Privacy Policy — ParkOS
Last updated: 17 July 2026
Effective from: 17 July 2026
1. Who we are and what this policy covers
ParkOS (“ParkOS”, “we”, “us”, “our”) is parking-lot management software for India, available at parkingmanager.online.
ParkOS is sold to businesses — the owners and operators of parking lots (each, an “Operator”). Operators use ParkOS to run their lots: managing monthly members, recording payments and dues, issuing receipts, and managing staff.
This Privacy Policy explains what personal data we handle, why, and the choices and rights available to the people whose data is involved. It applies to the ParkOS web application, mobile apps, and related services (together, the “Service”).
A note on roles (important — see Section 3):For an Operator's own account data, ParkOS acts as a Data Fiduciary / Controller. For the data an Operator stores about their members, vehicles and staff, the Operator is the Data Fiduciary / Controller and ParkOS is a Data Processor acting on the Operator's instructions.
This policy is written with reference to India's Digital Personal Data Protection Act, 2023 (DPDP Act).
2. What data we collect and why
2.1 Operator account data (ParkOS is the Controller)
When an Operator signs up and uses ParkOS, we collect and store:
| Data | Why we handle it |
|---|---|
| Name, email address, phone number | Creating and identifying the account; login; support; billing communication |
| Password (stored only as a one-way hash) | Authenticating logins securely |
| One-time passcodes (OTP), stored hashed, and external auth identifiers | Verifying phone/email and enabling sign-in |
| Timezone and preferred language (English/Hindi) | Showing correct times and localised messages |
| Staff user accounts the Operator creates (name, phone, email, role) | Letting the Operator's staff use the Service |
| Billing/subscription identifiers from our payment provider (see Section 4) | Managing the Operator's ParkOS subscription |
2.2 The Operator's member and lot data (ParkOS is the Processor)
On the Operator's behalf and under the Operator's control, ParkOS stores the records the Operator enters or generates to run their lot. This can include:
- Members: name, phone number, email, membership status, monthly amount, discounts, assigned slot/zone, start and end dates, notes, and any member photos the Operator uploads.
- Vehicles: vehicle registration number, vehicle type, make/model/colour, and any RC (registration certificate) image the Operator uploads.
- Payments and dues: amounts, payment method (cash, UPI, or online), period, discounts and refunds, receipt numbers and receipt files, and payment proof images the Operator uploads.
- Operational records: parking sessions/tickets, shift reports, expenses, and reminder/notification logs.
ParkOS processes this data only to provide the Service to the Operator (for example, to show a members list, calculate pending dues, generate receipts, and send reminders). We do not use an Operator's member data for our own purposes.
2.3 Device and technical data
- Push-notification device tokens (Firebase Cloud Messaging tokens), platform and app version, so we can deliver notifications to the right device.
- Standard technical logs (such as IP address, timestamps, and error/audit events) needed to operate, secure, and debug the Service.
We do not run advertising trackers, and we do not sell personal data.
3. Roles and responsibilities (Controller vs Processor)
- For Operator account data, ParkOS decides the purposes and means of processing and is therefore the Controller / Data Fiduciary.
- For members', vehicles' and staff data entered by the Operator, the Operator is the Controller / Data Fiduciary — the Operator decides what to collect and why, and is responsible for having a lawful basis (including obtaining any required consent) to collect it and to put it into ParkOS.
- ParkOS is the Processorfor that data. We act on the Operator's documented instructions, keep the data confidential, apply the security measures described in Section 7, and assist the Operator in meeting its own legal obligations (including responding to data-principal requests and reporting breaches).
If you are a member of a parking lot and want to access, correct, or delete your data, please contact the Operator of that lot in the first instance, because they control that data. ParkOS will support the Operator in handling your request (see Section 8).
