Privacy Policy
Version 1.2 · Last updated 1 September 2026
1. Data Controller
ParkReply OÜ
Registry code: 17572396
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Email: contact@parkreply.com
2. Scope
This Policy applies to ParkReply accounts, the Driver App, Driver Web, Scanner Web, interactions with ParkReply QR codes, chats, emergency features, support and problem reports, the website, and ParkReply Pro subscriptions.
3. Account and Authentication Data
To create, secure, and administer an account, ParkReply may process the phone number, Firebase Auth identifier (UID), authentication metadata, account and security events, and data required to verify the phone number.
4. Profile Information
Depending on the information provided and features used, ParkReply may process first name, last name, email address if provided, phone number, country or country code, language, preferences, and account plan or status information.
5. Vehicle Information
ParkReply may process the vehicle make and model, registration or licence plate number, and the association between the vehicle, account, and a ParkReply QR code.
6. ParkReply QR Codes and Public Identifiers
ParkReply processes public QR identifiers, their activation and status, their association with an account, and information needed for limited public QR resolution. The owner’s private phone number and private email address are not exposed by the QR code.
When the account is deleted, QR identifiers owned by the user are deactivated and their association with the owner is removed or anonymised as necessary.
7. Use of the ParkReply Scanner
Scanner Web may use anonymous Firebase authentication and process a scanner device identifier, visitor code, QR identifier, conversation references, local state, rate limits or cooldowns, and signals needed to prevent abuse.
8. Messages and Conversations
To provide messaging, ParkReply may process message content, chat ID, sender type, timestamps, public QR identifier, participant identifiers, conversation status, and moderation-related data.
Anti-abuse restrictions may address spam, harassment, threats, abusive or promotional content, prohibited sharing of personal contact details, links, and duplicate or excessive submissions.
9. Reports, Moderation and Security
ParkReply may process reports and their reasons, restrictions and blocks, security events, rate limits, and information needed for fraud or abuse prevention and administrative review.
10. Emergency Features
For an emergency request, ParkReply may process the QR identifier, scanner identifiers, visitor name, organisation, verified phone number, reason or message, request status, owner response, administrative decisions or events, and, where applicable, trusted contact information.
ParkReply is a private communication tool.
ParkReply is not:
• the police;
• an ambulance service;
• the fire service;
• an emergency medical service;
• a public emergency-dispatch service;
• a guaranteed rescue service.
In the event of immediate danger or a genuine emergency, the user must contact the appropriate official emergency services directly.
No time displayed in ParkReply constitutes a guarantee of response or intervention.
11. Trusted or Family Contacts
ParkReply may process a trusted or family contact’s name, phone number, country code, and relationship. The user must have a legitimate basis or the necessary authority to provide another person’s contact details.
12. Support and Problem Reports
To handle a support request or problem report, ParkReply may retain the ticket number, user or account reference, category or problem type, subject, message, support replies, status, and timestamps.
After account deletion, these histories may be anonymised where they must be retained, including for security, legal obligations, or case follow-up.
13. Notifications
ParkReply uses Firebase Cloud Messaging and may process FCM tokens to send service, support, chat, emergency, or account notifications. Account-owned tokens and related notifications are deleted as part of account deletion.
Firebase SDKs may also process a Firebase Installation ID, Firebase App ID, app version, and technical metadata such as platform, operating-system version, device model, brand, or form factor. Firebase Authentication and Cloud Functions may process the IP address, user-agent strings, and integrity tokens or signals needed for authentication, security, and abuse prevention.
14. ParkReply Pro and Subscriptions
On Android, ParkReply Pro is a yearly auto-renewing subscription purchased through Google Play. Google Play processes the payment, and RevenueCat is used to manage the subscription lifecycle and Pro entitlement.
Subscription data processed through RevenueCat may include what is necessary to provide and maintain Pro access: a pseudonymous ParkReply/App User ID, platform or store, product or subscription identifier, purchase, renewal and expiry state, entitlement status, cancellation, refund or revocation state, and transaction-related technical metadata.
RevenueCat processes purchase history on a required, non-ephemeral basis to provide subscription functionality and purchase and subscription analytics.
ParkReply does not directly receive or store the complete payment-card credentials used for an Android subscription purchase; Google Play processes the payment.
15. Apple and Google Payments
Google Play processes Android subscription payments. ParkReply does not directly receive or store complete card details for those purchases. The Google Play account and payment processing are also subject to Google’s terms and policies.
16. Stripe Payments
Stripe may process supported ParkReply Web or direct payments, including transaction amount and currency, payment information, fraud and security data, and refund or dispute data. Where Stripe processes card data directly, ParkReply should not retain complete card details.
17. Subscription Management and Cancellation
On Android, ParkReply Pro displays the current subscription status and provides “Manage Subscription”, which opens Google Play subscription management for management and cancellation.
Cancellation normally stops the next automatic renewal. Paid access may continue until the end of the paid entitlement period; a refund, revocation, or expiry may end the entitlement earlier.
18. Account Deletion and Subscription
Deleting a ParkReply account does not automatically cancel an Apple App Store or Google Play subscription.
To stop renewal, the user must manage or cancel the subscription through the applicable store before deleting the ParkReply account.
