Privacy Policy for the Rezu App and Platform
Effective date: August 30, 2026
Last updated: October 4, 2026
§1. Data Controller
- The controller of personal data of Users of the Rezu Platform (the "Platform", the "Service", the "App") is Karolina Tomaszyk, ul. Tadeusza Rejtana 4/29, 60-653 Poznań, Poland, NIP (Polish tax ID): 6653018221, REGON (business registry number): 381357920 (the "Controller").
- For matters relating to the protection of personal data, you can contact us at kontakt@getrezu.pl or at the postal address given in para. 1 above.
- The Controller has not appointed a Data Protection Officer (DPO). All inquiries should be directed to the email address above.
§2. Purposes, Legal Bases, and Retention Periods
| Purpose of processing | Scope of data | Legal basis (GDPR) | Retention period |
|---|---|---|---|
| Account registration and management | Email address, Google/Apple ID identifier, phone number (optional), name/display name, role in the app | Art. 6(1)(b) (performance of a contract) | Until the User deletes their Account |
| Carrying out a Booking | Vehicle license plate, booking time, spot address and bay number, access code | Art. 6(1)(b) (performance of a contract) | For the duration of the agreement, plus 5 years from the end of the accounting year (tax purposes) |
| Ratings and reviews system | Star rating, comment text | Art. 6(1)(f) (legitimate interest — building trust on the Platform) | Until the Account is deleted or a justified objection is raised |
| Evidentiary verification of a spot's condition (check-in/check-out) | Optional photos of the spot/vehicle, file metadata | Art. 6(1)(f) (legitimate interest — protection against claims and dispute handling) | Deleted when the Account is deleted, unless an active dispute is ongoing (until it is finally resolved) |
| KYC verification and Owner payouts | Identity data, bank account, tax data | Art. 6(1)(c) (legal obligation — AML/DAC7) | As set by the payment provider (Stripe) and by tax-law requirements (min. 5 years) |
| Sharing details needed for a sales document (company invoice) | The Renter's company details entered with the Booking: company name (for a sole proprietorship, usually the person's own name), tax identification number (NIP or VAT number), registered address and country; a business Host's company details: name, tax identification number, registered address | Art. 6(1)(b) (performance of a contract) and Art. 6(1)(f) (legitimate interest of the Controller and of the other party to the transaction in being able to issue and to receive a sales document) | For as long as the Booking record is kept, and for the period required by tax and accounting law |
| Measuring how well our pages and materials work (entry source) | A short tag of the page or material from which the User moved to the browser version of the app (e.g. “wilda_hero_owner”), saved with a spot listing, a demand request or at first sign-in. No IP address, no referring page, no ad click identifiers | Art. 6(1)(f) (legitimate interest – finding out which of our pages and materials bring spot listings and requests) | 12 months from when the tag is saved, and no longer than until the Account is deleted or an objection is upheld; after that only aggregate counts remain, not linked to any person |
| Correspondence with boards and managers of residential buildings (housing communities) | Name of the housing community or managing company, name and role of the contact person, phone number, email address, the content of replies, the code printed on the envelope | Art. 6(1)(f) (legitimate interest – presenting Rezu and corresponding with the board or manager of a building); phone calls only with consent (Art. 6(1)(a) GDPR in conjunction with Art. 398 of the Polish Electronic Communications Law), which can be withdrawn at any time | 12 months from the last contact, or until an objection is upheld (for consent to phone calls, until it is withdrawn), whichever comes first |
| Website traffic statistics (Vercel Web Analytics) | Addresses visited, referring page, country, region and city derived from the IP address (the IP address itself is not stored), device and browser type; events: a click on an app download button and a pass through our download link (platform and utm campaign parameters) | Art. 6(1)(f) (legitimate interest – understanding site traffic and how well our materials work) | Aggregate data; the hash that recognises a visit is discarded after 24 hours |
| Analytics and improvement of the in-browser app (PostHog) | Screens visited (address without identifiers or parameters, except the entry-source tag), in-app events (e.g. map moves with zoom level and city, pin clicks, viewing a spot, booking steps, payment, sign-in, an error code shown), clicks described by the button's name (without its text), click heatmaps, repeated clicks and clicks with no effect, referring domain, device, OS and browser type, screen size; after sign-in, the internal Account identifier. Nothing typed into forms | Art. 6(1)(f) (legitimate interest – understanding how the app is used and removing obstacles) | Up to 12 months from collection; earlier if an objection is upheld |
