Privacy Policy
1. Data Controller
Alluring Code, LDA is the data controller responsible for processing your personal data through the TeslaSync service ("Service") at teslasync.com.
For any privacy-related inquiries or to exercise your rights, contact us at: [enable JavaScript to see email]
2. Data We Collect
We collect and process the following categories of personal data:
| Data Category | Details | Legal Basis |
|---|---|---|
| Account Data | Name, email address (from Tesla OAuth) | Contract performance |
| Authentication Tokens | Tesla OAuth access and refresh tokens (encrypted at rest) | Contract performance |
| Vehicle Data | Vehicle Identification Number (VIN), user-assigned labels | Contract performance |
| Invoice Data | Charging invoices, amounts, dates, locations, PDF documents; TeslaSync Premium subscription invoices and PDF documents | Contract performance |
| Billing Data | Stripe customer and subscription identifiers; billing notification email addresses (when you opt in) | Contract performance / Consent |
| Preferences | Email notification settings, charging-invoice and billing recipient email addresses, email frequency | Consent |
| Usage Data | IP address, user agent, event logs for security and diagnostics | Legitimate interest |
3. How We Use Your Data
Your personal data is processed for the following purposes:
- Service delivery — retrieving, storing, and delivering your Tesla charging invoices and TeslaSync subscription invoices
- Authentication — verifying your identity through Tesla's OAuth system
- Billing — processing Premium subscriptions and issuing subscription invoices via Stripe
- Notifications — sending email alerts for new charging invoices and billing emails (only when you opt in)
- Security — detecting and preventing unauthorized access, fraud, and abuse
- Service improvement — analyzing anonymized usage patterns to improve reliability
4. Data Storage and Security
Your data is stored on servers located in Germany (EU), hosted by Hetzner Online GmbH. All data processing occurs within the European Economic Area (EEA).
We implement the following security measures:
- Tesla OAuth tokens are encrypted at rest using Fernet symmetric encryption
- All communications are encrypted in transit via TLS/HTTPS
- Database access is restricted to the application service
- We do not store your Tesla password — only OAuth tokens issued by Tesla
5. Data Retention
We retain your data for the following periods:
- Account and invoice data — retained while your account is active; deleted within 30 days of account deletion or disconnection request
- Authentication tokens — deleted immediately upon Tesla account disconnection
- Usage/security logs — retained for up to 90 days for security and diagnostic purposes
- Contact form submissions — retained for up to 12 months or until the inquiry is resolved
6. Third-Party Data Sharing
We do not sell your personal data. Your data may be shared with the following categories of third parties, solely for service operation:
- Tesla, Inc. — API calls to retrieve your invoice data (governed by Tesla's privacy policy)
- Stripe, Inc. — payment processing for Premium subscriptions; Stripe receives billing identifiers and payment details you provide at checkout (governed by Stripe's privacy policy)
- Email delivery providers — to send charging-invoice and billing notification emails (e.g., Resend); only recipient email addresses and email content are shared
- Infrastructure providers — Hetzner Online GmbH (hosting), Cloudflare (DNS and CDN); these providers process data under their own GDPR-compliant terms
- Umami Analytics — privacy-focused, cookie-free web analytics; no personal data or IP addresses are collected or shared
We do not sell personal data. Sub-processors operate under GDPR-compliant data processing agreements. Where a payment provider processes data outside the EEA, transfers rely on appropriate safeguards (such as Standard Contractual Clauses).
7. Cookies and Tracking
TeslaSync uses only strictly necessary cookies required for the service to function:
- Session cookie (
sessionid) — maintains your login session - CSRF token (
csrftoken) — protects against cross-site request forgery
For website analytics, we use Umami Analytics, a privacy-focused, cookie-free analytics tool. Umami does not use cookies, does not collect personal data, and does not track users across sites. All data is aggregated and no individual visitor profiles are created. Umami is fully GDPR compliant and does not require cookie consent. Learn more at umami.is/privacy.
We do not use advertising cookies or any other third-party tracking technologies.
8. Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights:
- Right of access (Art. 15) — obtain a copy of all personal data we hold about you
- Right to rectification (Art. 16) — correct inaccurate or incomplete personal data
- Right to erasure (Art. 17) — request deletion of your personal data ("right to be forgotten")
- Right to restriction (Art. 18) — restrict the processing of your personal data
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time for consent-based processing
To exercise any of these rights, contact us at [enable JavaScript to see email]. We will respond within 30 days as required by law.
You can also exercise some rights directly through the Service: disconnect your Tesla account (deletes tokens), disable email notifications, or request data export via CSV.
9. Data Protection Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Portuguese data protection authority:
Comissao Nacional de Protecao de Dados (CNPD)
Av. D. Carlos I, 134 - 1.º
1200-651 Lisboa, Portugal
Website: www.cnpd.pt
10. Children's Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated through the Service. The "last updated" date at the top indicates the most recent revision.
12. Contact
For privacy inquiries, data access requests, or to exercise your GDPR rights:
Alluring Code, LDA
Email: [enable JavaScript to see email]
Or use our contact form