Privacy Policy
Last updated: 19 August 2026
This is a translation. Only the German version is legally binding: the controller is a German company and the German text is the one that has been legally reviewed. If the two versions differ, the German version prevails.
This policy applies to the website chargereport.app and to the ChargeReport app for iPhone and iPad. Wherever the two differ, we say so explicitly — above all in sections 7 and 9.
1. Controller
The controller for the processing of personal data within the meaning of the General Data Protection Regulation is:
Star Media GmbH
Nottebohmweg 18
59494 Soest
Germany
Managing directors: Dieter Bleicher, Jens Twesmann
Commercial register: Amtsgericht Arnsberg (Arnsberg local court), HRB 6247
VAT identification number: DE215474212
Email: info@chargereport.app
For questions about data protection and to exercise your rights: datenschutz@chargereport.app
2. What this service does
ChargeReport reads the charging sessions from the wallbox at your home and turns them into a monthly record. We send that record to your employer on your behalf, so that they can reimburse you tax-free for the electricity you used to charge your company car.
Passing on that data is the whole point of the service, not a side effect. It is described separately and in full in section 5. Please read that section before you enter an employer address.
3. Principles
We collect personal data where it is needed to run the service. Some of it is mandatory, because without it no record can be produced; the rest is voluntary. Which details are voluntary is stated with each type of data in section 4.
4. What data we process
4.1 Account and master data
| Data | Purpose | Mandatory? |
|---|---|---|
| First and last name | Name of the person the monthly report is issued for; customer name at our payment provider | Mandatory — without a name no report is produced |
| Email address | Sign-in, delivery of our messages, customer identifier at our payment provider | Mandatory |
| Password | Sign-in. Managed by our sign-in service and never available to us in plain text | Mandatory |
| Vehicle registration number | Appears in the report PDF, in the subject line and in the file name of the email to your employer, and in the declaration of conformity | Mandatory — without a registration number no report is produced |
| Address: street, house number, postcode, town, country | Header of the report — it shows where the wallbox is installed; otherwise used as the billing address at our payment provider | Voluntary; we do remind you if it is missing. Country is pre-set to "DE" |
| Language | Language of the report, of our emails and of your invoices | Pre-set |
| Your employer's email address | Recipient of the monthly report — see section 5 | Required for sending; without it we still produce the report but do not send it |
| Copy address (CC) | Second recipient of the same report email. Who you enter here is up to you — a second HR contact, your tax adviser or your leasing company, for example | Voluntary |
| IBAN, BIC, name of your bank | Appear in the report PDF so that your employer can transfer the reimbursement to you | Voluntary — see the paragraph below |
| Reimbursement model and price per kWh, optionally with a validity period | Calculation of the reimbursement amount | Pre-set (flat rate); your own price only if you want one |
| Reporting interval, automatic sending | Controls the period covered and whether the report goes out without further action from you | Pre-set |
| Account type and membership of an employer account | Controls whether the report goes to a stored address or becomes visible inside your employer's account | Set by the system |
| Additional drivers using the same wallbox — per driver: name, registration number, employer address, copy address, IBAN, BIC, bank, own price per kWh, charging card ID | Separate reports per driver | Voluntary |
| Phone number for support | Technical questions about connecting your wallbox — we only get in touch when the setup is stuck. Not for marketing, not for billing, not for signing in. We call; we write on WhatsApp only if you have additionally allowed it — see the next row and section 4.8 | optional — deletable in your account at any time |
| Consent to WhatsApp, together with the time it was given and whether you set it yourself or we entered it after speaking with you | Allows us to write to you on WhatsApp about support questions. We record time and origin because we must be able to demonstrate a consent | optional — the box is never pre-ticked and can be unticked at any time; without a phone number it does not appear |
Signing in works with your email address and a password. We do not offer sign-in via an account with another provider.
Your bank details are voluntary — and in most cases unnecessary. The field is meant for employers who transfer the reimbursement to you separately. If it runs through payroll, and that is the normal case, your employer already knows your account: then leave the field empty. Without bank details your record is produced exactly the same way and goes to your employer exactly the same way — the PDF is simply missing that one line. Inside an employer account the field does not exist at all.
Checking the IBAN. We calculate the check digits of your IBAN ourselves (ISO 7064, mod 97) — the same calculation your bank performs. Your account number does not leave our systems in the process. Until 14 August 2026 it was sent to the external service openIBAN to determine the BIC and the bank name; we have stopped doing that. Since then you enter the BIC and the bank name yourself, if you want them shown in the report — neither is required for a SEPA transfer within the EU.
4.2 Billing
For a paid subscription we process your billing address, where applicable your company name and VAT identification number, the status of your subscription, the invoices themselves and your payment history.
The history of your subscription. For every change — sign-up, activation, failed payment, resumption, cancellation — we keep one line: the type of change, the point in time, the monthly fee and the identifiers under which your subscription and your customer record are held at our payment provider. We evaluate this in aggregate to see how many customers stay and how many leave. It has no effect on your billing.
Your payment details themselves — card number and the like — are entered directly at our payment provider. They pass by our servers and are not stored by us.
4.3 Wallbox connection and charging data
Access credentials for your wallbox or for the manufacturer's cloud. Depending on the manufacturer these are: the email address and password of your manufacturer account, an API key, a serial number with a token, or an OAuth token. For self-connected wallboxes (OCPP) and for Shelly push mode we generate a connection token instead.
How we protect them. Your access credentials are not held in plain text in our database. We encrypt them before storing them, using AES-256-GCM. The key for this is not in the database but kept separately, in the environment of our server. Anyone reading the database could do nothing with these fields.
Details about your wallbox: manufacturer and type of connection, device or system ID, name and brand. For self-connected wallboxes additionally whatever the device reports about itself: manufacturer, model, serial number, firmware version, protocol version, operating state and the time of the last message.
