This document is published in English and in eight translations. The English text is the authoritative one: where a translation and the English differ, the English governs.
1. In short
- To book, you give a name, an email address and a phone number. A vehicle registration and a flight number are optional.
- Those details go to the operator of the car park you booked, because they are the people who have to find your car and release it to you. They are the ones responsible for that record.
- Nothing is asked for that a booking does not need: no account, no password, no date of birth, no postal address. Card details go into the payment processor’s own form and travel to it directly — Parkena never sees them.
- This site runs no analytics and sets no cookies of its own. Your browser keeps the theme you chose and, briefly during a payment, the booking’s email address; the payment step loads one script, Stripe’s. Nobody is tracking you here.
- Prices move on their own, but never because of anything about you. There is no profile of you anywhere in this platform.
2. Who is responsible for what
Two companies are involved in every booking, and European data-protection law wants to know which of them decides what happens to your details. The honest answer is that both do, for different purposes.
The car park operator
The operator is the controller of your booking. It is their car park, their inventory, their staff who will call the number you gave if your car is due at 04:40 and you are not there, and theirs is the barrier your car has to come back through. The booking, the contact record and the vehicle are written into the operator’s own records, which no other operator can see. The sale itself is Parkena’s — see the paragraph below.
Parkena
Parkena is the controller for running the platform: publishing the listings, quoting the price, taking the payment in its own name, writing the booking accurately, keeping its own record of the sale as it was struck, and keeping the service secure and honest. Parkena also operates the database and the console the operator uses, and in that role acts as a processor on the operator’s behalf.
Because one database holds both sides, the split above is about purposes rather than about machines. Parkena has technical access to the records it stores for operators, and says so here rather than implying a separation that does not physically exist.
[ TO BE COMPLETED BEFORE LAUNCH — the controller’s legal entity name, registered address and contact address for data-protection requests ]
[ TO BE COMPLETED BEFORE LAUNCH — whether a data protection officer is required and, if so, who it is — and the written processing agreement between Parkena and each operator ]
3. What is collected when you book
This is the whole list of what a booking collects. It is the parameter list of the one database function a booking goes through, so there is nothing collected quietly beside it. Card details are not on it and never join it: the card form on the payment step is Stripe’s, and section 4 says what that means.
From the form
- First name and last name. Required — a car cannot be released to someone who cannot be named.
- Email address. Required. Stored case-insensitively, because an address differing only in capitals is the same address.
- Phone number. Required. This is the number the car park rings, so it is kept current rather than frozen with the sale.
- Vehicle registration. Optional. Stored in capitals with spaces and punctuation removed, so that one car is one car at the barrier. The platform can also carry the country the plate is registered in; the current booking form does not ask for it.
- Flight number. Optional. Stored in capitals, and used to expect you when a flight is late.
From the booking itself
- The car park, the drop-off and pick-up times as wall-clock times at that car park, and the time zone they are read in.
- The sale as it was struck: the currency, the total, one line per chargeable day, and the platform’s cancellation terms as they stood at that moment. This part is frozen and is never rewritten, because it is the record of what you agreed to.
- The booking status and the payment status, which start as pending and pending.
- A reference, generated by the database from the booking’s own identifier.
- The times the record was created and last changed.
- The language you were browsing in when you booked, so that a message about the booking can be written in it.
One derived value, and what it is for
The booking also stores a fingerprint computed from the car park, the two dates, your email address and your registration — a SHA-256 hash, not the values themselves. Its only job is to recognise a second press of the Reserve button as the same booking rather than a second car. It is not an identifier used for anything else, it is never shared, and it is not reversible into your details.
When you only search
Searching sends the place and the dates you typed to the database so that it can price stays for them. Nothing identifying you is attached, and nothing about a search is stored.
4. What is not collected
- Card details never reach Parkena. Paying happens in a form that Stripe, the payment processor, puts on the page: what you type there goes to Stripe directly, and what Parkena keeps is the amount, the currency and whether the booking is paid — never the card.
- No traveller account, no password, no login. There is nothing to sign into.
- No postal address, no date of birth, no document number.
