Privacy
GuestLot exists to document a short window: a customer’s vehicle arriving at a shop, sitting there, and leaving. We collect what that job requires and we stop when the job ends.
We do not sell vehicle data. With owner authorization, shop staff may see the last reported vehicle location and its timestamp during custody. Owner reports omit precise location and private staff observations, and sharing requires the shop’s explicit choice.
Who is who
GuestLot is a product of Moon Sherpa Labs. Our direct customers are shops. The people whose vehicles those shops hold — vehicle owners — are not our customers, do not have accounts with us, and are the people this policy is most concerned with protecting.
What we collect
From shops
- Account and location details: business name, address, staff names and email addresses, role assignments.
- Billing information, processed by our payment processor. We do not store full card numbers.
- Product usage: which features are used, errors encountered, and support correspondence.
About a visit
- Vehicle identification: VIN, make and model, and the odometer reading at check-in and hand-back.
- The owner's email address, used to deliver the pre-authorization link and the AccessReceipt — plus a mobile number if the shop records one (optional).
- The custody window: check-in time, expected pickup, actual hand-back, and which staff member handled each step.
- Key custody: whether an NFC key card was left, and staff-recorded handover information.
- Staff observations, recorded locations, and supporting documents added to the visit, with author and timestamps.
- Job policy applied: the movement thresholds and settings for that trade.
From the vehicle, only if the owner authorizes it
- Vehicle state such as state of charge, odometer, and lock status, from available authorized Tesla API readings.
- Location readings only where the owner granted vehicle_location access, including the last reported coordinates and timestamp for the authorized shop during the custody visit.
- Charging events, reported as Supercharger session counts and timestamps.
- Service Mode state when available. Tesla Fleet API cannot remotely enter or lock Service Mode.
If the owner does not authorize, none of the vehicle section applies. The visit record simply says so, and the receipt reads “not recorded” rather than showing a zero. See how authorization works and how to revoke it.
Why we collect it
- To run the custody window: check a vehicle in, apply the job policy, and hand it back.
- To alert a shop to events that matter during a visit — an after-hours lot exit, an unexpected odometer jump, a charging session, a low battery.
- To retain a custody record for the shop and provide an owner report if the shop explicitly enables sharing.
- To operate, secure, support, and bill for the service.
That list is exhaustive by intent. If a use is not on it, it is not a use we have. New purposes require a new consent conversation, not a quiet policy edit.
What we never do
- We never sell vehicle data. Not to data brokers, not to insurers, not to consumer reporting agencies, not to advertisers.
- We do not expose precise vehicle coordinates or private staff observations in public owner reports. Authorized shop staff may see last reported location with source and timestamp.
- We never track employees. Movement is attributed to a vehicle and a custody window, not to a person's whereabouts.
- Hand-back closes the GuestLot custody connection. This is distinct from removing every Tesla-side key or driver invitation; those require a separate access review.
- We never ask an owner for their Tesla account credentials. Authorization happens on Tesla's own screen.
- We never log a shop into an owner's Tesla account.
Regulators have spent the last two years making examples of connected-car programs that did the opposite — the FTC’s finalized order against GM and OnStar in January 2026 included a five-year ban on sharing geolocation data with consumer reporting agencies (ftc.gov). We would rather be structurally incapable of that than merely opposed to it.
The consent window
Vehicle data collection is bounded by the visit. The owner authorizes, either at the counter or in advance through pre-authorization; access activates when the vehicle reaches the shop; GuestLot’s custody connection closes at hand-back and the visit readings are retained. Staff may add separately timestamped documentation; this does not change the original vehicle readings.
The owner can end the window earlier at any time, without telling the shop and without telling us: Tesla Account > Security > Third-Party Apps, or delete the virtual key from the vehicle’s Locks screen.
How long we keep things
- Visit records are retained for the shop as a business record of custody, because that is the point of the product.
- Live vehicle data collection ends at hand-back. What remains is the closed snapshot, not an ongoing feed.
- Account and billing records are retained as long as required for tax and accounting purposes.
- Owners can ask us to delete their contact details from a visit record; see owner rights below.
Owner rights
If your vehicle was checked in somewhere and you received an AccessReceipt, you have rights with respect to that record regardless of which state you live in. We will honor these requests whether or not your jurisdiction requires it.
- Access: ask us what a specific visit record contains.
- Correction: ask us to fix something factually wrong in it.
- Deletion: ask us to delete your contact details, and to delete vehicle data associated with a visit, subject to the shop's own record-keeping obligations.
- Revocation: end vehicle access yourself, at any time, through Tesla — no request to us needed.
- No sale opt-out is necessary, because we do not sell data. If that ever changes, it would be an opt-in.
Requests go to privacy@guestlot.com. We will ask for enough information to be confident we are talking to the right person, and nothing beyond that.
Who else touches the data
- Tesla, as the source of authorized vehicle data.
- Named processors, each under contract: Supabase (database and authentication, US region), Vercel (hosting), Stripe (payments — we never see card numbers), Resend (the owner notices we send: the pre-authorization link, window extensions, and the receipt), Tesla (vehicle data, under the owner's own authorization), Google Analytics (reviewed public marketing pages only), and Ahrefs Analytics (historical marketing analytics collected before September 16, 2026). We do not load analytics on receipt, authorization, sign-in, signup, or staff app pages. Marketing interaction events exclude checklist answers and customer details. If we ever add text messages, the carrier is named here before the first one is sent.
- Nobody else. We do not share vehicle data with insurers, lenders, brokers, or advertising networks.
Security
We use encryption in transit, scoped access controls, and least-privilege credentials, and we request the narrowest Tesla scopes each feature needs. We will not pretend this makes us unbreakable. If we ever have a breach affecting vehicle or owner data, we will say so directly and promptly rather than through a lawyer’s summary.
Changes to this policy
If we change something material — a new category of data, a new recipient, a longer retention period — we will update the effective date and notify shop account owners. We will not introduce a new use of vehicle data by editing this page quietly.
Contact
Moon Sherpa Labs, for the GuestLot service. Privacy questions: privacy@guestlot.com. Everything else: contact. Related reading: limits we will not hide, terms, and what the Tesla Fleet API permits.