Privacy Policy
This Privacy Policy explains what personal data Rezu (the βPlatformβ, βweβ) processes in connection with the mobile app and this website, why, on what legal basis, for how long we keep it, and what rights you have under Regulation (EU) 2016/679 (GDPR). It is consistent with the consent screen shown in the app before the first action that requires an account (βWe process your phone number, booking details, and spot location solely to provide the service. We don't share your data with third parties.β) and expands on it in full.
1. Who we are (data controller)
The data controller is [FOUNDER TO FILL IN: full legal name and form of the entity operating Neighbor Parking (sole proprietorship / company), registered address, Polish tax ID (NIP), company registry number (REGON)]. Until that entity is established and filled in here, data-protection matters can be directed to kontakt@rezu.pl.
We have not appointed a Data Protection Officer β not required at this pilot's current scale. This should be re-checked as part of a proper legal review.
Below we describe the data we process in three parts: data common to every user (Β§2), data specific to using the Platform as a Driver/Renter (Β§3), and data specific to the Owner role (Β§4). Many people fill both roles at once β in that case both sections apply to them.
2. Data common to all users
The list below covers only data the app and backend actually collect today β we deliberately do not list features that exist in the product design but aren't wired to any real data flow yet (see the photo note at the end of this section).
Account and login
- Phone number β the sole account identifier and login method (a one-time SMS code, valid 10 minutes). We store no passwords at all β the app has no password-based login.
- Name / display name (optional) β shown to the other party on a booking.
- Role β owner, renter, or both.
- Rating and rating count β average star rating and written comments other users leave after a completed stay. This applies in both directions: you are rated both as a Driver and as an Owner.
Technical and security data
- IP address β only when requesting an SMS code, to limit how many codes can be requested and to prevent abuse (a real SMS costs real money to send). Related security logs are kept for a maximum of 24 hours and deleted automatically.
- Push notification token β an identifier for your device within the push notification service (Expo/Apple/Google), used only to deliver booking notifications.
- In-app notification history β stored so you can look back at past notifications.
What we do NOT collect today: the app has no camera or photo-upload feature at all β not for the spot itself, not for vehicle condition. If that feature is ever built, this document will be updated BEFORE it ships, not after.
3. Driver (Renter) data
The data below is processed in addition, when you use the Platform as a Driver β i.e. you search for and book a parking spot.
- Vehicle license plate β required on every booking, so the spot owner knows whose car is parked on their spot.
- Expected arrival/departure time(optional) β if you choose to provide it.
- Report and rating comment text β free text you choose to write as a Driver.
Device location
- With your consent (the OS-level iOS/Android permission prompt), the app reads your device's GPS location solely to center the map on your area. This location is processed ENTIRELY ON YOUR DEVICE β it is never saved or sent to our servers. You can decline the permission; the app then falls back to a default area.
Payment for a booking (BLIK)
- Today (pilot phase), settlement between a renter and an owner happens manually: the renter pays the owner directly by bank transfer (BLIK), and the owner manually confirms receipt in the app. The Platform does not process card numbers or the BLIK transaction itself.
4. Owner data
The data below is processed in addition, when you use the Platform as an Owner β i.e. you list a parking spot for rent.
- Parking spot address and bay number, geographic coordinates β entered by the owner when listing a spot. The address is publicly visible in search; the exact bay number and gate code are only revealed once a booking is confirmed.
- Report and rating comment text β free text you write as an Owner about a Driver (the same mechanism as Β§3, working in both directions).
Billing and payouts
- Bank account number (IBAN) β the payout form in the app stores this data ONLY locally on your device today; it is not transmitted to or stored on our servers. This will change once a real payment integration ships (see below) β this document will be updated at that point.
- Owner billing/tax profile β legal or company name, address, country, tax ID (NIP) or EU VAT number β collected when an owner wants to receive a consolidated invoice for the Platform's commission.
- KYC verification documents (proof of identity, proof of address, tax ID) β collected directly by Stripe (Stripe Connect, Express accounts) as part of its own hosted Owner-onboarding flow β NOT by Rezu's own servers; we keep no local copy of these documents or identity data (see Β§6 and Β§7 below). Submitting these documents is a statutory requirement under anti-money-laundering (AML) regulations that Stripe, as a licensed payment institution, must comply with β it is not an arbitrary request from Rezu. This onboarding flow applies today to ALL owners using the Platform's payout rails β not only cross-border bookings β and also helps collect the tax ID needed for DAC7 reporting (see below in this section). Stripe is currently in TEST MODE only (no production credentials are connected) β the pilot still runs on the manual BLIK settlement described in Β§3.
Tax reporting obligation (DAC7)
As the operator of a digital platform that enables paid parking-spot rentals, Rezu may be subject to obligations under the DAC7 directive (Council Directive (EU) 2021/514, implemented in Poland via the act on the exchange of tax information with other countries) β an annual obligation to report to the Polish tax authority (Szef KAS) data about owners (βSellersβ under DAC7) who earn income through the Platform, including their identity, address, tax ID, and the amount and number of transactions in a given year.
The data collected in an owner's billing profile (described above in this section) is groundwork for this obligation, but full DAC7 reporting (thresholds, the exact reported data set, the technical reporting channel to KAS) is not yet technically implemented β [TO BE CONFIRMED: requires review with an accountant/tax advisor before real payments go live in production]. If DAC7 reporting applies to you as an owner, we will notify you separately before the first report is filed.
5. Legal bases for processing (GDPR Art. 6)
- Art. 6(1)(b) β processing necessary to perform the contract for the Platform's services (account creation, bookings, payouts, ratings).
- Art. 6(1)(c) β compliance with legal obligations, including tax and reporting obligations (see Β§4, DAC7 section).
- Art. 6(1)(f) β our legitimate interest: preventing abuse and fraud (SMS code rate limits, account suspensions), handling reports and disputes, and establishing or defending legal claims.
- Art. 6(1)(a) β consent, where we explicitly ask for it (e.g. OS-level access to your device location). You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
6. Who we share data with
We do not sell personal data and we do not share it with third parties for marketing purposes β that promise from the app's consent screen still fully holds. Data may be entrusted (as a processor, under GDPR Art. 28) to vendors that provide the technical infrastructure the service needs:
- Database and backend hosting β Neon (Postgres database) and Vercel (application/API hosting, serverless functions). A separate Data Processing Agreement (DPA) will be signed with each before real users go live in production.
- SMS (OTP) code vendor β not yet selected or connected. Login codes are generated and logged server-side (in test environments, returned directly in the API response β never in a production environment with real users). This document and the app's consent screen will be updated once a vendor is chosen, along with a processing agreement.
- Payment providers β Tpay (domestic PLN payments, unchanged) and Stripe (Stripe Connect: cross-border/foreign-currency payments AND onboarding, KYC verification, and payouts for ALL owners using the Platform β including those settled domestically through Tpay). Stripe replaces the previously planned Mangopay integration (migrated 2026-08-20) and today runs in TEST MODE only β no production credentials are connected; the pilot still runs on the manual BLIK settlement described in Β§3. Owner onboarding, identity verification (KYC), and payout bank-account collection happen entirely on Stripe's own hosted pages β Rezu never stores a local copy of that data (unlike the earlier Mangopay-based design). Stripe, Inc. most likely acts as a separate data controller for its own regulatory KYC/AML obligations as a licensed payment institution [TO BE CONFIRMED LEGALLY] β see the international-transfer notice below.
- International data transfer (Stripe, USA) β GDPR Art. 13(1)(f): the contracting entity for users outside the Americas is Stripe's European company, based in Ireland [TO BE CONFIRMED LEGALLY: exact registered name of this entity], but under Stripe's global technical infrastructure, data may be further transferred to its US parent company, outside the EEA. Using Stripe as our payment processor and as the Owner onboarding/KYC platform may therefore involve transferring personal data (including identity data collected during Owner onboarding) to the US. Such a transfer can rest on two independent bases: (1) the European Commission's adequacy decision of 10 July 2023 (EU 2023/1795) for the EU-U.S. Data Privacy Framework (DPF), provided the relevant Stripe entity is actually on the current list of certified participants, and (2) β independently of DPF, as a safeguard in case it is ever struck down (as happened previously to Safe Harbor and Privacy Shield) β Standard Contractual Clauses (SCCs, GDPR Art. 46), approved by the European Commission and forming part of the Data Processing Agreement (DPA) Stripe offers. Details: stripe.com/dpa and stripe.com/legal/privacy-center. [TO BE CONFIRMED LEGALLY: exactly which Stripe entity is currently DPF-certified, and the exact transfer mechanism actually applicable to Rezu's data β verify directly in the signed Stripe DPA before production launch].
- inFakt (invoicing) β a planned integration to issue consolidated monthly commission invoices to owners operating a registered business; not yet active (no connected credentials).
- Push notification provider β Expo/Apple/Google, limited to the device token, solely to deliver booking notifications.
We may also disclose data to public authorities where required by law (e.g. tax authorities under the DAC7 obligation β see Β§4, DAC7 section, courts, law enforcement). We use no advertising trackers or ad networks of any kind β confirmed by reviewing the app and website code (no analytics or advertising SDK exists anywhere in the codebase).
