Privacy Policy
Effective Date: August 14, 2026 · Version 2.4
ChargePeer, Inc. ("ChargePeer", "we", "us", or "our") is dedicated to safeguarding your privacy and protecting the personal data of all users of our peer-to-peer charging marketplace ("Platform", "Service"). This Privacy Policy explains our practices regarding the collection, use, disclosure, transfer, and retention of personal data, and outlines your rights under the General Data Protection Regulation (EU/UK GDPR), California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and applicable international privacy legislation.
1. Data Controller & Data Protection Officer
For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679) and UK GDPR, the Data Controller responsible for your personal data is ChargePeer, Inc. We have appointed a dedicated Data Protection Officer (DPO) to oversee privacy compliance, data protection impact assessments, and supervisory authority communications. You may contact our DPO directly at [email protected] or reach our Privacy Team at [email protected].
2. Categories of Data We Collect
We collect only the personal information necessary to deliver, secure, and optimize our peer-to-peer charging services:
• Account & Identification Data: Full name, verified email address, phone number, encrypted password credentials, public handle, and two-factor authentication (TOTP) status.
• Identity Verification & KYC Records: Government-issued identification, driver's license details, vehicle registration, and proof of address where required for high-volume Provider listings or regulatory compliance.
• Geolocation Data: Precise geospatial coordinates (GPS/latitude/longitude) collected exclusively when searching for nearby chargers, navigating to a booked station, or verifying physical proximity via NFC/BLE handshake.
• Charging Telemetry & Session Records: Real-time voltage, current (kW), total delivered energy (kWh), state of charge (SoC), charging duration, start/end timestamps, and station connector types.
• Financial & Transaction Data: Billing address, payment card tokens (processed securely via PCI-DSS Level 1 payment processors; ChargePeer does not store full credit card numbers), transaction history, VSC credit ledger records, and payout bank routing identifiers.
• Technical & Telemetry Data: IP address, browser user-agent, operating system, device hardware identifiers, crash logs, and session interaction timestamps.
3. Lawful Bases for Processing (GDPR Article 6)
We process your personal data under the following legal bases:
• Performance of a Contract (Art. 6(1)(b)): To establish your account, route charging reservations, process escrow payments, facilitate host-driver communication, and deliver core marketplace services.
• Legitimate Interests (Art. 6(1)(f)): To prevent fraudulent bookings, detect security intrusions, verify charging session telemetry, resolve billing disputes, and improve platform performance.
• Compliance with Legal Obligations (Art. 6(1)(c)): To comply with tax, statutory accounting, financial reporting, and anti-money laundering (AML) regulations.
• Consent (Art. 6(1)(a)): For precise background location tracking and optional marketing communications. You may withdraw consent at any time via device settings or account preferences.
4. How We Use and Protect Location Data
Precise location data is sensitive. We enforce strict minimization: Seekers' real-time locations are never publicly broadcast. During an active booking, approximate distance and ETA coordinates are shared solely with the matched Provider for arrival coordination. Station Providers' fixed charger locations are displayed on the public radar map only when their station listing is set to active. Location history is decoupled from user profile records after session billing finalization.
5. Data Sharing & Sub-Processors
We do not sell, rent, or monetize your personal information to third-party data brokers. We share data only with authorized sub-processors bound by strict Data Processing Agreements (DPAs):
• Payment Gateways & Banking Partners: Stripe, Inc. (PCI-DSS compliant payment processing and merchant payouts).
• Cloud Infrastructure & Hosting: Encrypted European and US datacenter providers for API compute and database storage.
• Mapping & Geocoding Providers: OpenStreetMap / Carto for tile rendering (only coordinate bounding boxes are transmitted; no personal IDs).
• Transactional Communications: Encrypted email delivery workers for 2FA codes, booking confirmations, and security alerts.
• Law Enforcement & Regulatory Authorities: Only when strictly required by enforceable subpoena, court order, or applicable statutory mandate.
6. International Data Transfers & Safeguards
When personal data originating in the European Economic Area (EEA), United Kingdom, or Switzerland is transferred to servers outside these regions, ChargePeer ensures an adequate level of protection by implementing European Commission Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs), and robust technical safeguards including end-to-end transport encryption (TLS 1.3) and AES-256 storage encryption.
7. Data Retention & Erasure Schedules
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected:
• Active Account Data: Retained for the lifetime of your active account.
• Financial & Tax Records: Retained for seven (7) years following the transaction date to satisfy statutory tax, audit, and commercial accounting obligations.
• Charging Session Telemetry: Retained in granular format for ninety (90) days for dispute mediation and fraud detection, after which data is aggregated or permanently anonymized.
• Authentication & Security Logs: Retained for thirty (30) days for intrusion detection and system integrity auditing.
8. Your Rights Under GDPR & CCPA/CPRA
Depending on your residency, you possess statutory rights regarding your personal information:
• Right of Access (Art. 15 GDPR): Request a copy of all personal data we hold about you.
• Right to Rectification (Art. 16 GDPR): Correct inaccurate, incomplete, or outdated information.
• Right to Erasure ("Right to be Forgotten", Art. 17 GDPR): Request permanent deletion of your personal data, subject to legal retention exemptions.
• Right to Restriction of Processing (Art. 18 GDPR): Limit how we process your data in specific circumstances.
• Right to Data Portability (Art. 20 GDPR): Export your structured account and transaction data in machine-readable JSON/CSV format.
• Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests.
• CCPA/CPRA Rights: California residents have the right to know what personal information is collected, request deletion, correct inaccurate data, opt-out of cross-context behavioral advertising, and receive non-discriminatory service.
To exercise any of these rights, email [email protected]. We respond to all verified requests within thirty (30) calendar days without charge.
9. Security Architecture & Incident Response
ChargePeer implements industry-standard technical and organizational measures (TOMs) including zero-trust access controls, mandatory multi-factor authentication for administrative access, role-based database permissions, continuous automated vulnerability scanning, and cryptographic hashing (Argon2id/bcrypt) for credential storage. In the event of a confirmed security breach affecting personal data, ChargePeer will notify relevant supervisory authorities and affected users within seventy-two (72) hours in accordance with Articles 33 and 34 of the GDPR.
10. Cookies, Local Storage & Tracking Preferences
ChargePeer utilizes essential local storage tokens and first-party session cookies strictly required for user authentication, security verification, theme preferences, and localized language rendering. We do not deploy third-party cross-site advertising trackers or invasive tracking cookies. You may configure your browser to reject cookies, though certain authenticated features of the Platform may become unavailable.
11. Children's Privacy
The Platform is strictly intended for individuals aged eighteen (18) and older. ChargePeer does not knowingly collect, solicit, or process personal information from children under sixteen (16) years of age. If we discover that personal data of a minor has been collected without verifiable parental consent, we will promptly delete the data from our active systems.
12. Changes to this Policy & Supervisory Complaints
We may update this Privacy Policy periodically to reflect technological advancements, operational changes, or new regulatory mandates. When modifications are made, we will update the Effective Date at the top of this page and provide prominent in-app notification for material revisions.
If you are located in the European Union or United Kingdom and believe our processing of your personal data infringes applicable data protection law, you have the right to lodge a formal complaint with your local Data Protection Supervisory Authority (such as the CNIL in France, the DPC in Ireland, the ICO in the United Kingdom, or the CNPD in Portugal).
13. Privacy Contact Information
For all privacy inquiries, data subject access requests, or compliance notices, please contact:
ChargePeer Privacy & Data Governance Office
Email: [email protected]
Data Protection Officer: [email protected]