Charging sessions. For each charge: the time the plug went in, the end of the charging session, the energy charged in kilowatt hours, the billing month and the source of the measurement (from the manufacturer's cloud, via the charging protocol, from a sub-meter, or entered by you by hand). If your wallbox reports a charging card, its ID as well — it serves to tell several drivers at the same wallbox apart. The charging card ID does not appear in the report to your employer.
Measurement samples. Where a wallbox does not deliver charging sessions itself, we reconstruct them from measured values: for a Shelly sub-meter from timestamp, instantaneous power and meter reading; for GoodWe from meter reading, power, state of charge, details of the last charge and the number of the charging card used for it. When polling the manufacturer's cloud we fetch one measured value every five minutes, so up to 288 samples per device per day. If the device reports to our gateway of its own accord, we store at most one sample per minute, so up to 1,440 samples per device per day. For OCPP charges we store meter readings at start and stop, the start and stop times, the stop reason, the connector and the manufacturer's transaction ID.
Charging cards marked as private. You can mark a charging card as private — the card for your second car, for example. For this we store the ID of the card and a name you choose yourself. Every charge made with that card is then automatically taken out of the billing, retroactively as well for those charges that are not yet in any report. This list is maintained by you alone.
Excluding individual charges. When a charge is removed from the report, we store the time, the reason, who excluded it and any note. Charges can be excluded by:
- You yourself — with one click in the list of your charges, or by classifying a charge as private in the confirmation form.
- An automatic check, if the charge belongs to a charging card you have marked as private.
- Your employer, if you take part through their account: an administrator of the employer account can strike out a single charge. They have to state a reason for doing so; we record who it was and when. This reduces your reimbursement amount — you can see the exclusion together with its reason and time in your own view.
What your employer cannot do: they cannot undo an exclusion that you brought about — neither your own click, nor a charge from your private card, nor a charge you classified as private. The system explicitly refuses them in all three cases. A charge you have declared private cannot be pulled back into your billing by anybody else.
Connection status. The time and result of the last poll, error messages, the number of charges delivered. This serves to detect faults.
Requests about unsupported wallboxes. If you report a model we do not yet connect to: email address, brand, model, whether a manufacturer app exists, its name and your comment. The request is stored and at the same time sent to our operations mailbox — see section 8.5.
4.4 Confirming charges, odometer reading and odometer photo
This processing only takes place if you switch it on or if your employer requires it for their account.
These two cases are not the same thing, and the difference matters to you. If you switch confirmation on yourself, you can switch it off again at any time, and charges without confirmation are billed as normal. If, on the other hand, your employer requires it, it is their account setting — you cannot switch it off, and unconfirmed charges are then not included in the reimbursement. The confirmation requirement and the odometer reading can be switched separately; your employer can therefore require confirmation and do without the odometer reading. Why we are allowed to do this for them is explained in section 5.4 and in the table in section 12.
If it is switched on, we process:
- Your classification of each charge: business or expressly private. Charges classified as private are removed from the billing immediately and we record the reason.
- The time of confirmation and the time at which we asked.
- The vehicle's odometer reading in whole kilometres — as evidence and as a cross-check: from two readings and the energy in between we work out a consumption per 100 km. Your odometer reading does not appear in any report: neither the monthly PDF nor the combined PDF nor the payroll export contains it. If you switch confirmation on yourself, it therefore stays with us — your employer does not get to see it. If you take part through an employer account, they do see it in the charge view of their account; that is described in section 5.2.
- A "confirmed despite warning" flag, if you expressly confirm a reading that we have flagged as implausible.
- Derived analyses: consumption per 100 km, indications of "charged without driving", meters running backwards, or jumps in mileage. We do not store these values but recalculate them each time they are requested. They lead to no automatic reduction of your reimbursement.
- A photo of your odometer — expressly voluntary. Confirmation works without it. Image files up to 10 MB in JPEG, PNG or WebP format.
Three things about the photo you should know.
What happens to it on your device. Before the photo leaves your device, we re-encode it. In doing so the extra information your camera writes into the file is lost — among other things the time the picture was taken and, if your device records it, the place it was taken. Only the image itself reaches us.
Who can see it. The image is stored in a non-public area. It can be retrieved by you and — if you take part through an employer account — by the administrators of that account, via a link that is valid for only a few minutes. Nobody else: for all other access the area is locked. If you take part without an employer account, only you can see the image.
If you change your mind. If you select a photo and then do not send the confirmation after all, we remove the image at the latest when the access link expires.
The request itself. We create an access link containing a random value, valid for 30 days, which leads to the confirmation form without signing in. We send it by email and, if you have allowed it, additionally as a notification to your device. The message contains the date, the number of charges and the total kilowatt hours.
Treat this link like a password and do not pass it on — whoever has it can see and confirm that day's charges without signing in.
4.5 Data in an employer account (business customers)
If you use ChargeReport through an account belonging to your employer, we additionally process:
- Employee number and assignment to one of your employer's companies — both are maintained by your employer, not by you. Their purpose is the assignment in the payroll run.
- Your employer's company master data: name, legal name, address, VAT ID, adviser and client number of their tax adviser, wage type.
- Invitation and membership data: email address, role, status, the time of the invitation and of its acceptance, plus an invitation token with an expiry date.
4.6 Technical data and logs
Errors in your browser. If an error occurs in your browser, we automatically transmit: the error message (up to 2,000 characters), the call stack with file and line details (up to 8,000 characters), the address of the page on which the error occurred, your browser including its version and your operating system, the file name, line and column of the script that triggered it, and — for one particular type of error — the page you visited before. If you are signed in, your user ID is attached to it. If the page address contains an access value, we shorten it before logging it.
Not logged are calls from development machines, the contentless browser placeholder message "Script error." and two known third-party script signatures.
Errors on our servers and during the regular polls are logged as well, where applicable with your user ID and the ID of your wallbox. Each entry also carries a field for the context in which the error occurred. What is in it depends on the place that reports the error — today you will find there, among other things, the ID of your device and of your wallbox connection, the name you have given your wallbox, and the identifiers under which your customer record and your invoice are held at our payment provider.
