Privacy Policy

Last updated: March 2026

What We Collect

All users (with or without an account)

  • Location data -- Used only to find nearby stations and chargers. Processed in real-time and never stored on our servers.
  • Local storage -- Preferences (fuel type, dark mode, view mode) are saved in your browser only.
  • Analytics -- If you consent, we use PostHog for anonymous usage analytics. No personal data is collected.

Registered users (with an account)

If you create an account, we additionally store:

  • Email address -- Required for account creation and used to send verification emails, password resets, and price alert notifications.
  • Name -- Optional, used for display purposes only.
  • Password -- Securely encrypted. We never store or have access to your plain-text password.
  • Vehicle data -- If you use the Virtual Garage feature, your saved vehicle specifications (fuel type, tank size, MPG, etc.) are stored to auto-fill the route planner.
  • Favourite stations -- Station IDs you have starred are stored to show your favourites list.
  • Saved routes -- Waypoints and route configuration for routes you choose to save.
  • Price alert preferences -- Fuel type, postcode, threshold price, and notification settings for alerts you configure.
  • Session data -- IP address and user agent are stored with your session for security monitoring. Sessions expire after 7 days.

Google Sign-In users

  • If you sign in with Google, we receive your email address, name, and profile picture from Google. We do not access any other Google data.

How We Use Your Data

  • Account management -- Email verification, password resets, session management.
  • Price alerts -- Checking fuel and EV prices against your thresholds and sending you email notifications.
  • Personalisation -- Loading your saved vehicles, favourite stations, and preferences.
  • We do not sell, share, or transfer your data to third parties for marketing or advertising.

Data Retention

  • Account data -- Retained as long as your account is active. You can delete your account at any time.
  • Sessions -- Automatically expire after 7 days. Expired sessions are periodically cleaned up.
  • Station reports -- Reporter IP addresses are stored for rate limiting and are not shared publicly.

Third-Party Services

  • Cloudflare -- Hosting and data storage. Your data is stored securely on Cloudflare's infrastructure.
  • Google -- If you choose to sign in with Google, authentication is handled by Google.
  • PostHog -- Anonymous product analytics (opt-in only).
  • Google/Apple Maps -- Only when you click “Directions”, opening in a new tab.

Security

  • Passwords are securely encrypted and never stored in plain text.
  • All connections are encrypted via HTTPS.
  • Sessions are secured using industry-standard practices.
  • Rate limiting protects against abuse.

Your Rights

  • Access -- You can view all your stored data via your account settings, garage, favourites, and alerts pages.
  • Deletion -- You can delete individual vehicles, favourites, routes, and alerts at any time. Contact us to delete your entire account.
  • Portability -- Your data is available through the account pages.
  • Opt-out -- You can disable price alert emails in account settings. You can withdraw analytics consent by clearing cookies.

Contact

Questions about privacy or your data? Email hello@petrolpal.co.uk