Our security commitment
We follow a security-by-design and data-minimisation approach: we collect only what is needed to provide the service, protect it with recognised industry safeguards, and never sell your data. Our practices are reviewed and improved over time.
What data we collect
When you subscribe, we collect your account details and the billing information needed to process your subscription (payment details are handled by our payment provider, Stripe). For the service itself, the trip data needed to build your mileage log — date, distance, drive state and location captured from your connected Tesla. We do not collect more than we need.
How we use your data
Your data is used solely to provide the service: capturing trips, classifying them as business or personal, and producing compliance reports and exports for you. We do not use your data for advertising and we never sell or rent it to third parties.
Encryption
All data is encrypted in transit using TLS (HTTPS) and encrypted at rest by our infrastructure providers. Access to production systems is restricted and authenticated.
Access control and Tesla connection
The connection to your Tesla uses official OAuth authorisation with the minimum scopes required, and you can revoke access at any time from your Tesla account. Internally, we apply least-privilege access: only authorised personnel can access production data, and only when necessary.
Hosting and sub-processors
This website is hosted by Netlify, Inc. The service relies on a limited set of sub-processors (such as the hosting provider Netlify, the Tesla Fleet API, our payment provider Stripe, and Google Analytics). Each sub-processor is bound by appropriate data-protection terms. A current list is available on request.
Data retention and what happens if you leave
You can export your data at any time. Your subscription starts with a free trial, and if you cancel your subscription or close your account, we delete your personal data and trip history within 30 days, except where we must retain limited records to meet a legal obligation.
GDPR compliance
The data controller is ODYSSEE (see the Legal Notice). We process data on clear lawful bases (your consent or the performance of the contract) and honour your rights of access, rectification, erasure, restriction, objection and portability. Where data is processed outside the EU (for example by a US host), we rely on appropriate safeguards such as Standard Contractual Clauses. See our Privacy Policy for details, or contact us to exercise your rights.
Incident response
We maintain procedures to detect and respond to security incidents. In the event of a personal-data breach likely to affect your rights, we will notify the competent supervisory authority without undue delay (and within 72 hours where required) and inform affected users as required by law.
Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, please contact security@odoproof.com. Please give us a reasonable opportunity to address the issue before any public disclosure.