Privacy policy
The short version
Park Sorted has no accounts, no logins, and no advertising. We don't build a profile of you, we don't track you between sessions or across apps, and we never sell or share your information with data brokers.
We hold no identifier that links one scan to another, or to a person. That is how the app is built, not a promise about our intentions — the records simply contain nothing to join them on. Two scans by the same driver are indistinguishable from two scans by two different drivers.
The one thing that needs care is the photo you take. We keep it for up to 30 days to check the app read the sign correctly, and a photo of a street sign also captures whatever was behind it. That is covered in full below.
Who we are
Park Sorted is operated by David Jackson trading as Create A Little Good (ABN 92 574 738 389), a sole trader based in Sydney, New South Wales, Australia.
Privacy questions, complaints, or requests: support@parksorted.com
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We treat those principles as binding on us regardless of whether the small-business turnover exemption might otherwise apply — we would rather meet the standard than argue about whether we have to.
The photo of the sign
When you scan, the photo is sent to our servers and forwarded to Google's Gemini API to read the sign. We then keep the photo for up to 30 days.
Why we keep it. Only to check our answer was right. If the app misreads a sign, the photo is the one way to find out why and fix it. We do not run face recognition, number-plate recognition, or any other analysis over it, and we do not use it to train models.
What might be in it. You are photographing a street, so the image may incidentally include number plates, shopfronts, house numbers, or people passing by. We do not seek any of that out and we do not extract it — but we are not going to pretend it isn't in the frame. If a photo would capture something you would rather we did not hold, don't take it — and if you have already taken it, the 30-day window below is the outside limit on how long we keep it.
After 30 days the photo is automatically and permanently deleted. What remains is a record with no photo and nothing identifying — the verdict, the state, and whether a fine was likely avoided — which is what keeps the public scan counter honest.
What a scan record contains
Alongside the photo, a scan record holds this and nothing else:
- The verdict we gave
- The date and time it happened, and the time of day and day of the week the app read the sign against — the timestamp is also what the 30-day deletion runs on
- The suburb and state
- Whether it was a public holiday or a school day
- How long each step took, so we can keep the app fast
- Our estimate of the fine avoided, which is what the public counter adds up
- A random reference for the record itself, and the photo's filename until it is deleted
None of it is tied to you. There is no account, no user ID, no device identifier, and no session identifier in the record. We do not store your IP address against a scan. The random reference identifies the record, not a person or a device: it is generated per scan and there is nothing to join two of them on.
Location
- Coarse location (state). Used to pick the right parking rules — NSW signs are not VIC signs. Usually derived from your network connection rather than GPS.
- Precise location — saving where you parked. The coordinate is stored on your device. We send it once to our server, which passes it to Google's Geocoding API to turn it into a street name for the label. Neither we nor Google keep it as part of any record — but it does leave your device, and we would rather say so than claim otherwise.
- The map of where you parked. The map is Apple Maps. When you open it, your device loads it straight from Apple (on the web, through Apple's MapKit JS), and to draw it Apple receives the map area around your saved spot, along with your IP address as any web request carries. That request goes from your device to Apple, not through us, and it is covered by Apple's privacy policy.
- A scan never carries your location. No scan record has a coordinate in it, so there is nothing here to opt in or out of. If that ever changes it will be opt-in, and this page will say so before it does.
Your IP address
Our servers see your IP address at the moment of a request, as every web server does. We use it only to limit abuse and cap how many scans can be made each day, and only as a keyed hash that is deleted within two days. The hash is made with a secret only our server holds, so the address cannot be recovered from it. We do not store your IP address against your scan.
What we don't collect at all
No name, email, phone number, or postal address. No account or password. No advertising identifier. No third-party analytics. No tracking pixels. No session recording. No cross-app or cross-site tracking. No cookies used to profile you. We do not buy, sell, rent, or trade personal information, and we never sell or share anything with data brokers.
We do not count you as a visitor. The scan total shown in the app is a count of scans, not of people — there is nothing in it to tell one person from another. The only thing we send to a third party for our own benefit is an error report when something breaks, described below.
Logs, diagnostics and measurement
Everything above describes what we deliberately store. This section describes what our infrastructure records as a by-product of running a service at all — the part most privacy policies leave out.
Server request logs
Our hosting providers write a log line for each request containing the IP address it came from, the URL, and the browser's user agent. This is ordinary web-server behaviour and we cannot switch it off. Vercel keeps these for a short window.
