United Kingdom edition

Privacy Notice

What personal data Niko collects, why, and what you can do about it.

Version 1.0 Effective 2026-09-01 Last updated 2026-08-27 Governed by the law of England and Wales
Draft — not yet in force. This edition still has 9 unfilled detail(s), shown highlighted below. They must be completed, and the wording reviewed by a qualified legal adviser in the United Kingdom, before it is published to users.
You are reading the United Kingdom edition. It is written for the law of England and Wales.
This is currently the only published edition. If you use Niko elsewhere, the mandatory consumer and data protection rules of the country you live in still apply to you.

The short version

We collect the minimum Niko needs to work: who you are, which vehicle is yours, and what you asked the vehicle to do. We never see or store your vehicle manufacturer password. We never store your full card number. We do not sell your data, and we do not use it for advertising.

Your vehicle's location is the most sensitive thing we handle. We request it only because the app shows you where your car is, we keep it only as long as we need to, and you can withdraw our access at any time by disconnecting the vehicle.

Who is responsible for your data

registered company name, exactly as at Companies House (company number Companies House registration number, registered office registered office address, including postcode) is the controller of the personal data described here. We are registered with the ICO under registration number ICO data protection fee registration number (register at ico.org.uk/registration).

For anything about privacy or your data, write to privacy address, e.g. privacy@nikoapp.co.uk, or to address the public can write to. We are not required to appoint a Data Protection Officer, so privacy enquiries are handled by the address above.

This notice is written for the United Kingdom and describes your rights under the UK GDPR and the Data Protection Act 2018.

What we collect and why

The table sets out every category of personal data we hold, why we hold it, and the lawful basis we rely on.

WhatWhy we need itLawful basis
Account
Your name, email address, a hashed password, whether your email is verified, when you accepted these terms, and your marketing preference.
To create and secure your account, to let you sign in, and to prove that terms were accepted. Performance of a contract. Consent, for marketing only.
Sign-in with Apple or Google
The identifier that provider gives us for you, the email address they release (which for Apple may be a private relay address), and when you last used it.
To let you sign in without a separate password, and to recognise you on your next visit. Performance of a contract.
Sessions
A one-way digest of each sign-in token, the device or browser description your app sends, and the times a session was issued, used, expired or revoked.
To keep you signed in, to let you sign other devices out, and to detect a stolen token being reused. Performance of a contract. Legitimate interests in securing accounts.
Manufacturer connection
An encrypted access token and refresh token for your vehicle manufacturer account, the permissions granted, when they expire, and which regional service your account belongs to.
To talk to your vehicle on your behalf. We never receive your manufacturer password. Performance of a contract.
Vehicle identity
Vehicle identification number (VIN), the manufacturer's own identifier, the name you have given the car, and when it was last reachable.
To list your vehicles and to address commands to the right one. Performance of a contract.
Vehicle state
Battery level, range, charge limit, charging state and current, whether the charge port, boot or front boot is open, whether the car is locked, whether Sentry Mode or Valet Mode is on, odometer reading, inside and outside temperature, climate setting, and the car's colour, wheels, trim and model.
To show you the state of your vehicle in the app. Performance of a contract.
Vehicle location
Latitude, longitude, heading, and the time the position was recorded.
To show you where your vehicle is on the map. We request this permission from your manufacturer only because the app offers that feature. Performance of a contract.
Commands and their outcomes
What you asked the vehicle to do, when, any values you set, whether it succeeded, how many attempts it took, and any error returned.
To carry out your instruction, to avoid sending it twice, to retry a command that failed, and to keep a record of what was sent to your vehicle and by whom. Performance of a contract. Legitimate interests in security and in being able to investigate a dispute.
Delivery and orders
Delivery addresses, order references, what was ordered, the amount and currency, and when it was placed.
To fulfil an order and to keep the accounting records the law requires. Performance of a contract. Legal obligation, for tax records.
Payment methods
Card brand, the last four digits, the expiry date, and a token held by our payment provider. We never store your full card number, and our database is built so that it cannot be.
To let you recognise a saved card, and to charge it through the provider. Performance of a contract.
Diagnostics
Crash reports, error messages, technical context about the failure, and the app version.
To find and fix faults. We are only told that a failure happened and what the software was doing. Legitimate interests in a working, secure product.
Product analytics
Which screens and features are used, and events such as a sign-in succeeding or a command failing.
To understand which parts of the app work and which do not. Legitimate interests, or your consent where the platform requires it.
Support
What you write to us, and our reply.
To answer you and to keep a record of the exchange. Legitimate interests in supporting our users.

