deep-dive

EV Charging Station Privacy: What Gets Collected When You Plug In

Every public charging session logs your location, time, payment details, and energy usage. ChargePoint, EVgo, and Electrify America all collect data differently. Here's what to know.

Plugging into a public EV charger feels like a mundane act — the modern equivalent of filling up a gas tank. But unlike a cash fuel purchase, every public charging session generates a detailed data record: where you were, when you arrived and left, how long you stayed, how much energy your vehicle drew, and how you paid.

That data lives with the charging network — ChargePoint, EVgo, Electrify America, Blink, and others — under privacy policies most drivers have never read. As EV adoption accelerates, the charging network layer is accumulating some of the most location-rich personal data created by everyday activity, in a regulatory environment that hasn’t fully caught up.


What Charging Networks Actually Collect

Public charging sessions generate data across several categories, and the scope is broader than most drivers realize:

Location data. Every session records the specific charger location — which is a precise GPS coordinate, not just a city or neighborhood. For drivers who charge regularly at the same stations (near home, near work, on a regular commute route), the location record builds into a detailed movement pattern over time. Unlike a phone’s approximate location history, charging location data is anchored to specific physical hardware, making it more precise and harder to obscure.

Session timing. Start and end times for every session are logged. Combined with location data, this creates a record of where you were and for how long — including dwell time at each location.

Energy usage. The amount of electricity drawn, measured in kilowatt-hours, is recorded per session. Combined with your vehicle model (which networks often know from registration or OCPP communication), energy usage data can reveal driving patterns, approximate distances traveled between charges, and indirectly, information about your vehicle’s state of health over time.

Payment information. Whether you pay through a credit card, a network membership, or a third-party app, payment data is associated with the session. For membership accounts, your payment method is linked to a persistent account that aggregates all your sessions.

Vehicle identification. Many charging protocols exchange vehicle identification information at the start of a session. The extent of this varies by network and charger generation, but OCPP-compliant chargers can log the vehicle’s make, model, and in some implementations, VIN-adjacent identifiers.

Account behavior. If you use a network’s mobile app to start sessions, pay, or check station availability, the app may collect standard mobile analytics: device type, OS version, app interaction patterns, and location data accessed by the app itself (distinct from the session location).


ChargePoint, EVgo, and Electrify America: What Their Policies Say

The three largest US public charging networks each have distinct privacy policies, and the differences are meaningful. What follows is based on their publicly available policies — which can change, so treat this as a starting point for your own review rather than a definitive current statement.

ChargePoint is the largest US charging network by number of stations. Its privacy policy permits sharing aggregated and de-identified data with business partners for purposes including analytics and network planning. It also allows sharing of personal information with affiliates, service providers, and in response to legal process. ChargePoint offers account holders the ability to request data access and deletion in jurisdictions where applicable laws require it (California, Colorado, Virginia, and others with strong state privacy laws).

EVgo similarly collects session data, account information, and vehicle data, and its policy allows sharing with partners for service improvement and marketing purposes. EVgo has expanded its network through partnerships with retailers and employers where charger access may be tied to third-party accounts, which adds additional entities to the data chain.

Electrify America, a subsidiary of Volkswagen Group, operates under a privacy framework that reflects European corporate privacy standards to some degree, though its US-facing policy is distinct from GDPR requirements. It collects location, session, payment, and vehicle data and allows sharing with service providers and legal authorities.

Blink Charging has a broader marketing data use clause in its policy and explicitly allows sharing of personal data with third parties for marketing purposes unless you opt out.

As of mid-year, none of these networks have faced enforcement actions in the US comparable to what European data protection authorities have imposed on other sectors. The EV charging layer is currently under-regulated relative to the sensitivity of data it collects.


Why Charging Data Is More Sensitive Than It Looks

Location data is often discussed as a general privacy concern without specifics. Charging data makes the concern concrete:

It’s more granular than phone location history. When you charge at a specific station, you’re associated with a precise address, often for 20–60 minutes at a stretch. That’s long enough to establish pattern-of-life information: you charge near a specific workplace three mornings per week, you charged at the hospital district on a Tuesday afternoon, you charged at a sports venue on game nights.

It’s persistent and linked to your vehicle identity. Unlike a cash fuel purchase that generates no record, charging sessions are logged to a persistent account tied to your payment method, your phone, and sometimes your vehicle. This creates a longitudinal record that grows more revealing over time.

It can reveal sensitive location types. The combination of precise location and timing can identify visits to medical facilities, places of worship, political events, addiction treatment centers, or other locations that carry privacy implications if disclosed. Unlike general browsing data, a charging record at a specific address is hard to explain as coincidental.

It may be sold to data brokers. Charging network privacy policies generally permit sharing with “business partners” and “affiliates” in terms that could include data broker relationships. The EV charging industry hasn’t faced the scrutiny that smartphone location data brokers have received, but the same monetization pathways exist.

It’s accessible to legal process. A subpoena or search warrant directed at a charging network can produce a detailed location history that would require separate warrants against multiple parties to reconstruct from other sources. Law enforcement interest in location data from charging networks has been documented in at least one published case, and the legal framework for protecting this data in the US is inconsistent across states.


