Teslatlas Hub
Privacy Policy
Hub runs under your control. Vehicle history and credentials belong on your host. Magrathean processes information it actually receives, including website activity and material you send for support. Optional providers have separate data flows.
Publisher: MAGRATHEAN UK LTD · Company number 16955343 · Contact: contact@magrathean.uk
Scope and responsibility
This notice covers Teslatlas Hub, its website pages, the shared Teslatlas product chooser and information submitted to Magrathean for support. Hub is self-hosted software: precise locations, journeys, charging history, vehicle identifiers, account tokens, network information and security logs can be processed on the host you operate.
Publishing the software does not make Magrathean the controller or processor of data that never reaches it. The person or organisation deciding why and how deployment data is processed ordinarily acts as its controller or equivalent responsible party. Magrathean is responsible for information it actually receives for its own purposes, including website activity, support correspondence, security reports and any separately agreed services.
Data on your host
Vehicle telemetry and routes can reveal home, work, routines and other sensitive information. Hub keeps vehicle history in operator-controlled local storage and provider credentials with the resident service. Connected providers and clients you configure have their own data flows and responsibilities.
You control access, hosting, backups, exports, retention and deletion. Protect credentials, pairing invitations, databases and recovery files. Review access for other drivers, family members, employees and passengers; provide any required notices and establish a lawful basis for your deployment. Business or fleet deployments may also need processor agreements, transfer safeguards and a data protection impact assessment.
The deployment data-protection guidance explains operator responsibilities. Software availability does not grant permission to monitor another person or access another account.
Optional geocoding
Geocoding is disabled by default and has no public default provider. If you enable it, you must supply an HTTPS endpoint. For each uncached lookup, Hub sends the vehicle’s precise latitude and longitude, zoom level 19, requested language, Hub user agent, operator IP address and ordinary request metadata to your chosen provider.
The response may include a precise street address and provider identifiers. Hub caches it alongside the lookup coordinate in your database. You select the recipient and must review its privacy, retention, international transfer, attribution, database-right and rate-limit terms.
Use a self-hosted or otherwise authorised Nominatim-compatible service. Do not assume the public OpenStreetMap Foundation Nominatim service permits vehicle tracking, bulk enrichment or personal-data submissions. Set geocoder.enabled = false to disable geocoder requests.
Optional terrain requests
Terrain enrichment is disabled by default in source builds and packaged Mac and Debian configurations. When enabled, a missing cached tile triggers an HTTPS request to AWS at elevation-tiles-prod.s3.amazonaws.com, with fallback to ESA’s step.esa.int/auxdata/dem/SRTMGL1/.
These providers receive the operator IP address, request metadata and the one-degree latitude/longitude tile containing the vehicle location. The URL does not contain the precise coordinate. This is SRTMGL1 elevation data, not ESA WorldCover.
Set terrain.enabled = false to disable this traffic. Existing cached terrain remains local, operator-controlled data.
Website analytics
The Teslatlas website, including the shared product chooser and Hub pages, uses Google Analytics and Cloudflare Web Analytics to measure website use and performance. This website measurement is separate from Hub’s vehicle collection and local history. Visiting this site does not upload your Hub database, account tokens or vehicle history to these analytics services.
Google Analytics uses browser identifiers and storage to measure page visits and selected link clicks. The website’s current Google tag settings grant analytics storage, advertising storage, advertising user data and ad personalisation, as well as functionality, personalisation and security storage. This notice does not describe website analytics as anonymous or cookie-free. Google’s handling of website data is subject to its own privacy information.
Cloudflare delivers and protects the website and provides web analytics. Requests can expose IP addresses, browser and network metadata to the website infrastructure; Cloudflare’s analytics measures page use and performance. It is a separate website service, not a destination for Hub telemetry.
Selected click events identify the product and link, such as a build guide, source repository, companion project or donation link. These event fields do not intentionally include credentials, form contents, vehicle data or arbitrary query strings. Browser privacy controls and content blockers may limit analytics without preventing normal navigation. See Google’s privacy policy and Cloudflare’s privacy policy for their processing and international-transfer information.
Support and security reports
If you send an email, screenshot, diagnostic bundle, log, database extract or security report, Magrathean receives what you choose to submit. It uses that information to investigate, reply and manage the reported issue. Ordinary log redaction does not make every diagnostic safe to share.
Review and minimise submissions first. Never post tokens, pairing invitations, VINs, precise locations, private logs or production databases in public GitHub issues. Use the private security-reporting route for vulnerabilities and the support policy for other problems. GitHub, email providers and other recipients process information under their own policies.
Retention and your choices
For your Hub deployment, you or your chosen operator decide retention, export and deletion, including copies in backups and downstream systems. Magrathean cannot delete or recover data it does not hold. Disabling a provider prevents future requests; it does not remove information already received by that provider.
For information sent to Magrathean, contact us to request access, correction or deletion, or raise a privacy concern. The response depends on the data held and applicable law, including any legal retention obligations. Website providers apply their own retention settings and policies. No fixed retention period for support submissions is specified in the Hub source notice.
For UK data-protection concerns, you may also contact the Information Commissioner’s Office; elsewhere, contact your competent supervisory authority. Deployment-data requests should first go to the operator responsible for that deployment.
Contact and source
MAGRATHEAN UK LTD, registered in England and Wales, company number 16955343. Registered office: 16 Caledonian Court West Street, Watford, England, WD17 1RY.
Contact contact@magrathean.uk for Hub privacy questions. This page follows the Hub privacy and data-protection source notice, with the website analytics disclosure above. It describes Hub and website processing separately; it does not replace another provider’s privacy notice.