中文 · Privacy · Terms

IonFlux mobile app

Privacy Policy

Last updated: July 16, 2026

1. Introduction

IonFlux (“App”) lets EV drivers discover supported charging connectors (FlashBot / FlashHub), create a consumer account, save payment methods, and start paid charging sessions through the FlashOps Consumer API.

This Privacy Policy explains what personal data we collect, why we process it, with whom we share it, and your choices. Where local law is stricter, we comply to the extent applicable.

2. Who is responsible?

IonDynamics is the controller for consumer account, payment orchestration metadata, and App usage data described below, unless a site operator is identified to you as a separate controller for on-site services.

Stripe acts as an independent controller / PSP for card data processed in Stripe’s systems under Stripe’s terms. Map providers process location-related data under their terms when maps are shown.

3. Data we collect

3.1 Account and profile.

Phone number is generally not editable via profile update APIs.

3.2 Authentication.

SMS one-time codes (stored short-term in cache, typically ~15 minutes, with send rate limits and verify attempt limits);

Session tokens (JWT, typical lifetime ~30 days) stored on your device.

3.3 Payments.

Stripe Customer ID and Payment Method IDs;

Display metadata: brand, last4, expiry, wallet type (e.g. Apple Pay / Google Pay), default flag;

PaymentIntent / authorization / capture / settlement references linked to charging sessions.

We do not store full card PAN or CVV on FlashOps servers. Card entry and wallets run through Stripe Payment Sheet.

3.4 Charging sessions.

Connector and parent device identifiers, session / order numbers, client source (ionflux);

Authorization and final amounts, currency, tariff snapshot;

Timestamps (authorized, charging start/end, settled);

Live / summary metrics used in the App (e.g. energy kWh, power, EV SOC estimates where available);

Optional fields that may exist in backend models (e.g. vehicle plate/VIN on session, summon coordinates) — summon/tracking is not part of the current MVP UX.

3.5 Location.

When you use nearby connector discovery or maps, the App may send your approximate or precise location (latitude / longitude) to our API (e.g. GET /consumer/connectors/nearby) and to map SDKs (Google Maps and/or Baidu Maps by region). You can revoke location permission in OS settings; nearby distance filtering may then be limited.

3.6 Device and technical data.

App version, device OS, network requests, IP address, timestamps, diagnostic logs needed to run and secure the service;

Locally stored preferences and optional on-device vehicle photo cache (not uploaded as consumer S3 avatars in the current consumer APIs).

3.7 Permissions (charge-oriented use).

Depending on OS and build, the App may request:

Network — required;

Location — maps and nearby connectors;

Notifications — if enabled for product alerts.

Older / non–charge-only builds may still declare camera, microphone, Bluetooth, or album permissions for legacy parking features. Those are not required for the FlashOps Pay & Start path; grant only what you need.

4. How we use data (purposes & legal bases)

We do not sell your personal information. We do not use consumer data for third-party advertising SDKs in the charge-only FlashOps client path described in product docs.

5. Sharing and processors

We share data only as needed with:

6. International transfers

Infrastructure and subprocessors may process data in the European Union and the United States (and other regions where providers operate). Where required, we use appropriate transfer safeguards (e.g. standard contractual clauses) as advised by counsel.

7. Retention

Backups may persist for a limited time after deletion from primary systems.

8. Security

We apply administrative and technical measures appropriate to the risk (HTTPS APIs, access control, hashed passwords, separation of card data via Stripe). No method is perfectly secure. Protect your phone and do not share OTP codes.

Note: Consumer session tokens may be stored in App preferences on device; protect the device with OS lock and sign out on shared devices.

9. Your rights

Depending on your location, you may have rights to access, rectify, erase, restrict, object, or port data, and to lodge a complaint with a supervisory authority.

Update display name, email, locale, and vehicle display fields in the App where available;

Add / remove / set default payment methods in Me → Payment;

Sign out to end the local session;

For account deletion or broader erasure requests, contact us (self-serve consumer delete may not yet be available in the FlashOps charge path).

We may need to verify your identity (e.g. via the registered phone number).

10. Children

The paid charging service is not directed to children. We do not knowingly collect personal data from children for IonFlux consumer charging. Contact us if you believe we have done so.

11. Changes

We may update this Policy and will revise the “Last updated” date. Material changes will be notified as required by law (in-App notice and/or other channels).

12. Contact

Privacy / support (placeholder — confirm before publish): privacy@iondynamics.energy / support@iondynamics.energy

Web context for operators: operation.iondynamics.energy (FlashOps Center — separate operator Privacy Policy)

13. Relationship to other policies

FlashOps Center & IonPilot Privacy Policy covers operator staff tools, not this consumer App.

Legacy consumer legal pages previously hosted on third-party domains (e.g. zongmutech) should be replaced by this Policy and the IonFlux Terms once published and linked from the App (ProtocolPrompts URLs).