and no card detail. Where any of these would otherwise appear in the address of a page or of a request, we replace it with a placeholder before the report leaves your browser. What remains is the technical detail of the fault described above.

Separately from any failure, the service tells Sentry when a page is opened, so that we may measure how often a release fails in use. That record consists of a randomly generated identifier for the page view, the time, and whether an error occurred. It identifies neither you nor your account, but it is sent on every page you open and not only when something goes wrong.

We do not record your screen. No session replay, performance tracing or profiling is enabled, and Sentry is instructed not to record the IP address a report is sent from, although that address is necessarily visible to it in the course of transmission, as it is to the recipient of any request made over the internet.

Billing data

If you set up billing, we create a customer record with Stripe using your email address and your Tesla account identifier, and we store the customer identifier Stripe returns to us along with that email address. We also keep a record of each monthly bill: the number of commands and signals it covers, the amount, and whether it was paid.

We do not collect your billing name, your billing address or your card details. Those are given directly to Stripe, on Stripe's own payment page, and are held by Stripe rather than by us. Where we show you a saved card, the brand, last four digits and expiry date are read from Stripe at the moment of display and are not stored on our servers.

Correspondence

The messages you send us through the feedback form in the service, which we store with the category you select, and the emails you send us and our replies, including any information you elect to include in them.

3. Sources of the data

Your name, email address, profile picture and Tesla account identifier are supplied to us by Tesla when you sign in, and the email address we give to Stripe is the one Tesla supplied. Correspondence comes from you directly, as do the commands you choose to send to a vehicle. Vehicle, location and telemetry data are obtained from Tesla, Inc. and its group companies through the Tesla Fleet API, and only after you have granted Podee access by means of Tesla's own authorisation process. We do not purchase personal data, and we obtain vehicle data from no other source.

You may withdraw Podee's access at any time through your Tesla account, which will prevent any further vehicle data reaching us. Withdrawal of access does not of itself delete data we have already received; as to which, seeYour rights.

4. Purposes of processing and lawful bases

PurposeData usedLawful basis
Providing the dashboard, live telemetry and fleet management features you have requestedAccount, vehicle, location, telemetryPerformance of a contract — Article 6(1)(b)
Relaying to Tesla the commands you send to a vehicle, and recording that you sent themAccount, vehicle, commandsPerformance of a contract — Article 6(1)(b)
Metering your command and signal usage and collecting paymentUsage, commands, billingPerformance of a contract — Article 6(1)(b)
Maintaining accounting and tax recordsBillingCompliance with a legal obligation — Article 6(1)(c)
Responding to your support enquiriesAccount, correspondencePerformance of a contract — Article 6(1)(b)
Maintaining the security of the service, diagnosing faults, preventing misuse, and enforcing our Acceptable Use PolicyUsage, technical, error reports, accountLegitimate interests — Article 6(1)(f)
Establishing which features are used in order to improve the product, using aggregated figures wherever these are sufficient for the purposeUsage, technicalLegitimate interests — Article 6(1)(f)
Sending service messages concerning outages, billing or changes to our termsAccountPerformance of a contract — Article 6(1)(b)
Sending marketing emails concerning new featuresAccountConsent — Article 6(1)(a), withdrawable at any time

Where we rely upon legitimate interests, we have assessed whether those interests are overridden by your rights and have limited the processing accordingly: we log only what is required in order to operate and secure the service, and product analysis is carried out on aggregated data rather than on individual journeys. You are entitled to object to any processing carried out on the basis of legitimate interests; as to which, seeYour rights.

We do not use your personal data for automated decision-making producing legal effects concerning you or similarly significantly affecting you, and we do not carry out profiling of that nature.

Where the two rows above require us to send you an email, we send it to the address held on your Tesla account, which is the only address we have for you. Service messages are sent because the Agreement provides for them — notice of an outage, of a failed payment, of a change in our charges or of a variation of our terms — and you cannot opt out of them for so long as you hold an account with us. Marketing emails are sent only where you have consented to receive them, each one carries a means of unsubscribing, and withdrawing that consent stops them without affecting anything else.

5. Individuals other than you

Where any other person drives or travels in a connected vehicle, Podee will record their journeys, notwithstanding that they hold no account with us. If you connect a vehicle that other people use, you are responsible for informing them that location and telemetry data is being collected and that it is visible to you. OurAcceptable Use Policy prohibits the use of Podee to monitor any individual without their knowledge, and we enforce that prohibition.

