ParkStash - Parking Management Software
Modern parking management solutions for property managers.
Page content
Data Processing Addendum | ParkStash
ParkStash Data Processing Addendum (DPA) — details on how ParkStash processes personal data on behalf of customers in connection with its platform and services.
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement, order form, terms of service, or other written agreement (the "Agreement") between ParkStash, Inc. ("ParkStash") and the customer using ParkStash services ("Customer").
This DPA applies where ParkStash processes Personal Data on behalf of Customer in connection with the ParkStash platform and related services ("Services").
1. Definitions
"Customer Personal Data"
means Personal Data processed by ParkStash on behalf of Customer in connection with the Services.
"Personal Data"
means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual, including information treated as "personal information," "personal data," or a similar term under applicable U.S. privacy laws.
"Processing"
means collecting, recording, organizing, storing, accessing, using, transmitting, disclosing, deleting, or otherwise handling Personal Data.
"Subprocessor"
means a third-party service provider engaged by ParkStash to process Customer Personal Data as necessary to provide the Services.
2. Relationship of the Parties
Customer determines the purposes for which Customer Personal Data is processed through the Services.
ParkStash processes Customer Personal Data on behalf of Customer as a service provider, contractor, or processor, as those terms may be defined under applicable U.S. privacy laws.
ParkStash will process Customer Personal Data only:
To provide, maintain, secure, and support the Services;
In accordance with Customer's use and configuration of the Services;
As otherwise instructed by Customer; or
As required by applicable law.
ParkStash will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioral advertising.
ParkStash will not retain, use, or disclose Customer Personal Data for purposes outside of providing the Services to Customer except as permitted or required by applicable law.
3. Categories of Personal Data
Depending on Customer's configuration and use of the Services, ParkStash may process:
Names;
Email addresses;
Phone numbers;
License plate numbers;
Vehicle information;
Parking permit and authorization information;
Parking reservations and parking activity;
Employee, resident, visitor, contractor, unit, or other identifiers configured by Customer;
Account and administrative information;
Enforcement records and photographs where enforcement functionality is enabled; and
Device, IP address, and technical logs associated with use and security of the Services.
ParkStash's Services are not designed to require Social Security numbers, driver's license numbers, financial account credentials, biometric identifiers, or other highly sensitive information unless separately agreed upon in writing.
Where payment functionality is enabled, payment card information is processed by ParkStash's payment processing provider and is not intended to be stored directly within ParkStash's application databases.
4. Purpose of Processing
ParkStash processes Customer Personal Data as necessary to provide parking management services, which may include:
Digital parking permit administration;
Vehicle registration;
Employee, resident, contractor, and visitor parking;
Parking reservations;
Parking authorization;
Parking enforcement;
License plate-based authorization and enforcement;
Customer support and troubleshooting;
Security and fraud prevention;
Reporting and analytics; and
Administration and maintenance of the Services.
5. Data Hosting and Location
ParkStash's production infrastructure is hosted using
Microsoft Azure
Customer application data is hosted within ParkStash's Azure environment in the
United States
6. Security Measures
ParkStash maintains reasonable administrative, technical, and organizational safeguards designed to protect Customer Personal Data against unauthorized access, disclosure, alteration, destruction, or loss.
These measures include, as applicable:
Encryption of data in transit using HTTPS/TLS;
Encryption of data at rest using Microsoft Azure-supported encryption;
Role-based access controls;
Least-privilege access principles;
Restricted access to production systems;
Authentication controls for administrative systems;
Application and infrastructure logging;
Security monitoring;
Software updates and patch management;
Vulnerability management;
Secure software development practices;
Network and cloud security controls;
Backup and recovery procedures; and
Confidentiality obligations for personnel with access to Customer Personal Data.
ParkStash may update its technical and organizational safeguards as its systems evolve, provided that the overall level of protection for Customer Personal Data is not materially reduced.
7. Confidentiality and Access
Access to Customer Personal Data is restricted to ParkStash personnel and authorized service providers who require access to perform legitimate business functions associated with providing the Services.
Personnel with access to Customer Personal Data are subject to appropriate confidentiality obligations.
8. Subprocessors
Customer authorizes ParkStash to use third-party service providers where reasonably necessary to provide the Services.
ParkStash's primary subprocessors include:
Purpose: Cloud infrastructure, hosting, storage, networking, databases, backups, and related infrastructure services.