When a self-connected wallbox establishes a connection, our gateway writes a log line with the IP address of your internet connection, the identifier of the connecting device (user agent) and the first eight characters of the connection token.
And it keeps writing afterwards. For as long as your wallbox is connected, the same log output records:
- the name you have given your wallbox — it appears in practically every line
- what the device reports about itself when it registers: manufacturer, model and — on devices using the newer protocol version — the firmware version
- for every start of charging the connector, the meter reading and the ID of the charging card used, in plain text; on devices using the newer protocol version the card ID also appears with every authorization request
- for every end of charging the transaction number and the meter reading
- with some wallboxes — Sungrow ones, for example — a suffix on the connection address which the device itself enters there and which as a rule is its serial number
These lines are not written into our database; they are held in the log output at the operator of our gateway (section 8.1). They serve to track down faults — without them there would be no way to establish why a wallbox is not delivering any charges. How long they stay there is stated in section 10.
To be distinguished from this is the wallbox's initial registration: what the device reports there about itself — manufacturer, model, serial number and firmware version — is also stored permanently in our database for devices using OCPP 2.0.1. That is described in section 4.3 as part of the wallbox details.
So that no misunderstanding arises in the first place: section 5.1 says that the ID of your charging card is not transmitted to your employer. That remains true — it is in no report. It does end up in this technical log all the same; it does not go out to anyone, but we are not keeping quiet about it.
IP address for abuse prevention. At one endpoint we limit the number of requests per IP address. For this purpose the address remains only briefly in memory; we do not store it for that.
Logs kept by our service providers. That does not mean your IP address is recorded nowhere. The companies that run our servers and our database keep their own access logs — those contain, for every request, the IP address, the identifier of your browser and the address called up; at the gateway the IP address of your home connection. This is technically unavoidable: without a sender address no server can answer. These logs arise at the providers, not at us; we only look at them to track down faults and to fend off attacks. How long they are kept there is stated in section 10. The same applies to the delivery of static files — images, fonts, the program code of the page — which runs over our host's worldwide delivery network; no account or charging data arises in the process.
Sign-in sessions. Independently of this, our sign-in service stores, for each signed-in session, the IP address and the browser identifier (user agent) with which it was opened. This is part of the sign-in library we use and serves the security of your account — it would allow someone signing in from an unfamiliar device to be spotted. A session ends when you sign out, when you have not used it for 30 days, and at the latest 180 days after signing in. When the session ends, the line including the IP address and browser identifier is deleted.
Log of our emails. Of the emails our system sends automatically, we store the recipient address, subject, type, time, success or failure, and the full text of the message. This concerns the monthly report, the query about a charge, invoices, invitations to an employer account, payroll files, reminders, fault notifications and offers. It serves traceability in support: the most common question there is not whether we wrote, but what it said. This log therefore also contains the contents of the report, confirmation and invitation emails. For how long is stated in section 10.
Two clarifications on this. First: when a password is reset, we remove the link before we log the message — a valid access link has no business being in a database. Second: not every message is in this log. Not included are, among others, the welcome email after registration, a message written to you by hand by us or a reply to your support request (whose text is instead held where section 4.8 describes it), notices concerning your subscription, and the message to an employer's shared mailbox.
4.7 Feedback when an account is deleted
If you delete your account, we ask voluntarily for the reason and offer a free-text field. We store the reason, the comment, your plan, the age of the account and whether a subscription existed. The link to you as a person disappears when your account is deleted.
4.8 Support and messages between you and us
Support cases. If you write to us via the support form in the dashboard, we store the case with subject, processing status, the time it was created and the times of the most recent reply from you and from us. For every case we store every single message: the full text, whether it came from you or from us, who wrote it and when.
Every new request and every reply of yours additionally goes as an email to our operations mailbox — with your name, your email address and the full text. See section 8.5.
Messages from us to you. If we write to you from the admin area — with a reply or an offer, for example — we store the subject and text of the message as well as who sent it.
WhatsApp — only with a phone number and explicit consent. Both are needed. A stored phone number alone allows us to call, not to write; the box for that is a separate one, it is never pre-ticked, and without a phone number it does not appear at all.
If you have set both, the conversation with you is mirrored into your customer file: the text and attachments of every message, its direction and the time. The reason is the same as for the email log — the most common question in support is not whether we wrote, but what it said.
Only the conversation with you is mirrored. The connection technically attaches to the entire support phone, so our boundary takes effect when saving. Anything that does not belong to an account with a stored number and a given consent is discarded — without the number, the name or the content being recorded anywhere.
You can withdraw your consent at any time — with the same box in your account that you used to give it. After that no new conversation is created. A conversation already mirrored stays in your file until the period in section 10 has expired or you delete your account.
What WhatsApp itself sees. WhatsApp is a Meta service. As with every message you write there, it passes through their systems — the mirroring changes nothing about that, and we have no influence over it. If you would rather not, you can still reach us by email and through the support form.
4.9 Internal classifications and notes on your account
For operational purposes we keep a few notes on your account that you cannot see yourself:
- Classification of your account: what phase of use it is in, how many charges have accrued since your last report, when your last charge was, how many reports there have been so far, and when this classification was last calculated. It serves to spot accounts where something is stuck.
- Which reminder emails you have already received — per stage with a timestamp, so that the same reminder does not arrive twice.
- Acknowledged plausibility findings: if we have examined a finding about your charging data and ticked it off as harmless, we store the area, the reference, the value it was based on, a note and the time.
- Connection attempts with Sungrow: for every attempt via the Sungrow sign-in route we store the beginning of the return code, whether the protection value was present and valid, which endpoints were tried in which order, which of them answered, how many systems were shared, the result with its reason, and the connection that resulted. This serves to track down faults in a connection route that experience shows often fails.
- Rejected connection attempts from your wallbox: If your wallbox contacts our charge point server using an address that belongs to no connection, or to one that has since been replaced, we record the address part it presented, the path it addressed, your wallbox's device identifier, the reason for rejection and a counter — aggregated per hour. Without IP address. For a wallbox that never reports in, this is the only way to establish whether it reaches us at all or whether nothing arrives.