19. Orders and Physical Products
Physical products may be offered later and are not necessarily currently available. When available, ParkReply may process customer identity, contact details, shipping address, product and order data, price and currency, status, transaction metadata, and an optional order note.
20. Locally Stored Data
ParkReply may store the language preference, scanner device identifier, visitor code, local conversation references, cooldown or rate-limit state, and session-related information locally.
No advertising or tracking SDK is currently identified. If non-essential trackers are introduced later, appropriate consent will be implemented where required by law.
21. Processing Purposes
Data is processed to create and authenticate accounts, enable QR communication and messaging, provide Pro features, manage subscriptions and payments, send notifications, handle emergency and support requests, provide moderation and security, prevent fraud, perform account deletion, comply with legal obligations, and establish, exercise, or defend legal claims.
22. Legal Bases
Depending on the processing, ParkReply relies on performance of a contract, its legitimate interests—including securing and improving the service and preventing abuse—compliance with a legal obligation, or consent where required.
Vital interests may be relied upon only in exceptional circumstances where the legal criteria are actually met. A request labelled as an emergency in ParkReply therefore does not automatically rely on this legal basis.
23. Recipients and Service Providers
Current service providers include Firebase Authentication, Cloud Firestore, Cloud Functions for Firebase, Firebase Cloud Messaging, Firebase Installations, Firebase Hosting, and Firebase phone-verification infrastructure.
Current Android subscription providers include Google Play and RevenueCat. The Apple App Store or Stripe may be used for supported platforms or payment channels. Firebase Storage is not described here as actively collecting user-uploaded files where no effective upload feature exists.
ParkReply does not sell its users’ personal data to advertisers.
24. International Transfers
Some service providers may operate internationally. Where the GDPR applies, transfers of data outside the European Economic Area must rely on applicable legal safeguards. ParkReply does not assume unverified technical Firebase processing regions here.
25. Retention
Data is retained only for as long as necessary for the service purposes. The period depends on the relevant function, security and fraud-prevention needs, legal, accounting or tax obligations, and disputes or legal claims.
Operational closure of a request or conversation does not necessarily result in immediate deletion. ParkReply does not promise a fixed technical period where one is not actually implemented.
26. Permanent Account Deletion
Deletion may be requested in the app or through the public Web page at https://parkreply.com/account-deletion. The current process locks the account, deactivates and unlinks user-owned QR codes, and deletes private account data, FCM tokens and notifications, family contacts, the user’s revenueCatSubscriptionSync record, UID-linked supportTicketSubmissions idempotency references and, where applicable, queued SMS items and contact snapshots linked to the account.
The RevenueCat customer profile associated with the Firebase UID is deleted server-side. An HTTP 200 response confirming deletion or an HTTP 404 response indicating that the customer is already absent is treated as an ensure-deleted outcome. Deleting the RevenueCat customer profile does not cancel or refund the Google Play subscription; the user must separately manage or cancel the subscription through Google Play. UID-linked identifiers in chats, scanner data, emergency requests, reports, and other shared records are deleted or irreversibly anonymised according to the record type. Operational, moderation, security, or transaction history that must be retained is retained without a link to the deleted account through structured account identifiers. The account profile is deleted, and the Firebase Auth account is then deleted after cleanup that still depends on the UID has completed.
A minimal anonymous completion record may be retained. The deletion process may take up to 30 days.
27. Your Data Protection Rights
Subject to legal conditions, you may request access to, correction or deletion of your data, restriction of processing, object to processing, exercise portability rights, and withdraw consent where it is the legal basis. You may also lodge a complaint with a supervisory authority.
ParkReply does not claim to provide an automated export tool. For a manual request, write to contact@parkreply.com.
28. Users Outside the European Union
This Policy takes a global approach based primarily on European principles and the GDPR. Depending on your jurisdiction, mandatory local rights may also apply. ParkReply will respect applicable mandatory rights without claiming to be subject to or compliant with every law worldwide.
29. Minors
A ParkReply account is intended for people aged at least 16.
People under 16 must not create a Driver account unless permitted by law and all required authorisation exists. The Scanner can technically be used without a Driver account; minors must use it in accordance with applicable law and under a parent’s or guardian’s responsibility where required. ParkReply is not specifically directed at children.
30. Security
ParkReply implements measures such as authentication, Firestore rules, callable backend function authorisation, administrator-role controls, rate limiting, anti-abuse controls, deletion locking, and data anonymisation or deletion.
Data transmitted between the app and Firebase and RevenueCat services is encrypted in transit using HTTPS/TLS.
No measure guarantees absolute security. ParkReply does not claim that communications are end-to-end encrypted.
31. Automated Decisions and Restrictions
ParkReply may automatically apply rate limits, content filtering, cooldowns, restrictions after repeated reports, and other abuse-prevention controls. Where required by law, the user may contact ParkReply at contact@parkreply.com to request appropriate human review.
32. Supervisory Authority
Users in the European Economic Area may lodge a complaint with the competent data protection authority. Users in France may in particular contact the CNIL. The CNIL is not necessarily ParkReply’s lead supervisory authority.
33. Changes to This Policy
This Policy may be updated when features, service providers, applicable law, or data practices change. The version and update date identify the applicable text.
34. Contact
ParkReply OÜ
Registry code: 17572396
Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Email: contact@parkreply.com