Legal

Privacy policy.

What we collect when you charge with FlashGrid, why we collect it, who we share it with, how long we keep it, and the choices you have over it.

Effective: 6 August 2026

Last updated: 6 August 2026

1. Who we are and what this covers

Flash Grid (Pvt) Ltd (“FlashGrid”, “we”, “us”) operates the FlashGrid EV-charging network in Sri Lanka, the FlashGrid mobile app, and this website. We are the controller of the personal data described here.

This policy covers you whether you visit this website, hold a FlashGrid account and wallet, charge on the FlashGrid network or on a partner sub-network, or contact our support team. It explains what we collect, why, who we share it with, how long we keep it, and the choices you have.

  • Controller: Flash Grid (Pvt) Ltd
  • Registration no.: PV 00367750
  • Address: 183 Aadiyapatham Road, Jaffna 40000, Sri Lanka
  • Privacy contact: [email protected]

2. Information you give us

You provide some information directly, mostly when you open an account or ask us for help:

  • Account details — name, mobile number, email address, and the password or one-time code used to sign in.
  • Vehicle details — make, model, and connector type, so we can show you chargers your car can actually use.
  • Wallet and payment details — top-up amounts, transaction references, and the card brand and last four digits returned to us by our payment service provider (see clause 6).
  • Support correspondence — the messages, photos, and screenshots you send us about a charger or a bill, and our replies.
  • Anything you volunteer — survey answers, feedback, or a partner/host enquiry.

If you choose not to give us account or payment details, you will not be able to open a wallet or start a charging session.

3. Information we collect automatically

When you use the app or this website, we and our hosting and infrastructure providers record technical information automatically:

  • IP address and approximate region derived from it.
  • Date, time, and time-zone offset of each request.
  • Standard HTTP header information, including the referring page and the page you go to next.
  • Pages or screens viewed, links tapped, and time spent on each.
  • Device type, operating system and version, browser type and version, screen size, and language.
  • App version and build, plus crash reports, error traces, and performance diagnostics.
  • Charging session records — start and end time, duration, energy delivered in kWh, charge point and connector identifier, applied tariff, and the total in LKR.

Session records are operational data as much as personal data: they produce your receipt, settle your wallet, and satisfy our reporting obligations to the regulator.

4. Location information

The app asks for permission to use your device location so it can show chargers near you, give directions, and confirm you are at the charge point you are trying to start. Precise location is used at the moment you use those features; we do not track your device continuously in the background.

You can refuse or withdraw location permission at any time in your device settings (iOS: Settings → Privacy & Security → Location Services; Android: Settings → Location → App permissions). The app keeps working — you will need to search for a station or enter a location by hand instead.

Separately from device location, the charge point you use tells us where a session happened. That is inherent to charging and cannot be switched off while you charge.

5. Information we receive from others

Some information reaches us from third parties rather than from you:

  • Our payment service provider tells us whether a top-up succeeded, and returns a transaction reference plus the card brand and last four digits.
  • Partner networks and roaming partners send us the session data needed to bill a session you started on their infrastructure.
  • Site hosts — the businesses and property owners hosting FlashGrid chargers — may pass on contact details or an account query relating to a driver at their site.
  • App stores and our push-notification provider give us aggregate delivery and install data, not the content of your account.

6. Payment data and card details

Card top-ups are processed by WebXPay, our licensed payment service provider in Sri Lanka. You enter your card details on WebXPay’s secure, PCI-DSS-compliant payment page, authenticated with 3-D Secure where your bank supports it.

FlashGrid never receives, handles, or stores your full card number, expiry date, or CVV. What we do store against your account is the card brand, the last four digits, the amount, and the WebXPay transaction reference — enough to show you a recognisable payment history, match a refund to the right card, and investigate a disputed charge.

If you raise a chargeback, we will share the relevant session and payment records with our payment service provider and your issuing bank as evidence.

7. How we use your information

We use the information above to:

  • Create and administer your account and LKR wallet.
  • Authorise, meter, and settle charging sessions, and issue an itemised receipt for each one.
  • Process top-ups, refunds, and billing disputes.
  • Show you nearby chargers, live availability, and directions.
  • Answer your support requests and tell you when a session or charger has a problem.
  • Keep the service secure — detect and investigate fraud, account takeover, tampering with a charge point, and misuse of the network.
  • Monitor reliability, diagnose faults, and improve the app and the network.
  • Meet our legal, tax, and regulatory obligations, including reporting to the Public Utilities Commission of Sri Lanka (PUCSL).
  • Send you service messages, and — only if you have not opted out — news about FlashGrid products and offers.

We rely on the contract with you for everything needed to deliver charging and billing, on our legitimate interest in a secure and reliable network for fraud prevention and diagnostics, on legal obligation for regulatory and tax records, and on your consent for precise location and for marketing.

We do not sell your personal data, and we do not use it for automated decisions with a legal effect on you.

8. Who we share it with

We share personal data only where it is needed, and only with:

  • Our payment service provider (WebXPay) and the banks and card schemes behind it, to take top-ups and issue refunds.
  • Partner and roaming networks, limited to the data required to complete and bill a session on their infrastructure.
  • Site hosts, in aggregate — utilisation and uptime at their site, not driver identities.
  • Service providers acting on our instructions: cloud hosting, communications and OTP delivery, customer-support tooling, and crash/diagnostics reporting.
  • Regulators, tax authorities, courts, and law enforcement, where Sri Lankan law requires it — including reporting to the Public Utilities Commission of Sri Lanka (PUCSL).
  • Professional advisers (legal, audit, insurance) where necessary to protect or exercise our rights.

