Privacy Policy
This Privacy Policy explains what personal data Rezu (the “Platform”, “we”) processes in connection with the mobile app and this website, why, on what legal basis, for how long we keep it, and what rights you have under Regulation (EU) 2016/679 (GDPR). It is consistent with the consent screen shown in the app before the first action that requires an account (“We process your phone number, booking details, and spot location solely to provide the service. We don't share your data with third parties.”) and expands on it in full.
1. Who we are (data controller)
The data controller is [FOUNDER TO FILL IN: full legal name and form of the entity operating Neighbor Parking (sole proprietorship / company), registered address, Polish tax ID (NIP), company registry number (REGON)]. Until that entity is established and filled in here, data-protection matters can be directed to kontakt@rezu.pl.
We have not appointed a Data Protection Officer — not required at this pilot's current scale. This should be re-checked as part of a proper legal review.
2. What data we process, and why
The list below covers only data the app and backend actually collect today — we deliberately do not list features that exist in the product design but aren't wired to any real data flow yet (see the photo note at the end of this section).
Account and login
- Phone number — the sole account identifier and login method (a one-time SMS code, valid 10 minutes). We store no passwords at all — the app has no password-based login.
- Name / display name (optional) — shown to the other party on a booking.
- Role — owner, renter, or both.
- Rating and rating count — average star rating and written comments other users leave after a completed stay.
Bookings
- Vehicle license plate — required on every booking, so the spot owner knows whose car is parked on their spot.
- Parking spot address and bay number, geographic coordinates — entered by the owner when listing a spot. The address is publicly visible in search; the exact bay number and gate code are only revealed once a booking is confirmed.
- Expected arrival/departure time(optional) — if you choose to provide it.
- Report and rating comment text — free text you choose to write.
Device location
- With your consent (the OS-level iOS/Android permission prompt), the app reads your device's GPS location solely to center the map on your area. This location is processed ENTIRELY ON YOUR DEVICE — it is never saved or sent to our servers. You can decline the permission; the app then falls back to a default area.
Payments and settlement
- Today (pilot phase), settlement between a renter and an owner happens manually: the renter pays the owner directly by bank transfer (BLIK), and the owner manually confirms receipt in the app. The Platform does not process card numbers or the BLIK transaction itself.
- Bank account number (IBAN) — the payout form in the app stores this data ONLY locally on your device today; it is not transmitted to or stored on our servers. This will change once a real payment integration ships (see below) — this document will be updated at that point.
- Owner billing/tax profile — legal or company name, address, country, tax ID (NIP) or EU VAT number — collected when an owner wants to receive a consolidated invoice for the Platform's commission.
- KYC verification documents (proof of identity, proof of address) — collected ONLY from owners using the cross-border payout path (Mangopay), which is not yet live (no production credentials are connected) — the pilot runs on the manual BLIK settlement described above.
Technical and security data
- IP address — only when requesting an SMS code, to limit how many codes can be requested and to prevent abuse (a real SMS costs real money to send). Related security logs are kept for a maximum of 24 hours and deleted automatically.
- Push notification token — an identifier for your device within the push notification service (Expo/Apple/Google), used only to deliver booking notifications.
- In-app notification history — stored so you can look back at past notifications.
What we do NOT collect today: the app has no camera or photo-upload feature at all — not for the spot itself, not for vehicle condition. If that feature is ever built, this document will be updated BEFORE it ships, not after.
3. Legal bases for processing (GDPR Art. 6)
- Art. 6(1)(b) — processing necessary to perform the contract for the Platform's services (account creation, bookings, payouts, ratings).
- Art. 6(1)(c) — compliance with legal obligations, including tax and reporting obligations (see §6, DAC7).
- Art. 6(1)(f) — our legitimate interest: preventing abuse and fraud (SMS code rate limits, account suspensions), handling reports and disputes, and establishing or defending legal claims.
- Art. 6(1)(a) — consent, where we explicitly ask for it (e.g. OS-level access to your device location). You can withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
4. Who we share data with
We do not sell personal data and we do not share it with third parties for marketing purposes — that promise from the app's consent screen still fully holds. Data may be entrusted (as a processor, under GDPR Art. 28) to vendors that provide the technical infrastructure the service needs:
- Database and backend hosting — Neon (Postgres database) and Vercel (application/API hosting, serverless functions). A separate Data Processing Agreement (DPA) will be signed with each before real users go live in production.
- SMS (OTP) code vendor — not yet selected or connected. Login codes are generated and logged server-side (in test environments, returned directly in the API response — never in a production environment with real users). This document and the app's consent screen will be updated once a vendor is chosen, along with a processing agreement.
- Payment providers — Tpay (domestic PLN payments) and Mangopay (cross-border payments, wallets, KYC). The integrations exist in code but are not connected to real credentials or production accounts today — payments are currently settled manually (BLIK, confirmed by the owner, see §2). Once live, each provider will receive only the data needed to process a payment, payout, or KYC check — under a processing agreement, or, in Mangopay's case as a regulated payment institution responsible for its own KYC obligations, potentially as a separate data controller for KYC data [TO BE CONFIRMED LEGALLY].
