Draft. Not yet reviewed by a lawyer.
ParkFluent Privacy Policy
DRAFT for lawyer review. Not yet in force. Everything in [[DOUBLE BRACKETS]] is a placeholder that must be filled in before launch. Items marked LAWYER need a lawyer's judgment. Written from what the code does in October 2026; if the app changes, this must change with it.
Effective date: October 2026 (the day of the first public release; set the exact date at deploy) Who we are: ParkFluent is a product of DESSIGNE LLC ("we", "us"). Contact: hello@parkfluent.com.
ParkFluent is a map that shows what the posted signs say about parking on New York City curbs, for the time and length of stay you pick. This page explains what information the app uses, where it goes, and what you can do about it. The short version: we do not have accounts, we do not sell your data, there are no payments, and your phone's location stays on your phone unless you choose to send a sign photo.
1. What we collect, and why
Your location
- The blue dot, "Show my location", drive mode and "I parked here" read your phone's location on your device. The position is used to draw the dot, point the map and find the curb you are on. It is not sent to our servers for these features.
- Your parked car (the street, side, time and the time your parking runs out) is saved on your phone only (in the browser or app storage) so the banner and countdown can show. Clear it with "I have left this spot".
- If you send a sign photo (below), the app reads your location once to check you are near the stretch. Your coordinates are sent with the photo only to measure that distance; we do not store them, only the distance and the GPS accuracy.
- Location permission is yours to grant or refuse in your phone's settings. If you refuse, the map still works; you just do not get the dot or the nearby-photo prompt.
Sign photos (optional, "Help us check the signs")
- When the app is near a stretch where we are unsure what the signs say, it may ask you to photograph them. Nothing is sent until you take or choose a photo and tap send.
- On your phone, before upload: the photo is shrunk, people and vehicles are blurred (using Google's MediaPipe, which runs on your device and is hosted on our own site), and it is re-saved as a plain JPEG, which removes camera metadata such as the location tags. Please do not photograph people, faces or licence plates; the blur is automatic and can miss things.
- After upload: the photo goes to a private storage area (Vercel Blob). A person on our team looks at each photo before it can change anything on the map; photos are never applied to the map automatically. Stored with it: which stretch it was for, what our map said there, the distance and GPS accuracy, the time, a fingerprint of the blurred picture (to spot duplicates), your device identifier, and the nickname and email if you gave them.
- Photos are used only to check and improve the map, and are deleted after 12 months.
Feedback, points and the leaderboard
- The "Is this right?" thumbs, the Feedback form and ticket-check reports send us: your thumb or rating, an optional note, the stretch and rule you were looking at, the time and stay you had set, the app's data version, and a random device identifier the app makes on your phone. A nickname and an email are optional.
- Notes are scanned and anything that looks like a licence plate is replaced with "[plate removed]". Please do not write plates, names or other personal details in notes.
- Feedback records are kept for 12 months. Points are counted per device identifier. The public leaderboard shows nicknames and points only; your email is never shown. Your email, if given, is used only to contact you about rewards. Points are a thank-you and have no cash value; nothing can be redeemed during the free period, and we may change or end the points programme (see the Terms).
Push reminders (optional)
- If you turn on "Remind me" or street-cleaning alerts, your browser or phone gives us a push address (a device token). We store, in a private area, one small record per device: that token, the street name and rule of the spot you parked, when your parking runs out, when to remind you, the language you use. For street-cleaning alerts, we store the token, the weekdays of cleaning on your saved block, a street label and the language. We do not store your coordinates for reminders.
- We use these only to send the reminders you asked for. A reminder record is deleted after the reminder has been sent, or when you turn it off in the app. Push messages travel through the push service of your browser or phone maker (for example Apple, Google or Mozilla).
The assistant (optional, beta)
- If the voice/chat assistant is switched on, what you say or type is sent to our server and then to an AI language model (Anthropic's Claude Haiku, through the Vercel AI Gateway) whose only job is to turn your words into trip settings (place, day, time, stay length). It never sees curbs, rules or results; it does not decide what is legal.
- Voice: if you use the microphone, your phone's own speech recognition turns speech into text (on some devices the phone maker's or browser maker's speech service handles this; see their policies). We receive text only, not audio.
- We keep a count (not the words) of requests per device per day to limit abuse, and we log the number of tokens and cost of each request. We do not log what you asked. The AI provider processes the text to answer; see their terms [[LAWYER: confirm Vercel AI Gateway and Anthropic data-retention settings, zero-data-retention if available]].