Service providers are bound to use the data only for the purpose we set, and never for their own marketing.

9. Cookies and similar technologies

This marketing site sets no advertising cookies, loads no third-party analytics or ad scripts, and does not track you across other websites.

The app and the account areas use strictly necessary storage only — cookies, local storage, and session tokens that keep you signed in, remember your preferences, and protect against fraudulent requests. These cannot be switched off without breaking sign-in.

Web fonts on this site are served by Google Fonts, which means Google receives your IP address and browser details when a font loads. That is the only third-party request this site makes. You can block it with a browser extension or by disabling remote fonts; the site stays readable in a fallback typeface.

10. Analytics and measurement

We measure product usage with aggregated, in-house reporting built on the operational data described in clause 3 — how often sessions succeed, which screens are used, where the app is slow. Reporting is aggregated and not used to profile individual drivers.

If we later introduce a third-party analytics provider, this clause and the date at the top of this page will be updated before it goes live.

11. How long we keep it

  • Account details — for as long as your account is open, then up to 12 months after closure so you can reopen it and so we can handle any late dispute.
  • Charging session and billing records — retained to meet Sri Lankan tax and PUCSL regulatory reporting obligations, which require financial records to be kept for several years after the transaction.
  • Payment references (brand, last four digits, transaction reference) — kept with the corresponding billing record for the same period.
  • Support correspondence — up to 24 months after the request is closed.
  • Technical logs, crash reports, and diagnostics — typically 90 days, unless a log is part of a live security or fraud investigation.

When a retention period ends we delete the data or irreversibly anonymise it. Anonymised, aggregated statistics — total energy delivered, network uptime — are kept indefinitely and can no longer identify you.

12. How we protect your information

We apply administrative, physical, and technical safeguards to the data under our control: encryption in transit, access limited to staff who need it for their role, audit logging of administrative access, and segregation of card handling to our PCI-DSS-compliant payment service provider so that card numbers never reach our systems.

No website, app, or internet transmission is ever completely secure, and we cannot guarantee that unauthorised access, data loss, or a breach will never occur. Transmission is at your own risk.

Your part matters too: keep your sign-in details and one-time codes to yourself, never share your account for commercial resale, and sign out on shared devices. If you think someone else has used your account or wallet, tell us immediately at [email protected] so we can freeze it.

If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant authorities as required by Sri Lankan law. Report a suspected vulnerability to [email protected].

13. Your rights and choices

You can ask us to:

  • Give you a copy of the personal data we hold about you.
  • Correct anything inaccurate or out of date — most account and vehicle details you can edit yourself in the app.
  • Delete your account and the data we are not legally required to keep. Billing and session records within a statutory retention period cannot be deleted on request.
  • Restrict or object to a particular use, including our legitimate-interest processing.
  • Withdraw a consent you gave — such as location or marketing — without affecting what we did before you withdrew it.

Send requests to [email protected] from the email address on your account. We respond within 14 days. There is no charge unless a request is repetitive or clearly excessive.

To delete your account, use https://flashgrid.lk/delete-account — no app install or sign-in needed — or Settings → Account in the app. We confirm it is you, lock the account straight away, refund any wallet balance to your original card, and erase your personal details after 7 days. Your charging and payment records are kept in anonymised form for the periods in clause 11, as Sri Lankan tax and PUCSL rules require; once your account is anonymised they no longer identify you.

Marketing: every promotional email and push notification carries an unsubscribe or opt-out control, and you can turn marketing off in the app at any time. Service messages are not marketing and cannot be switched off while your account is open — these include payment receipts, refund confirmations, session and charger alerts, security and sign-in notices, outage warnings, and changes to these policies or our terms.

15. Children

FlashGrid is for adults: you must be 18 or over to hold an account, in line with our terms and conditions. We do not knowingly collect personal data from children. If you believe a child has given us their data, contact [email protected] and we will delete it.

16. Business transfers

If Flash Grid (Pvt) Ltd is involved in a merger, acquisition, financing, or a sale of some or all of its assets, personal data may be reviewed under confidentiality during due diligence and transferred as part of that transaction. The same applies in insolvency, administration, or receivership, where data would pass as a business asset.

Any acquirer remains bound by this policy for data transferred to it until you are given notice of, and where required consent to, a different one.

17. Changes to this policy

We update this policy when the law, our practices, or the service changes. The version published here, with the dates at the top of the page, is the one that applies. Material changes are notified in the app or by email before they take effect; continuing to use FlashGrid after that means you accept the updated policy.

18. Contact us

Privacy questions, data requests, and complaints: [email protected]. General support: [email protected], or +94 76 637 0574. Post: Flash Grid (Pvt) Ltd, 183 Aadiyapatham Road, Jaffna 40000, Sri Lanka.

This policy is governed by the laws of Sri Lanka. If you are not satisfied with our response, you may complain to the relevant Sri Lankan data-protection or consumer authority.