- inFakt (invoicing) — a planned integration to issue consolidated monthly commission invoices to owners operating a registered business; not yet active (no connected credentials).
- Push notification provider — Expo/Apple/Google, limited to the device token, solely to deliver booking notifications.
We may also disclose data to public authorities where required by law (e.g. tax authorities under the DAC7 obligation — see §6, courts, law enforcement). We use no advertising trackers or ad networks of any kind — confirmed by reviewing the app and website code (no analytics or advertising SDK exists anywhere in the codebase).
5. How long we keep data / account deletion
You can delete your account at any time in the app (Profile → Account → Delete account) or by writing to kontakt@rezu.pl — see Delete account. Below is EXACTLY what happens to your data once you delete your account, matching how the system actually behaves:
- Your phone number and name/display name are immediately and irreversibly overwritten with a non-identifying value — they cannot be recovered.
- Your account verification level is reset to “unverified”.
- Your vehicle plate on YOUR OWN past bookings (as a renter) is overwritten with that same irreversible value.
- Any KYC documents you may have submitted through the Mangopay path are deleted outright, not just anonymized.
- Your push notification tokens are deleted outright.
- Any active spot-demand requests you filed are deleted outright.
- Any spots you listed are deactivated (removed from search) but NOT deleted from the database — they're needed for settlement and for the booking history of other users who booked them.
- The booking record itself (dates, price, link to the other party) REMAINS in the database, linked to your account only through a non-identifying internal ID — this is necessary so the other party's own settlement and rating history isn't destroyed; they have a right to keep their own financial history intact.
- Commission-ledger entries, if your booking was already settled or invoiced, are kept permanently as an accounting record — independent of account deletion (a legal record-keeping obligation).
Beyond your account: abuse-prevention logs (login/SMS-code rate-limit attempts) are kept for a maximum of 24 hours and deleted automatically. Monthly settlement reports for homeowners' associations are kept as an immutable accounting record for as long as accounting/tax law requires [TO BE CONFIRMED: exact retention period with an accountant/lawyer, typically 5 years].
6. Tax reporting obligation (DAC7)
As the operator of a digital platform that enables paid parking-spot rentals, Rezu may be subject to obligations under the DAC7 directive (Council Directive (EU) 2021/514, implemented in Poland via the act on the exchange of tax information with other countries) — an annual obligation to report to the Polish tax authority (Szef KAS) data about owners (“Sellers” under DAC7) who earn income through the Platform, including their identity, address, tax ID, and the amount and number of transactions in a given year.
The data collected in an owner's billing profile (§2) is groundwork for this obligation, but full DAC7 reporting (thresholds, the exact reported data set, the technical reporting channel to KAS) is not yet technically implemented — [TO BE CONFIRMED: requires review with an accountant/tax advisor before real payments go live in production]. If DAC7 reporting applies to you as an owner, we will notify you separately before the first report is filed.
7. Your rights
- Access — ask us what data we hold about you.
- Rectification — change your name/display name yourself in the app; request other corrections by email.
- Erasure (“right to be forgotten”) — see §5 for exactly what our “Delete account” feature actually does.
- Restriction and objection — you can object to processing based on our legitimate interest (§3); we review each request individually.
- Portability — you can request your data in a machine-readable format.
- Withdrawing consent — at any time, without affecting the lawfulness of prior processing.
- Lodging a complaint — you have the right to complain to Poland's data protection authority (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw), or to your own country's supervisory authority.
We handle all of the above today by email, at kontakt@rezu.pl — [TO BE CONFIRMED: a formal target response time — GDPR requires a maximum of one month; today we commit to confirming an account-deletion request within 72 hours, as stated on the “Delete account” page].
8. Data security
- Login uses SMS codes (OTP) only — we store no passwords whatsoever.
- Login and SMS-code request rate limits protect against account takeover and abuse.
- All communication between the app and our servers is encrypted over HTTPS.
- Sensitive details (e.g. a gate code) are only ever revealed to the authorized party on a booking, and only at the right moment — a gate code, for example, is only shown once a booking is confirmed.
9. Cookies and analytics on this website
This website does NOT use any cookies or tracking technologies — confirmed by reviewing its code: no Google Analytics, no Facebook Pixel, no analytics or advertising tool of any kind. The mobile app likewise contains no analytics, advertising, or tracking SDK (confirmed by a dependency review) — that's exactly why we don't implement an App Tracking Transparency prompt: there is nothing for a user to consent to. If that ever changes, this section (and a separate Cookie Policy, if needed) will be updated BEFORE such a tool is deployed, not after the fact.
10. Changes to this Privacy Policy
We may update this document, in particular as we roll out further features (online payments, KYC, DAC7 reporting). We will notify you of material changes in the app.
11. Contact
kontakt@rezu.pl · +48 601 234 214
[FOUNDER TO FILL IN: the data controller's registered postal address]
Last updated: August 9, 2026.
You can request account deletion at any time — see Delete account.