| Session recordings in the in-browser app (only with consent, PostHog) | A masked record of how the app is used: screen layout, cursor movement, clicks, scrolling, window size, screen address without identifiers. All text, typed data, images and payment fields are hidden. After sign-in the recording is linked to the internal Account identifier | Art. 6(1)(a) (consent) in conjunction with Art. 399(1) of the Polish Electronic Communications Law | Up to 30 days from recording; earlier on request, including after consent is withdrawn |
| Error and stability monitoring (Sentry) | Error description and where in the code it happened, page address or screen name, device, OS and browser type, app version, the steps before the error (e.g. moving between screens), the duration of selected operations (performance measurement), a technical installation identifier of the mobile app assigned by the tool. No name, e-mail address or phone number | Art. 6(1)(f) (legitimate interest – detecting and fixing errors, security and stability of the service) | Up to 90 days from when the error was recorded |
| Waitlist (landing page) | Email address, preferred role (looking for a spot / have a spot), districts of interest (optional), intended rental length (optional), a free-text message (optional – please do not enter details we have not asked for, such as a phone number or address), hashed IP | Art. 6(1)(a) (consent) / Art. 6(1)(f) (form security) | Until the launch notification is sent, or consent is withdrawn |
| Security and technical analytics | IP address in security logs (login codes, admin sign-in, rate limits), push tokens, error logs | Art. 6(1)(f) (legitimate interest — preventing abuse and service stability) | IP addresses in security logs are deleted automatically after a maximum of 14 days (a cyclical purge run on the 1st and 15th of each month). Push tokens have no established automatic deletion deadline today and are removed when the Account is deleted. Data may additionally exist in encrypted database backups for up to 14 days |
Correspondence with boards and managers of residential buildings (housing communities). We write letters to the boards of housing communities and to building management companies to introduce Rezu. We take the address for such a letter from publicly available sources: managers' websites, publicly available business directories, public registers (KRS, CEIDG) and notices posted in the building. At that stage we usually know only the name of the community or company and its address. The remaining details, i.e. the name and role of the contact person (e.g. board member, building manager), phone number, email address and the content of the reply, we receive directly from the person who replies to us. The code on the envelope lets us match a reply to the letter it answers.
The legal basis is the Controller's legitimate interest (Art. 6(1)(f) GDPR), namely presenting Rezu and corresponding with the board or manager of a building. We do not call without consent: we only call a person who has asked for a call and given us a phone number (consent – Art. 6(1)(a) GDPR in conjunction with Art. 398 of the Polish Electronic Communications Law, “Prawo komunikacji elektronicznej”). Consent can be withdrawn at any time, e.g. by writing to kontakt@getrezu.pl or by saying so during a call; withdrawal does not affect the lawfulness of earlier calls. We keep the data for 12 months from the last contact, and delete it earlier if we uphold an objection or if consent to phone calls is withdrawn (in that case we delete the phone number). The data is available only to the Controller and to the hosting and email providers listed in §3, which store it on our behalf. We do not pass it on to other Users or for advertising purposes.
The person concerned has the rights described in §6, in particular the right to object (Art. 21 GDPR) to processing based on a legitimate interest, including processing for direct marketing. After an objection to direct marketing we stop contacting the person and keep only a note that we do not write to that community or manager again.
§3. Recipients of Data and Transfers Outside the EEA
Sharing data between Users: A phone number, name, and vehicle license plate are disclosed to the other party of a transaction only once a Booking has been confirmed and paid for.
Details needed for a sales document (company invoice): Rezu is an intermediary marketplace — the seller of the parking service is the Host (the Owner of the Spot), and it is the Host who issues their own sales document: an invoice, a receipt or another document, as their own tax situation requires. Rezu does not issue sales documents on the Host's behalf, does not generate them and does not store them. Rezu issues its own invoice, covering only Rezu's service fee, separately.
If, while booking, a Renter explicitly states that they need a document for their company, the company details they enter — company name (for a sole proprietorship this is usually the person's own name), tax identification number (NIP or VAT number), registered address and country, as far as the Renter provides them — are shown to the Host of that Booking: only after the Booking has been paid for, only to that Host, and only so that the Host can issue the sales document. Until the moment the Host first views those details, the Renter can still correct them.
If the Host is a business (a company account in their billing details), the Host's name, tax identification number and registered address are shown to the Renter of that paid Booking who asked for a company document, so that the Renter can identify the seller. The address of a Host who is a private individual is never shared.