- No analytics, no advertising identifiers and no pixels. The site sets no cookies of its own; your browser holds your theme choice and, during a payment, the booking’s email address, and the payment page loads Stripe’s script. See the cookies page, which says all of this in more detail.
- No location data. The site never asks the browser where you are.
5. How your details reach the operator
This website is a set of static files. When you press Reserve, look up a booking or cancel one, your browser sends the request over HTTPS to a small Parkena function that runs in front of the database. That function checks how many requests are arriving from one network address, then writes or reads the booking in the database under a restricted role. It logs only which route was called, whether it succeeded and how long it took — never your reference, your email address, your name or your network address — and keeps no copy of your details.
The database refuses a booking rather than guessing, and when it does it writes a line to its own server log naming the car park and the reason. That line carries no contact details.
6. Why we are allowed to hold it
- To take and perform the booking you asked for — the name, the email address, the phone number, the stay, the registration and the flight number. This is processing necessary for a contract with you (Article 6(1)(b) GDPR).
- To keep the platform working honestly: recognising a double submission so you are not booked twice, refusing a sale at a price you were not shown, holding a record that reconciles against the operator’s own books, and defending the service against abuse. These are our legitimate interests and the operator’s (Article 6(1)(f)).
- To keep the transaction record the law requires the operator to keep for tax and accounting purposes (Article 6(1)(c)).
Nothing here is done on the basis of consent, because nothing optional is done at all: there is no marketing, no analytics and no tracking to consent to. If that ever changes, it changes with a request rather than quietly.
8. Where it is stored, and transfers outside the EU
The two hosting providers above are American companies that offer European hosting regions, and both can be — and should be — configured to keep this data in Europe. Stripe and Resend are American as well, and the mechanism their processing relies on belongs in the same blank below. Which region the production system actually runs in, and on what legal mechanism any transfer outside the European Economic Area relies, are facts that must be stated here exactly rather than approximated:
[ TO BE COMPLETED BEFORE LAUNCH — the hosting region of the production database and of the website ]
[ TO BE COMPLETED BEFORE LAUNCH — the transfer mechanism relied on for any processing outside the EEA (standard contractual clauses, an adequacy decision, or the arrangement that replaces them) ]
Where the car park itself is in Switzerland, the operator holding your booking is Swiss. Switzerland is recognised by the European Commission as offering an adequate level of protection, so that particular hop needs no further mechanism.
9. How long it is kept
Plainly: nothing is deleted automatically. There is no scheduled deletion, no expiry job and no retention timer anywhere in this platform today, and this notice will not claim one.
A booking cannot be deleted at all. The privilege to delete one is granted to nobody — not to the operator, not to their owner account, not to the platform’s own service key — because a booking is a financial record and a contract, and whether a refund is owed is a question that has to remain answerable. A booking that does not happen is cancelled, and the cancelled record is the answer.
Your contact record is a separate row and is treated differently. It can be corrected, and it can be redacted in place, which is how an erasure request is honoured: the sale survives, the person disappears from it. A contact record that no booking points at can be deleted outright.
A redaction is not a blank. Your first and last name, your email address, your phone number and every vehicle registration on your bookings are overwritten with fixed markers, and the date it happened is recorded on the record. What is left cannot be used to reach you or to recognise you, and it cannot be undone.
The booking itself keeps its reference, its dates, its car park and its total, because that is the financial record. It no longer says who you are.
Your details are kept while the stay is still to come or the car is still with the operator. They have to be able to reach you and hand your car back to you. Once the stay is over — collected, or cancelled — the record can be redacted on request.
[ TO BE COMPLETED BEFORE LAUNCH — the retention schedule and the statutory minimum that sets it ]
10. Your rights
If the GDPR applies to you, you have the right to ask for a copy of the personal data held about you, to have it corrected, to have it erased, to have its use restricted, to receive it in a portable form, and to object to processing carried out on the basis of legitimate interests. You can also complain to a supervisory authority.
Erasure has the limit set out in section 9: the sale record survives an erasure request, redacted, because the law obliges the operator to keep it. Everything else about you can go.
The operator holding your booking is the fastest route for anything about that booking, and their name is on your confirmation. You can also write to Parkena, which operates the system the record sits in.