None of these classifications leads to an automated decision about you within the meaning of Article 22 GDPR.
5. Disclosure to your employer
This is the purpose of the service. Please read this section in full.
5.1 What is transmitted
Once you have entered an employer address and approved sending once, we send an email to that address at the end of every reporting period — and, if you have entered a copy address, to that one as well. The monthly record is attached to the email as a PDF.
The PDF contains:
- your name
- your address with street, postcode and town, insofar as you have entered it
- your vehicle registration number
- the name of your wallbox. If we retrieve your charging data via the manufacturer's cloud, we also state the device number under which your manufacturer lists the box. If your wallbox connects directly to us, the report contains only the name — the identifier of that connection is an access secret and does not belong in a document that leaves the house
- your IBAN, BIC and the name of your bank — only if you have entered them, and you only need them if your employer transfers the reimbursement separately. If they settle it through payroll (the normal case), leave the field empty and the line appears nowhere. If your account belongs to an employer account, this drops away entirely: there your bank details are in no report, and we do not even ask for them.
- every single charging session with a sequential number, date, start of charging, end of charging and kilowatt hours
- a marking of the lines you have entered by hand
- the reimbursement rate, and where a tariff changed, the rate per charging session as well
- total consumption and reimbursement amount
The subject line of the email and the file name of the attachment additionally contain your vehicle registration number. The text of the email states the period, the total consumption and the reimbursement amount.
Not in the PDF and not in the email are: the ID of your charging card, your odometer reading and your odometer photo, your password, your wallbox access credentials and the access identifier of a directly connected wallbox.
The odometer reading deserves a sentence of its own here, because it is the question asked most often: it appears in no report — not in the monthly PDF, not in the combined PDF and not in the payroll export. If you take part without an employer account and have switched confirmation on yourself, nobody but you sees it. If you take part through an account belonging to your employer, it is different — then it appears in the charge view of their account; see the next section.
5.2 If you take part through an account belonging to your employer
Then your employer additionally sees, inside their own account, for each charge: the time, duration, kilowatt hours, name of the wallbox, the odometer reading you reported, the "confirmed despite warning" flag, the plausibility findings, and the time, reason and note of an exclusion. Plus your name, your employee number and the company you are assigned to. The ID of your charging card is not included in this view.
If your employer requests a combined PDF, it contains a cover sheet with the name, registration number, kilowatt hours and amount per employee, and behind that, for each employee, a detail page with the address, wallbox name and all individual charges. Your bank details do not appear there — nor in any other report your company receives. In employer accounts the reimbursement runs through payroll; for that your company does not need your account details, it knows your salary account.
Two email addresses that your employer sets themselves. It does not in every case stay within their account:
- If an administrator has a report generated after the fact, an email goes to the report address the employer has stored. It contains your name, the period, your consumption and a link from which the report PDF can be downloaded.
- Invoices for the subscription go to a separate billing address, likewise set by the employer.
Both addresses can point to shared mailboxes read by more people than the account itself — who reads along there is decided by your employer, not by us.
5.3 Disclosure to your employer's payroll department
If your employer has switched on payroll file sending, we send files monthly to the address they specify — that may be their payroll department or their tax adviser. These files contain, per employee: employee number, name, company, period, kilowatt hours, price per kilowatt hour, amount, wage type and an indication of whether the line is based on a finished report or on a provisional calculation. At the employer's request additionally as a DATEV import file with adviser and client number.
If confirmation is switched on, only charges confirmed as business are included in the payroll export.
5.4 Your employer is a controller in their own right
Once the report has arrived at your employer, they process your data under their own responsibility and according to their own rules. For access, rectification, erasure or objection regarding the data stored there, please contact your employer.
If your employer runs an account of their own with us and sets in it whether you have to confirm charges and report an odometer reading, then we process these details for them and on their instructions. For that too, they are the controller.
5.5 How you control the disclosure
What options you have depends on whose account you are using. Please read the block that applies to you — the two cases differ considerably.
If you are our customer yourself (you signed up and enter your employer's address yourself):
- Before the first send to a newly entered employer address, we show you what goes to whom and ask for your approval. Without that approval no report leaves the house.
- Without a stored employer address we do not send any report. It is then only produced and filed for you in your account.
- You can change or delete the employer address and the copy address in your profile at any time.
- You can switch off automatic sending.
- You can exclude individual charges from the report.
- You can delete your bank details in your profile at any time; future reports then no longer contain them. If you have set up additional drivers at your wallbox with bank details of their own, delete those details where you entered them, in the drivers area. The profile field stands for you yourself, not for the others.
If you take part through your employer's account (you joined via an invitation):
Then the first four points above are not yours. There is no employer address entered by you that you could change or delete; sending is decided by the administrator of the account; and your charging data is directly visible to them in their account anyway, without any email being needed for it. What remains to you is:
- You can exclude individual charges from the report — that applies to every signed-in user, you included. And what you have declared private cannot be reversed by an administrator (section 4.3).
- You can delete your bank details in your profile at any time, with the same effect as above. In an employer account this field does not exist.
- Confirmation and odometer reading cannot be opted out of if your employer requires them — this is explained in section 4.4.
For everything beyond that — which addresses are stored, who reads along in the account, how long your employer keeps the reports — they are the controller (section 5.4). Only you and they can settle those questions between you; we have no say in them.
6. Your charging data is not marketing material
We use your charging data, your odometer reading, your bank details and the content of your reports exclusively to produce and deliver the record and to run the service. We do not sell them, do not pass them on for advertising purposes and do not evaluate them to build profiles. We hand the measurement tools named in section 9 no charging data, no odometer reading and no bank details.
Pages reached via an access link are excluded from measurement. Some of our links take you to a page without signing in — the query about a charge, an invitation from your employer, the reset of your password. The address of those pages contains an access value. On precisely those pages we do not load the tools named in section 9; they therefore never get to see the address of those pages.
