Privacy
TL;DR
We collect the minimum data needed to run a parking marketplace: account info, your vehicles, your location when you're using the map, and payment information processed by Stripe. We don't sell your data. We share the minimum necessary with the host of any spot you actually book, and with the integrations we depend on (Firebase, Stripe, Google Maps).
What we collect
Account information
When you create an account we collect your email address and, if you provide them, your first and last name and a profile photo. We rely on Firebase Authentication; passwords are hashed and never visible to us.
Vehicles
You may add vehicles (make, model, year, color, license plate, an optional VIN, and a chosen icon). License plate and VIN data are treated as personal identifying information — they are masked in the app UI by default, and the VIN is never shown to anyone but you.
If you use the camera to scan your license plate, the photo is processed entirely on your device using on-device text recognition. The photo is never uploaded to our servers or any third party — only the plate text you confirm is saved to your vehicle record.
Location
While the app is open, we read your device location to center the map on you. We do not collect background location. When you book a parking session, the location of the spot you booked is logged with your reservation.
Reservations and receipts
We store records of the parking sessions you book — spot, vehicle used, start and end time, amount paid, and status. These records are visible to you in your parking history.
Payment information
Card details are entered directly into Stripe's hosted payment fields. We never see, store, or transmit your full card number. We retain a Stripe customer identifier and the last 4 digits, brand, and expiry of any cards on file so you can choose between them.
For hosts: bank and identity information
If you become a host, Stripe Connect collects the identity and bank information required to pay you out and meet tax obligations. We rely on Stripe for that; we do not collect your social security or routing numbers ourselves.
App diagnostics
We collect anonymized analytics events (e.g. "viewed a parking location", "added a vehicle") via Firebase Analytics, and crash reports via Crashlytics, to fix bugs and prioritize features.
Why we use it
- To operate the marketplace — match parkers with hosts, process payments, and pay hosts out.
- To identify your vehicle at a spot you've booked.
- To send you transactional messages (reservation receipts, host onboarding emails, password resets).
- To debug and improve the app.
- To comply with tax, accounting, and legal obligations.
We do not use your data to train any third-party advertising profile. We do not sell your personal information.
Who we share with
Hosts
When you book a spot, the host of that spot can see your display name, the make/model/year/color/icon of the vehicle you booked with, and the last two characters of its license plate. They cannot see your email, phone, payment details, or other vehicles.
Service providers
- Firebase (Google): authentication, Firestore database, Cloud Functions, Storage, Hosting, Analytics, App Check, Crashlytics.
- Stripe: payment processing, Stripe Connect for host payouts, identity verification.
- Plaid: bank account linking for hosts who choose instant verification.
- Google Maps Platform: map tiles, place autocomplete, and geolocation.
Each is bound by their own privacy policies and by our data processing agreements with them.
Legal
We may disclose information if compelled by a valid legal process or to protect the rights, property, or safety of users, hosts, or the public.
Location data
Paaking only requests your location while the app is in the foreground. We do not request "always" location access, and we do not background-poll your location. Your live location is never shared with hosts; only the location of a spot you actually book is recorded.
Payments
Payment information is collected and processed by Stripe under their privacy policy and PCI obligations. We retain only the metadata needed to display your cards (brand, last 4, expiry), trigger payouts, and issue refunds.
How long we keep it
- Account: as long as your account exists. You can delete it at any time from the app or by emailing support.
- Reservations / receipts: seven years to meet tax and accounting obligations.
- Diagnostics: typically 30 days for crash logs, longer in aggregated form.
Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct it if it's wrong.
- Delete your account and associated personal data.
- Export your data in a portable format.
- Opt out of analytics (in app settings).
California, EU, UK, and similar residents have additional rights under CCPA / GDPR / UK GDPR. Email us at privacy@paaking.app to exercise them.
Children
Paaking is not directed to children under 13 (or under 16 in the EU/UK). If we learn we collected personal information from a child without the necessary parental consent, we delete it.
Changes to this policy
We will update the date at the top of this page when we change the policy. If the change is material we will also notify users in-app or by email before it takes effect.
Contact
Email privacy@paaking.app with questions, deletion requests, or data export requests.