Privacy Policy
Privacy Policy – MeruX App & Website. Version 1.2, effective June 1, 2026.
1. Data Controller
The controller within the meaning of the GDPR is:
Jens Schneider (Owner, bluepolicy)
Knütgenstr. 12
53721 Siegburg, Germany
Email: jens.schneider@bluepolicy.de
Phone: +49 178 1482348
Website: https://merux.app
2. Overview
This Privacy Policy informs you about the nature, scope and purpose of the processing of personal data in connection with your use of: the MeruX Mobile App (iOS & Android), the MeruX Website (https://merux.app), and the MeruX API Backend (accessed by the app).
MeruX is an electric vehicle (EV) charging management platform. Users can manage wallbox chargers (via OCPP protocol), monitor charging sessions, register vehicles, and generate billing reports.
3. Data Collected and Purposes
3.1 Account Registration & Authentication
Data types: full name, email address, phone number (optional), authentication method (email/password or Google Sign-In via OAuth), session tokens (JWT-based, stored in encrypted device storage), password (hashed/encrypted, never stored in plain text).
Purpose: creating and managing user accounts; authentication and authorization for API access. Legal basis: Art. 6(1)(b) GDPR (performance of contract). Third-party provider: Microsoft Azure Entra External ID (CIAM) – identity management, single sign-on. Server location: EU (West Europe). Legal basis for transfer: Art. 46 GDPR (Standard Contractual Clauses).
3.2 User Profile & Settings
Data types: address (street, city, postal code, state, country), profile picture URL (optional, stored in Azure Blob Storage), employee ID and employee name (optional, for B2B use), currency preference, report language preference, guest mode flag (anonymous use without account).
Purpose: app personalization; assignment of charging sessions to user accounts; B2B employee identification for billing purposes. Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR (legitimate interest in account personalization) for optional fields.
3.3 Chargers (Wallboxes)
Data types: serial number of the charging station; user-defined name, brand, model; installation address (street, city, postal code, country); location description (free text); connection status, security profile; communication data via OCPP 1.6/2.0.1 protocol (authenticated WebSocket); connector type (plug type, max. charging power in kW).
Purpose: operation and monitoring of charging infrastructure; fault detection; charge control; OCPP communication with the charging station. Legal basis: Art. 6(1)(b) GDPR.
3.4 Vehicle Data
Data types: user-defined vehicle name; make, model; license plate number; version history (when updated, previous versions are retained with a timestamp).
Purpose: assignment of charging sessions to a vehicle; analysis of charging activities; generation of billing reports (e.g., for tax benefit-in-kind documentation). Legal basis: Art. 6(1)(b) GDPR. Note on license plates: the license plate is personal data. It is used exclusively for vehicle identification in reports and is not shared with third parties.
3.5 Charging Sessions & Meter Values
Data types: session ID, start/end time; start/end meter reading (watt-hours); total energy transferred (kWh, aggregate and per phase L1/L2/L3); charging cost (total cost in EUR); stop reason (e.g., Remote, Local, EVDisconnected); real-time meter values (timestamped MeterValues via OCPP, JSON format); OCPP transaction ID; authorization tag (RFID tag ID, if used).
Purpose: billing and cost statement; generation of charge receipts (PDF with digital signature); tax documentation for company car charging at home; energy analysis; fault detection. Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (legal retention obligation for accounting records, §§ 238 et seq. HGB, 10 years).
3.6 Subscription & Payment Data
Data types: Stripe customer ID, subscription status, plan type; payment method details (card last four digits, expiry date – metadata only); billing address; transaction IDs, webhook events. Note: full payment card data (card number, etc.) is processed exclusively by Stripe. bluepolicy/MeruX does not store payment card information.
Purpose: processing subscription payments; feature unlocking; invoicing. Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (tax retention obligation). Third-party provider: Stripe Payments Europe, Ltd. (Ireland, EU). Stripe is engaged as a data processor. Data may be transferred to the USA based on Standard Contractual Clauses (SCCs) pursuant to Art. 46 GDPR.
