Privacy Policy

Last updated: 21 August 2026

ParkAhead ("we", "us", "our") operates the ParkAhead website and mobile app (the "Service"). This Privacy Policy explains what personal data we collect, why we use it, and the choices and rights you have under the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018.

1. Who we are (Data Controller)

ParkAhead is responsible for the personal data described in this policy. Our final company details will be published here before paid services launch. For any privacy request, contact: privacy@park-ahead.com.

2. Data we collect

  • Account data: email address, display name, profile image, and the authentication identifier supplied by email sign-in or a provider such as Google. Password credentials are handled by our authentication provider, not displayed to ParkAhead staff.
  • Location data: approximate or precise location only after you grant device permission. It helps centre the map and show nearby parking. You can withdraw permission in your device settings.
  • Vehicle information: optional details such as license plate, vehicle make/model, and EV charging needs, where you choose to provide them.
  • Parking, booking and feedback data: listing details, availability, booking times, access PINs or QR codes, ratings, feedback and reports.
  • Owner / business data: business name, contact details, city and parking-listing details for users who apply as parking owners.
  • Device and service data: IP address, browser or operating system, language, timestamps, error logs and, if you enable alerts, a push-notification device token.
  • Analytics data: usage information only when you choose analytics in our cookie preferences. We also respect a browser Do Not Track signal for analytics.

3. How we use your data and legal basis

  • To provide the Service (contract, Art. 6(1)(b) GDPR): show nearby parking and process bookings.
  • Location processing (consent, Art. 6(1)(a)): we ask for device permission before using your location.
  • Optional analytics (consent, Art. 6(1)(a)): we use analytics only after you allow it through Cookie preferences.
  • Payments and fraud prevention (contract + legitimate interests, Art. 6(1)(b)/(f)) when payment services are introduced.
  • Reputation, safety and abuse prevention (legitimate interests, Art. 6(1)(f)).
  • Legal obligations (Art. 6(1)(c)): tax records, responding to lawful requests.
  • Service emails (contract); marketing emails only with your consent and an unsubscribe link.

4. Sharing

We share data only with:

  • Cloudflare for hosting and security, and Supabase for authentication and the database.
  • Google Maps to render maps and search for nearby parking.
  • Firebase to deliver push notifications to devices that opt in.
  • Resend to deliver account and service emails.
  • Google Analytics and PostHog only when you allow analytics.
  • Payment processors to take and refund payments only after payment services are launched.
  • Other users — your display name, avatar and reputation are visible to owners you book with (and drivers who book your parking, if you're an owner). Your precise home address is never shown.
  • Law enforcement and regulators where legally required.

We do not sell your personal data.

5. International transfers

Some of our processors are located outside the EEA. Where this is the case we rely on EU Standard Contractual Clauses or equivalent safeguards.

6. Retention

  • Account data: until you delete your account, plus up to 30 days in backups.
  • Location: used while the relevant map or parking feature is active and retained only where needed for a specific booking or safety record.
  • Completed bookings: shown in "My bookings" for 24 hours after the end time, then moved to "Booking history" in your profile (and in the owner's profile for the corresponding owner). Booking history is automatically deleted 30 days after the booking ends.
  • Notification-device tokens: until you disable notifications, sign out of that device, or delete your account.
  • Payment and invoicing records: for the period required by applicable tax law, once payments are available.
  • Server logs: up to 90 days.

7. Your rights

You have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing based on legitimate interests. You can withdraw location permission in your device settings and change analytics preferences from the footer. To exercise your rights, or to request account deletion, email privacy@park-ahead.com. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus.

8. Security

We use HTTPS, provider-managed encryption at rest, protected authentication, and role-based access controls. No system is completely secure; please use a strong, unique password and keep your access details private.

9. Children

The Service is not intended for anyone under 16.

10. Changes

We may update this policy. Material changes will be notified in-app or by email at least 14 days before they take effect.