Privacy Policy
Last updated August 27, 2026. PlugLocate is a product of Outofbox Solutions.
Operator: Outofbox Solutions (“Outofbox,” “we,” “us,” or “our”)
Product: PlugLocate (the “App” and related website at
pluglocate.com)
Contact: support@pluglocate.app
This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use PlugLocate and our website. By using the App or website, you acknowledge this Policy. If you do not agree, do not use our services.
This document describes our practices for users and app stores. It is not legal advice. See also our Terms of Use.
1. Who we are
PlugLocate is a product of Outofbox Solutions. We provide an informational EV charging discovery experience: maps, search, trip planning aids, and optional community features. We are not a charging network operator and do not control stations, pricing, or live availability.
2. Scope
This Policy covers:
- The PlugLocate mobile application (iOS and Android)
- The public website at pluglocate.com
- Backend services we operate for the App (authentication, profiles, community content, catalogs)
Staff-only admin tools on the website may use session cookies for authenticated moderators. Those tools are not part of the consumer product experience.
3. Accounts are optional
You can browse core station discovery without creating an account (guest use). If you choose to sign in, we support email and password, Sign in with Apple, and Sign in with Google.
When you create or use an account, we process authentication data through our auth provider (Supabase Auth) and may store a profile linked to your user ID (for example display name, avatar image path, and optional vehicle plug-type preferences). Signed-in features such as cloud favorites, check-ins, tips, and photo submissions require an account.
4. Information we collect
4.1 Location information
- We request foreground (“when in use”) location permission to show nearby stations, calculate distances, center the map, bias search, support trip-related features, and look up walkable places near a station. We do not use background continuous tracking for these features.
- Location may be cached on your device for a limited time to improve performance.
- We do not maintain a server-side profile of your continuous GPS track.
- To deliver features, approximate or precise coordinates (and related search queries) may be sent to third-party services listed below (station lookup, geocoding, routing, Nearby amenities, and map tiles).
- We may cache Nearby amenity lookup results on our servers by geohash (approximate area), not tied to your user ID.
- You can disable location in device settings; some features will be limited.
4.2 Account and profile information
Depending on how you sign in, this may include:
- Email address
- Authentication credentials (passwords are hashed and managed by our auth provider; we do not store plaintext passwords)
- Name or display name (including names provided by Apple or Google on first sign-in, where applicable)
- Profile avatar you upload
- Optional default connector / plug-type preferences
4.3 User-generated and community content (when signed in)
- Favorites: station identifiers linked to your account
- Check-ins: station identifier, sentiment / success feedback, linked to your account (aggregates may be readable by others)
- Tips / comments: text you submit, linked to your account; approved tips may show a display name
- Station photos: images you upload plus related metadata (station identifier/name, submission time, platform/OS version, app version) for moderation and display
Photos and tips are typically reviewed before public display.
4.4 Device-local preferences and history
Stored primarily on your device, including:
- Search history (place descriptions and coordinates)
- Filter, sort, theme, and distance-unit preferences
- Local caches (location, favorites, amenities, and similar)
4.5 Communications
If you have an account or contact us, we may process your email address to send account security and authentication messages (confirmation, password reset / OTP, password-changed notices), transactional messages such as a welcome email, and responses to support requests. Email delivery may use processors such as Resend and our auth provider’s email configuration.
4.6 Website technical data
Our marketing site is primarily static. Hosting infrastructure (for example Vercel) and third-party resources (for example fonts loaded from Google Fonts) may process standard technical data such as IP address and request logs under their own practices. We do not currently embed a first-party advertising or product-analytics SDK on the marketing site. Admin login sessions use authentication cookies for authorized staff only.
4.7 App configuration and operational status
The App periodically requests lightweight operational configuration from our servers (for example maintenance or status messaging, minimum supported app versions for force-update notices, and dashboard-configured share or contact details such as a download URL, support email, and optionally a support phone number displayed in Settings). These requests are used to operate the product safely and do not include advertising or marketing analytics. We do not use this channel to build a continuous location history. We do not collect your phone number through this configuration — any phone shown is our published contact detail.
4.8 Information we do not collect (current product)
- Payment card or billing information (we do not sell charging sessions in-app)
- Advertising identifiers for ads; we do not use App Tracking Transparency for cross-app advertising
- We do not currently integrate a dedicated third-party crash-reporting or product-analytics SDK in the App. If that changes, we will update this Policy and relevant store disclosures.
5. How we use information
- Provide and operate PlugLocate (maps, search, distances, trip aids, Nearby places, accounts)
- Sync and display optional account features (profile, favorites, community content)
- Moderate user-submitted photos and tips
- Send authentication and security-related emails
- Deliver operational configuration (status messaging, minimum versions, support/share contact details)
- Protect API quota and prevent abuse (including TomTom-related counters)
- Respond to support requests
- Maintain security and troubleshoot issues
- Improve reliability and features of the service
- Comply with legal obligations where applicable
We do not sell your personal information. We do not use your data for third-party advertising networks.