3.7 Push Notifications
Data types: Expo Push Token (device-specific token for push messages); notification content and metadata (title, body, type, timestamp).
Purpose: real-time notifications about charging start/stop, charger errors, and session completion. Legal basis: Art. 6(1)(a) GDPR (consent – granted via system permission dialog); Art. 6(1)(b) GDPR for operationally essential status notifications. Third-party providers: Expo (Expo Inc., USA) – push delivery infrastructure, transfer to USA based on SCCs; Apple APNs (Ireland/USA) and Google FCM (USA) – forwarded by Expo.
3.8 Billing Reports & Meter Evidence
Data types: name, vehicle license plate, charging session data (see 3.5); generated PDF documents with digital signature (PKCS#7, Azure Key Vault); QR code link for verification.
Purpose: creation of legally compliant meter evidence for employees (tax proof for company car home charging); forwarding to employer for cost reimbursement. Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (§ 147 AO, 10-year retention). Storage location: Azure Blob Storage (container: meter-evidence), region: EU (West Europe).
3.9 Guest Mode
Data types: temporary session ID (no persistent user ID); charging session data during the guest session. Purpose: enables charging without account registration for guests (e.g., visitors). Legal basis: Art. 6(1)(b) GDPR (performance of contract for guest charging session).
3.10 Family / Sub-Accounts
Data types: link between user accounts within the same household / organization; has_family_account flag. Purpose: shared use of charging infrastructure by multiple persons in a household or organizational unit. Legal basis: Art. 6(1)(b) GDPR.
3.11 Energy Prices (Tibber OAuth Integration)
Data types: Tibber OAuth authorization code and access token (stored encrypted); Tibber Home ID (ID of the selected household electricity supply); Tibber contract address (postal code, city, country); market price data (dynamic electricity prices, anonymized).
Purpose: dynamic cost calculation based on current market prices via OAuth-linked Tibber account (optional, only when Tibber integration is enabled). Legal basis: Art. 6(1)(a) GDPR (consent via optional activation and explicit OAuth authorization step); Art. 6(1)(b) GDPR. Third-party provider: Tibber AS (Norway, EEA), processed under GDPR-equivalent rules. Revocation: the Tibber connection can be disconnected at any time in app settings. The stored token is deleted upon disconnection.
3.12 OCR & Image Processing (AI-Powered Feature)
Data types: images of charging stations/displays (user-uploaded, optional); extracted text information (meter readings, serial numbers). Purpose: automatic meter reading recognition via camera (optional feature for non-OCPP charging stations). Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(a) GDPR (consent for camera access). Third-party providers: OpenAI, Inc. (USA) – primary OCR via Vision API, transfer to USA based on SCCs; Microsoft Azure Computer Vision (EU region) – fallback.
EU AI Act Transparency (Art. 50 Regulation (EU) 2024/1689, applicable from August 2, 2026): this feature uses an AI system (OpenAI Vision API) for automated image analysis. No automated decision-making with legal effect takes place. Users can correct all recognized values at any time. The AI processes only the images uploaded by the user; OpenAI does not store the original data for training purposes (OpenAI API Terms of Service: no training on API data without opt-in).
3.13 Website Usage (merux.app)
Data types: IP address (anonymized after 24 hours); browser type, operating system; pages visited, timestamps, referrer; session cookies (technically necessary). Purpose: website delivery, technical operation, security (attack detection). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation); § 25(2) TDDDG for technically necessary cookies. Not used: Google Analytics, Meta Pixel, or similar tracking tools on the main website (confirmed: Cloudflare security cookies only, no analytics tracking).
3.14 Server Logs
Data types: IP address, HTTP method, URL, status code, timestamp; rate limiting data (IP-based, Redis); IP block list (for repeated violations, max. 1 hour). Purpose: operational security, error correction, abuse prevention. Legal basis: Art. 6(1)(f) GDPR. Retention: server logs are automatically deleted after 30 days.
3.15 Reimbursement Data (Reimbursement Tracking)
Data types: month and year of reimbursement period; reimbursement status (pending / submitted / reimbursed); total energy quantity (kWh), total amount, number of charging sessions, currency; free-text notes (optional, user-entered); timestamps.
