Version 2026-06-15.
Data minimization: we store only what is necessary to operate the Service.
The Service mainly processes vehicle / operational data (fuel, range, mileage, battery, position, faults) stored against a pseudonymous identifier and not enriched with personal profiles. The only identifying data is the minimal account linkage (your Telegram chat IDs and the credentials/tokens you provide).
Encrypted CarData tokens; vehicle/VIN identifiers (one or more vehicles per account); your bot token; allowed chat IDs; vehicle telematics (limited retention); your settings; the date and version of your terms acceptance; a hash of any API token. That is the whole list — only what is needed to run the Service for you.
To put common worries to rest, here is what we never hold:
You connect your own CarData access and instruct us to fetch your data; to provide history, charts and alerts that data is stored on our servers (in Switzerland — Oracle Cloud Zurich, on infrastructure certified to ISO 27001, SOC 2 and PCI DSS) solely to operate the Service for you. By accepting this Policy at registration you consent to this storage, and may withdraw it anytime (below).
Telematics kept a limited period then aggregated/deleted.
You can revoke access anytime in the manufacturer's CarData portal, and request export or
deletion of your data. Use /deletedata in your bot at any moment you wish:
everything we hold about you and your vehicle(s) — tokens, VINs, all telematics and GPS
history, settings and chat IDs — is permanently and irreversibly erased, wiped completely
with no trace left, within 30 days (usually right away).
HTTPS everywhere; tokens encrypted at rest; strict isolation per tenant — your bot and agent can access only your own vehicle(s), and no other customer of the Service can ever reach your data. The origin server is closed behind a Cloudflare tunnel with no inbound ports open, so no third party from the internet can reach it either. Data is stored in Switzerland (Oracle Cloud Zurich), on infrastructure independently certified to ISO/IEC 27001, SOC 2, BSI C5 and PCI DSS, and enrolled in the EU Cloud Code of Conduct (the certifications are the provider's). We comply with the EU GDPR and Switzerland's revised Federal Act on Data Protection (nFADP).
To run the Service we use a short, fixed list of infrastructure providers (sub-processors). They process data only on our instructions to operate the Service — never for their own purposes:
We do not add sub-processors casually; this Policy is updated if the list changes. telebimmer is an independent operator and is not affiliated with any of the above providers.
Your data reaches you through your own
Telegram bot, which only you control. Messages between you and your bot travel over Telegram's
encrypted protocol (MTProto) — encrypted in transit and at rest on Telegram's side — and your bot
replies only to the chats you explicitly allow (allowed_chats). No other user of our
Service, and no outsider, can talk to your bot or read its messages.
For export/deletion requests or privacy questions, email [email protected] — or use the /support command in the registration bot.
Telebimmer · monitoring your car via the official BMW CarData API
Terms · Privacy · Refunds · Legal notice · Contact · Reviews · FAQ
· Not affiliated with the vehicle manufacturer ·