Where we rely on legitimate interests

Where the table says “legitimate interests”, we have weighed our interest against your rights and concluded that our use is one you would reasonably expect and that it does not override your interests. Those interests are: keeping accounts and vehicles secure; detecting and preventing fraud and unauthorised access; diagnosing faults; and improving the product. You can object to any of it at any time — see your rights.

Location, and why we treat it carefully

  1. Vehicle location can reveal where you live, work and travel. We treat it as the most sensitive category we handle, even though it is not “special category” data under UK data protection law.
  2. We request location permission from your manufacturer only so that the app can show you your vehicle. We do not build movement profiles, we do not sell or share location with advertisers or data brokers, and we do not use it to infer anything about you.
  3. You can stop it at any time by disconnecting the vehicle in Niko, or by revoking our access in your manufacturer account.
  4. If a vehicle is used by more than one person, whoever connects it should tell the others that its position can be seen in the app.
  5. Niko reads whether Sentry Mode is switched on. It does not receive, store or have any access to camera footage from your vehicle.

Where the data comes from

  • From you — when you create an account, connect a vehicle, place an order, or contact us.
  • From your device — when the app reports an error or an event.
  • From your vehicle manufacturer — vehicle identity, state and location, which we receive because you authorised the connection.
  • From Apple or Google — if you choose to sign in with them, the identifier and email address they release to us.

Who we share it with

We do not sell your personal data and we never share it for anyone else's advertising. We share it only with the organisations below, only for the purposes shown, and only under a written contract that requires them to protect it.

WhoWhat they receiveWhy
Your vehicle manufacturer (Tesla, Inc. and its group)Your authorisation token and the commands you send; they return vehicle data to us.There is no other way to reach your vehicle. They are a separate controller of the data held in your manufacturer account, under their own privacy policy.
Apple — Sign in with Apple
Google — Google Sign-In
Only what is needed to complete a sign-in you started.To verify who you are without our holding a password.
Our hosting provider, hosting provider nameEverything we store, as the infrastructure it runs on.To run the service. Data is held in country the servers sit in.
PostHog — product analyticsUsage events tied to a pseudonymous identifier.To understand how the app is used. We use its European hosting, so this data stays in the EU.
Sentry — error monitoringCrash and error reports, with technical context.To find and fix faults.
Our email providerYour email address and the message being sent.To deliver verification, sign-in and service emails.
Our payment providerCard details you enter, which go to them directly.To take payment. They are a separate controller for payment and fraud checks.

We also look up electricity tariff prices from Octopus Energy so the app can estimate charging cost. Those are published prices: we do not send them any of your personal data.

Beyond that, we will disclose data only where the law requires it, where we must to establish or defend a legal claim, to protect someone's safety, or to a buyer if the business is sold — in which case we would tell you first.

Sending data outside the United Kingdom

  1. Our own systems keep your data in country the servers sit in. Our analytics provider is configured to use European hosting.
  2. Some of the organisations above are based outside the United Kingdom, principally in the United States. Where data reaches them we rely either on UK adequacy regulations covering the destination, or on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment.
  3. You can ask us for a copy of the safeguards that apply to any particular transfer by writing to privacy address, e.g. privacy@nikoapp.co.uk.

How long we keep it

WhatHow long
Account and identityWhile your account is open, then 30 days after you close it, so an accidental deletion can be undone.
Manufacturer tokensDeleted as soon as you disconnect the vehicle or close your account.
SessionsUntil the session expires or is revoked, then 90 days for security investigation.
Vehicle state and locationHeld only as long as needed to show it to you and to serve recent history in the app; not retained after the vehicle is disconnected.
Commands and the audit record12 months. A record of what was sent to a vehicle is what allows a dispute about it to be resolved.
Orders, invoices and payment records6 years after the end of the tax year they relate to, because tax law requires it.
Diagnostics and analyticsUp to 12 months, then deleted or aggregated so no individual can be identified.
Support correspondence24 months after the matter is closed.

