PotatoCharge respects your privacy. This policy explains what data we collect, why, and your rights under the General Data Protection Regulation (GDPR — EU regulation 2016/679).
1. Data controller
Data is processed by PotatoCharge, a peer-to-peer EV charging platform operating in Wallonia. Contact: hello@potatocharge.be.
2. Data collected and purposes
We only collect the data strictly needed to run the service:
| Category | Purpose | Legal basis |
|---|---|---|
| Identity (first name, last name, email) | Account creation and management, transactional communications | Contract performance |
| Postal address, ZIP code | Charger geolocation, host/driver matching | Contract performance |
| Vehicle (brand, model, battery capacity) | Charging session estimation, compatibility | Contract performance |
| Charger data (address, photos, power) | Publishing on the map for drivers | Contract performance |
| Bookings, sessions, dashboard photos | Billing, consumption proof, dispute resolution | Contract performance, legal obligation |
| Stripe customer ID | Payment processing | Contract performance |
3. Retention period
Account data is kept while your account is active. Billing data (bookings, sessions, payments) is kept for 10 years in accordance with Belgian accounting law. Upon account deletion, personal data is erased within 30 days, except where legal retention obligations apply.
4. Sharing with third parties
We never sell your data. It's only shared with processors strictly needed for the service:
- Stripe (Ireland, EU adequate) — payment processing and secure payment-method storage. Stripe's privacy policy.
- Brevo (France) — transactional email delivery (confirmations, reminders, notifications). Brevo's privacy policy.
- OpenStreetMap / Nominatim — charger address geocoding. Requests are sent client-side from your browser.
- European cloud hosting — encrypted storage of photos (dashboard, chargers).
- Mercure Hub — real-time delivery of charger status and chat messages, with no persistent personal content.
- Google Analytics 4 (Google Ireland Limited) — anonymous audience measurement with IP anonymisation, only if you accepted in the cookie banner. Retention 14 months. See our cookie policy for details and opt-out.
All processors are bound by a contract compliant with article 28 of the GDPR.
5. Your rights
At any time, you can exercise the following rights:
- Right of access to your data
- Right to rectification if any data is inaccurate
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to portability (export your data)
- Right to object to processing
- Right to lodge a complaint with the Belgian Data Protection Authority
To exercise these rights, write to privacy@potatocharge.be. We reply within 30 days maximum.
6. Security
Passwords are hashed (bcrypt). Communications are encrypted with TLS 1.3. The site supports two-factor authentication (TOTP) for additional protection.
7. Changes
This policy may be updated. Any substantial change will be notified by email before it takes effect.