Skip to content
parkly

Privacy policy

The controller is Terarium j.d.o.o., Sokolgradska ulica 84, 10000 Zagreb, Hrvatska, company ID 96284727269. Data questions: info@parkly.hr

Who this covers

These rules apply to visitors who are not signed in, to drivers with an account, and to advertisers who publish a parking space. What we process about you depends on which of the three you are doing.

What we collect

Account: your name, email address, password in encrypted form, phone number and when it was verified, interface language, last sign-in time and failed sign-in attempts.

Google sign-in: if you choose to sign in with Google, we receive from Google a stable identifier for your account, your name, your email address and a link to your profile picture where Google sends one.

Listing: street name and house number, postcode, the exact coordinates of the space, description, price, availability window, features of the space and its charging, and photos.

Photos: a photo of a space can capture someone else's vehicle, number plate, house number or neighbouring property. The advertiser warrants they may publish it; we may remove it, and anyone shown in a photo can ask for removal at info@parkly.hr.

Enquiries and messages: message content, participants and timestamps. We do not read messages routinely and never use them for marketing or profiling; we access them only after a report or complaint, for moderation, or for a legal claim.

Listings and orders: the status and dates of a publication you bought, amounts, issued invoices, whether you bought as a private person or a business, and the company ID and name when you buy as a business. We never see or store card details, Stripe handles them.

Consents: we record the literal wording the screen showed you, which box you ticked, the time, your IP address, browser details and the version of the Terms in force. We also record your marketing consent and your setting for showing your phone number to signed-in users on your listing.

Technical data: IP address, browser details and timestamps, recorded with sign-ins, phone-number reveals, consents, complaints and entries in the activity log.

We do not ask for sensitive data. Do not put into a listing description or a message anything that does not belong there, company IDs, health data or documents.

Location of the space

When an owner hides the exact location, neither the street nor the real point is public: the map shows a point shifted by 80 to 200 metres and a circle around it, and the owner shares the exact address themselves. We strip EXIF data from photos, because it carries GPS coordinates.

If the owner chooses to show the location, the street name and a point on the map become public. The house number stays out of the public service either way.

Phone numbers and contact between users

An owner's phone number is not in the listing. Only a signed-in user can see it, and only if the owner turned that option on for that listing. An anonymous visitor never sees it. Every reveal is logged (who, which listing, when and from which IP address) so numbers cannot be harvested automatically.

Why we process it, and on what basis

  • Running your account, publishing and displaying listings, passing on messages and charging for a publication, performance of a contract, art. 6(1)(b) GDPR.
  • Issuing invoices, accounting, handling complaints and withdrawal statements, and duties under the Digital Services Act, legal obligation, art. 6(1)(c).
  • Security, fraud and abuse prevention (phone-reveal logs, rate limits, activity log), content moderation and defending legal claims, legitimate interest, art. 6(1)(f). We process only what that needs, and you can object to it.
  • Marketing messages and showing your phone number to signed-in users on your listing, consent, art. 6(1)(a). You can withdraw consent at any time, with no effect on the rest of the service.

Who we pass data to

We do not sell personal data and do not hand it over for training artificial-intelligence models. To run the service we use these providers:

  • DigitalOcean, servers, database and photo storage, in the Frankfurt data centre.
  • Vercel, serving the web interface and counting visits, without cookies and without tracking across sites.
  • Stripe, the one-off payment for a publication, and payment receipts. For part of its processing, such as fraud prevention and its own legal duties, Stripe acts as an independent controller.
  • Resend, sending transactional email (email verification, order and expiry notices, replies to requests).
  • Infobip, sending the SMS code that verifies a phone number.
  • MapTiler, maps and turning an address into coordinates. When a map loads, your browser sends MapTiler its IP address; address lookup goes through our server, so your browser does not talk to them directly.
  • Google, only if you choose to sign in with a Google account. Google then acts as an independent controller for its own processing.

Our accountants and lawyer may also see data in the course of their work, as may public authorities when they request it on a lawful basis.

Transfers outside the EU

Servers, database and photos are in the European Union. Some providers are United States companies or have group companies there, so a transfer outside the EU is possible. We make such transfers only with the safeguards in Chapter V GDPR, the European Commission's standard contractual clauses, or the EU–US Data Privacy Framework where the provider is certified.

Cookies

We set only the cookies that sign-in and form protection cannot work without, so we ask for no consent and show no pop-up. Every cookie and its purpose is listed on Cookies.

How long we keep it

  • We keep an account as long as it exists. If you ask for deletion, the account closes immediately and all your sessions stop working; the record remains briefly for support and possible legal claims, and is then removed.
  • We keep listings and photos as long as you keep them in your account. When the active period ends the listing stops being publicly visible, but that does not delete it: we keep the data for another 90 days so you can put it back on sale, and delete it after that. You can remove it at any time.
  • We keep enquiries and messages as long as they are needed to arrange the rental and to defend possible claims. We have no automatic deletion after a fixed period yet; you can ask us to delete them by email.
  • Consumer complaints are kept for one year from receipt, as the Croatian Consumer Protection Act requires.
  • Invoices and accounting records are kept for as long as tax and accounting law requires.
  • Records of consents, orders and withdrawal statements are kept for the term of the contract and afterwards until claims are time-barred; they are the evidence of what the screen said, and when.
  • Security records (sign-ins, phone-number reveals and the activity log) are kept as long as they are needed to prevent abuse and as evidence in a dispute.

Your rights

You have the right of access to your data, rectification of inaccurate data, erasure, restriction of processing, portability, objection to processing based on legitimate interest, and withdrawal of consent at any time.

You can delete your account yourself, in your account settings. For everything else, including a copy of your data, write to info@parkly.hr. There is no export button in the interface yet. We answer within one month; if the request is complex we may extend that by two months and will tell you.

Erasure does not reach what someone has already copied from a publicly published listing, or data we are required by law to keep, such as issued invoices.

You can also complain to the supervisory authority: Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, azop@azop.hr.

Automated decision-making

We take no decisions based solely on automated processing that would have legal effects for you. A person decides whether a listing is removed or an account restricted, every such decision states whether automated means were used, and you can appeal against it.

Security

Passwords are stored only as a cryptographic hash, traffic is encrypted, session cookies are not readable by scripts, tokens are stored hashed, and access to data is restricted. If a data breach occurs that poses a risk to your rights, we notify AZOP within 72 hours, and you where the risk is high.

Age

Parkly is not intended for people under 16. When you register you confirm that you are at least 16.

Changes

We publish changes to these rules on this page. The Croatian version is the authoritative one.