Privacy Policy
Last updated: June 7, 2026
This policy describes the current EV TrustSeal MVP privacy position. It should be kept in sync with the implementation and reviewed before production launch.
1. Who We Are
EV TrustSeal provides telemetry-backed EV battery verification reports for sellers and buyers. For account, vehicle, audit, report publication, payment-linkage, consent, and privacy-request data, EV TrustSeal acts as the controller.
This policy is written for an MVP launch focused on EU and Australian privacy expectations. It is not a substitute for legal advice, and production legal wording should be reviewed before launch.
2. Information We Collect
Account data: name, email address, hashed password, email verification status, role, referral code, and timestamps.
Vehicle and telemetry data: vehicle make, model, year, VIN, odometer, battery and charge telemetry, Enode vehicle identifiers, Enode connection status, audit sessions, audit events, report snapshots, serial numbers, and QR verification URLs.
Payment and affiliate data: Stripe checkout session IDs, Stripe payment intent IDs, amount, currency, payment status, referral code, affiliate contact details, payout records, and related timestamps.
Support and privacy request data: contact details, selected request topic, message content, request status, verification timestamps, and administrative handling metadata.
Operational data: sanitized route, error, request, consent, security, and delivery metadata needed to operate and secure the service.
3. Enode Vehicle Telemetry
Sellers connect vehicles through Enode. EV TrustSeal requests read-only vehicle telemetry for the purpose of creating battery audit sessions and verification reports.
The current product flow does not require access to control a vehicle. EV TrustSeal should not store or publish Enode raw payloads beyond what is necessary for audit integrity and operational troubleshooting.
Raw Enode snapshots and webhook payloads must be minimized, sanitized, or scrubbed under the retention rules in the GDPR plan.
4. Public Verification Reports
A report is private while it is in draft. When a seller explicitly publishes a report, the public verification page and PDF may show VIN, odometer, make, model, year, audit metrics, report timestamp, report serial number, and QR verification URL.
Published report data is intended to be shared with prospective buyers. Sellers must consent to this publication before payment and publication.
If a report is revoked or deleted, public verification and PDF access should return 404 and the report document should be removed or scrubbed from active application storage.
5. Payments And Retained Records
Payments are processed by Stripe. EV TrustSeal does not store card numbers or full card details.
EV TrustSeal may retain minimal local payment records after account deletion where required for tax, accounting, chargebacks, fraud prevention, webhook idempotency, or legal defence. These records may include amount, currency, status, Stripe session ID, Stripe payment intent ID, timestamps, and deleted report references where needed.
Retained payment records are not used for marketing, analytics, or product profiling.
6. Analytics, Cookies, And Logs
Necessary cookies and session storage are used to run the service. Google Analytics is optional and must be disabled by default until analytics consent is granted.
If Google Analytics is enabled, EV TrustSeal must not send emails, VIN, odometer, report serials, Stripe identifiers, Enode identifiers, raw report data, or user identifiers to Google Analytics. Public verification URLs must be tracked as a redacted route such as /verify/[serial].
Vercel and Sentry may process sanitized operational logs or errors. EV TrustSeal must not log VIN, odometer, email, raw Enode payloads, report snapshots, Stripe customer data, cookies, tokens, request headers, passwords, verification tokens, or secrets.
7. Vendors And Cross-Border Processing
EV TrustSeal uses service providers including Vercel for hosting, MongoDB Atlas for database storage and backups, Enode for vehicle telemetry, Stripe for payments, Resend for email, Google Analytics for optional consent-based analytics, and Sentry for optional sanitized error monitoring.
These providers may process data outside Australia or the European Union depending on their infrastructure, selected regions, support access, and backup or log handling.
EV TrustSeal remains responsible for using these providers in a way that supports privacy rights, appropriate retention, and data minimization.
8. Retention, Deletion, And Backups
Account deletion and erasure requests delete or scrub active product data, including account profile data, Enode connections, vehicle records, audit sessions, audit events, reports, report snapshots, and public verification records, except where limited records must be retained for payment, tax, chargeback, fraud prevention, or legal reasons.
Deleted data may remain temporarily in MongoDB Atlas or vendor backups until those backups expire. If a backup restore reintroduces deleted personal data, EV TrustSeal should rerun the deletion or scrubbing process.
Raw telemetry and client-error data should be minimized and scrubbed according to the retention rules in the GDPR plan.
9. Your Rights
Depending on your location and applicable law, you may request access, export, correction, deletion, restriction, or consent withdrawal for your personal information.
EV TrustSeal uses GDPR-grade rights handling as the MVP baseline while also supporting Australian Privacy Principles expectations for transparency, access, and correction.
Some records may be retained when necessary for legal, accounting, tax, security, fraud prevention, or dispute-resolution purposes.
10. Contact
Use the support form to contact EV TrustSeal about privacy requests, account deletion, correction, report publication or revocation, billing, vehicle connection issues, technical issues, or general questions.
Contact us through the support form.