6. How we share information
6.1 Service providers / processors
- Supabase — authentication, database, file storage, edge functions
- Google — Sign in with Google; optionally Maps when you choose to open directions
- Apple — Sign in with Apple; optionally Maps when you choose to open directions
- Resend (and related email infrastructure) — transactional and auth-related email
- Hosting providers (for example Vercel) — website hosting and related logs
6.2 Functional third-party data and map services
To show stations, places, routes, amenities, and maps, the App may send queries and/or coordinates to services such as Open Charge Map; U.S. DOE Alternative Fuel Data Center / NLR-derived catalog data we host; OpenStreetMap-related services (including Nominatim), Photon (Komoot), Overpass API, OSRM — including Nearby walkable places (food, restrooms, shops, and similar) around a selected station; and map tile providers (for example CARTO / OSM-based tiles). When a signed-in user explicitly selects “Check live ports,” we also send the selected station’s coordinates and identifying station details through our backend to TomTom to locate a matching charging site and retrieve cached or current connector availability. Upstream TomTom requests are not made for guests, on list/map browsing, or in the background. Guests and signed-in users may still call our eligibility endpoint with a station identifier only (no TomTom upstream call) so the App can decide whether to show the live-ports control. We also keep short-lived per-user and/or IP quota counters related to TomTom usage to protect API quota and prevent abuse (not for advertising). These providers process requests under their own privacy policies.
6.3 Legal and safety
We may disclose information if required by law, legal process, or to protect the rights, safety, and security of users, Outofbox Solutions, or the public.
6.4 Business transfers
If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to appropriate confidentiality.
6.5 Public community content
Approved tips, public profile display names/avatars used in community UI, and aggregate check-in signals may be visible to other users of the App.
7. Third-party data we display (not collected from you)
PlugLocate is largely an aggregator / directory. Station, map, amenity, and routing information is obtained from third parties and public datasets, including U.S. DOE AFDC / NLR-sourced catalog data, Open Charge Map (CC BY 4.0 where applicable), OpenStreetMap contributors and related services (including Nearby walkable places while you charge), and OSRM for driving route geometry. Signed-in users may also request best-effort live port availability from TomTom.
We display this information for convenience. Accuracy, completeness, pricing, connector details, access rules, Nearby place listings, hours, and availability can change without notice and may be wrong or out of date. Additional liability and warranty disclaimers appear in our Terms of Use.
8. Retention
- Account and profile data: retained while your account remains active, or as needed for security and legal compliance
- Favorites, check-ins, and tips / comments: retained until you delete them (where the product allows), you delete your account, or we remove them through moderation or legal requirements. When you delete your account in the App, these records linked to your user ID are removed via our deletion process (cascade), subject to backups and legal holds.
- Station photos: images you submit may remain in the shared station catalog after account deletion because photo submissions are not always cascade-deleted with your auth user. We may remove photos through moderation or on request where feasible.
- Device caches and local preferences: until you clear app data or uninstall
- Email and support records: retained as reasonably needed to provide support and maintain security
- Server amenity geohash cache: retained for performance for a limited operational period (not tied to your user ID)
- TomTom station mapping and availability cache: retained to reduce third-party API calls and protect service quota; mappings may be long-lived, while availability freshness is server-configured
- TomTom quota / rate-limit counters: short-lived per-user and/or IP records used only for quota protection and abuse prevention
Account deletion
You can delete your account in the App (Profile / Settings where available) or by emailing support@pluglocate.app. When deletion succeeds we delete your auth user and profile (including removing your avatar from storage where stored under your user ID); remove favorites, check-ins, and tips linked to your account; may leave previously submitted station photos in the shared catalog; and may retain email/support logs, security records, and short-lived quota counters as needed for legal, security, or abuse-prevention reasons. Approved community tips you posted are removed with your account; they are not kept as anonymous posts by default.
9. Security
We use technical and organizational measures appropriate to our size and the nature of the data, including:
- Encrypted transport (HTTPS) to our backends
- Access controls and row-level security patterns on our backend where applicable
- Encrypted session storage on device for auth tokens
- Moderation of certain user-generated content before public display
No method of transmission or storage is 100% secure. You are responsible for keeping your device and account credentials safe.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of certain personal information, or to object to or restrict certain processing.
You can:
- Control location, camera, and photo-library permissions in device settings
- Edit profile information in the App when signed in
- Delete your account in the App (where available) or request deletion by emailing support@pluglocate.app
- Request access or correction by contacting us at the same email
- Uninstall the App to stop on-device collection going forward
California / similar U.S. state privacy laws: We do not sell personal information and do not share personal information for cross-context behavioral advertising as those terms are commonly defined. Contact us to exercise applicable state privacy rights.
EEA/UK (if applicable): We process data to provide the service you request, for our legitimate interests in operating a secure product, and/or with consent where required. Contact us to exercise GDPR-style rights. We may ask you to verify your identity before fulfilling certain requests.
11. Children’s privacy
PlugLocate is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The App is intended for drivers and EV owners who can lawfully use the service (generally 16+). If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
12. International processing
We and our processors may process information in Canada, the United States, and other countries where our providers operate. Those countries may have different data-protection laws than your home jurisdiction.
13. Changes to this Policy
We may update this Privacy Policy from time to time. We will revise the “Last Updated” date and post the updated Policy at this URL. Material changes may also be communicated in-app or by email when appropriate. Continued use of the App or website after an update means you accept the revised Policy, to the extent permitted by law.
14. App Store and Play Store disclosures
Apple App Store Privacy Labels and Google Play Data Safety forms are separate structured disclosures. We aim to keep them consistent with this Policy. Store forms should be refreshed whenever collection practices change (for example optional accounts and linked community content).
15. Contact us
Outofbox Solutions — PlugLocate privacy inquiries
Email: support@pluglocate.app
Website: https://www.pluglocate.com
Terms of Use: https://www.pluglocate.com/terms