4. Third parties we share data with
We use a small number of trusted service providers. We share only what each provider needs, and only for the purposes below.
| Provider | Purpose | What is shared |
|---|---|---|
| Razorpay (payment gateway, India) | Processing online card/UPI/netbanking payments — both an Operator's ParkOS subscription and, where enabled, members' online dues payments | Payment amount, order/payment identifiers, and the payer details the payment flow requires. Card and bank credentials are handled by Razorpay, not stored by ParkOS. |
| Firebase Cloud Messaging (Google) | Delivering push notifications to Operator/staff devices | Device push token and the notification content |
| Cloud hosting provider (VPS) | Running the application and database | All Service data, stored on the server |
| S3-compatible object storage | Encrypted backups and stored files (e.g. receipts, uploaded images) | Backup copies of Service data and uploaded files |
Each provider processes data under its own terms and its contract with us. We do not permit them to use the data for their own purposes, and we share only the data needed for the purpose described above.
5. Where data is stored and how long we keep it
- Storage location: Service data is hosted on cloud servers and backed up in encrypted form to S3-compatible object storage.
- Retention while active:We keep an Operator's data for as long as their account is active, so the Service works and financial/receipt history stays intact.
- Financial records: Payment, receipt, and audit records may be retained for as long as applicable Indian tax and accounting law requires, even after other data is deleted.
- After termination: See the ParkOS Terms of Service for export and deletion on account closure. On request and after any legally required retention period, we will delete or irreversibly anonymise personal data.
- Backups: Backups are rotated on a schedule and expire automatically; deletions propagate to backups as they cycle out rather than instantly.
6. Cookies and similar technologies
The ParkOS web application uses only the cookies/local storage needed to keep you logged in and to make the app work (for example, session and preference storage). We do not use third-party advertising cookies.
7. How we protect data
We apply security measures appropriate to the data we handle, including:
- Tenant isolation:Each Operator's data is separated at the database level using row-level security (RLS) keyed to the Operator's tenant, so one Operator's queries cannot read another Operator's data.
- Encryption in transit: Connections to the Service use HTTPS/TLS.
- Encrypted backups: Backups are stored in encrypted form.
- Hashed credentials: Passwords and one-time passcodes are stored only as one-way hashes, never in plain text.
- Immutable financial audit log:Money-affecting changes (recording, allocating, or refunding payments, confirming online payments, and changing a member's monthly amount) are written to an append-only audit trail. This log is immutable at the database level — the application account is granted only the ability to add entries, not to modify or delete them.
- Access control:Staff access within an Operator's account is governed by roles the Operator assigns.
No system is perfectly secure, and we cannot guarantee absolute security. In the event of a personal-data breach, we will act in accordance with the DPDP Act and notify the affected parties and the Data Protection Board of India as required, and — where ParkOS is the Processor — assist the Operator (as Controller) in meeting its notification obligations.
8. Your rights
Subject to applicable law, individuals whose personal data we handle have rights to:
- Access the personal data held about them;
- Correct or update inaccurate or incomplete data;
- Erase their data, subject to legal retention requirements;
- Nominate another person to exercise their rights in the event of death or incapacity, as provided under the DPDP Act;
- Grievance redressal — raise a complaint about how their data is handled.
How to exercise your rights:
- If you are an Operator (about your own account data), contact us at privacy@parkingmanager.online.
- If you are a member or staff member of a parking lot, contact the Operator of that lot, who controls your data. ParkOS will assist the Operator in fulfilling your request.
We will respond within the timelines required by applicable law.
9. Grievance Officer
In accordance with the DPDP Act and applicable Indian law, you may raise any concern about how your personal data is handled with our Grievance Officer, reachable at grievance@parkingmanager.online.
For other data-protection matters you may also contact us at privacy@parkingmanager.online.
We aim to acknowledge grievances promptly and resolve them within the period required by law.
10. Children's data
ParkOS is a business tool and is not directed at children. Operators should not enter the personal data of a child (as defined under the DPDP Act) without the verifiable consent of a parent or lawful guardian, as the DPDP Act requires. As Controller of member data, the Operator is responsible for obtaining any such consent. If we learn that a child's data has been processed without the required consent, we will assist the relevant Operator in addressing it.
11. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “Last updated” date and notify Operators through the Service or by email. Continued use of the Service after an update means the updated policy applies.
12. Contact us
- Website: parkingmanager.online
- General and support: support@parkingmanager.online
- Privacy and data requests: privacy@parkingmanager.online
- Grievance Officer: grievance@parkingmanager.online