No other data from either party's profile is shared through this flow — in particular no email address, phone number or Account data. The only recipient of these details is the other party to that same Booking. A tax identification number provided may additionally be checked against public taxpayer registers (the VAT taxpayer list maintained by the Head of Poland's National Revenue Administration, or the EU VIES system); that is a lookup of the number in a register, not a disclosure of data to another User.
Legal basis and retention: performance of a contract (Art. 6(1)(b) GDPR) and the legitimate interest of the Controller and of the other party to the transaction in making it possible to issue and to receive a sales document required by tax law (Art. 6(1)(f) GDPR). These details are kept for as long as the Booking record is kept, and for the period required by tax and accounting law. All the rights described in §6 of this Policy apply to these details as well, including the right of access, the right to rectification, and the right to object to processing based on a legitimate interest.
Processors: The Controller entrusts the processing of data to cloud and technology service providers under data processing agreements (DPAs):
- Neon Inc. (hosting of the Postgres database — Frankfurt, EU).
- Vercel Inc. (server hosting, Vercel Blob file storage and Vercel Web Analytics traffic statistics).
- Resend Inc. (sending emails containing transactional codes).
- home.pl S.A. (the kontakt@getrezu.pl mailbox — Poland).
- PostHog, Inc. (USA) (analytics and session recordings in the in-browser app — data stored in PostHog's EU cloud, Frankfurt).
- Functional Software, Inc. d/b/a Sentry (USA) (error monitoring for the website, the mobile app and the server — data stored in Sentry's EU region, Frankfurt).
- OpenStreetMap Foundation (the Nominatim geocoding service — converting an entered address into map coordinates).
- Expo (Google LLC) (delivering push notifications to the mobile app).
Independent data controllers:
- Stripe Payments Europe, Ltd. / Stripe, Inc.: For identity verification (KYC/AML), card payment processing, payouts to Owners, and payment fraud prevention (including the Stripe cookies described in §8). Stripe processes personal data as a separate, independent controller under its own privacy policy.
- Google LLC / Apple Inc.: For the social sign-on (Single Sign-On) process.
Transfer of data to third countries (USA): Transfers of data to the USA (e.g. Stripe, Vercel, Sentry) are based on the European Commission's adequacy decision on the EU-U.S. Data Privacy Framework (DPF), or on Standard Contractual Clauses (SCCs) approved by the European Commission.
Data from in-browser app analytics (PostHog) and error monitoring (Sentry) is stored on servers in the European Union (Frankfurt). Both providers are US companies, so their staff may access the data from the USA, e.g. for technical support; such access is based on the DPF or the SCCs named in that provider's data processing agreement.
Compliance with legal obligations (DAC7): Billing data of Owners who earn income through the Platform may be disclosed to the tax authorities (the head of the National Revenue Administration, Szef KAS) in fulfillment of obligations arising from the DAC7 Directive.
§4. The Spot-Condition Photo Feature and Third-Party Data
Taking photos as part of the check-in/check-out procedure is entirely optional and serves solely as the User's own evidence in the event of a dispute over damage to the spot or a vehicle. The Controller is not responsible for the content of such a photo or for any infringement the User commits while taking it.
License plates or the images of third parties incidentally captured in the background of a photo are processed on the basis of a legitimate interest (Art. 6(1)(f) GDPR) in conducting a reliable review of disputes. A third party has the right to object by writing to kontakt@getrezu.pl.
§5. Account Deletion Procedure and Data Retention
You have the right to delete your Account at any time, directly in the App (Profile → Account → Delete account) or by sending a request to kontakt@getrezu.pl.
Effects of deleting your Account:
- Your email address, phone number, and profile data are immediately and irreversibly anonymized.
- Associated files on the Vercel Blob server (photos) are deleted, except for cases that are the subject of an active dispute.
- Historical Booking records remain in the database in anonymized form (with the personal link removed) in order to preserve accounting consistency and protect the rights of the other party to a Booking.
- Identity documentation verified by Stripe is subject to the retention rules Stripe applies under AML regulations.
Backups. Given the nature of the backup rotation cycle, personal data may physically remain in encrypted backups for up to 14 days from the moment Account deletion is requested.
§6. Your Rights
You have the right to:
- Access the content of your data and receive a copy of it (Art. 15 GDPR).
- Rectify (correct) your data (Art. 16 GDPR).
- Erasure of your data ("the right to be forgotten"), subject to §5 of this document (Art. 17 GDPR).