The ticket checker
- If you enter a parking-ticket summons number, our server looks it up in NYC Open Data (public records) and tells you where and when it was written and what our map said then. We do not store the summons number or any plate. The lookup is not logged with the number. We keep an anonymous accuracy record (the stretch, the code, the day and minute, whether our map agreed), with no summons number.
Usage analytics (PostHog)
- We use PostHog to understand which features are used and to fix problems: page views, taps on map layers, theme and language changes, sheet opens, a heatmap of where people tap, and the status colour of a curb you opened (not the street or position). Events carry no exact coordinates (anything coordinate-like is rounded to about 100 m) and no query strings. We do not record sessions or screen video. Text boxes are masked, and the address search, feedback, assistant, ticket and photo screens are excluded from tap capture.
- The analytics are anonymous: PostHog is set to create profiles only for identified users, and we do not identify anyone.
- Your choice: Settings has "Share anonymous usage data", on by default. Turn it off and nothing is sent to PostHog. Your browser's Do Not Track or Global Privacy Control setting also turns it off automatically.
- This website (parkfluent.com) uses the same PostHog analytics: page views, clicks (including which "Open the map" button you used) and a heatmap of clicks. No session recording and no profiles. It keeps a random visitor identifier in your browser's local storage and sets no cookies. Do Not Track or Global Privacy Control turns it off.
- We keep analytics for up to 12 months. PostHog processes this on our behalf in the United States.
Error reports (Sentry)
- Sentry receives error reports (what failed, the page path, browser and device type) and a sample of 10% of page loads for speed. We strip query strings and, on our server, cookies and headers before sending. Sentry does not record sessions. Error reports are kept for up to 90 days.
Technical data
- Our host (Vercel) and our services see your IP address and browser details when your device connects, as every website does, and we use the IP to limit abuse (for example, a few lookups per minute). We do not use it to track you.
- Third-party map services: the map itself is Google Maps; Google receives your device's requests for map tiles and may collect data under its own policy. Address search uses NYC's public GeoSearch service. We do not control how those services handle data.
What stays on your device
The app saves these in your browser or app storage: language, theme and map choices, the parked car, reminder settings, your device identifier, nickname and email if you typed them, which prompts you have seen, and a day-pass record (unused). Clearing the app's data erases them. The assistant sets one cookie (pc_dev, up to one year) to count daily requests.
2. What we do not do
- No accounts or sign-in yet. No payments, subscriptions or advertising today: everything is free for now. The code for Premium and rewarded ads exists but is switched off; if we turn it on we will update this policy first and, for ads, ask you first.
- We do not sell personal information and do not share it for advertising.
- ParkFluent is for people 16 and older. We do not knowingly collect data from anyone under 16; if you think a child has sent us information, write to us and we will delete it. LAWYER: confirm the 16+ threshold and any app-store age rating.
3. Who we share information with (processors)
Vercel (hosting, private storage, AI gateway), Anthropic (assistant model, through Vercel), PostHog (analytics), Sentry (error reports), Google (map), and the push services listed above. They act on our instructions or as independent services as described. We may disclose information if the law requires it, or to protect people or our rights. If we sell or restructure the business, the data may move with it, under this policy.
4. How long we keep things
- Feedback records and sign photos: 12 months.
- Push reminder and alert records: deleted after the reminder is sent, or when you turn it off (alerts: until you turn them off).
- Analytics (PostHog): up to 12 months.
- Error reports (Sentry): up to 90 days.
- Request counters (abuse limits): one day.
- Everything on your own phone: until you clear it.
5. Your choices and rights
- Turn off location in your phone's settings; clear the parked car; turn reminders off in the app; use your browser's Do Not Track; clear the app's data; do not send photos or feedback.
- Ask us to see or delete the information tied to your device identifier, nickname or email: write to hello@parkfluent.com and include the device identifier shown in the app's About screen (we cannot find you otherwise, because we hold no account). [[LAWYER: rights wording for New York residents, California (CCPA/CPRA) and, if the app is available outside the US, EU/UK GDPR; decide whether a "Do not sell or share" statement is needed (we do not sell or share)]].
6. Security
Data is sent over HTTPS, photos and reminder records sit in private storage, and access is limited to people who need it. No system is perfectly secure, and we cannot promise it.
7. Changes
If we change this policy we will update the date above and, for material changes, tell you in the app. Using the app after a change means you accept it.
8. Contact
DESSIGNE LLC (ParkFluent), hello@parkfluent.com.