Twilio
Purpose: Sending transactional SMS and other communications associated with the Services.
Mailgun
Purpose: Sending transactional email communications associated with the Services.
ParkStash requires subprocessors that process Customer Personal Data on its behalf to maintain appropriate privacy and security protections.
ParkStash remains responsible for its obligations under this DPA when using subprocessors to process Customer Personal Data on its behalf.
ParkStash may update its subprocessors as its Services evolve. Upon request, ParkStash will provide information regarding material subprocessors involved in processing Customer Personal Data.
9. Data Retention and Deletion
ParkStash retains Customer Personal Data only for as long as reasonably necessary to:
Provide the Services;
Maintain security and operational records;
Satisfy contractual requirements;
Comply with applicable legal obligations; and
Maintain appropriate backup and disaster recovery systems.
Upon termination of the Services or Customer's written request, and subject to applicable legal and contractual retention requirements, ParkStash will delete or return Customer Personal Data within a commercially reasonable period.
Customer Personal Data contained in backups may remain until the applicable backup is overwritten or expires in accordance with ParkStash's normal backup retention processes. Such information will remain protected and will not be used for other purposes.
10. Individual Privacy Requests
Taking into account the nature of the Processing, ParkStash will provide reasonable assistance to Customer in responding to requests from individuals exercising applicable privacy rights relating to Customer Personal Data.
If ParkStash receives a privacy request directly from an individual concerning Customer Personal Data controlled by Customer, ParkStash may direct the individual to Customer or notify Customer of the request, unless applicable law requires ParkStash to respond directly.
11. Security Incidents
ParkStash maintains procedures for identifying, investigating, and responding to security incidents.
ParkStash will notify Customer without undue delay after becoming aware of a confirmed security breach involving unauthorized access to, acquisition of, or disclosure of Customer Personal Data where notification is required under applicable law or the Agreement.
ParkStash will take reasonable steps to investigate, contain, and remediate the incident and will provide Customer with reasonably available information necessary for Customer to satisfy applicable legal obligations.
12. Customer Data
Customer retains all rights and interests in Customer Personal Data.
ParkStash does not sell Customer Personal Data.
ParkStash does not use Customer Personal Data for advertising.
ParkStash does not use Customer Personal Data to train artificial intelligence or machine-learning models.
13. Compliance Assistance
Upon reasonable request, ParkStash will provide Customer with information reasonably necessary to evaluate ParkStash's privacy and security practices relating to the Services.
ParkStash will reasonably cooperate with Customer's privacy and security review processes, including responding to reasonable vendor security or privacy questionnaires.
14. U.S. Privacy Requirements
To the extent applicable U.S. privacy laws characterize ParkStash as a service provider, contractor, or processor with respect to Customer Personal Data, ParkStash will:
Process Customer Personal Data only for the limited and specified purposes described in the Agreement and this DPA;
Provide the level of privacy protection required by applicable law;
Not sell Customer Personal Data;
Not share Customer Personal Data for cross-context behavioral advertising;
Not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law; and
Notify Customer if ParkStash determines that it can no longer meet its applicable privacy obligations.
Where required by applicable law, Customer may take reasonable and appropriate steps to help ensure that ParkStash uses Customer Personal Data consistently with Customer's obligations under applicable privacy laws.
15. Changes to this DPA
ParkStash may update this DPA from time to time to reflect changes to the Services, security practices, subprocessors, or applicable laws.
Material changes will be reflected by updating the "Last Updated" date above.
16. Relationship to Other Agreements
This DPA supplements the Agreement governing Customer's use of ParkStash.
If there is a conflict between this DPA and the Agreement regarding the processing and protection of Customer Personal Data, this DPA will control with respect to that subject matter.
The limitations of liability and other contractual provisions contained in the Agreement continue to apply unless otherwise required by applicable law.
Additional Privacy Resources
Additional information regarding ParkStash's privacy practices is available through the documents below.
Privacy Policy
How ParkStash collects, uses, and protects your personal information.
findparkstash.com/privacy-policy
Terms of Service
The terms and conditions governing use of the ParkStash platform.
findparkstash.com/terms-of-service
ALPR Privacy Policy
ParkStash's privacy practices relating to automated license plate recognition.
findparkstash.com/alpr-privacy-policy
For privacy or security questions, contact ParkStash at
support@findparkstash.com