Asking the operator is not a form of words: erasing your details is a control on the booking in the software they run every day, and an owner or a manager of that business can do it there and then once your stay is over. Nobody at Parkena has to be involved, and nobody has to write any code.
Write to [email protected]. Mark the message as a data-protection request so it is not handled as ordinary support — it starts a clock that ordinary support does not.
[ TO BE COMPLETED BEFORE LAUNCH — the postal address for data-protection requests ]
[ TO BE COMPLETED BEFORE LAUNCH — the supervisory authority a complaint should be addressed to ]
Until those two lines are filled in, the working route is the email address on the contact page. It reaches a person, and a request sent there will be dealt with — but it is a general support inbox rather than a channel built for requests of this kind, and it is not a substitute for the formal address a controller has to publish.
11. Automated decisions, and why prices move
No decision with a legal or similarly significant effect on you is made automatically, and no profile of you exists anywhere in this platform.
Prices do move by themselves, and that deserves a straight answer rather than a denial. Where an operator has set a range instead of a fixed price, the platform picks the daily price inside it from exactly two inputs: how full that car park already is on that date, and how many days away the date is. It has no other inputs. It does not know who is asking, it does not read a browsing history, it does not consider the device, and it cannot: none of that reaches the calculation. Two people asking for the same stay at the same moment are quoted the same number.
12. How it is protected
- Everything travels over HTTPS.
- There is no traveller account, so there is no password of yours to lose.
- The key this website carries in the browser is not a secret and is not a skeleton key: it can reach exactly two database functions — the price list and an id generator — and no tables at all. Reserving, looking up and cancelling a booking all go through a separate function that the key does not unlock. It cannot read a booking, yours or anybody else’s.
- Operators are isolated from one another by row-level security in the database, not by application code that could be routed around.
- Errors raised inside a booking are masked before they reach the browser, so a refusal cannot be used to learn how full a car park is or what another operator has configured.
Those rules are covered by an automated test suite that runs against the database itself. No external penetration test has been commissioned yet, and this notice does not claim one.
13. If you are an operator
A console account holds your name and email address, the operator you belong to, your role in it, and any invitations you sent or accepted. Sign-in is handled by Supabase Auth; your session and the operator you last worked in are kept in your browser’s local storage so that you stay signed in.
The bookings and contact records in your console are your customers’ data and you are their controller. Parkena processes them on your instructions in order to run the software.
Because you are the controller of those records, an erasure request from one of your travellers is yours to honour. The console does it: open the booking, and the traveller card has an action that redacts their name, email address, phone number and number plate in place while keeping the booking. An owner or a manager can use it once the stay is over.
[ TO BE COMPLETED BEFORE LAUNCH — the data processing agreement operators enter into, and its sub-processor annex ]
14. Children
Parkena is a service for people old enough to hold a driving licence and book a car park. It is not directed at children and no part of it asks for a child’s details.
15. Reviews you write
At least 24 hours after you have picked your car up, Parkena raises one request to ask how the stay went — one for each booking, and a second is impossible rather than merely unlikely. Those requests are not being delivered at present: Parkena’s own mail is not in service, and this notice will not describe a message as sent until it is. When it is, that request is the only one there is: no reminder follows it, and ignoring it ends the matter.
A review you write is published. The score, the headline, what went well, what could have been better and the kind of trip you were on all go on that car park’s page on Parkena, where anybody can read them. The operator sees the same review in their console and may reply to it in public.
The byline is your first name and, when your booking recorded one, the country your number plate is registered in. Nothing else about you travels with it: not your surname, not your email address, not your phone number, not the plate itself and not your flight number.
If your contact record is redacted, as section 9 describes, the first name and the country are removed from every review you wrote and it reads as coming from a traveller with no name. The score and the words stay published, because they are about the car park rather than about you.
A review stays on the car park’s page for as long as that car park is listed on Parkena.
[ TO BE COMPLETED BEFORE LAUNCH — the lawful basis for sending the review request and for publishing a review, and how long a published review is kept ]
16. Changes to this notice
This notice changes when the product changes, and the date at the top is when it last did. There is no mailing list to announce a change through — the only mail Parkena sends you is about a booking you made — so the date is the notice.