- Restriction of processing (Art. 18 GDPR) and data portability (Art. 20 GDPR).
- Object to processing based on our legitimate interest (Art. 21 GDPR).
- Lodge a complaint with the supervisory authority: the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, Poland.
A request to exercise any of these rights should be sent to kontakt@getrezu.pl. We will respond within 30 days.
§7. Geolocation and Device Permissions
GPS location: Read only with your explicit consent, granted through the mobile operating system (iOS/Android), in order to calculate the distance to a parking spot. Coordinates are processed only "in-flight" and are not saved to your User profile.
Camera: The app accesses the camera only at the moment you take an optional evidence photo as part of the Booking procedure. The app does not access your private photo library without your knowledge.
§8. Cookies, Browser Storage and Analytics
The Rezu website and the in-browser app store on your device only what the table below lists. We do not use advertising tools or tools that track you across websites. We do not use Google Analytics or Facebook Pixel.
| Name | Where | Type and lifetime | Purpose | Do we ask for consent |
|---|---|---|---|---|
| rezu_session | In-browser app | Rezu cookie (not readable by page scripts), 30 days or until sign-out | Keeping you signed in | No – strictly necessary for the service you ask for |
| __stripe_mid, __stripe_sid (and m on m.stripe.com) | In-browser app | Stripe cookies: 1 year, 30 minutes (m – per Stripe's policy) | Payment fraud prevention; set by Stripe as a separate controller (§3) | No – we treat them as necessary for a secure payment |
| rezu_replay_consent | In-browser app | Local storage, until you change your choice or clear browser data | Remembering your answer to the session-recording question (“yes” or “no” and the date) | No – it remembers your decision |
| rezu.lang, rz-recent-searches, rz-list-banner-dismissed | In-browser app | Local storage, until you clear browser data | Chosen language, recent map searches (on your device only), a dismissed notice | No – settings you ask for |
| rezu.* (e.g. rezu.neighbor_parking_stripe_publishable_key, rezu.fs:…) | In-browser app | Local storage, until you clear browser data | Technical app settings, e.g. the payment module's public key, a first-launch marker, read notifications | No – needed for the app to work |
| rezu.neighbor_parking_anonymous_client_id | In-browser app (in the mobile app: device storage) | Local storage, no expiry; created only when you report “no space here” | A random identifier so that repeated no-space reports from the same device are not counted twice | No – created only by your report |
| rezu_acq_src | In-browser app | Session storage, at most 30 minutes | Entry-source tag (described below) | No |
| rz-draft:…, rz-otp-next:…, rz-user-loc | In-browser app | Session storage, until the tab is closed | A form draft kept while you sign in, when the next sign-in code can be sent (the entry name contains the e-mail address), your last map position if you allow location. This data does not leave your device | No – needed for the feature you use |
| rezu_attribution | Website getrezu.app | Session storage, until the tab is closed | Entry-source tag (utm campaign parameters) | No |
| Session token, settings, crash reports | Mobile app (iOS, Android) | Secure device storage and app files, until sign-out or uninstall | Sign-in, settings, crash reports waiting to be sent to Sentry | No – needed for the app to work and to fix crashes |
When you sign in with Google or Apple, the sign-in window belongs to that company and it may use its own cookies there, under its own privacy policy. You can delete or block the entries in the table at any time in your browser settings; without the rezu_session cookie you cannot stay signed in, and without the Stripe cookies a payment may fail.
Entry-source tag. Links from our website to the browser version of the app, and links in our materials (e.g. posts, emails to people on the waitlist, leaflets), carry a short tag in the address, such as “?src=wilda_hero_owner” or “utm_source=waitlist”. The tag describes the page or material, not you: everyone who clicks the same link gets the same tag. So that it is not lost on the way, your browser keeps it in session storage: the website until you close the tab, the browser app for at most 30 minutes, and we delete it as soon as it has been used. We do not store it in cookies or in the browser's persistent storage (localStorage). You can clear or block session storage at any time in your browser settings; the website and the app then work normally, just without the tag.
If you add a spot listing, submit a demand request or sign in for the first time, we save this tag together with the listing, the request or your Account. This tells us which pages and materials actually bring in spots and requests. We do not save your IP address, the referring page, ad click identifiers (e.g. fbclid, gclid) or the full address with its parameters. Only the Controller has access to the tag (and the hosting providers listed in §3, which store data on our behalf). We do not show it to other Users, we do not share it for advertising, and it does not affect what you see in the app or any prices. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in assessing how well our pages and materials work. We keep the tag for 12 months, then delete it and keep only aggregate counts. You can object (Art. 21 GDPR) by writing to the address in §1; we will then delete the tag from your data.