6. Recipients of personal data

We do not sell personal data, and we do not disclose it for the marketing purposes of any other person. We disclose it only to the following categories of recipient:

Tesla Motors Netherlands B.V. and the Tesla group
The source of vehicle data, and the company with which we hold the Fleet API Agreement under which we obtain it. Requests made on your behalf are made to Tesla under the authorisation you have granted. Tesla may use the information submitted to it through the Fleet API in accordance with its ownprivacy notice, which governs Tesla's handling of that information rather than this policy.
Google Cloud (Google Kubernetes Engine)
Operates the servers on which the service runs and stores the database, and logs the requests that reach them, including the IP address each came from. Your account, vehicle, location and billing data are held here, in Google's europe-west2 region, which is located in London, United Kingdom.
Render
Serves the Podee web application to your browser. The files it serves are the same for every visitor, and it holds no account, vehicle or location data of yours; it does, however, log the requests your browser makes for those files, including the IP address each came from.
Functional Software, Inc., trading as Sentry
Receives and stores the error reports and page-open records described under Error reports above, so that we may diagnose faults in the service. Reports are sent to Sentry's European region, and are stored there. Sentry processes them on our instructions and not for its own purposes, under a data processing addendum we have entered into with it, and we send it no vehicle, location or billing data. Sentry engages sub-processors of its own, publishes a list of them, and is required to give us notice before that list changes.
Stripe Payments Europe, Ltd.
Processes card payments and holds your card details, your billing name and your billing address, none of which reach us. We give Stripe your email address and your Tesla account identifier so that it can identify the customer record as yours, and we receive back confirmation of payment and the limited billing data identified above.
Professional advisers and authorities
Our accountants, insurers and legal advisers where necessary, and law enforcement agencies or regulators where we are under a legal obligation to disclose, or where disclosure is necessary in order to protect the life or safety of any person.

In the event that the business is sold or merged, personal data may be transferred to the acquirer. We will notify you before any such transfer occurs and before this policy is amended in consequence.

7. Transfers outside the United Kingdom

Your account, vehicle and location data are stored in the United Kingdom, in Google Cloud's europe-west2 region in London, and we access that data only from within the United Kingdom. Storing it therefore involves no transfer of it outside the United Kingdom. Google is itself established in the United States, however, and its personnel and sub-processors may reach those systems in the course of operating and supporting them. Google is certified under the EU–US Data Privacy Framework and its UK Extension, and access of that kind is made in reliance upon that certification.

Error reports are sent to Sentry's European region, and the reports themselves are stored there rather than in the United States. Sentry is nonetheless established in the United States, and in respect of any personal data transferred to it there its data processing addendum relies upon the UK Extension to the EU–US Data Privacy Framework, providing that if that framework is invalidated or ceases to apply the parties fall back upon the EU Standard Contractual Clauses as amended by the UK Addendum.

Render Services, Inc., which serves the application to your browser, is established in the United States and is certified under the EU–US Data Privacy Framework and its UK Extension. Transfers to it are made in reliance upon that certification, and its data processing addendum additionally incorporates the EU Standard Contractual Clauses as amended by the UK Addendum, upon which the parties fall back should that certification cease to apply.

Your card payments are processed under a contract with Stripe Payments Europe, Limited, which is established in Ireland. The European Economic Area is covered by UK adequacy regulations, and no separate safeguard is required for the data we pass to it. Stripe transfers that data onward to Stripe, LLC in the United States, and that onward transfer is governed by Stripe's data transfers addendum, which applies the EU Standard Contractual Clauses as amended by the UK Addendum.

Vehicle data is obtained from Tesla under its Fleet API Agreement. Because we are established outside the United States, the Tesla party to that agreement is Tesla Motors Netherlands B.V., a company established in the Netherlands. The European Economic Area is covered by UK adequacy regulations, and no separate safeguard is therefore required for the data passing between us and it. Under that agreement each of us is an independent controller of the personal data it holds, and Tesla's own handling of your data, including any transfer of it within the Tesla group, is governed by Tesla's privacy notice rather than by this policy.

Where a transfer relies upon such safeguards, you may request a copy of them by writing toprivacy@podee.app.

8. Retention

We keep your data for so long as it is necessary for the service you are using, and no longer. What Podee does is show you the state of your vehicles and the history of that state, so the history is not a by-product of the service — it is the service. We therefore retain it for so long as your account is open, and we do not expire or thin it out as it ages.

It stops being necessary when you stop using Podee. You may ask us to delete your data at any time by writing toprivacy@podee.app, and asking us to close your account has the same effect: in either case we delete what we hold within 30 days. Three things stand outside that arrangement: your Tesla tokens, which are deleted as soon as you sign out; the error reports held by Sentry, which Sentry deletes upon its own cycle; and the records we are required by law to keep. Each is identified in the table below.

DataRetention
Location and journey historyKept for so long as your account is open, since displaying that history is what the service does. Deleted within 30 days of your account being closed, or of your asking us to delete it
Other telemetry (battery level, odometer, software version)Kept for so long as your account is open, and deleted within 30 days of its closure or of your asking us to delete it
Vehicle identity (VIN, Tesla's vehicle identifiers, access type)Kept for so long as your account is open, and deleted within 30 days of its closure. A VIN appearing in a billing record is kept with that record for the period given for billing and payment records below
Account dataKept for so long as your account is open, and deleted within 30 days of its closure
Tesla access and refresh tokensDeleted when you sign out. If you do not sign out, they remain in our database until your account is closed or you ask us to delete them, although they will in time cease to work
Commands you have sent to a vehicleKept for so long as your account is open, and deleted within 30 days of its closure, save that the billed summary — the vehicle, the number of commands, the period and the amount — is retained for 6 years from the end of the relevant financial year, as required by UK tax law
Feedback you submit in the serviceKept for so long as your account is open, and deleted within 30 days of its closure
Billing and payment recordsKept for at least 6 years from the end of the relevant financial year, as UK tax law requires. We are unable to delete these at your request within that period
Server and security logsHeld until they are rotated out upon our hosting provider's own cycle. We are unable to remove individual entries from logs already written
Error reports and page-open records held by SentryDeleted by Sentry upon its own cycle, 30 days from receipt, after which they are not accessible to us
Support correspondenceKept for so long as your account is open, and deleted within 30 days of its closure
Records of Acceptable Use enforcementKept for so long as your account is open, and deleted within 30 days of its closure. Where we have suspended or closed an account for misuse we may instead keep the record, in order to identify repeated misuse and to defend legal claims

Whether your data goes because you asked us to delete it or because your account was closed, we act within 30 days and the effect is the same. Data that we are required to keep for the reasons given above is retained, and we will tell you what has been kept and why.

Separately from any request of yours, our agreement with Tesla requires us to delete the vehicle data we hold if that agreement comes to an end. Were that to happen we would delete it, whether or not you had asked us to, and the service would in any event cease to function; see clause 8 of ourTerms of Service.

9. Security

Data is encrypted in transit and at rest. Your Tesla access and refresh tokens are encrypted a second time by the service itself before being stored, under a key that is held apart from the database, with the result that a copy of the database on its own does not disclose them. Access to production systems is restricted to those members of staff who require it, is protected by multi-factor authentication, and is logged. If you believe you have identified a security vulnerability, please report it in the manner described in oursecurity.txt.

Where a personal data breach is likely to result in a risk to your rights and freedoms, we will report it to the Information Commissioner's Office within 72 hours, and where the risk is high we will notify you without undue delay.

10. Your rights

Under the UK GDPR you have the following rights:

To exercise any of these rights, write to privacy@podee.app. We will respond within one month of receipt, and no fee is payable. We may require you to verify your identity before we do so. Where a request is manifestly unfounded or excessive we may charge a reasonable fee or decline to act upon it, and in either case we will explain our reasons.

11. Complaints

If you are dissatisfied with our handling of your personal data, we ask that you raise the matter with us first atprivacy@podee.app so that we may address it. You are in any event entitled to lodge a complaint with the Information Commissioner's Office at any time:

Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Helpline: 0303 123 1113
ico.org.uk/make-a-complaint

12. Cookies

Podee uses strictly necessary cookies and local storage only. Our Cookie Policy identifies every item we set and the purpose of each.

13. Children

Podee is not intended for use by any person under the age of 18, and we do not knowingly collect personal data relating to children. As access depends upon holding a Tesla account, we carry out no separate age check of our own. If you believe that a child has signed in to Podee, please notify us and we will close the account and delete the data held under it.

14. Amendments to this policy

We amend this policy when our processing of your personal data changes. The date shown at the top of this page identifies the current version. Where an amendment materially affects you, we will notify you by email before it takes effect.