7. The app for iPhone and iPad
The app is a native shell around the same application you also use in the browser. Everything stated above applies to it, with the following particularities.
7.1 Notifications and device identifiers
As soon as the app starts, your device registers with Apple's notification service; Apple issues a device token in the process. This happens without being asked and regardless of whether you later allow notifications — the operating system requires no consent for this registration. We do not evaluate this token. The built-in Google component stays silent until then: an installation ID and a Firebase token only come into being at the moment you expressly allow notifications.
If you allow notifications, we store:
- the identifier with which we address your device — in the app a Firebase token, in the browser an endpoint address with two encryption keys
- the type of subscription (app or browser)
- the browser or the device identifier
- the time it was set up and the time of the last successful delivery
Delivery to the app runs via Google Firebase Cloud Messaging. Firebase receives the token, the title and text of the message and a data field with the destination inside the app. Specifically: for the monthly report the period and kilowatt hours, for the confirmation query the date, number of charges and kilowatt hours. No access value is transmitted in the process — the notification takes you into your signed-in view. On iPhone and iPad, Firebase then passes the message on to your device via Apple's notification service; Apple is therefore a recipient as well.
Delivery to the browser runs via the push service of your browser maker (depending on the browser, Apple, Google or Mozilla). That service receives the encrypted message at the address it issued.
Notifications are voluntary. You can switch them off in your device settings at any time; subscriptions that can no longer be reached are deleted by us automatically.
7.2 Camera and photo library
The app requests access to the camera and the photo library. The access serves one purpose only: the voluntary photo of your odometer reading in the confirmation form. The app does not read your photo library and does not access any image you have not selected or taken yourself.
The request only appears when you tap "Photograph odometer" in the confirmation form. If you decline it, confirmation still works — just without a photo.
7.3 What does not happen in the app — and what does
No advertising and no analytics tools run in the app. Neither Google Ads nor LinkedIn nor Plausible is loaded there. That is why no consent banner appears in the app — there would be nothing to consent to.
This is solved on the server side and not by a script in the browser: requests from the app are recognised at the server, and the scripts in question are not delivered in the first place.
Also not in the app: prices, registration and payment routes.
What very much does happen in the app. The app contains Google components for delivering the notifications (Firebase Cloud Messaging and the basic components belonging to it). They are loaded from the start but only contact Google once you have allowed notifications. The analytics function of Firebase (Firebase Analytics) is switched off and not even included in the app. The statement "no tools of this kind run in the app" applies to advertising and audience measurement, not to the delivery components.
7.4 Cookies in the app
In the app only technically necessary cookies are set: one for your sign-in and one for the language you have chosen. Advertising and analytics cookies are not set there. For the website, section 9 applies — there it is different.
8. Recipients of your data
With the providers that process on our behalf, data processing agreements under Article 28 GDPR are in place.
8.0 Where your data is held
Your account, your charging sessions, your reports and the photos you upload are held in a database in Stockholm (Sweden). The program parts that process your data and generate the pages run in Frankfurt am Main — as does the gateway at which a self-connected wallbox registers. These three locations are in the European Union.
Two qualifications, so that the sentence does not promise more than it delivers. Static files — images, fonts, the program code of the page — are delivered over a worldwide delivery network; access logs containing your IP address arise in the process (section 4.6), but no account or charging data. And the scheduled runs that regularly poll your wallbox and generate the reports run at a provider outside the EU; they access the database in Stockholm while doing so. Both are in the table below and in section 8.7.
8.1 Operation and storage
| Recipient | What for | Place of processing |
|---|---|---|
| Vercel | Execution of the server code and delivery of the website | Frankfurt am Main; static files worldwide via the delivery network |
| Supabase | Database, sign-in and file storage — all account, charging, billing and error data as well as the report PDFs and the odometer photos are held here | Stockholm, Sweden |
| Fly.io | Operation of our gateway for self-connected wallboxes and for Shelly push mode. Charging transactions, charging card IDs and meter readings pass through it. The log output additionally shows the IP address of your internet connection, the name of your wallbox, manufacturer, model and firmware, the meter readings at the beginning and end of every charge as well as the ID of the charging card used — the full list is in section 4.6 | Frankfurt am Main |
| Trigger.dev | Execution of the scheduled runs: wallbox polling, report generation, plausibility checking, account maintenance. The runs access the database in Stockholm; the run logs contain user and wallbox identifiers | United States |
8.2 Sending, mailboxes and payment
| Recipient | What for |
|---|---|
| Resend | Sending of all emails including attachments: report PDFs with name, address, registration number, where applicable IBAN and all individual charges; payroll files with employee numbers and amounts; invoices; confirmation emails with charging times and access link; reminders; fault notifications |
| Microsoft | Operation of our email mailboxes. Every message you address to us — replies to our reports, invoices and reminders as well as support requests — arrives in a mailbox at Microsoft and is stored there |
| Unipile | Connection to WhatsApp. The conversation with those customers who have consented runs through Unipile: phone number, displayed name, and the text and attachments of every message. Unipile stores this content encrypted in France until the WhatsApp connection is disconnected. The connection additionally runs via proxy providers — see 8.7 |
| Meta (WhatsApp) | Delivery of the messages themselves. Meta processes every message exchanged over WhatsApp on its way between your device and ours — as with any other WhatsApp conversation |
| Stripe | Payment processing. Receives the email address, name or company name, language preference, our user ID, billing address and VAT ID; the payment details themselves you enter directly there. Stripe states that it is certified to PCI DSS Level 1 |
We do not measure whether you open our emails or click on links in them.