When a period ends we delete the data or irreversibly anonymise it. Backups are overwritten on their own cycle, so a deleted record may persist in a backup for a short period before it is written over.

Your rights

UK data protection law gives you the following rights. Exercising any of them is free, and we will answer within 30 days. If a request is unusually complex we may extend that, and we will tell you why.

  • Access. Ask for a copy of the personal data we hold about you, and for an explanation of how we use it.
  • Rectification. Have inaccurate data corrected and incomplete data completed.
  • Erasure. Ask us to delete your data where we no longer need it, where you withdraw consent we relied on, or where you object and we have no overriding ground to continue.
  • Restriction. Ask us to pause our use of your data while a dispute about its accuracy or our grounds is resolved.
  • Portability. Receive the data you gave us in a structured, commonly used, machine-readable format, and have it sent to another provider where that is technically feasible.
  • Objection. Object to processing we base on our legitimate interests. Where you object to direct marketing we will always stop.
  • Withdraw consent. Withdraw consent at any time, without affecting anything we did lawfully before you withdrew it.
  • Automated decisions. Not be subject to a decision producing legal or similarly significant effects that is made solely by automated means. We do not make decisions of that kind.

To exercise a right, write to privacy address, e.g. privacy@nikoapp.co.uk. We may need to confirm who you are first, so that we do not disclose your data to somebody else. Some of these you can do yourself in the app at any time: export your data, sign out other devices, disconnect a vehicle, change your marketing preference, or delete your account.

Complaining

If you are unhappy with how we have handled your data, please tell us at privacy address, e.g. privacy@nikoapp.co.uk so that we can put it right.

You also have the right to complain to the Information Commissioner's Office (ICO), the supervisory authority for the United Kingdom. You can complain to the ICO without going through us first, and doing so costs nothing.

Marketing

  1. We send marketing email only if you have asked for it. Under the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) that means an opt-in you gave deliberately — never a pre-ticked box.
  2. Every marketing message carries a one-click unsubscribe, and you can change the setting in the app at any time.
  3. Service messages are different, and you cannot opt out of them while you hold an account: verifying your email, a sign-in link, a security alert, an order confirmation, or notice of a change to these documents.

Cookies and similar technologies

  1. Our website at https://nikoapp.co.uk sets no cookies and loads no third-party trackers. There is nothing here to consent to, which is why you are not being asked.
  2. The mobile app stores a sign-in token on your device so that you stay signed in. It is strictly necessary for the service you asked for, and removing it would sign you out.
  3. If we ever introduce non-essential cookies or similar technology, we will ask for your consent first, as the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR) requires, and update this notice.

Automated decisions

We do not make decisions about you by solely automated means that produce legal effects or otherwise significantly affect you, and we do not profile you for that purpose. Automatic retries and rate limits are technical mechanisms, not decisions about you.

Children

Niko is not for children. You must be at least 18 to hold an account, and we do not knowingly collect data from anyone under 13. If you believe a child has given us data, write to privacy address, e.g. privacy@nikoapp.co.uk and we will delete it.

How we protect it

  • Everything travels over TLS, and manufacturer tokens are encrypted before they are written to the database.
  • Passwords are stored only as a slow one-way hash. We cannot read them, and neither can anyone who obtains the database.
  • Sign-in sessions rotate, and a token presented twice revokes the whole family of sessions it belongs to — so a stolen token stops working.
  • Sign-in and sign-up are rate-limited to make guessing impractical.
  • Card numbers are never stored. The database schema is written so that storing one would be a database error rather than a decision someone could quietly make.
  • Access to production data is limited to those who need it.

No system is perfectly secure. If a breach ever puts your rights at risk, we will tell the ICO within 72 hours where required, and tell you without undue delay where the risk to you is high.

Changes to this notice

We will update this notice when what we do changes. Every version is dated and published at https://nikoapp.co.uk/legal/. If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect. This version is 1.0, effective 2026-09-01.