1. Overview & Scope
This Privacy Policy explains how ParkingBreeze LLC ("ParkingBreeze", "we", "us", or "our") collects, uses, protects, and discloses information when you use our website (parkingbreeze.com), software applications, QR code payment interfaces, mobile attendant manifests, and related services (collectively, the "Platform").
This Policy applies to:
- "Drivers" or "Parkers": Individuals who scan a ParkingBreeze QR code, access our mobile checkout, or pay for parking at any participating facility.
- "Operators" or "Clients": Commercial parking operators, property managers, municipalities, event venues, and asset owners who use ParkingBreeze to manage lots, stalls, enforcement, and revenue collection.
- "Visitors": Individuals who browse our public marketing website or contact our team for inquiries.
2. Information We Collect
We only collect the minimum information strictly necessary to process parking sessions, enforce parking permissions, and remit revenues to facility operators:
A. Information Provided by Drivers
- Vehicle License Plate Number & State/Jurisdiction: Used exclusively to identify the permitted vehicle on the operator’s active enforcement roster.
- Phone Number (Optional): If you request an SMS parking confirmation, expiration reminder, or remote time-extension link.
- Email Address (Optional): If you choose to receive an itemized digital expense receipt or tax invoice.
- Payment Details: Handled securely via tokenization through our payment gateway partner, Stripe Inc. We never view, collect, or store raw credit or debit card numbers, expiration dates, or security codes (CVV) on our servers.
B. Information Provided by Operators
- Operator Profile: Business name, corporate registration, business address, EIN/tax ID, and contact phone numbers.
- Banking & Settlement Information: Bank account routing numbers and Stripe Connected Account credentials required for direct automated daily payout disbursements.
- Facility Geometry: Parking lot boundaries, stall numbers, rate cards, and geographic coordinates.
C. Automatically Collected Technical Data
- Session & Scan Metadata: Timestamp of QR scan, lot identifier code, device browser type, operating system version, and IP address.
- Approximate Geolocation: Used solely during the instant of the QR scan to verify that the driver is physically located in proximity to the designated parking lot and prevent erroneous payments for remote facilities. We do not track continuous background GPS location.
3. Vehicle & License Plate Data (LPR) Policy
License plate numbers and associated camera reads collected via our web platform or integrated Automated License Plate Recognition (ALPR) systems are treated with strict confidentiality:
- Purpose Limitation: License plate data is collected solely for the operational purposes of verifying paid parking sessions, calculating duration, and enabling field attendants or automated gates to identify unauthorized parking.
- No Commercial Resale: We do not sell, license, rent, or trade license plate data or vehicular movement history to vehicle data brokers, advertising agencies, or marketing companies.
- Attendant Access: Enforcement personnel only see license plates associated with active, expiring, or unauthorized vehicles within their assigned geofenced territory during their active shifts.
4. How We Use Information
We process collected data for the following lawful and legitimate business interests:
- To initiate, process, tokenize, and settle parking transactions.
- To provide real-time occupancy updates and enforcement manifests to facility attendants.
- To deliver automated SMS alerts 15 minutes prior to session expiration, allowing drivers to extend time remotely.
- To deliver itemized receipts and tax documentation for corporate expense reporting.
- To detect, investigate, and prevent fraudulent payment attempts, chargebacks, and unauthorized access.
- To comply with legal obligations, tax filings, and legitimate regulatory audits.
5. Payment Security & PCI-DSS Compliance
ParkingBreeze maintains the highest standards of financial data security:
- PCI-DSS Level 1: All payment transactions are processed using Stripe Connect, certified under PCI Service Provider Level 1—the most stringent security certification available in the payments industry.
- Direct Browser Tokenization: Payment credentials entered by drivers on mobile checkout are sent directly from the driver’s browser to Stripe's encrypted vault via HTTPS using end-to-end TLS 1.3 cryptography. Our servers receive only a one-time cryptographic token and the last 4 digits of the payment method for receipt generation.
- Apple Pay & Google Pay: Digital wallet payments utilize device-specific Device Account Numbers (tokens) and dynamic cryptographic security codes, ensuring your actual card number is never exposed.
6. Sharing & Disclosures
We do not sell personal information. We disclose data only in the specific operational scenarios outlined below:
- To Parking Lot Operators: We provide operators and their authorized field attendants with the license plate number, paid arrival and departure timestamps, and spot/zone number to permit authorized parking. Operators do not have access to driver payment card numbers or personal contact info unless a driver explicitly submits a dispute.
- To Authorized Enforcement & Tow Contractors: In cases of non-payment or parking infractions, unauthorized vehicle license plates and infraction timestamps may be shared with licensed enforcement or towing partners designated by the lot operator.
- Service Providers: We share data with verified infrastructure vendors who support cloud hosting (Amazon Web Services), payment processing (Stripe), and transactional SMS delivery (Twilio). All vendors are bound by strict Data Processing Agreements (DPAs).
- Legal Compliance & Public Safety: We may disclose information if required by law, subpoena, court order, or when necessary to protect the life, safety, or property of individuals.
7. Data Retention & Deletion
We retain data only as long as necessary to fulfill the purposes described in this policy:
- Driver Transaction Records: Stored for 7 years to comply with statutory commercial tax, accounting, and audit standards.
- License Plate Logs: Session logs for non-violating, fully paid sessions are automatically anonymized or purged within 90 days of session completion, unless municipal contracts mandate specific alternative retention cycles.
- SMS Delivery Logs: Phone numbers used solely for one-time SMS expiration reminders are unlinked from active sessions within 30 days.
8. Security Safeguards
We employ administrative, physical, and technical safeguards engineered to protect your information against unauthorized access, destruction, or disclosure:
- Full AES-256 bit encryption at rest for all database volumes and encrypted file backups.
- Mandatory TLS 1.3 encryption for all data in transit across public networks.
- Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) required for all administrative personnel.
- Continuous automated vulnerability scanning, intrusion detection systems, and regular third-party penetration testing.
9. Your Privacy Rights
Depending on your state or country of residence (including California under CCPA/CPRA, and the European Union under GDPR), you may hold specific legal rights regarding your personal data:
- Right to Know & Access: You may request an itemized copy of the personal information we maintain regarding your account or vehicle.
- Right to Rectification: You may request correction of inaccurate vehicle or contact data.
- Right to Deletion: You may request erasure of your personal data, subject to legal and tax retention exemptions.
- Right to Opt-Out of SMS: You can opt out of SMS parking notifications at any time by replying "STOP" to any automated text message.
- Non-Discrimination: We will never deny services, charge different rates, or degrade quality if you exercise your statutory privacy rights.
11. Contact Our Privacy Team
If you have questions, concerns, or requests regarding this Privacy Policy or our data handling practices, please contact our Data Protection Officer:
Email: privacy@parkingbreeze.com
Direct Toll-Free: +1 (800) 555-0199
Mailing Address: 100 Congress Avenue, Suite 2000, Austin, TX 78701, USA