Privacy Policy
Last updated: June 8, 2026
Marit.es ("we", "us", or "our") operates the Marit.es application, a Tesla vehicle monitoring and management platform available at app.marit.es. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection law.
1. Data Controller
The data controller responsible for your personal data is:
2. Data We Collect
When you use Marit.es, we collect:
- Tesla account tokens — obtained via Tesla's official OAuth flow. We store access and refresh tokens, both encrypted at rest, to maintain your connection without repeated logins.
- Vehicle data — including battery level, location history, drive records, charge sessions, sentry events, and vehicle state — fetched from your Tesla account via the Tesla Fleet API.
- Device identifier — a randomly generated UUID created on first app launch, not linked to your hardware or account, used solely as a stable key to update your FCM push notification token if it rotates. We also store the FCM token itself to deliver notifications.
- Notification preferences — notification types and schedules you configure within the app.
- App edition — whether you use Marit.es Core or Marit.es Lite, stored alongside your FCM token to route notifications correctly.
We do not collect your Tesla account password. Authentication is handled entirely through Tesla's official OAuth 2.0 flow.
3. Legal Basis for Processing
We process your personal data on the following legal bases (GDPR Article 6):
- Performance of a contract (Art. 6(1)(b)) — processing your vehicle data, tokens, and notification delivery identifier is necessary to provide the Marit.es service you have signed up for.
- Legitimate interests (Art. 6(1)(f)) — we process minimal technical data (logs, error traces) to maintain service security, detect abuse, and debug issues. These interests do not override your fundamental rights.
- Consent (Art. 6(1)(a)) — where we ask for optional permissions (e.g. additional notification types), we rely on your explicit consent, which you may withdraw at any time.
4. How We Use Your Data
Your data is used exclusively to provide Marit.es functionality:
- Displaying vehicle status, driving history, and charging history in the app.
- Sending push notifications for sentry alerts and other vehicle events you have enabled.
- Executing vehicle commands (e.g. sentry mode, honk horn) that you explicitly initiate.
- Storing your notification preferences and schedule settings.
We do not sell your personal data or use it to build advertising profiles. The Marit.es Lite app may display contextual banner advertisements served by a third-party ad network. These ads are not targeted using your vehicle data or personal information — ad content is determined by the ad provider based on contextual signals only (e.g. general app category). When this feature is active, the ad provider's own privacy policy will apply to their data collection.
5. Data Storage and Location
Your data is stored on servers we operate. We apply industry-standard security measures including HTTPS encryption in transit, encrypted storage for all tokens (both access and refresh), and restricted server access. Tokens are never exposed to third parties.
We never see or store your Tesla password. Login happens directly on Tesla's own OAuth page — your credentials are entered on tesla.com, not in Marit.es. Additionally, Tesla's Fleet API requires every vehicle command to be cryptographically signed with a key stored securely on our servers and verified by the car itself, so a leaked token alone cannot be used to unlock, start, or control your vehicle.
Our servers are located within the European Union. If your data is ever transferred outside the EU, we ensure equivalent protection is in place (see Section 7).
6. Data Retention
- Access and refresh tokens — retained for as long as your account is active. Deleted immediately upon account deletion or token revocation.
- Vehicle data (drives, charges, sentry events) — retained for up to 2 years, or until you delete your account.
- Device UUID and FCM token — retained until you uninstall the app or revoke notification permissions. The UUID is a random identifier generated on first launch and holds no hardware or personal information.
- Notification preferences — retained for as long as your account is active.
You may request deletion of all your data at any time by contacting [email protected].
7. International Data Transfers
Some third-party services we use are based outside the European Economic Area (EEA):
- Tesla Fleet API — Tesla, Inc. is headquartered in the United States. Vehicle data is fetched from Tesla's servers in the US. Tesla participates in data transfer frameworks and its transfers are subject to its own privacy commitments. See Tesla's Privacy Policy.
- Firebase Cloud Messaging (Google) — Google LLC is headquartered in the United States. FCM tokens and push notification payloads are processed by Google. Google relies on Standard Contractual Clauses (SCCs) for transfers from the EU. See Google's Privacy Policy.
We only transfer the minimum data necessary to these services to operate the functionality described in this policy.
8. Third-Party Services
We do not use Google Analytics, Facebook Pixel, or any other tracking or advertising SDK in the Marit.es Core app.
9. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of access (Art. 15) — you may request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — you may request correction of inaccurate data.
- Right to erasure (Art. 17) — you may request deletion of your personal data ("right to be forgotten").
- Right to restriction of processing (Art. 18) — you may request that we limit how we use your data in certain circumstances.
- Right to data portability (Art. 20) — you may request your data in a structured, machine-readable format.
- Right to object (Art. 21) — you may object to processing based on legitimate interests.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to lodge a complaint with your national data protection supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA). In other EU member states, contact your local DPA.
10. Cookies
The Marit.es marketing website (marit.es) does not use tracking or advertising cookies. The app at app.marit.es uses a session cookie solely to maintain your authenticated session. This cookie is strictly necessary for the service to function and does not require consent under applicable law.
11. Children's Privacy
Marit.es is not directed at persons under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. For material changes, we will notify you via the app or email where possible.
13. Contact
For privacy-related questions or to exercise your rights, contact us at [email protected].