Phum EVTrust & Privacy

Trust & Privacy

This page is maintained by the Phum EV team to answer common security and privacy questions about the app. It describes current, app-visible controls and practices. It is not an independent certification or audit, and statements about platform features are not endorsed by Lovable.

Shared responsibility

Phum EV is built on the Lovable platform and uses Lovable Cloud (managed Supabase) for its database, authentication, storage, and server functions. Lovable provides the underlying infrastructure; the Phum EV team is responsible for application logic, access rules, content, and how customer data is used inside the app. Customers are responsible for protecting their own login credentials and Telegram account.

Access & authentication

End users sign in through the Telegram Mini App using their Telegram identity. Staff and admin accounts use email-based authentication managed by Lovable Cloud. Sensitive actions and admin pages require an active staff role; role and permission checks are enforced on the server, not only in the browser.

Database access is protected by row-level security policies and column-level grants so that users only see records they are allowed to see, and sensitive fields such as payment provider credentials are not exposed through the public API.

Data we collect & how we use it

Depending on the features you use, Phum EV may store: your Telegram profile (id, name, username, photo), vehicle and trip records you create, charging sessions, orders and payment status, feedback, and basic activity logs used to operate the app. We use this data to provide the features you interact with, to support orders and charging, and to improve the app.

For specific retention windows, deletion procedures, regional data residency, or regulated-data handling, please contact the Phum EV team using the address below.

Subprocessors & integrations

Phum EV relies on the following service providers to operate: Lovable / Supabase (hosting, database, auth, storage, server functions), Telegram (Mini App identity and messaging), Google Maps (maps and place data), and the configured payment providers (e.g. Bakong / KHQR) used to accept payments. Each provider processes only the data needed to deliver its function.

Cookies, storage & analytics

The app uses browser local storage and cookies that are required to keep you signed in, remember your preferences (such as theme and selected vehicle), and protect requests against tampering. It does not deploy third-party advertising trackers.

Compliance & certifications

Phum EV does not currently claim a specific external certification (such as SOC 2, ISO 27001, PCI DSS, HIPAA, or GDPR adequacy) on this page. If you need a formal compliance statement, a Data Processing Agreement, or a subprocessor list for procurement, please contact the Phum EV team and we will respond with the appropriate documentation.

Security & privacy contact

To report a suspected vulnerability, request data deletion, or ask a privacy question, please contact the Phum EV team through the in-app feedback form, or reach the team via the Telegram channel listed inside the app. We aim to acknowledge security reports promptly and to work with reporters in good faith.

This page is editable project content maintained by the app owner. It is not a Lovable-issued certification and does not constitute legal advice.