8.3 Notifications
| Recipient | What for |
|---|---|
| Google (Firebase Cloud Messaging) | Delivery of the notifications to the app. Receives the device token, title, text and the data field with the destination inside the app. As soon as you allow notifications, Google additionally receives the installation ID of the built-in Firebase component — see 7.1 |
| Apple (notification service) | Final delivery leg of the app notifications on iPhone and iPad. Issues the device token when the app starts and receives the message passed on by Firebase |
| Push services of the browser makers (Apple, Google, Mozilla — depending on the browser) | Delivery of the notifications in the browser |
8.4 Wallbox manufacturers
To retrieve your charging data we connect to the cloud of your wallbox manufacturer. In doing so we transmit the access credentials you have entered. Only the manufacturer of your own wallbox is affected. Which server the manufacturer operates for this is not our decision.
| Manufacturer | What is transmitted | Processing to the best of our knowledge |
|---|---|---|
| Easee | Email address and password of your Easee account at every sign-in | Norway (EEA) |
| Zaptec | Email address and password of your Zaptec account | Norway (EEA) |
| Ohme | Your sign-in credentials. Google in addition: Ohme handles its sign-in via Google Firebase, which is why the email address and password of your Ohme account are transmitted to Google | United Kingdom |
| myenergi | Serial number of your hub and your API key | United Kingdom |
| GoodWe (SEMS+) | Email address and password of your SEMS account at every poll | China |
| go-e | Serial number and API token of your wallbox | European Union |
| Wallbox / Pulsar | Email address and password of your account | European Union |
| V2C | Your API key | European Union |
| Charge Amps | Email address and password of your account, together with our partner key | European Union |
| Elli / Volkswagen | Only for existing connections; new ones are blocked | European Union |
| Sungrow | As a rule you share your system with our service account; we then poll with our own credentials and your password is not stored. For legacy connections your credentials or a token are held by us. In either case Sungrow learns that your system is shared with ChargeReport | European Union |
| Shelly / Allterco | Your cloud key. In push mode the device connects directly to our gateway; the Shelly cloud remains the fallback route | European Union |
With an OCPP connection and in Shelly push mode there is no polling at a manufacturer: your wallbox connects directly to our gateway. This applies among others to wallboxes from KEBA — no data flows there.
8.5 Ourselves as a recipient
Certain events trigger an email to our operations mailbox. The following go there:
- On every registration: name, email address, account type and the wallbox brand chosen
- On wallbox faults: your email address, name, wallbox name, manufacturer, language and the error text
- On technical errors: error message, page address, context and call stack — for signed-in users with your user ID
- Every support ticket and every reply of yours within it — with your name, your email address and the full text; your address additionally appears as the reply address in the email
- If you report a wallbox that is not yet supported: your email address, brand, model, whether a manufacturer app exists, its name and your comment
- Weekly a summary of the plausibility check: number of accounts checked, number of charges checked, number of accounts with findings and — where present — the billing month and the finding text of the deviating reports
- Notices concerning the tax flat rate for electricity, which contain no user data
This mailbox is operated by Microsoft (section 8.2).
8.6 Not a recipient of your data
For producing blog and marketing texts and for research we use artificial intelligence tools. Your account, charging or report data does not flow there.
8.7 Transfer to countries outside the EU
This cannot be avoided in every case:
- Notifications to your device. A push message has to run over the delivery service your device provides for it. For the iPhone app that is Firebase Cloud Messaging from Google; for notifications in the browser it is the address your browser names to us for the purpose — with Safari a service from Apple, with Chrome one from Google. Both companies are based in the USA. What is transmitted is the device identifier and the text of the message.
- The cloud of your wallbox manufacturer, insofar as it is outside the EU — see the table in 8.4.
- Our service providers based in the USA: Vercel, Supabase, Stripe, Resend, Fly.io, Trigger.dev, Google and Microsoft. With Vercel, Supabase and Fly.io the processing takes place in the EU, as described in 8.0; access from the USA cannot, however, be ruled out.
- The scheduled runs at Trigger.dev. This is not a question of possible access but the normal case: these runs are executed in the United States and access the database in Stockholm from there. What is transmitted in the process is account and charging data to the extent the respective run needs it; the run logs contain user and wallbox identifiers.
- The connection path to WhatsApp. Our provider Unipile stores in France, but routes the connection via proxy providers: in Lithuania, Israel, the United States and Singapore. Messages pass through those providers encrypted — they see the connection data, that is source and destination address, but not any content. For Israel there is an adequacy decision of the European Commission; for the United States and Singapore, Unipile bases the transfer on standard contractual clauses. Meta, which operates WhatsApp, is based in the USA.
- The delivery of static files over our host's worldwide network. Access logs containing your IP address arise in the process; account or charging data is not contained in them.
Insofar as there is no adequacy decision by the European Commission for the destination country, we base these transfers on the standard contractual clauses under Article 46(2)(c) GDPR. For the United Kingdom an adequacy decision exists; for recipients in the USA it does too, insofar as they are certified under the EU-US Data Privacy Framework.
8.8 Industry contacts who are not our customers
This section does not concern you as a customer. It is here because alongside everything else we keep a contact list for our own public relations work, and you should know that even though it does not affect you.
It contains the name, role, company and business email address of industry contacts — editorial teams, trade portals, industry media. We did not obtain these details from the people concerned but took them from publicly accessible sources: legal notices, contact pages, trade articles. For every entry we note which page it comes from.
We use them to write to industry contacts once. The legal basis is our legitimate interest in approaching suitable business partners (Article 6(1)(f) GDPR). To prepare these messages we use a language model from Anthropic; sending runs via Microsoft. We delete an entry twelve months after the last approach, and immediately upon objection.
Every one of these messages carries at the end who the controller is, which source the address comes from, how long we keep it — and a separately set out note that an informal reply is enough never to be written to again. Articles 14 and 21(4) GDPR require this, and it is there because the first message is the only moment at which we reach these people.
Anyone on this list has the same rights as our customers — access, rectification, erasure and objection (section 13). A message to datenschutz@chargereport.app is enough; on request we will also name the source of the entry.
9. Website: cookies, analytics and advertising tools
This section applies only to the website chargereport.app. None of it takes place in the app — see section 7.3.