Vercel Web Analytics (website). For website traffic statistics we use Vercel Web Analytics. It stores nothing on your device. It recognises a visit by a hash built from request data, discarded after 24 hours. It collects the addresses visited, the referring page, an approximate location (country, region, city derived from the IP address, without storing the address itself), device and browser type, and two events: a click on an app download button and a pass through our download link, with the platform (iOS, Android) and campaign parameters (utm). We see aggregate data only. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in understanding site traffic and how well our materials work.
PostHog (in-browser app analytics). To understand how you use the app in the browser (which screens you visit, where you give up, what does not work) we use PostHog Cloud in the EU (Frankfurt). It runs in a mode that stores nothing on your device: no cookies, no localStorage, no sessionStorage. The visitor identifier exists only in the memory of the open tab and disappears when you reload or close it.
We collect: the screens visited (address without identifiers or parameters, except the entry-source tag), the referring domain, device, OS and browser type, screen size, clicks described by the button's name in the app (e.g. “web-book-submit”, never its text), click heatmaps, frustration signals (repeated clicks and clicks that do nothing) and events such as: map moves (zoom level and city), map filter and layer changes, pin clicks, a map search (only whether anything was found), viewing a spot, booking steps and the dates picked (in ranges, e.g. “4–7 days ahead”), payment and payment errors, cancelling a booking, adding a listing, a demand request, leaving a review (role and number of stars), signing in, starting Rezu Long, and an error code shown. We do not collect what you type into forms: phone number, e-mail, licence plate, address, the search phrase, codes (one-time or gate), payment details, or review text.
Your device's IP address reaches PostHog technically, as with any internet connection. We do not store it with the events; before discarding it PostHog may derive an approximate location (country, city) from it. After you sign in we attach events to the internal Account identifier (a pseudonym, not your name, e-mail or phone) and stop after you sign out. Analytics data is kept for up to 12 months. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in improving the app. Analytics does not start at all when your browser sends a “Do Not Track” or “Global Privacy Control” signal. You can object (Art. 21 GDPR) by writing to the address in §1; right away you can also turn on one of those signals or block the domain eu.i.posthog.com.
Session recordings (only with your consent). On your first visit to the in-browser app a small window asks whether we may record how you use the site. “I agree” and “No, thanks” are equally prominent. Recording starts only after you click “I agree”. All text on the page, everything you type and images are hidden in the recording: we see the screen layout, cursor movement, clicks and scrolling, but not names, phone numbers, e-mail addresses, licence plates, addresses, codes or payment details. Stripe payment fields are outside the recording. Screens with particularly confidential data are not recorded at all (including the agreement, the payment return, payout details, invoice details, vehicles, account deletion and the review link). If you are signed in, the recording is linked to your internal Account identifier, so it is not anonymous.
The legal basis is your consent (Art. 6(1)(a) GDPR in conjunction with Art. 399(1) of the Polish Electronic Communications Law). You can change or withdraw consent at any time with the “Privacy settings” link in the bottom-left corner of the in-browser app. Recording stops immediately. Withdrawal does not affect the lawfulness of earlier recordings; on request (address in §1) we delete them before the retention period ends. Recordings are kept for up to 30 days. We do not ask and do not record when your browser sends a “Do Not Track” or “Global Privacy Control” signal.
Sentry (error monitoring). To detect and fix failures quickly, the website, the mobile app and our server send error reports to Sentry (EU region, Frankfurt): the error description and where in the code it happened, the page address or screen name, device, OS and browser type, app version, the steps before the error (e.g. moving between screens) and the duration of selected operations. Reports from the mobile app may contain a technical installation identifier assigned by Sentry. We do not send your name, e-mail address or phone number to Sentry, and Sentry does not record the screen. Reports are kept for up to 90 days. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in the security and stability of the service. You can object (Art. 21 GDPR) by writing to the address in §1.
Mobile app. The iOS and Android app contains no analytics or advertising tools. It uses only the Sentry error monitoring described above.
§9. Changes to This Privacy Policy
The Controller reserves the right to make changes to this Privacy Policy in the event of changes in the law or the rollout of new features (e.g. automated payments, DAC7). Users will be notified of material changes in advance, through the App or by email.
Last updated: October 4, 2026.