7. How long we keep data / account deletion
You can delete your account at any time in the app (Profile β Account β Delete account) or by writing to kontakt@rezu.pl β see Delete account. Below is EXACTLY what happens to your data once you delete your account, matching how the system actually behaves:
- Your phone number and name/display name are immediately and irreversibly overwritten with a non-identifying value β they cannot be recovered.
- Your account verification level is reset to βunverifiedβ.
- Your vehicle plate on YOUR OWN past bookings (as a renter) is overwritten with that same irreversible value.
- Your Stripe Connect account link (the Stripe account ID stored in our database) is deleted and your onboarding status is reset to βnot startedβ β BUT the underlying identity/KYC data itself, held on Stripe's own servers, is NOT automatically deleted by this mechanism β that remains outside our direct control. Whether to also trigger a separate deletion request directly with Stripe is an open product/legal decision, not yet implemented [TO BE CONFIRMED LEGALLY / TO BE BUILT]. (Rezu has never kept a local copy of KYC documents for the Stripe path β unlike the earlier Mangopay-based design, which had a local documents table.)
- Your push notification tokens are deleted outright.
- Any active spot-demand requests you filed are deleted outright.
- Any spots you listed are deactivated (removed from search) but NOT deleted from the database β they're needed for settlement and for the booking history of other users who booked them.
- The booking record itself (dates, price, link to the other party) REMAINS in the database, linked to your account only through a non-identifying internal ID β this is necessary so the other party's own settlement and rating history isn't destroyed; they have a right to keep their own financial history intact.
- Commission-ledger entries, if your booking was already settled or invoiced, are kept permanently as an accounting record β independent of account deletion (a legal record-keeping obligation).
Beyond your account: abuse-prevention logs (login/SMS-code rate-limit attempts) are kept for a maximum of 24 hours and deleted automatically. Monthly settlement reports for homeowners' associations are kept as an immutable accounting record for as long as accounting/tax law requires [TO BE CONFIRMED: exact retention period with an accountant/lawyer, typically 5 years].
8. Your rights
- Access β ask us what data we hold about you.
- Rectification β change your name/display name yourself in the app; request other corrections by email.
- Erasure (βright to be forgottenβ) β see Β§7 for exactly what our βDelete accountβ feature actually does.
- Restriction and objection β you can object to processing based on our legitimate interest (Β§5); we review each request individually.
- Portability β you can request your data in a machine-readable format.
- Withdrawing consent β at any time, without affecting the lawfulness of prior processing.
- Lodging a complaint β you have the right to complain to Poland's data protection authority (Prezes UrzΔdu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw), or to your own country's supervisory authority.
We handle all of the above today by email, at kontakt@rezu.pl β [TO BE CONFIRMED: a formal target response time β GDPR requires a maximum of one month; today we commit to confirming an account-deletion request within 72 hours, as stated on the βDelete accountβ page].
9. Data security
- Login uses SMS codes (OTP) only β we store no passwords whatsoever.
- Login and SMS-code request rate limits protect against account takeover and abuse.
- All communication between the app and our servers is encrypted over HTTPS.
- Sensitive details (e.g. a gate code) are only ever revealed to the authorized party on a booking, and only at the right moment β a gate code, for example, is only shown once a booking is confirmed.
10. Cookies and analytics on this website
This website does NOT use cookies or any technology that stores or reads data on your device β that's why we don't show a cookie-consent banner (there is nothing to consent to under the ePrivacy Directive / Polish Telecommunications Law). For site traffic statistics we use Vercel Web Analytics, a tool that stores no files on your device and identifies visitors only via a temporary hash generated from the request (not a cookie), automatically discarded after 24 hours. It collects aggregated data only: the URLs visited, the referring page, an approximate location (country/region/ city derived from IP, without storing the IP address itself), and device/browser type β none of it capable of identifying an individual or tracking them across sites. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in understanding and improving the site. We do not use Google Analytics, Facebook Pixel, or any advertising tool. The mobile app still contains no analytics, advertising, or tracking SDK (confirmed by a dependency review) β that's exactly why we don't implement an App Tracking Transparency prompt: there is nothing for a user to consent to. If that ever changes, this section will be updated BEFORE such a tool is deployed, not after the fact.
11. Changes to this Privacy Policy
We may update this document, in particular as we roll out further features (online payments, KYC, DAC7 reporting). We will notify you of material changes in the app.
12. Contact
kontakt@rezu.pl Β· +48 601 234 214
[FOUNDER TO FILL IN: the data controller's registered postal address]
Last updated: August 21, 2026.
You can request account deletion at any time β see Delete account.