Legal

    Privacy Policy

    Version 2.2 Effective Date: 25 July 2026 Last Updated: 28 August 2026

    PixellEnergy Solutions Private Limited ("PixellEnergy", "we", "us") operates the PixellEnergy EV lifestyle app, the PixellEnergy Balance, and related services. We are the Data Fiduciary for the personal data described here and process it under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the "DPDP law").

    This notice is standalone and itemised: you can see, item by item, what personal data we collect, why, and how to exercise your rights — without needing to read any other document. It is available in English; on request we will provide it in a language listed in the Eighth Schedule to the Constitution of India.


    1. Quick Summary

    • Guest mode: You can browse chargers without an account. When you do, your map position is used only to answer that request and is not stored or linked to you. An account (phone + OTP) is required only to start a charging session, pay, or use the PixellEnergy Balance.
    • We collect only what the Service needs: account details, your location only while the app is open, vehicle details, payment info (via our payment partners), charging and balance activity, and — only if you set them up — the emergency contacts you enter for Safety & SOS.
    • We do not sell your data and do not access your device's address book, SMS, call logs, or browsing history.
    • Some features share data with others only at your request (e.g. an SOS can share your approximate location with contacts you chose).
    • Your personal data is stored in India. The only disclosed cross-border flow is optional, opt-in product analytics (see §7–§8), which stays off until you consent.
    • You can access, correct, erase, export, nominate, and withdraw consent at any time, and raise a grievance.

    2. Who We Are & How to Contact Us

    Data Fiduciary: PixellEnergy Solutions Private Limited, Unicorn Club #113, 11th Cross, 19th Main, HSR Layout Sector 4, Bengaluru, Karnataka 560102, India.

    Data Protection Officer / Grievance Officer: Rahul — dpo@pixellenergy.com · +91 90720 02055.

    A direct link to withdraw consent, exercise your rights, or complain to the Data Protection Board is available in the app under Profile → Privacy, and by email to the DPO above.


    3. Personal Data We Collect (Itemised)

    CategoryWhatPurpose
    AccountName, phone number (used for OTP login), email (optional), vehicle detailsCreate and secure your account; deliver the Service
    LocationForeground (app-open) location onlyFind chargers, plan trips, and — if you use SOS — nearest-charger and location sharing you choose
    Guest (no account) map browsingApproximate map position sent with the request; no profile createdReturn nearby chargers for that request only — not stored, not logged against you, not linked to any identity
    CameraQR-code scan; optional vehicle photoStart a charging session; personalise your vehicle
    PaymentHandled by our PCI-DSS payment partners; we do not store full card numbersProcess charging payments, Balance top-ups, refunds
    Charging & Balance activitySessions, tariffs, invoices, Balance transactions, telemetryDeliver, bill, and support the Service; issue GST invoices
    Emergency contacts (optional SOS)Name and phone of up to five contacts you manually enter — we do not read your address bookSafety & SOS, only when you enable it
    Device & usageDevice, app, and diagnostic dataReliability, security, fraud prevention

    Guest mode (Android and iOS). You can browse chargers without an account. When you do, your map position is used only to answer that request and is not stored or linked to you. You only need to sign in (phone + OTP) when you want to start a charging session, pay, top up or use your PixellEnergy Balance, or use account features such as Safety & SOS, family sharing, and invoices.

    We request each category by affirmative consent, per purpose, with the exact notice recorded at the time.


    4. How We Use Your Data

    • Service delivery — discovery, charging, payments, Balance, receipts, support.
    • Safety & emergency response (SOS) — only when you enable and trigger it (§6).
    • Analytics & improvementseparate, optional consent; identifiers scrubbed (§7).
    • Marketingseparate, optional consent; you can opt out anytime.
    • Legal & financial compliance — tax invoices, records we are required to keep, fraud prevention, and responding to lawful requests.

    We rely on your consent for each purpose, and on legitimate/legal obligations where the DPDP law permits (e.g. retaining billing records).


    5. Consent & Your Control

    Consent is requested per purpose, by clear affirmative action, and is as easy to withdraw as to give; each consent is logged with the exact notice shown. Service, analytics, and marketing consents are independent — declining analytics or marketing does not affect your ability to use the Service. Withdrawing consent stops future processing for that purpose (it does not undo lawful past processing or records we must keep). Where a registered Consent Manager is available under the DPDP law, you may manage your consents through it.


    6. Safety & SOS — Shared Only At Your Request

    The feature is off until you use it; every sharing action is your explicit choice, with a specific notice and recorded consent.

