← parkoo

Privacy Policy

Last updated: October 2026 · parkoo · Lausanne, Canton Vaud, Switzerland

parkoo processes personal data in accordance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the EU General Data Protection Regulation (GDPR).

01Introduction & scope

This Privacy Policy explains how Nedim Bajraktarevic, sole proprietor ("parkoo", "we", "us", "our"), Chemin du Boisy 36, 1004 Lausanne, Switzerland, registered in Switzerland under company number CHE-425.610.056, collects, uses, stores, and shares personal data when you use the parkoo.app mobile app, website, or any related service (collectively, the "Platform"). It applies to all users — drivers, hosts, and visitors. By using the Platform you acknowledge you have read and understood this policy.

02Data controller

The data controller responsible for your personal data is Nedim Bajraktarevic ("parkoo"), Chemin du Boisy 36, 1004 Lausanne, Switzerland (CHE-425.610.056). For privacy-related queries or to exercise your rights, contact us at hello@parkoo.app.

03How we collect your data

We collect data you provide directly (during registration, bookings, listings, identity verification, or when you contact support), data generated automatically by your use of the Platform (device identifiers, usage logs, GPS coordinates when the app is open), data from third-party partners (identity verification results, payment tokenisation references), and data inferred from your activity (search patterns, preferences). We do not purchase personal data from data brokers.

04Legal basis for processing

Under the EU GDPR and the Swiss FADP, we process your data on the following legal bases: (a) Contract performance — to create your account, process bookings, and facilitate payments; (b) Legal obligation — to comply with anti-money laundering, tax, and identity verification requirements; (c) Legitimate interests — to detect fraud, improve Platform safety, and send service notifications; (d) Consent — for optional marketing communications and non-essential advertising cookies, which you can withdraw at any time. Platform tax reporting: collecting, verifying and reporting Host information under the rules described in Terms Section 11(j) is necessary to comply with a legal obligation (Art. 6(1)(c) GDPR; Swiss FADP).

05How we use your data

We use your personal data to: operate and maintain your account; process bookings and payments; verify your identity; provide customer support; send transactional notifications (booking confirmations, access codes, receipts); detect and prevent fraud or abuse; comply with legal obligations; conduct anonymised analytics to improve the Platform; and, with your explicit consent, send you promotional offers or feature announcements. We do not sell your personal data to third parties.

06Data sharing & third parties

We share your data only as necessary: (a) with the other party in a booking (drivers see the host's first name and access instructions; hosts see the driver's first name and vehicle details (make, model, colour and licence plate) — never each other's last name). Where a host has connected a licence-plate camera at their entrance ("Gate access"), we additionally share the booking's licence plate and booked time window with that host's gate system so a booked vehicle can be admitted automatically; the hardware or software vendor operating that gate acts as the host's processor, not ours; (b) with our payment processor (Stripe) for transaction processing; (c) with our infrastructure provider Supabase (database, authentication, and file storage — data hosted within the EU, specifically Ireland); (d) with analytics tools using anonymised, aggregated data only; (e) with Google (Firebase Cloud Messaging) and Apple (APNs) to deliver push notifications to your device; (f) with Google, Microsoft, or Apple, where you choose to sign in to the Platform using one of those accounts; (g) with Komoot GmbH (Photon) to convert a searched location into an address, and with CARTO to display the map; (h) with Resend to send transactional emails on our behalf; (i) with law enforcement or regulatory authorities when legally required; (j) for Hosts concerned, with the tax authority of the EU Member State where parkoo is registered for platform reporting, which passes it on to the tax authorities of the Host's country of residence and of the country where the parking space is located, and with equivalent authorities in other countries such as Norway: the Host information that platform reporting rules (DAC7) require parkoo to report once a year (see Terms, Section 11(j)). Identity verification is carried out directly by the parkoo team and is not outsourced to any third-party verification provider. All third-party processors are bound by data processing agreements meeting GDPR standards.

07International transfers

Your data is hosted and processed primarily within the European Union (Ireland), by our cloud infrastructure provider, with parkoo itself registered and operated from Switzerland. Where data is transferred to countries outside the EU/EEA that lack an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent Swiss transfer mechanisms, to ensure an adequate level of protection.