9.1 Technically necessary cookies
We set these without consent, because without them the service does not work:
| Cookie | Purpose | Lifetime |
|---|---|---|
Sign-in cookie of our sign-in service (name begins with sb-) | Sign-in and refresh of your session | 400 days |
NEXT_LOCALE | Remembers your choice of language | until the browser is closed |
sungrow_oauth_state | Protection against forged requests when connecting a Sungrow system | 10 minutes |
9.2 Storage in your browser
Some values we place in your browser's local storage. They do not leave your device and are not transmitted to us:
| Key | What it contains |
|---|---|
cookie_consent | Your decision in the consent banner |
theme | Your choice between light and dark display |
chargereport_wallbox_brand | The wallbox brand noted in advance, if you arrived via a brand page — it pre-fills the registration form |
reports_last_seen | The time at which you last opened the reports bell. From this the interface can tell which reports are new to you |
pwa_install_dismissed | A note that you dismissed the "Add to home screen" prompt |
push_optin_dismissed | A note that you dismissed the question about notifications |
The consent banner and the installation prompt do not appear in the app; the two corresponding values consequently do not arise there either.
9.3 Google Ads
On the website we include the advertising tag from Google Ads — only once you have chosen "Accept all" in the consent banner. For as long as you have not agreed or have chosen "Only necessary", nothing is loaded from Google and no request goes there.
After a completed registration we transmit a conversion event to Google Ads. What is transmitted is exclusively the identifier of the event — no email address, no name, no amount.
| Cookie | Set by | Lifetime |
|---|---|---|
_gcl_au | us, for attributing ad clicks | 90 days |
IDE, test_cookie | Google on its own domains, for advertising | 13 months and 15 minutes respectively |
9.4 LinkedIn Insight Tag
On the website we include the Insight Tag from LinkedIn — likewise only after "Accept all". Its purpose is to measure the success of our ads on LinkedIn: it tells us how many people landed with us after clicking one of our ads — not who they were.
| Cookie | Set by | Lifetime |
|---|---|---|
li_gc, bcookie, bscookie | 6 months to 2 years | |
UserMatchHistory, AnalyticsSyncHistory | 30 days | |
lidc | 1 day |
9.5 Audience measurement with Plausible
On the website we measure our reach with Plausible — only after "Accept all". Outgoing links, file downloads and individual events marked by us are recorded as well. Plausible states that it sets no cookies for this and stores nothing on your device, and that it counts visits without recognising you across pages. We are passing this on as the provider's statement — what a third-party script does in your browser is not something we can vouch for. That is why we ask you beforehand in any case: without your consent the script is not loaded.
9.6 Stripe in the browser
On the payment pages of the dashboard we load a script from Stripe with which you enter your payment method. Your payment details go directly to Stripe in the process, not via our servers. In the app these pages are not displayed at all.
| Cookie | Set by | Lifetime |
|---|---|---|
__stripe_mid | Stripe, for fraud prevention | 1 year |
__stripe_sid | Stripe, for fraud prevention | 30 minutes |
9.7 How to withdraw your consent
You can change your decision from the consent banner at any time: via the "Cookie settings" link in the footer of every page. If you withdraw your consent, the tools from 9.3 to 9.5 are no longer loaded.
10. Retention periods
We delete personal data as soon as the purpose for which we collected it no longer applies, and insofar as no statutory retention obligation stands in the way. Periods of one year and longer expire at the end of the calendar year in which they are reached; shorter periods we calculate to the day.
| What | Period |
|---|---|
| Account and master data | until you delete your account |
| List of charging cards marked as private | until you remove the entry, at the latest until your account is deleted |
| Charging sessions and report PDFs | 6 years |
| Confirmations: business/private classification and odometer reading | 6 years, like the charge they belong to |
| Charging protocol data from a self-connected wallbox (meter readings at start and stop) | 6 years, like the charge they belong to |
| Sending log of the payroll files | 6 years |
| Acknowledged plausibility findings | 6 years, like the report concerned |
| Invoices and billing data | 8 years — here tax law obliges us to keep them |
| Odometer photos | 12 months from the time taken; immediately if your account is deleted |
| Odometer photos you selected but never sent | 32 days |
| Confirmation requests | 90 days |
| Measurement samples from sub-meters and inverters | 90 days |
| WhatsApp conversation: text and attachments | until you delete your account |
| Log of our emails: the full text of the message | 30 days |
| Log of our emails: the sending line of the monthly report (recipient, subject, time, result) | 6 years |
| Log of our emails: all remaining lines | 12 months |
| Error logs | 90 days |
| Log output of our gateway (section 4.6) as well as the access logs of our server providers with IP address, browser identifier and address called up | 30 days — we do not keep these logs ourselves; the period is that of the respective provider |
| Sign-in sessions with IP address and browser identifier | 30 days without use, at most 180 days from signing in |
| Push subscriptions | immediately, as soon as the delivery service reports them as invalid; otherwise 12 months after the last successful delivery |
| Support cases, support messages, messages from the admin area | 3 years after the case is closed |
| Requests about unsupported wallboxes | email address removed after 12 months; brand, model and comment remain without the address |
| Connection attempts with Sungrow | 90 days |
| Rejected connection attempts from your wallbox | 90 days |
| Classification of your account, notes on reminder emails | live with the account, are continuously overwritten |
| History of your subscription (section 4.2) | 3 years — after your account is deleted, with no link to you |
| Voluntary feedback on the reason for cancelling (with no personal reference) | 3 years |
Accounts with no connected wallbox. If you registered but never connected a wallbox, we point this out to you by email after 30 days. If you do not respond to that, we pseudonymise the account a further 14 days later.
10.1 Deleting your account
You can delete your account yourself at any time — in the dashboard under account settings.
The following then happens: we cancel any existing subscription and delete your customer record at the payment provider. We remove your report PDFs and your odometer photos from storage. We delete the log of the emails sent to you including your address and the text of the messages. We delete your sign-in account; via the database links this also removes your profile, charging sessions, reports, invoices, wallbox connections, drivers, confirmations, messages and support cases.
