Privacy Policy

Last updated: 17 August 2026

Who is responsible for your data

The controller of the personal data described in this policy is:

SmartPark Solutions Sp. z o.o.

47/10 Domaniewska Street, 02-672 Warsaw, Poland

E-mail: hello@parkflow.io
Phone: +48 573 503 979

We have not appointed a Data Protection Officer. Please send any data protection matter to the address above, marking it "Personal data" — it will reach the person responsible.

ParkFlow® is the parking management platform operated by SmartPark Solutions Sp. z o.o. This policy covers the parkflow.io website, the ParkFlow accounts we provide to parking operators, and our contact and marketing communication.

Two different roles: controller and processor

ParkFlow is software that parking operators use to run their own business. This matters for your rights, because it decides who you should turn to.

We are the controller

for data we decide about ourselves: visitors to parkflow.io, people who contact us, parking operators and their staff who hold a ParkFlow account, and our own billing and marketing. This policy describes that processing.

We are only a processor

for data that a parking operator processes inside their own ParkFlow account — reservations, driver contact details, vehicle registration numbers, arrival and departure times, payments and invoices. The parking operator is the controller of that data. It decides why and how the data is used and for how long it is kept; we only act on its documented instructions under a data processing agreement (Art. 28 GDPR), and we do not use that data for our own purposes.

If you parked or made a reservation and want to exercise your rights, address the request to the parking operator you booked with — its details are on your booking confirmation, receipt or invoice. If you send the request to us instead, we will pass it on to the operator without undue delay and let you know whom we passed it to, but we cannot decide about it ourselves.

What we owe the operator under that agreement: we process its data only on its instructions, we keep our staff bound by confidentiality, we secure the data (Art. 32 GDPR), we help the operator answer requests like yours and meet its own obligations, we notify it of a personal data breach without undue delay, and at the end of the contract we delete or return the data. We engage sub-processors — hosting, e-mail delivery, monitoring — only under the same obligations, and the operator is informed of them and may object.

Operators: the data processing agreement is part of your contract with us. If you need a copy, or a list of current sub-processors, write to hello@parkflow.io.

What we collect, why, and for how long

DataPurposeLegal basisRetention
Enquiries: name, e-mail, phone number, the content of your message and any attachmentsAnswering you and, where relevant, taking steps before entering into a contractArt. 6(1)(b) GDPR (steps before a contract) and Art. 6(1)(f) — our legitimate interest in handling correspondenceFor as long as needed to handle the matter, then up to 3 years (limitation of claims)
Account and trial: name, company name, business address, e-mail, phone number, login and activity records in the panelCreating and running your ParkFlow account, support, security of the serviceArt. 6(1)(b) GDPR (performance of the contract); Art. 6(1)(f) for account securityFor the duration of the contract, then up to 3 years (limitation of claims)
Billing: invoice and payment data for the subscriptionIssuing and settling invoices, tax and accounting obligationsArt. 6(1)(c) GDPR (legal obligation)5 years from the end of the calendar year in which the tax became due
Technical logs: IP address, browser and device type, referring page, dates and times of requestsKeeping the service available and secure, diagnosing faults, preventing abuseArt. 6(1)(f) GDPR (legitimate interest in the security of our systems)Up to 12 months, longer only for an incident under investigation
Analytics: cookies and identifiers described in the section belowMeasuring how the website is used and improving itArt. 6(1)(a) GDPR (your consent)Up to 14 months, or until you withdraw consent
Marketing to business contacts: e-mail address, company, contact historySending information about ParkFlow to parking operators and prospective customersArt. 6(1)(f) GDPR (direct marketing of our own services), or your consent where the law requires itUntil you object or withdraw consent

Providing data is voluntary, but without it we cannot answer an enquiry, set up an account, or issue an invoice.

Location Data

The ParkFlow Driver application collects location data during use and in the background. It is used solely to show the real-time position of shuttle buses to the parking operator running that service, and it is processed on that operator's behalf — the operator is the controller of it. The data is not shared with third parties and is not used for any other purpose.

Cookies and analytics

Cookies that are necessary to display the site and remember your privacy choice are always set. Analytics and marketing cookies are set only after you accept them in the banner — until then Google Consent Mode keeps them switched off.

We use Google Analytics (Google Ireland Limited) to see how visitors use the site. Your choice is stored in your browser's local storage under cookie:consent. To withdraw consent, clear your browser's storage and cookies for parkflow.io — the banner will appear again — or block cookies in your browser settings.

The site loads fonts from Google Fonts, which means Google receives your IP address when a page opens. We do not use that data ourselves.

Who receives your data

We share data only where it is needed, with:

  • our hosting and infrastructure providers, who keep our production systems in the European Union, and in the United States for customers we serve from that region;
  • providers of e-mail delivery, error monitoring and support tools;
  • payment providers and accounting software used for our own invoicing;
  • Google, for website analytics and fonts;
  • our accountants and legal advisers, and public authorities where the law requires it.

Where a provider processes data outside the European Economic Area, the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards in place.

We do not sell personal data, and we do not make decisions about you by automated means that produce legal effects or similarly significantly affect you.

Your rights

Where we are the controller, you have the right to:

  • access your data and receive a copy of it (Art. 15 GDPR);
  • have inaccurate or incomplete data corrected (Art. 16);
  • have your data erased (Art. 17);
  • have processing restricted (Art. 18);
  • receive your data in a portable format or have it sent to another organisation (Art. 20);
  • object to processing based on our legitimate interest, including direct marketing — an objection to marketing is always effective (Art. 21);
  • withdraw consent at any time, without affecting processing carried out before the withdrawal (Art. 7(3)).

Write to hello@parkflow.io or to our postal address. We answer within one month of receiving the request; if the matter is complex we may extend that by up to two further months and will tell you why (Art. 12(3) GDPR).

Exercising your rights is free of charge. Only for a manifestly unfounded or excessive request — in particular a repetitive one — may we charge a reasonable fee covering our administrative costs or refuse to act, and we will explain why if that happens (Art. 12(5) GDPR).

Before we act on a request we need to be reasonably sure who is asking. Normally it is enough that the request comes from the e-mail address or the account we already hold for you. If we have genuine doubts about your identity we may ask for additional information that helps confirm it (Art. 12(6) GDPR) — we will ask only for what is necessary, we will not ask for a copy of your ID document, and the answer will not be used for anything else.

You may also lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw.

If your request concerns a reservation, a vehicle or a parking stay, please see "Two different roles" above — those rights are exercised against the parking operator, and we will help it answer you.

Children

ParkFlow is a service for businesses and is not directed at children. Where processing rests on consent, a child needs to be at least 16 years old for that consent to be valid — the age set by Art. 8 GDPR, which Poland has not lowered; below that age the consent of a parent or guardian is required. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

California residents

If you live in California, the CCPA/CPRA gives you the right to know what personal information we have collected about you, where it came from, why we collected it and whom we shared it with; to receive a copy of it; to have it corrected or deleted; to limit the use of sensitive personal information; and not to be discriminated against for exercising any of these rights.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. Where we handle data on behalf of a parking operator we act as its service provider and use the data only to provide the service — such a request should be sent to the operator, exactly as described in "Two different roles" above.

To exercise these rights write to hello@parkflow.io. We respond within 45 days and may extend that once, by a further 45 days, if the request is complex — we will tell you if we do. An authorised agent may act for you if you give them written permission.

Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we process your data, we will inform account holders by e-mail before it takes effect.