Privacy policy

This privacy policy explains which personal data are processed in connection with the website, the TOST app and the functions offered, for which purposes this takes place, and which rights data subjects have. Personal data are processed only where legally permitted or where consent has been given. The specific processing operations, legal bases, recipients and storage periods are described below.

1. Definitions

This privacy policy is based on the terms used by the European legislator when adopting the General Data Protection Regulation (GDPR). This privacy policy is intended to be easy to read and understand for the public as well as for customers and business partners. To ensure this, the terms used are explained below.

The following terms are used in this privacy policy:

2. Name and address of the controller

The controller within the meaning of the GDPR and other applicable data protection laws is:

Christian Hillebrand
Kornblumenweg 7
61184 Karben

Telephone: +49 (0) 6039 93 44 816
Email: contact [at] tesla-order-status-tracker [dot] de

3. Collection of general data and information

When the website is accessed by a person or an automated system, general data and information may be collected and stored in the server log files. This may include browser type and version, operating system, referring website, pages accessed, date and time of access, IP address, internet service provider and other data used to protect the information technology systems against attacks.

These data are used to deliver the website correctly, optimise its content, ensure the long-term operation and security of the systems and provide information to law-enforcement authorities where required after a cyberattack. The data are evaluated statistically for these purposes and stored separately from personal data provided by a user. The legal basis is Article 6(1)(f) GDPR.

4. Routine erasure and restriction

Personal data are stored only for as long as necessary to achieve the purpose of processing or as required by applicable law. When the purpose no longer applies or a statutory retention period expires, the data are routinely restricted or erased in accordance with the applicable legal requirements.

5. Rights of the data subject

6. Legal bases for processing

Processing based on consent relies on Article 6(1)(a) GDPR. Processing necessary to perform a contract or take steps at the request of the data subject before entering into a contract relies on Article 6(1)(b) GDPR. Processing necessary to comply with a legal obligation relies on Article 6(1)(c) GDPR. Processing necessary to protect vital interests may rely on Article 6(1)(d) GDPR. Processing necessary for a legitimate interest relies on Article 6(1)(f) GDPR, unless the interests or fundamental rights and freedoms of the data subject override that interest.

7. Legitimate interests

Where processing is based on Article 6(1)(f) GDPR, the legitimate interests are the secure operation of the website and TOST services, protection against misuse and the performance of the business activity.

8. Storage period

Personal data are stored for the period required for the relevant purpose or by applicable statutory retention obligations. Once the purpose and any retention obligation have ended, the data are erased unless they are still required for contract performance or the establishment of a contractual relationship.

9. Requirement to provide personal data

The provision of personal data may be required by law or contract, or may be necessary to enter into a contract. Whether data must be provided and the consequences of not providing them depend on the relevant processing operation and will be explained where applicable. Data that are technically necessary to use a function cannot be omitted if that function is to be used.

10. Automated decision-making

As a responsible company, we do not use automated decision-making or profiling.

This privacy policy was created using the privacy-policy generator of DGD Deutsche Gesellschaft für Datenschutz GmbH, which conducts data protection audits, in cooperation with the law firm WILDE BEUGER SOLMECKE.

TOST app and TOST servers: specific processing

11. Local processing and Tesla retrieval

The TOST app retrieves data from the user's Tesla account at the user's request and generally processes the resulting order, vehicle, task and history data locally on the user's device. The TOST app does not transmit this content to the TOST servers. Tesla is responsible for authentication and retrieval from the Tesla account; Tesla's own privacy information also applies.

12. Combined technical request

The TOST app combines several technically necessary functions in a single request to the TOST servers. These functions include checking for updates, news and notices, updating option codes and checking whether a fetch is permitted. Depending on the request, the selected modules and the technical information required for the relevant update are transmitted.

13. Option codes

To update locally stored option codes, the TOST app transmits the time of the last successful update to the TOST servers. This means that only new or changed entries need to be loaded.

14. Updates

The TOST app transmits its version, the selected update channel and the platform so that suitable updates and security-related updates for the operating system in use can be provided.

15. Fetch authorisation and internal usage statistics

For the technical check whether a fetch is permitted, a pseudonymous identifier, a random request identifier and a timestamp are processed. These data are used for authorisation and protection against misuse. The resulting usage data are used for internal, highly aggregated usage statistics.

16. Optional telemetry

Only with explicit consent does the TOST app transmit additional usage data to the TOST servers. These data include pseudonymised order identifiers, vehicle models, language and country, app version, update channel and usage parameters used during retrieval. They are used for error analysis, quality improvements and prioritising functions that are actually used. Consent may be withdrawn at any time in the app's settings.

17. Recipients, logging and storage period

The TOST servers are operated at Hetzner. Only app-related and operationally necessary information is transmitted to the TOST servers. Tesla-related order and vehicle data remain on the user's device. The transmitted information may include module selection, version and update status, platform, news status, the option-code update time and the pseudonymous identifier used for the fetch check. The transmitted identifiers are pseudonymised and additionally protected on the servers. Standard technical connection data such as IP address, time, user agent and error logs may arise during operation. Pseudonymous fetch data are stored for no more than six months after the last relevant activity. The user-related data are then erased. Non-personal aggregate values may remain for internal statistics.

Update checks are additionally aggregated without user identifiers by UTC day, app version, update channel and platform for internal compatibility and update planning. These statistics are not assigned to individual users.

18. Rocket.Chat

The TOST app offers an optional chat function based on Rocket.Chat. The chat is operated on TOST servers. The live-chat widget embedded on the website and the chat function in the TOST app use the same chat service. If you use the chat, the account data required for registration and sign-in, as well as your chat posts, messages and contact data, are processed. These data are used only to provide and operate the chat function. They are not transmitted to external chat providers. Connection data such as IP address, time and user agent may also be processed for technical communication. The functions offered in the chat and the statutory data-subject rights apply to the content and deletion of your chat account.