What remains afterwards, with no link to you as a person: technical error logs for at most 90 days, the history of your subscription and any voluntary feedback on the reason for cancelling — in each case with no attribution to you.
One exception that is not ours to make. If you take part through an account belonging to your employer, your employee number remains in their account; your email address we remove there too. The employee number belongs to their payroll, for which they have retention obligations of their own — without it they could no longer assign the reimbursements already booked to a payroll account. To have it deleted, please contact your employer (section 5.4).
Where we are not allowed to delete. Invoices and the associated billing data we have to keep for eight years. To that extent we cannot comply with a deletion request; this data is blocked for any other use.
11. Data security
- Transmission between your device and our servers is encrypted (TLS).
- Wallbox access credentials are stored encrypted (AES-256-GCM), with the key kept separately from the database.
- Your password is managed by our sign-in service; it is never available to us in plain text.
- Your payment details you enter directly at the payment provider; they do not pass over our servers.
- Access to your report PDFs and odometer photos is limited to your own account and — with an employer account — to its administrators; the storage is not public.
12. Legal bases
| Processing | Legal basis |
|---|---|
| Creating and running an account, connecting a wallbox, retrieving charging data, producing the record | Article 6(1)(b) GDPR (performance of the contract with you) |
| Storage of the wallbox access credentials | Article 6(1)(b) GDPR |
| Transmission of the record to your employer — name, address, registration number, wallbox, charging sessions, reimbursement rate and amount | Article 6(1)(b) GDPR |
| Transmission of IBAN, BIC and bank name to your employer | Article 6(1)(a) GDPR (consent), revocable by deleting them in your profile |
| Odometer reading, where you switch confirmation on | Article 6(1)(b) GDPR |
| Odometer photo | Article 6(1)(a) GDPR (consent) |
| Odometer reading and confirmation where your employer requires them for their account; likewise the exclusion of individual charges by an administrator of their account | Article 88 GDPR in conjunction with Section 26(1) BDSG (German Federal Data Protection Act) — carrying out the employment relationship at the employer; to that extent we process on their instructions |
| Disclosure to your employer's payroll department and tax adviser | Article 6(1)(b) GDPR arising from the contract with your employer |
| Payment processing | Article 6(1)(b) GDPR |
| History of your subscription (section 4.2) | Article 6(1)(b) GDPR for the line itself — it records the status of your contract; Article 6(1)(f) GDPR for the aggregated evaluation of how many customers stay |
| Retention of the invoices | Article 6(1)(c) GDPR (Section 147 AO, German Fiscal Code; Section 14b UStG, German VAT Act) |
| Error logs, fault detection, abuse prevention | Article 6(1)(f) GDPR — legitimate interest in the security and functioning of the service (Recital 49) |
| Report, confirmation query, fault notification and invoice by email | Article 6(1)(b) GDPR |
| Notifications to your device | Article 6(1)(a) GDPR, additionally Section 25(1) TDDDG (German Digital Services Data Protection Act) for storing the delivery identifier on your device |
| Reminders about an incomplete set-up | Article 6(1)(f) GDPR |
| Offers by email to existing customers | Article 6(1)(f) GDPR in conjunction with Section 7(3) UWG (German Act against Unfair Competition); otherwise consent. Every such message contains, as Section 7(3) no. 4 UWG requires, a note about your right to object — an informal objection is enough and costs you nothing |
| Support cases | Article 6(1)(b) GDPR |
| Internal classifications and notes (section 4.9) | Article 6(1)(f) GDPR — they serve to spot connections that are stuck before you receive an incomplete report |
| Google Ads and LinkedIn (website) | Article 6(1)(a) GDPR, additionally Section 25(1) TDDDG |
| Audience measurement with Plausible (website) | Article 6(1)(a) GDPR |
| Pseudonymisation of unused accounts | no separate legal basis required — it opens up no new processing but implements Article 17(1)(a) and the storage limitation principle (Article 5(1)(e)) |
| Messages over WhatsApp and mirroring of the conversation into your customer file | Article 6(1)(a) GDPR (consent), revocable in your account at any time |
| Phone number for technical call-backs | Article 6(1)(a) GDPR (consent), deletable in your account at any time |
13. Your rights
Under the General Data Protection Regulation you have the right to:
- Access to the data stored about you (Article 15)
- Rectification of incorrect data (Article 16). Your master, vehicle and bank details you can change yourself in your profile at any time.
- Erasure (Article 17) — see section 10.1
- Restriction of processing (Article 18)
- Data portability (Article 20) — see below
- Objection to processing based on legitimate interests (Article 21)
- Withdrawal of a consent given, with effect for the future (Article 7(3)). Consent to cookies and measurement tools you withdraw via the "Cookie settings" link in the footer; notifications you switch off in your device settings.
13.1 Data export — you can trigger it yourself
In the dashboard you will find a button with which you download your data as a JSON file. It contains: your account data, your full profile including bank details and billing address, your wallbox connections, all charging sessions with your confirmations and odometer readings, additional drivers at your wallbox with their master data and charging cards, your reports and invoices, your membership of an employer account including your employee number, your support cases with all messages, our messages to you, your push subscriptions and the index of our emails to you. The export is complete even after long use.
Not in the file are: the raw measured values that some wallboxes and sub-meters deliver minute by minute — they amount to hundreds of thousands of lines per device per year and are already contained in your charging sessions in aggregated form — as well as your report PDFs and your odometer photos as files. The reports you can download in the dashboard at any time; everything else you receive on request, and we answer within one month.
13.2 Account deletion — you can trigger it yourself
Likewise in the dashboard, under account settings. What happens in the process is described in section 10.1.
13.3 Contact us
For all other matters you can reach us at datenschutz@chargereport.app. We answer within one month.
13.4 Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent one is
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia)
Kavalleriestraße 2-4
40213 Düsseldorf
14. Changes to this policy
We adapt this policy when the service changes. The version in force at any given time can be found on this page.
End of the policy text.