Purpose: supporting the employee reimbursement workflow vis-à-vis the employer; summarizing charging billing data by calendar month for tax and organizational purposes (German BMF letter of 11 November 2025). Legal basis: Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (§ 147 AO statutory retention obligation). Retention: linked to the associated charging session (8 years under § 147 AO).
3.16 Company Vehicle Selection (B2B Feature)
Data types: employee consent record (employee ID, tenant ID, status, employee name, email); vehicle designation (vehicle ID, make, model, name, license plate, approval status, rejection reason, timestamp).
Purpose: linking company vehicles to employee accounts for B2B tenants; approval workflow for employer administrators. Legal basis: Art. 6(1)(b) GDPR (performance of contract in B2B context); Art. 6(1)(f) GDPR (legitimate interest of the employer in managing company vehicles). Note: this feature is only active for users belonging to a corporate account (tenant). Data is visible exclusively to the relevant employer administrator and the affected employee.
4. Recipients and Processors
We engage the following service providers as data processors (Art. 28 GDPR):
- Microsoft Azure — cloud hosting (VMs, database), Blob Storage, Key Vault — EU (West Europe) — Art. 46 GDPR (SCCs + EU DPA)
- Microsoft Azure Entra ID (CIAM) — identity management, authentication — EU / USA — Art. 46 GDPR (SCCs)
- Azure Communication Services — email OTP delivery — EU / USA — Art. 46 GDPR (SCCs)
- Stripe Payments Europe, Ltd. — payment processing, subscriptions — EU (Ireland) / USA — Art. 46 GDPR (SCCs)
- Expo (Expo Inc.) — push notifications — USA — Art. 46 GDPR (SCCs)
- Apple Inc. (APNs) — iOS push notifications — USA (EU routing) — Art. 46 GDPR (SCCs)
- Google LLC (FCM) — Android push notifications — USA (EU routing) — Art. 46 GDPR (SCCs)
- OpenAI, Inc. — OCR / image analysis (optional feature) — USA — Art. 46 GDPR (SCCs)
- Tibber AS — dynamic electricity pricing (optional) — Norway (EEA) — Art. 45/46 GDPR
- Apple App Store / Google Play — app distribution — USA — own privacy policies
A complete sub-processor list is available at: https://merux.app/subprocessors
5. International Data Transfers
Some of the processors listed above process data in the USA or other third countries outside the EU/EEA. These transfers are safeguarded by: EU Standard Contractual Clauses (SCCs) pursuant to Art. 46(2)(c) GDPR (2021 edition); adequacy decisions by the European Commission (where applicable, e.g., Norway); the EU-U.S. Data Privacy Framework (for certified U.S. companies). We can provide the specific safeguards on request.
6. Retention Periods
- User account data — until account deletion + 30 days (recovery period)
- Charging session data — 3 years (active use) + up to 10 years for accounting records (§ 147 AO)
- Meter evidence (PDFs) — 10 years (§ 147 AO, statutory retention)
- Push tokens — until logout / app uninstall
- Server logs — 30 days
- Deleted users — pseudonymized, max. 90 days
- Redis cache (rate limiting) — max. 1 hour (IP blocks)
After the retention period expires, data is automatically deleted or anonymized unless statutory retention obligations require otherwise.
7. Your Rights
As a data subject, you have the following rights:
- Right of access (Art. 15 GDPR): you may request information about the personal data we hold about you.
- Right to rectification (Art. 16 GDPR): you may request correction of inaccurate or incomplete data. Many details can be updated directly in the app under Settings → Profile.
- Right to erasure (Art. 17 GDPR): you may request deletion of your data. The app provides a direct option under Settings → Delete Account. Statutory retention obligations (e.g., accounting records under § 147 AO) may prevent full deletion.
- Right to restriction of processing (Art. 18 GDPR): you may request restriction of processing where the statutory conditions are met.
- Right to data portability (Art. 20 GDPR): you may request your data in a machine-readable format (JSON/CSV), where processing is based on consent or contract and carried out by automated means.