This is why coordinates are sent in the body of a request rather than in the web address. A URL containing your coordinates would be written into that same log line, next to your IP address — a precise record of where you were standing. Request bodies are not logged, so the two are never recorded together. That is a property of how the app is built, not a promise about what we choose to look at.
Error reporting (Sentry)
When something breaks we send the error and its stack trace to Functional Software, Inc. (Sentry) in the United States, so we can fix it. IP addresses are not attached. Session replay is switched off, so nothing reconstructs what was on your screen — we receive the error and where in the code it happened, and nothing about what you were looking at.
No visitor analytics
We do not run web analytics. There is no page-view tracking, no visitor counting, and no performance beacon — not even a privacy-preserving one. We removed them: counting visits would have meant deriving an identifier for each visitor, and we would rather not hold one at all than hold one we have to explain.
Crash reporting on iOS
The iOS app uses Apple's MetricKit to report crashes, freezes and performance figures. There is no third-party SDK involved: Apple collects it and shows it to us, and it contains no personal data.
Who we share with
| Recipient | What they receive | Why | Where |
|---|---|---|---|
| Google LLC — Gemini API | The sign photo | To read the sign | United States |
| Google LLC — Geocoding API | A coordinate, when you save a park or scan | To turn it into a street name | United States |
| Google LLC — Firebase | The scan record and photo (30 days) | Hosting and storage | United States |
| Vercel Inc. | Ordinary web request data | Hosting | United States / global edge |
| Apple Inc. — Apple Maps (MapKit JS on the web) | The map area around your saved car, and your IP address, when you open the map | To draw the map of where you parked | Apple infrastructure |
| Functional Software, Inc. (Sentry) | Error and crash reports | So we can fix what breaks | United States |
| Apple Inc. (MetricKit) | Crash and performance reports, iOS only | So we can fix crashes | Apple infrastructure |
We disclose information to no one else, including law enforcement, unless required by Australian law — and in practice we would have very little to give, because the records are not linked to anyone.
Sending data overseas
Photos and scan records are processed by Google in the United States, and our hosting may process requests outside Australia. By using Park Sorted you consent to this.
We take reasonable steps under Australian Privacy Principle 8 and rely on these providers' contractual commitments — Google's API terms and privacy policy — to protect your information to a standard comparable with Australian law. The map of where you parked is served by Apple, which may also be from outside Australia.
How long we keep things
| Data | Kept for |
|---|---|
| Sign photo | Up to 30 days, then permanently deleted |
| Scan record (no photo, nothing identifying) | Indefinitely, as anonymous aggregate |
| Coordinate sent to name the street where you parked | Not stored — used and discarded |
| Saved parked-car location | On your device only, until you clear it or delete the app |
| Hashed IP for rate limiting | Up to two days |
| Server request logs (IP, URL, user agent) | Short provider-set windows |
| Error reports | Sentry's retention, currently 90 days |
Access and correction
You have the right to ask what personal information an organisation holds about you, and to have it corrected.
We will almost certainly be unable to fulfil such a request, and that is by design. Because we store no identifier against any record, we have no way to find the scans that came from you, or to prove which ones did. We are not withholding anything — we genuinely cannot tell your records apart from anyone else's.
If you believe a specific photo of yours is still within the 30-day window and you want it removed sooner, email support@parksorted.com with the approximate date, time, and location, and we will do what we reasonably can — though we may not be able to identify it with confidence. If you still have the verdict on screen, its Wrong verdict? link puts the scan's random reference in the email, which lets us find that one record exactly. Otherwise, waiting 30 days achieves the same result automatically.
Data breaches
If a breach occurs that is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Practically, the most sensitive thing we hold is up to 30 days of street photographs that are not linked to anyone. We designed it that way so a breach would expose as little as possible.
Children
Park Sorted is intended for licensed drivers and is not directed at children. We do not knowingly collect information from anyone under 16 — and since we collect no identifying information from anyone, we have no way to determine age.
Security
Photos and records are stored in Google Firebase with access restricted to the operators of Park Sorted. Traffic is encrypted in transit. Administrative access is protected by a separate credential and is limited to reviewing scan accuracy.
Changes to this policy
If we change what we collect or who we share it with, we will update this page and change the “last reviewed” date. Material changes will be surfaced in the app.
Complaints
Contact us first at support@parksorted.com — we will respond within 30 days.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.