Privacy Policy

Effective date: August 15, 2026. This Privacy Policy describes the data flows used by the current VoltEdgeSystem build for the public demo, Tesla account connection, vehicle and charging features, analytics, contact form, and workspace-based Smart Charging. Functional workspace creation and Tesla-related processing require acceptance of the complete Mandatory User Authorization Notice through the session-gated production consent form. Public evaluation does not submit, store, or activate consent.

Tesla account connection

VoltEdgeSystem starts Tesla account connection through Tesla OAuth. During sign-in, the app creates temporary PKCE, state, and return-path cookies to complete the callback flow.

After a successful callback, the app creates a short-lived, server-only pending consent transaction. Normal Tesla access and refresh-token persistence, workspace creation, telemetry setup, bulk data reads, and command-capable processing occur only after valid signed consent activation. The encrypted HttpOnly session cookie stores authenticated session state and may carry Tesla token fields required by authenticated API routes. The consent record itself does not store raw cookie values, private keys, or authorization headers.

Tesla passwords are not submitted to VoltEdgeSystem. Access tokens are credentials and are handled as account-connection data; do not include passwords or private keys in support messages.

Product and contact data

The public demo can be opened without Tesla sign-in. When you send the contact form, the app sends the submitted subject, email, company, area, message, request metadata, and any logged-in user context to the configured contact recipients.

The contact form also uses a captcha token and answer to reduce automated submissions.

Cookies and similar technologies

VoltEdgeSystem uses strictly necessary first-party cookies for authenticated sessions, Tesla OAuth state and PKCE callback protection, and request-forgery protection. First-party theme and dashboard-layout preference cookies may persist for up to one year. These cookies are not used for marketing or sale.

  • voltedge_session: encrypted authenticated session state; HttpOnly, Secure in production, and SameSite=Lax.
  • OAuth callback cookies: temporary Tesla verifier, state, and return-path cookies; they expire after 10 minutes.
  • voltedge_home_csrf: request-forgery protection for home-state requests; session-scoped.
  • Preference cookies: voltedge-theme and voltedge-dashboard-layout; may persist for up to one year.
  • Google Analytics cookies: optional third-party analytics cookies on eligible public pages only, when configured by deployment. Analytics is excluded from authentication, Control Board, administrator, and API routes.

Vehicle and charging data

After accepted consent activation, VoltEdgeSystem may process the approved Tesla account and product categories needed for enabled features. These include account identity and profile; vehicle identity, VIN, configuration, and state; battery, charging, range, and energy state; location, navigation, home/away, and movement-related information; climate, door/lock, body, and vehicle settings; safety, diagnostic, and vehicle-fault information; Wall Connector identity and state; Energy Site identity, configuration, and power-flow information; approved Fleet Telemetry fields and intervals; and user access and command-activity audit records.

Smart Charging requires Fleet Telemetry. VoltEdgeSystem receives only the approved Fleet Telemetry fields and intervals defined in the current Telemetry Configuration. Telemetry may be delayed, incomplete, stale, unavailable, buffered, or replayed after an interruption. These flows should be enabled only for a vehicle and account that you are authorized to control.

Why data is used

After consent, data is used to authenticate accounts, display authorized vehicle and energy information, retrieve provider price information, evaluate configured charging rules, operate the approved Fleet Telemetry and Smart-Charging flows, process support requests, protect the service, measure public-page usage when analytics is enabled, and maintain the current product. Smart Charging is best effort and does not guarantee charging completion, savings, uninterrupted operation, or correct command execution.

Data may be processed by Tesla for the connected account flow, the configured email provider for contact delivery, and Google Analytics when its measurement ID is enabled. The contact captcha is generated and verified by the VoltEdgeSystem service. VoltEdgeSystem does not ask for a Tesla password through its own forms.

The launch product is intended for people in the United States who are at least 18 years old and use a non-commercial Tesla vehicle. You must be authorized to access each selected Tesla account, vehicle, Wall Connector, Energy Site, and related data. Wall Connector features apply only when a Wall Connector is available.

VoltEdgeSystem does not use account, vehicle, telemetry, snapshot, activity, command, or derived information for marketing. VoltEdgeSystem does not sell, rent, or license this information to third parties. Approved service providers may process information only as required to operate approved services and under approved controls.

Provider prices and Smart Charging

You select an electricity provider when provider pricing is configured. VoltEdgeSystem retrieves price information through that provider's price API and uses the poller-refreshed, workspace-wide live-price value for Smart-Charging decisions. Per-vehicle Energy Site price fields are not an alternate source.

A missing or stale workspace price, vehicle state, or required telemetry produces no Smart-Charging decision or charging action. Smart Charging may be delayed, unavailable, use incomplete data, issue no command, or receive a rejected or unconfirmed result. The launch allowlist contains exactly six operations: vehicle wake-up, charging start, charging stop, Telemetry create, Telemetry setup, and Telemetry update.

Latest snapshots and activity

Current product values are maintained as latest snapshots for the declared data elements; a newer value replaces the prior value. VoltEdgeSystem does not create a historical vehicle-data timeline under this product flow.

Separate operational records may retain consent, security, login, command, deletion, support, and reliability activity for security, support, audit, and service operations. These records are not vehicle-state history.

Current-session controls

Logging out destroys the current VoltEdgeSystem session and clears the main session cookie. The current build also clears demo mode and legacy Tesla token cookies during logout.

Retention, requests, and security

Session, account, vehicle, telemetry, configuration, support, consent, activity, and security records are retained according to their operational, security, and legal purpose. User logon and user-initiated command activity is retained under approved retention requirements and may be retained longer when required for security or legal compliance. You may withdraw consent at any time; withdrawal stops future Smart-Charging activity and future data processing. After a verified deletion request, VoltEdgeSystem targets deletion or irreversible anonymization of VoltEdgeSystem-controlled application data within 14 calendar days. Tesla-side records, provider-held data, backups, and vehicle-side virtual keys are separate outcomes. Contact us to ask about access, correction, deletion, or a copy of information associated with your account.

VoltEdgeSystem uses server-managed sessions and access controls, but no internet service can guarantee absolute security. Do not send passwords, access tokens, private keys, or sensitive vehicle details through the contact form.

The consent record includes the package and document versions and hashes, acceptance timestamp, effective Tesla permissions, telemetry and command configuration references, and approved security context. Security context may include source IP, request-derived location where available, browser and device details, locale, timezone, and session, transaction, request, or correlation identifiers.

The service is not directed to children. If you believe a child submitted personal information, contact us so the request can be reviewed. This policy may be updated as product behavior or applicable requirements change; the effective date above will be updated when the published policy changes.

Questions about these flows can be sent through Contact. Review Terms for the usage rules that apply to the same product surfaces.