    • Range alerts — while the app is open, we estimate range from the battery level you enter plus foreground location and may alert you on your screen; not shared.
    • Alerting your contacts (SMS) — on SOS (or auto-trigger at critically low battery), if enabled, we SMS the emergency contacts you entered (via MSG91). You are responsible for telling those contacts you listed them.
    • Sharing your location — if you choose, we create a secure link your contacts (and linked family) can open. Default is approximate (~500 m); you may choose exact. The link expires after 2 hours and you can revoke it sooner.
    • Community (V2V) broadcast — if you choose, we broadcast a help request to nearby opted-in volunteers showing only a masked approximate area.
    • Mobile charging unit — if available and requested, we share the dispatch details needed to reach you.
    • Emergency services — the screen can dial 112/108 via your phone's dialer; we do not place the call or share data with emergency services through the app.

    Legal basis for all SOS sharing is your consent; you can delete your contacts and stop using it anytime.


    7. Who We Share With (Sub-processors)

    Never sold; shared only to the minimum necessary to run the Service, under contract:

    • Payments: Razorpay and Cashfree (India).
    • SMS/OTP: MSG91 (India).
    • Hosting: Supabase (database / auth / functions, Mumbai / ap-south-1) and Cloudflare (CDN and secure reverse-proxy for Indian-network reachability).
    • Maps: Google Maps Platform (map/location queries).
    • Notifications / config: Firebase.
    • Diagnostics (error monitoring): Sentry — identifiers scrubbed.
    • Product analytics (optional, opt-in): PostHog (United States) — this is the only cross-border transfer, it is off until you consent, and identifiers are scrubbed.
    • Charging / roaming / franchise partners — as needed to fulfil a session you start.
    • Legal — where lawfully required.

    8. Storage & Cross-Border Processing

    Your personal data is stored at rest in India (Mumbai). The only disclosed transfer outside India is opt-in PostHog product analytics (US) (§7), which is off until you consent. Limited in-transit processing occurs as in §7 (Cloudflare edge may route encrypted traffic; map features send location queries to Google), under contractual and technical safeguards. We do not transfer personal data outside India except as permitted by the DPDP law.


    9. Retention

    • Account data: while your account is active.
    • Charging & financial records (invoices, Balance, tax): retained for the period required by the Income Tax Act, 1961 and GST law (typically up to 8 years).
    • SOS: event and SMS-delivery logs retained for safety audit (anonymised for analytics); shared-location links expire after 2 hours.
    • Deletion: on your request or account closure, personal data is soft-deleted and then permanently deleted after 30 days, except records we are legally required to keep.

    10. Your Rights (DPDP law)

    Free of charge, you may:

    • Access a summary of the personal data we process about you;
    • Correct / update / complete inaccurate data (we act within the timelines prescribed, ordinarily within 90 days for corrections);
    • Erase your data where the purpose is fulfilled and no law requires us to keep it;
    • Withdraw consent at any time;
    • Nominate another individual to exercise your rights in the event of death or incapacity;
    • Export your data — we fulfil export requests within 7 days;
    • Raise a grievance (§13).

    Exercise these via Profile → Privacy in the app, or by emailing the DPO.


    11. Data Breach Notification

    On becoming aware of a personal-data breach, we follow the two-stage process under Rule 7 of the DPDP Rules, 2025:

    1. we give the Data Protection Board of India an immediate intimation, followed by a detailed report within 72 hours (or longer if the Board allows); and
    2. we notify affected users without undue delay, describing the breach, its likely consequences, and the steps we and you can take.

    12. Children

    The Service is intended for adults (18+) only. We do not knowingly collect the personal data of children, and we do not undertake behavioural monitoring or targeted advertising directed at children.


    13. Grievance Redressal & the Board

    Contact our Data Protection / Grievance Officer at dpo@pixellenergy.com (or the address in §16). We will acknowledge your grievance within 72 hours and endeavour to resolve it within 30 days (up to 45 days for complex matters). If you remain unsatisfied, you may complain to the Data Protection Board of India.


    14. Security

    We protect your data with encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, least-privilege service credentials, PII scrubbing in logs and analytics, and periodic security review.


    15. Changes to This Policy

    We will post updates here with a new version and date, and — where the law requires — seek fresh consent for material changes.


    16. Contact

    PixellEnergy Solutions Private Limited Data Protection & Grievance Officer Unicorn Club #113, 11th Cross, 19th Main, HSR Layout Sector 4 Bengaluru, Karnataka 560102, India Email: dpo@pixellenergy.com · Phone: +91 90720 02055