Privacy Policy
Last updated: March 2026
What We Collect
All users (with or without an account)
- Location data -- Used only to find nearby stations and chargers. Processed in real-time and never stored on our servers.
- Local storage -- Preferences (fuel type, dark mode, view mode) are saved in your browser only.
- Analytics -- If you consent, we use PostHog for anonymous usage analytics. No personal data is collected.
Registered users (with an account)
If you create an account, we additionally store:
- Email address -- Required for account creation and used to send verification emails, password resets, and price alert notifications.
- Name -- Optional, used for display purposes only.
- Password -- Securely encrypted. We never store or have access to your plain-text password.
- Vehicle data -- If you use the Virtual Garage feature, your saved vehicle specifications (fuel type, tank size, MPG, etc.) are stored to auto-fill the route planner.
- Favourite stations -- Station IDs you have starred are stored to show your favourites list.
- Saved routes -- Waypoints and route configuration for routes you choose to save.
- Price alert preferences -- Fuel type, postcode, threshold price, and notification settings for alerts you configure.
- Session data -- IP address and user agent are stored with your session for security monitoring. Sessions expire after 7 days.
Google Sign-In users
- If you sign in with Google, we receive your email address, name, and profile picture from Google. We do not access any other Google data.
How We Use Your Data
- Account management -- Email verification, password resets, session management.
- Price alerts -- Checking fuel and EV prices against your thresholds and sending you email notifications.
- Personalisation -- Loading your saved vehicles, favourite stations, and preferences.
- We do not sell, share, or transfer your data to third parties for marketing or advertising.
Data Retention
- Account data -- Retained as long as your account is active. You can delete your account at any time.
- Sessions -- Automatically expire after 7 days. Expired sessions are periodically cleaned up.
- Station reports -- Reporter IP addresses are stored for rate limiting and are not shared publicly.
Third-Party Services
- Cloudflare -- Hosting and data storage. Your data is stored securely on Cloudflare's infrastructure.
- Google -- If you choose to sign in with Google, authentication is handled by Google.
- PostHog -- Anonymous product analytics (opt-in only).
- Google/Apple Maps -- Only when you click “Directions”, opening in a new tab.
Security
- Passwords are securely encrypted and never stored in plain text.
- All connections are encrypted via HTTPS.
- Sessions are secured using industry-standard practices.
- Rate limiting protects against abuse.
Your Rights
- Access -- You can view all your stored data via your account settings, garage, favourites, and alerts pages.
- Deletion -- You can delete individual vehicles, favourites, routes, and alerts at any time. Contact us to delete your entire account.
- Portability -- Your data is available through the account pages.
- Opt-out -- You can disable price alert emails in account settings. You can withdraw analytics consent by clearing cookies.
Contact
Questions about privacy or your data? Email hello@petrolpal.co.uk