1. Data controller
The controller of your personal data is Vladimir Ćotrić (fizičko lice (MVP / pre registracije)), based in Beograd, Srbija. For any privacy questions write to privacy@parkdaj.com.
2. Data we collect
- Account data: email address, full name, password (cryptographically hashed), unit number, name of the building you belong to.
- Usage data: availability posts, bookings, spot requests, notification preferences.
- Technical data: session cookies for login (Supabase Auth), basic access logs (IP, user agent) kept by the hosting provider for security.
We do not collect location data, phone contacts, or precise home addresses — only the unit number within the building your admin registers.
3. Purposes of processing
- Providing the service (registration, sign-in, spot sharing and booking).
- Sending transactional emails (account confirmation, password reset, invites).
- In-app notifications about activity in your building.
- Security, abuse prevention, and debugging.
4. Legal basis
- Contract performance (Art. 6(1)(b) GDPR) — for core service functionality.
- Consent — for optional notifications and marketing (we do not send marketing emails at this time).
- Legitimate interest — for security and abuse prevention.
5. Storage and third parties
Your data is stored with the following processors:
- Supabase (authentication, database) — servers in the EU region.
- Railway (application hosting) — servers in the EU region.
These partners process data only on our instructions and under a data processing agreement (DPA). We do not sell your data to third parties and do not use it for targeted marketing.
6. Who can see your data on the platform
- Other residents of the same building can see: your name, unit number, spots you have shared, and sharing statistics.
- Building admins see the resident list and assigned spots.
- Your email address is visible only to building admins.
7. Your rights (GDPR)
- Right to access your data.
- Right to rectify inaccurate data.
- Right to erase your account and data (“right to be forgotten”).
- Right to data portability (JSON export on request).
- Right to object and withdraw consent.
- Right to lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection (www.poverenik.rs).
To exercise these rights write to privacy@parkdaj.com. We respond within 30 days.
8. Retention
Data is kept while your account is active. On deletion, data is permanently removed within 30 days, except records the law requires us to retain longer (e.g., security logs).
9. Cookies
We only use essential cookies needed for login (Supabase auth session) and to remember your language preference. We do not use analytics or marketing cookies at this time.
10. Changes to this policy
Material changes will be announced in-app and/or by email at least 14 days before they take effect.
11. Contact
Privacy questions: privacy@parkdaj.com.