08Data retention

We retain your personal data for as long as your account is active, or as needed to provide services and comply with legal obligations. Specifically: while your account is active, your account data is held as needed to provide the service; once you close your account, your profile is anonymised immediately (your name, contact details, and address are removed), and the anonymised record is retained thereafter for the same reason your booking and payout history is (see below) — it remains linked to real financial records that Swiss law requires us to keep; booking records are retained for 10 years for tax and legal purposes; identity verification documents (the ID and selfie photos you submit) are retained while your account remains active, deleted within 30 days if your verification is rejected, or within 24 months of account closure if it was approved — the fact and outcome of your verification is kept separately and is not affected by this; records relating to a dispute, fraud investigation, or safety incident are retained for as long as needed to resolve or defend the matter, and are deleted once that need ends; reviews you have written or received continue to be retained after your account is closed, since other Users relying on a Listing's review history have a legitimate interest in that record being preserved, and your name is anonymised on any such record following closure; messages you exchange with other Users are retained for 10 years, matching the booking retention period, since the other party to a conversation has their own legitimate interest in that record being preserved for as long as a related claim could be raised — your name is likewise anonymised on any such record following closure; support communications are retained for 2 years; notifications are retained for 90 days; device tokens are deleted after 180 days without an active app session; gate access event logs (licence-plate reads at a Host's entrance) are retained for 12 months; crash logs and usage analytics are anonymised after 12 months. You may request earlier deletion of other data categories subject to legal retention obligations. Information collected for platform tax reporting is retained for 10 years, in line with the retention of booking records.

09Cookies & tracking

Our mobile app does not use cookies — it stores your session token in your device's local storage so you stay signed in, and nothing else. Our website currently uses strictly necessary cookies only (authentication and security), which cannot be disabled as the website cannot function without them. We do not currently use any advertising or marketing cookies, and we do not currently share data with Google, Meta, LinkedIn, or any other advertising partner. If this changes in future, any such cookie will only ever be set with your consent, given via the banner shown on the website; you can review or change your choice at any time via "cookie preferences" at the bottom of the page.

10Your rights

Under GDPR and FADP you have the right to: (a) Access — obtain a copy of the personal data we hold about you; (b) Rectification — correct inaccurate or incomplete data; (c) Erasure ("right to be forgotten") — request deletion of your data where no legal retention obligation applies; (d) Portability — receive your data in a structured, machine-readable format; (e) Restriction — ask us to pause processing while a dispute is resolved; (f) Objection — object to processing based on legitimate interests; (g) Withdraw consent — at any time for consent-based processing, without affecting prior lawful processing. We will respond to all requests within 30 days.

11How to exercise your rights

Use the "Download my data" and "Delete my account" links at the bottom of this Privacy Policy, or the "Delete my account" option in Profile → Settings within the app. We may ask you to verify your identity before processing the request. There is no charge for exercising your rights. If we are unable to fulfil a request, we will explain why in writing.

12Data security

We implement industry-standard technical and organisational security measures including: TLS 1.3 encryption in transit; AES-256 encryption at rest for sensitive fields; role-based access controls limiting internal data access to those with a business need; regular penetration testing by independent security researchers; and a documented incident response plan. In the event of a data breach that poses a high risk to your rights, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it.

13Children's privacy

The Platform is not directed at persons under 18 years of age. We do not knowingly collect personal data from minors. If you believe a child has created an account or provided us with personal data, please contact us via the Contact support form available within the app and we will delete the information promptly.

14Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. Material changes will be communicated via in-app notification or email at least 14 days before they take effect. The "last updated" date at the top of this policy will always reflect the most recent revision. We encourage you to review this policy periodically.

15Complaints

If you are dissatisfied with how we handle your data, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, or — if you are located in the EU — with your local data protection authority. We encourage you to contact us first via the Contact support form available within the app so we can attempt to resolve the issue directly.

parkoo — Nedim Bajraktarevic · Chemin du Boisy 36, 1004 Lausanne, Switzerland · CHE-425.610.056 · hello@parkoo.app