- Right to object (Art. 21 GDPR): you may object to processing based on Art. 6(1)(f) GDPR (legitimate interest).
- Right to withdraw consent (Art. 7(3) GDPR): you may withdraw consent at any time with effect for the future (e.g., push notifications via device settings).
Exercising your rights: please contact us by email at jens.schneider@bluepolicy.de. We will process your request within 30 days.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. Competent authority for bluepolicy (North Rhine-Westphalia, Germany):
State Commissioner for Data Protection and Freedom of Information NRW
(Landesbeauftragte für Datenschutz und Informationsfreiheit NRW)
Postfach 20 04 44
40102 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Website: https://www.ldi.nrw.de
9. Data Security
We implement technical and organizational measures (TOMs) to protect your data:
- Transport encryption: TLS 1.2+ for all API connections (HTTPS only)
- OCPP connections: WebSocket Secure (WSS) with authentication tokens
- Database connections: SSL encryption (PostgreSQL 15)
- Token storage (app): expo-secure-store (iOS Keychain / Android Keystore)
- Password hashing: bcrypt
- PDF signatures: PKCS#7 digital signature via Azure Key Vault
- Rate limiting: 100 requests/minute per IP (Redis-backed)
- IP blocking: automatic blocking after 50 suspicious requests
- Tenant isolation: all database queries are scoped to tenant_id
- Infrastructure: Azure VM with Docker, Nginx reverse proxy, Let's Encrypt SSL
A detailed description of our security measures is provided in our Technical & Organizational Measures (TOM) document.
10. Cookies and Similar Technologies
App (iOS/Android): the MeruX app uses secure storage (expo-secure-store) for authentication tokens — technically necessary, not a cookie in the traditional sense — and a device-specific push token, only with your consent.
Website (merux.app): technically necessary cookies/session tokens required for website operation. No consent required (§ 25(2)(2) TDDDG). Full cookie information is available in the Cookie Policy at https://merux.app. All cookies used are technically necessary; no marketing or analytics cookies are set.
11. Special Notes for Business Users (B2B)
Where you use MeruX within an organizational context: the controller for employee data processing (e.g., license plates, charging sessions) is typically your employer (the organization). bluepolicy may act as a data processor in this context. In such cases, we enter into a Data Processing Agreement (DPA) with your employer pursuant to Art. 28 GDPR. For inquiries about your personal data, please also contact your employer.
12. Special Categories of Data
MeruX does not process special categories of personal data within the meaning of Art. 9 GDPR (e.g., no health, racial, or biometric data). Regarding travel/location profiles: charger installation addresses may allow inferences about regular locations. This data is not used for profiling purposes and is not shared with advertisers.
13. AI Systems and Automated Decision-Making (EU AI Act)
13.1 AI systems in use — pursuant to Art. 50 of Regulation (EU) 2024/1689 (EU AI Act, applicable from August 2, 2026), we inform you about the use of AI systems: OpenAI Vision API — OCR receipt capture (non-OCPP charging) — provider OpenAI, Inc., USA — minimal risk (Art. 50 transparency obligation).
13.2 Automated decision-making — no automated decision-making within the meaning of Art. 22 GDPR (including profiling with legal effects) takes place. MeruX is not a high-risk AI system within the meaning of Annex III of the EU AI Act.
14. Children
MeruX is not directed at persons under 18 years of age. We do not knowingly collect data from minors. If you are a parent or guardian and become aware that your child has submitted personal data, please contact us.
15. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy if legal requirements change or we introduce new features. The current version is always available at https://merux.app/privacy. For material changes, registered users will be notified by email or in-app notification.
16. Contact for Privacy Inquiries
For data protection questions:
Jens Schneider (Owner, bluepolicy)
Knütgenstr. 12
53721 Siegburg, Germany
Email: jens.schneider@bluepolicy.de
Data Protection Officer: as a sole trader with fewer than 20 persons regularly engaged in automated processing, bluepolicy is not required to appoint a Data Protection Officer under Art. 37 GDPR.
Last updated: May 12, 2026 | Version 1.2 | Effective 2026-06-01