Privacy Policy

Last updated: July 2026

This Privacy Policy explains how ParkTRAX (“we”, the “Platform”) processes personal data in providing parking-management software to residential societies. It is written to align with India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).

1. Controllers and our role

Each society that uses ParkTRAX is the Data Fiduciary (controller) for the personal data of its residents, visitors, and guards. ParkTRAX acts as a Data Processor on the society’s instructions, under a Data Processing Agreement accepted by the society at onboarding.

2. Data we process

Vehicle and resident details (owner name, flat number, phone, email, registration number), visitor details, parking reports (including photos, an optional voice note, GPS location, and detected plate), fines, parking agreements, guard accounts and shift logs (including check-in selfies and location), and audit logs. Guard devices are fingerprinted for security.

3. Purposes & lawful basis

We process this data solely to operate the parking service for the society (vehicle verification, violation reporting, visitor and slot management, fines, compliance analytics, and communications). The lawful basis is the society’s legitimate management of its premises and, where required, the consent captured at registration.

4. Sharing & sub-processors

We do not sell personal data. We share it only with sub-processors that help us run the service: an email delivery provider (for notices/invoices) and a cloud object-storage provider (for images and documents). Data may be processed on infrastructure inside or outside India in line with applicable law.

5. Security

Data in transit is encrypted with TLS. The auth token and the guard app’s offline cache are encrypted at rest; stored images/documents use server-side encryption and are served through short-lived signed links. Access is role-based and audit-logged.

6. Retention

Personal data is retained for as long as the society uses the service, plus a limited period thereafter, after which reports, photos, and scans beyond the retention window are purged. A society may request earlier deletion.

7. Your rights

Subject to the DPDP Act, data principals may request access to, correction of, or erasure of their personal data, and may withdraw consent. Because the society is the controller, please raise such requests with your society’s administrator; we assist the society in fulfilling them (including erasure and data-portability exports).

8. Grievances

For privacy questions or grievances, contact the ParkTRAX Grievance Officer at privacy@thecodetheory.com. We will acknowledge and address requests within the timelines required by law.

9. Changes

We may update this policy; material changes will be notified to societies. The “Last updated” date above reflects the current version.

See also our Terms of Service.