How Jurisdiction Affects Your Rights

The US has no comprehensive federal privacy law that uniformly applies to EV charging data. Your rights depend almost entirely on which state you’re in:

California (CCPA/CPRA) gives California residents the right to know what personal information is collected, request deletion, opt out of data sales, and receive non-discriminatory service when they exercise these rights. California residents can request that ChargePoint, EVgo, and other networks delete their personal data and opt out of data sales.

Colorado, Virginia, Connecticut, and a growing number of states have enacted similar frameworks that give residents rights over their personal data, including the right to access and delete charging session records.

Most other states currently have no comprehensive consumer privacy law that meaningfully applies to charging networks. If you’re in a state without applicable privacy laws, your practical recourse if a charging network mishandles your data is limited.

GDPR. If you’re in Europe, GDPR gives you robust rights over any personal data collected during a charging session, including the right to access, correct, and delete that data. European networks must obtain legal basis for data processing and are subject to enforcement by data protection authorities.


What the Vehicle Itself Sends

The charging network isn’t the only entity collecting data during a charging session. Modern EVs transmit telemetry independently:

The vehicle manufacturer. Connected EVs typically report charging sessions, battery state, energy consumption, and location to the manufacturer’s servers as part of the vehicle’s telematics system. This is separate from the charging network’s data collection and governed by the manufacturer’s own privacy policy, which most vehicle owners have never read.

Third-party charging services. Apps like PlugShare, A Better Routeplanner, and vehicle manufacturer apps may collect location and session data through their own channels when you use them to navigate or pay for charging.

Grid and utility data. In some regions, smart charging programs share session data with utility companies for grid management purposes. This is usually opt-in for participation in managed charging programs but may not require explicit notice for the basic data transmission.

The charging session, in other words, touches more data pipelines than the charger itself. A complete picture of who has your charging data includes the network, the vehicle manufacturer, and potentially apps and utilities as well.


Practical Steps to Reduce Charging Data Exposure

You can’t make a public charging session invisible — location and energy data are intrinsic to the service. But a few practices reduce the scope of additional data collection:

Pay without an account where possible. Some chargers — particularly NACS-compliant stations — now support plug-and-charge with payment handled through the vehicle or a tap-to-pay method, without requiring a network app account. Using pay-per-session rather than a membership account limits how much data is aggregated under a persistent identity.

Review network app permissions on your phone. Charging apps may request location access, push notifications, and other permissions beyond what’s necessary to manage a session. Grant minimal permissions — “only while using the app” for location rather than “always.”

Read the privacy policy of your primary network. It will tell you what they share, with whom, and under what conditions. Look specifically for “third-party sharing,” “marketing partners,” and “data sales” language — these clauses reveal the monetization potential of your session data.

Exercise data rights where applicable. If you’re in a state with applicable privacy laws, you can submit a deletion request to charging networks to purge your historical session data. This won’t prevent future collection, but it eliminates the historical record.

Check your vehicle manufacturer’s privacy settings. Most connected EVs have telematics privacy settings in the vehicle’s infotainment system or in the manufacturer’s app. Review what your vehicle is transmitting and whether you’ve opted in to any data-sharing programs beyond what’s required for basic operation.


The Regulatory Gap Worth Watching

As of now, EV charging data is one of the least scrutinized data categories in personal transportation, despite being among the most location-rich. The charging network layer — the companies operating the physical infrastructure — is a newer industry than mobile carriers or social platforms, and regulators haven’t yet treated it with the same attention those industries receive.

That’s likely to change. State attorneys general and federal regulators have shown increasing interest in location data as a category, and charging networks’ data practices are a natural extension of that focus. The GDPR enforcement environment in Europe has already begun addressing EV charging data under existing data protection frameworks.

For drivers, the practical implication is to treat your charging data as you would any other location record — something generated whether you think about it or not, stored longer than you might expect, and potentially shared through channels that aren’t immediately obvious from the experience of plugging in your car.


Storing Your Files Privately in a Connected World

The same principle that applies to charging data applies across connected devices: the more your daily activities route through cloud services, the more data you generate that you don’t directly control.

This matters for files and memories beyond location data — photos, documents, personal records that you back up or store online. The question for any cloud service is what happens to that data beyond the core service function you’re using it for: who can see it, whether it’s used for AI training or advertising, how long it’s retained after you close your account, and what rights you have to request its deletion.

daftei stores personal files with AES-256 encryption at rest and TLS 1.3 in transit, is GDPR and CCPA compliant, and maintains a policy of never selling user data, never showing ads, and never training third-party AI models on user content. Account deletion triggers a 30-day grace window before permanent, irreversible erasure — not an indefinite hold. These commitments apply at the policy level, not just at the technical level.

The broader context of data collection — from charging networks, from connected vehicles, from every digital service you use — makes it more valuable, not less, to have at least some places where data is handled differently. A personal file archive is one of those places where the handling choices are worth making deliberately.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts