1Introduction
Zeropark Smart Parking ("Zeropark," "we," "us," "our") operates the Zeropark smart parking marketplace platform ("Platform"), serving two categories of individuals:
- Users — drivers who discover and book parking spots.
- Providers — individuals or businesses who list parking spots for booking.
This Privacy Policy explains what personal data we collect from Users and Providers, why we collect it, how it is used, stored, shared, and protected, and what rights you have over it. It applies across our web app, mobile app, and admin-facing tools.
By using the Platform, you consent to the data practices described in this Policy, to the extent required under applicable Indian data protection law, including the Digital Personal Data Protection Act, 2023.
2Data We Collect
2.1 Information You Provide Directly
| Category | Examples | Collected From |
|---|---|---|
| Identity & contact details | Full name, email address, phone number, avatar/profile photo | Users & Providers |
| Account credentials | Password (stored as a bcrypt hash — never in plain text), OAuth tokens (Google/Apple) | Users & Providers |
| Vehicle information | Licence plate number, make, model, vehicle type | Users |
| Location data (address-level) | Spot address, city, country, precise lat/lng pin | Providers (for spot listings) |
| Spot listing details | Spot name, description, photos, amenities/features, slot configuration, pricing policies | Providers |
| Payment-related metadata | Transaction ID, payment status, amount, currency — not full card/UPI credentials | Users & Providers |
| Payout details | Bank account / UPI ID for payouts, business/GST details (if applicable) | Providers |
| Communications | Reviews, ratings, support tickets, messages to ZeroPark | Users & Providers |
| Device tokens | Firebase Cloud Messaging (FCM) token for push notifications | Users & Providers |
2.2 Information Collected Automatically
- Precise or approximate device location (with permission) to power nearby-spot search and map display.
- Usage data: pages/screens visited, search queries, session duration, feature interactions.
- Device & technical data: IP address, device type, OS version, browser type, app version.
- Cookies and similar technologies on the web app — see our separate Cookie Policy for full details.
2.3 Information from Third Parties
- Razorpay (payment gateway): payment status and transaction confirmations. Razorpay independently collects and processes your full payment instrument details under its own privacy policy and RBI-mandated tokenisation rules.
- Google Maps Platform: geocoding, places, and directions data used to power maps and address autocomplete.
- Firebase (Google): push notification delivery and, where enabled, crash/analytics data.
- OAuth providers (Google/Apple): basic profile information (name, email) if you choose social login.
3Why We Collect Your Data (Purpose of Processing)
We process personal data for the following purposes, consistent with collecting basic identity information (email, phone number, and related details) to offer and improve our services:
- 1Account creation & authentication — Email/phone verification, OTP delivery, login, session management.
- 2Core marketplace functionality — Matching Users with nearby Providers, resolving pricing, creating and managing reservations, generating QR codes for check-in/check-out.
- 3Payments & payouts — Processing reservation and subscription payments via Razorpay; calculating and disbursing Provider payouts.
- 4Communication — Transactional messages (booking confirmations, receipts, OTPs), and — where you have opted in — promotional messages.
- 5Trust & safety — Fraud detection, abuse prevention, enforcing the Acceptable Use Policy and Community Guidelines, admin review of flagged listings/users.
- 6Service improvement — Understanding usage patterns to improve search relevance, app performance, and feature design.
- 7Legal & regulatory compliance — Tax records, dispute resolution, responding to lawful government or law-enforcement requests.
- 8Provider contact unlock feature — Sharing a Provider's registered contact details with a User who has unlocked that Provider (within free quota or via paid subscription), and vice versa, strictly for coordinating a booking.
We do not sell personal data to third parties for their independent marketing purposes.
4Legal Basis for Processing
Under the DPDPA, we process personal data on the basis of:
- Consent — obtained at account registration, permission prompts (e.g., location access), and opt-in checkboxes for marketing communications.
- Legitimate use — for purposes such as fraud prevention, service functionality, and responding to a request you have made (e.g., processing a booking you initiated).
- Legal obligation — retention of transaction and tax records as required under Indian law.
You may withdraw consent at any time (see Section 8), though this may limit or disable certain features (e.g., disabling location access will disable nearby-spot search).
5How We Share Your Data
We share personal data only as necessary, with the following categories of recipients:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Razorpay | Name, contact details, transaction amount | Payment processing (Razorpay is a PCI-DSS compliant, RBI-authorised payment aggregator) |
| Google Maps Platform | Search location, address queries | Geocoding, map rendering, directions |
| Firebase (Google) | Device token | Push notification delivery |
| Providers (for Users) | Name, contact number, vehicle plate, reservation details | Enabling the Provider to identify and admit a booked User |
| Users (for Providers) | Provider business name and contact details | Enabled only after contact-unlock, per the subscription/free-quota model |
| ZeroPark Admin/Support staff | As needed | Support resolution, spot approval, fraud investigation |
| Government/regulatory authorities | As legally compelled | Compliance with lawful requests, court orders, or statutory obligations |
| Successor entity | All relevant data | In the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections |
We do not share full payment credentials (card numbers, CVV, UPI PIN) with any party other than Razorpay, which processes them directly.
6Data of Providers — Additional Notes
6.1 Provider business information (spot address, pricing, amenities, photos) is publicly displayed on the discovery map and spot detail pages to Users, as this is the core function of a spot listing.
6.2 Provider payout details (bank account/UPI) are used solely for disbursing earnings and are handled with the same security controls as User payment data.
6.3 Where a Provider is a registered business, GST or business registration details (if collected) are used for invoicing and tax compliance only.
7Data Security
7.1 We apply industry-standard technical and organisational measures, including:
- Password hashing (bcrypt), JWT-based stateless authentication, and role-based access control (User/Provider/Admin).
- Encryption in transit (TLS/HTTPS) for all API traffic.
- Database access restricted to authorised backend services; no direct public database access.
- Payment data never stored on ZeroPark servers — handled exclusively by Razorpay.
7.2 No system is completely secure. In the event of a data breach affecting personal data, we will notify affected individuals and the relevant authority (e.g., the Data Protection Board of India, once constituted) as required under applicable law.
8Your Rights
Subject to applicable law (including the DPDPA), you have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate or incomplete data (available directly via account settings for most fields).
- Withdraw consent for optional processing (e.g., marketing communications, location access).
- Request erasure of your account and associated personal data, subject to legally mandated retention (see our Data Retention Policy).
- Nominate another individual to exercise your rights in the event of death or incapacity, where supported by law.
- Grievance redressal — raise a complaint with our Grievance/Data Protection Officer (Section 10) before approaching the Data Protection Board of India.
To exercise these rights, contact privacy@zeropark.in. We will respond within the timeline prescribed by applicable law.
9Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, or as required by law (e.g., financial records under Indian tax law). Detailed retention periods per data category are set out in our separate Data Retention Policy. Upon account deletion, we anonymise or delete personal data except where retention is legally required (e.g., completed transaction records).
10Grievance Officer / Data Protection Contact
11Children's Privacy
The Platform is not directed at individuals under 18. We do not knowingly collect personal data from minors. If we become aware that we have inadvertently collected data from a minor without verifiable parental/guardian consent as required under the DPDPA, we will delete it promptly.
12International Data Transfers
Our infrastructure is primarily hosted in India-accessible regions (currently Render/Vercel, with a planned migration to a DigitalOcean Bangalore region). Certain third-party processors (e.g., Google Maps, Firebase) may process data on servers located outside India. Where such transfers occur, we rely on the processors' own compliance frameworks and, where applicable, contractual safeguards consistent with DPDPA requirements.
13Cookies
Our web application uses cookies and similar technologies for authentication (httpOnly session cookies), preference storage, and analytics. Full details are provided in our separate Cookie Policy.
14Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via the app, email, or SMS before taking effect. The "Last Updated" date at the top reflects the most recent revision.
15Contact Us
For any privacy-related questions, contact: