Privacy policy
This app shows car parks on a map. It is built to ask you for as little as possible. This page states what it actually collects, and above all what it does not.
Who is responsible for this data
The data controller is the publisher of the app, whose identity and address appear below.
- Mickaël Lebret, sole trader under French law.
- Address: 170 avenue de Colmar, 68200 Mulhouse, France
- SIREN 829 094 390. Not listed in the trade and companies register, entered in the French national business register on 2017-04-13.
- EU VAT number: FR64829094390
- Phone: +33 7 65 17 17 96
Your location
Your GPS location does not leave your phone. It is used only to centre the map and to compute walking times on the device. It is not sent to any server, ours or anyone else's, and it is not recorded.
One point we owe you in all honesty: to draw the map, the app downloads tiles identified by their position in the world. The server that serves them can therefore infer the area you are looking at, as with any online map. Our promise covers the data we record, not the mechanics of the web.
The app never asks for permission to track your location in the background, and does not track it.
What we record, if you create an account
Browsing the map requires no account. An account becomes necessary to contribute a fact or to attach a subscription. In that case we keep the categories of data listed below, as well as the internal log of administration actions taken on your account (a gifted access, for example), whose retention period is given further down.
- Your account: your email address, a pseudonym if you choose one, and the creation and last sign-in dates.
- Your sign-in methods: the provider used (Apple, Google, or a code sent by email) and the technical identifier it hands us. We receive neither your name, nor your photo, nor your contacts.
- Your devices: a technical key specific to each installation, the platform and the app version. That key exists to limit abuse, not to follow you.
- Your contributions: the OpenStreetMap identifier of the car park concerned, the fact you declared (free, paid, blue zone), and the date. These facts are public by nature, see the next section.
- Your saved spots, for as long as synchronisation stays on: the coordinates of car parks you set aside yourself. These are places you pointed at, not your location. Synchronisation has been on by default since 12 August 2026, and you can stop it at any time in Settings, then Account, which also offers to erase the copy already held on our servers.
- Your subscription: the plan, the store, the status and the expiry date. If we gift you Premium access, its start and end dates and its reason (a support gesture, for example). We never see your payment method.
- Moderation decisions concerning you: what was decided, on what grounds, and when. These tokens come from a closed list on purpose, so that they stay translatable. If your account is deleted, the decision stays on record but is no longer linked to you.
- Your suspension, if any: the date, the grounds and the end date when there is one. This record disappears with your account if you delete it.
- Your other declared information: the OpenStreetMap identifier of the car park concerned, the fact you declared (covered, maximum height, number of bays marked for disabled drivers), its value and the date. These facts are public by nature, see the next section.
- Your ratings: the OpenStreetMap identifier of the car park you rated, the score you gave, the tags you picked from a closed list, and the dates. There is no free-text field anywhere. If you delete your account, your ratings are erased rather than anonymised, because an opinion is not a fact anyone else can verify.
- Your reports: the car park concerned, the reason you picked from a closed list, and the date. We keep them so that we can handle the notification and justify the decision. The person whose rating you report never learns who reported it.
- Your photos: the OpenStreetMap identifier of the car park, the file name of the images produced, their dimensions and the dates. The images themselves live on our server, outside the database. There is no caption field. If you delete your account, your photos are erased rather than anonymised, and the files are destroyed on disk, not only the rows that name them.
- Your photo reports: the car park concerned, the reason chosen from a closed list, and the date. We keep them so we can handle the notification and justify the decision. The person whose photo you report never learns who reported it.
- Your cancellation request, if you make one: declared full name, confirmation email address, requested cancellation date and notification date. We keep it for five years, as proof of your request and in defence of our rights in the event of a dispute, even after your account is deleted.
- The reminder about your annual subscription's renewal: the date we sent it to you, whether the sending succeeded, and a fingerprint of the address used, never the address itself. We keep it for five years after the due date it targeted, as proof of sending in case of a dispute, even after your account is deleted.
- Your withdrawal declaration, if you make one: declared full name, confirmation email address, and the date it was sent. We keep it for five years, as proof of your action and in defence of our rights in case of a dispute, even after your account is deleted.
What this data is for
Signing you in, attributing your contributions so we know which one is the most recent, finding your saved spots on another device for as long as synchronisation stays on, opening the paid features to the people who paid for them or to whom we gift them, answering your support requests, informing you when a Premium access is granted to you, informing you before an annual subscription renews, and limiting abuse. We build no advertising profile and we sell nothing.
On what legal basis
Here are the legal bases we rely on, and no other. None of the processing described here rests on your consent: a setting the app ships already switched on asks nothing of you, so it cannot amount to consent, and we will not call it that. What you keep instead is a right to object, described further down.
- Performance of the contract, for your account, your sign-in methods, your contributions, your subscription, the Premium access we gift you and the support you ask us for. Without these there is no account to sign back into, no contribution anyone can attribute to its author, no subscription or gifted access to unlock, and no way to answer your support request.
- Our legitimate interest, for saved-spot synchronisation, for the device key that limits abuse, for moderation decisions, and for the internal log of administration actions. For synchronisation, the interest is that you find under your account what you saved there, and it is limited to places you pointed at yourself. For the device key and moderation decisions, it is protecting the service and the people who use it. For the administration log, it is being able to account for every action taken on an account.
- A legal obligation, for the reports you send us and for the reminder sent before an annual subscription renews. The European Digital Services Act requires us to handle these notifications and to state the reasons for our decisions: without the report, the decision would have no stated reason. Article L215-1 of the French consumer code requires this reminder, between three months and one month before the due date.
What goes out to third parties
We name here everything that leaves the app towards anyone other than us.
- When you search for a place by name, the text you type is sent to the OpenStreetMap search service. Neither your location nor the area you are looking at goes with it.
- When you set a car park aside, its coordinates are sent once to the same service to give it a readable name, rounded to two decimals, which is roughly one kilometre. This happens once per place, never again.
- The background map is served by a tile host, which therefore sees the areas requested, as explained above.
- Purchases go through Apple or Google when made in the app, and through our payment provider when made on this site. In both cases the technical provider RevenueCat tells us whether a subscription is active, and your account identifier is passed to it at payment time so that the subscription is attached to it. No payment details ever pass through us.
- No advertising tracker, no social network, no third-party audience measurement. The usage measurement we plan is a server we host ourselves, and it sends only a duration bucket, a zoom band and the kind of action. No coordinates, no personal identifier. As of this document, that measurement is not switched on.
For how long
Your account data is kept for as long as the account exists. One-time sign-in codes expire within minutes. Deleting a saved spot leaves a technical marker for ninety days, long enough for your devices to catch up.
When you delete your account it is erased immediately, along with your sign-in methods, your devices and your saved spots. Your contributions stay, but detached from you: they no longer carry any link to your account and they stop counting as your voice. We keep them because they describe the world, not you, and because they have already been shared publicly.
Moderation decisions are recorded in a log, kept for one year (365 days) from the last decision taken on the same content. A challenge leads to a new decision, which restarts that period. After it, the record is deleted.
The internal log of administration actions (a gifted access, for example) is kept for 24 months from each action.
Your rights, and how to exercise them without writing to us
You have the rights of access, rectification, erasure, portability, restriction and objection set out in the General Data Protection Regulation.
- Access and portability: in the app, Settings then Account, the export button hands you the data listed above in a readable, reusable format, immediately, with no prior request. What it does not contain, such as the internal log of administration actions, is flagged in it.
- Erasure: in the same place, account deletion is immediate and final. It is never blocked by a technical limit.
- Objection: saved-spot synchronisation rests on our legitimate interest, so you may object to it without giving a reason. In the app, Settings then Account, the synchronisation switch stops it immediately and offers to erase the copy already held on our servers. You may also object to the device key, to moderation decisions and to the administration log, but we may refuse those three: without them the service can no longer protect itself, protect other people, or account for what is done on an account.
- You may also lodge a complaint with the data protection authority of your country.
Where the data lives
On a server located in Strasbourg, France, therefore inside the European Union. We do not transfer the data outside the European Union. Payments, for their part, are handled by Apple, Google and RevenueCat under their own policies.
Host: OVH SAS, 2 rue Kellermann, 59100 Roubaix, France.
Children
This app is not aimed at children under sixteen and we do not knowingly collect their data.
Changes
This page carries a version number and a last-changed date. Any evolution is published here before it applies.
Writing to us
For any question about this policy, write to the address below.
This address is also our single point of contact under Articles 11 and 12 of the European Digital Services Act, and under Article 15 of the European regulation on terrorist content online. It can be reached electronically, without an account and free of charge, in French and in English. A person answers, no automated tool decides in their place.
See also the terms of use, the terms of sale and the open data attribution page.