The short version. We collect the minimum data needed to sell you a parking pass and get you into the lot: your name, email, phone, vehicle plate, and payment details (processed by Stripe, we never see your card number). We don't sell your data to advertisers. You can delete your account any time. If you have questions, email legal@parkministry.com.

01Overview

This Privacy Policy explains what information Park Ministry Inc. ("Park Ministry", "we", "us") collects when you use our website, mobile apps, and services (together, the "Service"), how we use it, who we share it with, and what rights you have over it.

This policy applies to buyers (people purchasing parking passes), operators (businesses selling passes through us), and visitors who browse without an account. We are a New York-based company and follow the California Consumer Privacy Act (CCPA/CPRA), the European Union General Data Protection Regulation (GDPR), the UK GDPR, and similar US state privacy laws.

02What we collect

You give us

  • Account details: full name, email address, phone number, preferred language and currency.
  • Vehicle details: make, model, license plate. Required so the operator knows whose car to expect.
  • Payment details: card number, expiry, CVC, billing postal code. These go directly to Stripe, our payment processor. Park Ministry servers never store your full card number; we only keep the last four digits and a token.
  • Communications: messages you send to support, reviews, survey responses.

We collect automatically

  • Usage data: pages viewed, searches performed, bookings made, device type, browser, IP address (truncated after 30 days), session timestamps.
  • Cookies & similar tech: see §8.

We do not collect

  • Biometric data (face, fingerprint). Our apps never request it.
  • Social security / government ID numbers. We have no use for them.
  • Contact lists, photos, or microphone access.

03How we use your information

We use the data we collect for these purposes and nothing else:

  • Fulfil your bookings. Send your pass to the operator, confirm vehicle plate, display your QR code at the gate.
  • Payments and refunds. Charge your card, issue refunds, detect fraud.
  • Customer support. Answer your questions, resolve disputes, honour the Park Ministry Guarantee.
  • Product improvement. Measure which features are used, find bugs, improve search relevance. This uses aggregated or pseudonymised data whenever possible.
  • Communications you ask for. Booking confirmations, receipts, reminders. You can turn off marketing emails in your account.
  • Legal obligations. Respond to valid subpoenas, tax reporting, anti-money-laundering checks.
We never sell your personal data to advertisers. We do not run third-party ad networks, we do not share your identity with data brokers, and we do not profile you for advertising on other sites.

05Who we share information with

Operators

When you buy a pass, we share your name, email, phone, and vehicle plate with the operator of that lot. They need this to verify you on arrival. Operators are bound by contract to use the data only to fulfil the booking.

Service providers

  • Stripe — payment processing. Subject to Stripe's own privacy policy.
  • Resend — transactional email (receipts, pass delivery).
  • Supabase — application hosting, database, and file storage (data stored in the United States, US East / Ohio region).
  • Vercel — website hosting and content delivery.

Each of these processors is under a data-processing agreement with us and may only use your data to deliver the service they're contracted for.

Legal requests

We may disclose information when we have a good-faith belief it's required to comply with a subpoena, court order, or other legal process, or to protect someone's safety. We will push back on overbroad requests and notify you unless legally prohibited from doing so.

Business transfers

If Park Ministry is acquired or merged, your data may be transferred to the acquiring entity, which will be bound by this Privacy Policy or a successor with equivalent protections. We'll notify you if this happens.

06How long we keep your data

  • Account data : while your account is active. Deleted 30 days after you close the account (grace period so you can recover it).
  • Booking records : 7 years after the booking date, as required by Canadian and EU tax law.
  • Payment tokens : deleted when you remove the card or close your account.
  • Support messages : 3 years after the last message, then deleted.
  • Server logs : 90 days. IP addresses are truncated to the first three octets after 30 days.
  • Backups : encrypted backups are retained up to 35 days after deletion, then overwritten.

07Your rights

Regardless of where you live, you can:

  • Access : download a copy of the data we hold on you.
  • Correct : fix wrong or outdated information (most of it you can edit yourself in your account).
  • Delete : close your account and have personal data removed, subject to legal retention requirements above.
  • Port : receive your data in a structured, machine-readable format.
  • Object or restrict : tell us to stop using your data for a specific purpose (e.g., product analytics).
  • Withdraw consent for anything we do based on consent (marketing, GPS).
  • Complain to your local data-protection authority. In the US, the FTC handles privacy complaints; California residents can contact the CA Attorney General; in the EU, your national supervisory authority.

Requests can be made by emailing us at privacy@parkministry.com in the app. If that's not enough, email legal@parkministry.com and we'll respond within 30 days (or sooner if the law requires).

08Cookies & similar technologies

We use the minimum set of cookies to make the site work:

  • Strictly necessary — session cookies that keep you logged in, remember your cart, and prevent cross-site request forgery. No consent required; the site can't function without them.
  • Preferences : currency, language, recently viewed lots. Stored in localStorage.
  • Analytics : first-party, aggregated page-view counts. We do not use Google Analytics, Facebook Pixel, or any third-party ad/analytics service.

You can clear cookies any time in your browser settings. Doing so will sign you out and reset your preferences.

09Children's privacy

Park Ministry is not intended for children under 16. We don't knowingly collect personal data from anyone under 16. If you believe a child has created an account, email legal@parkministry.com and we'll delete it promptly.

10International data transfers

Park Ministry is a US-based company headquartered in New York, NY. Your data is stored in the United States (with Supabase, in the US East / Ohio region). We operate in the United States only and do not transfer your personal data outside the country.

11How we protect your data

  • TLS 1.2+ on every connection.
  • Passwords are hashed with bcrypt (work factor 12). We never see or store your password.
  • Production databases are encrypted at rest (AES-256).
  • Access to production data is limited to a small number of engineers on a need-to-know basis, logged, and reviewed.
  • Annual third-party penetration tests and quarterly internal security reviews.

If we ever discover a breach affecting your personal data, we'll notify you within 72 hours of confirmation.

If you find a vulnerability, please email security@parkministry.com. We do not pursue good-faith researchers who follow responsible-disclosure practice.

12Changes to this policy

If we make a material change — something that expands how we use your data, introduces a new category of data we collect, or adds a new third-party recipient — we'll email every active user at least 30 days before it takes effect. Non-material changes (clarifications, typo fixes, new service provider in the same category) are posted here with an updated "Last updated" date.

If you disagree with a material change, you can close your account before it takes effect and we'll refund any unused pre-paid balance.

13Contact us

Park Ministry LLC
2248 Broadway #2196
New York, NY 10024
USA