Last updated: October 2026
1. Data Controller
The data controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws and provisions is:
Tobias Niepel
Postfach 71 01 10
47198 Duisburg, Germany
Email: info@parxapp.com
2. Data Collected and Purposes
When using the parX app, the following personal data is collected and processed:
·
Registration data: email address, username, password (stored as a bcrypt hash) – to create and manage your account.
·
Check-in data: parks and attractions visited, optional notes, timestamps – to display them in the activity feed and your user profile.
·
Chat messages: content of direct messages and public park chats – to provide the messaging feature.
·
Profile picture (avatar): image file you upload – to display it in your profile and the feed.
·
Push token: device token for Firebase Cloud Messaging – to deliver push notifications (e.g. new messages, friend requests).
·
Device ID (app): a random, anonymous installation ID together with the platform (iOS/Android), app language, app version and time of last use – also without an account. We use it solely for aggregated usage statistics (legitimate interest, Art. 6(1)(f) GDPR); if you are logged in, it is linked to your account. Entries that have not been used for 12 months are deleted automatically.
·
Friendships: friend requests you send and receive and their status – to display the activity feed.
·
Session cookie: technically necessary JWT cookie parx_session (httpOnly, valid for 30 days) – to authenticate you during your session.
3. Legal Bases (Art. 6 GDPR)
·
Art. 6(1)(b) GDPR: processing for the performance of a contract – all data necessary to provide the app's features.
·
Art. 6(1)(f) GDPR: legitimate interests – technical security, abuse prevention, operation of our infrastructure.
·
Art. 6(1)(a) GDPR: consent – optional features such as push notifications (revocable at any time in the app settings).
4. Retention Period
Data is stored for as long as your account is active. When your account is deleted, all personal data is deleted within 30 days, unless statutory retention obligations require otherwise. Log data is deleted after 90 days at the latest. Chat messages are retained until the conversation or the account is deleted.
You can delete your account yourself at any time: open Settings in the app and tap “Delete Account” at the bottom.
5. Disclosure to Third Parties
Personal data is not sold to third parties. It is only transmitted to the following service providers acting as data processors:
·
Firebase Cloud Messaging (Google LLC): delivery of push notifications. Push tokens are transmitted to Google's servers in the USA. This transfer is based on the EU Standard Contractual Clauses (Art. 46 GDPR).
·
Database server: hosted in Karlsruhe, Germany. A data processing agreement pursuant to Art. 28 GDPR is in place.
6. Your Rights
You have the following rights regarding your personal data:
·
Access (Art. 15 GDPR): what data we hold about you.
·
Rectification (Art. 16 GDPR): correction of inaccurate data.
·
Erasure (Art. 17 GDPR): deletion of your account and all data via the app settings or by email.
·
Restriction of processing (Art. 18 GDPR).
·
Data portability (Art. 20 GDPR): export of your data on request.
·
Objection (Art. 21 GDPR): objection to processing based on legitimate interests.
To exercise these rights, contact us at: hi@parxapp.com
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence.
7. Cookies and Local Storage
The app uses only technically necessary cookies:
·
parx_session: httpOnly JWT cookie for authentication, valid for 30 days. Contains the user ID and session information.
·
parx_setup: temporary httpOnly JWT cookie used during registration, valid for 15 minutes.
No tracking cookies or advertising cookies are used.
8. Data Security
Data is transmitted between the app and our server exclusively via encrypted HTTPS/TLS connections. Passwords are never stored in plain text, but only as a bcrypt hash with an individual salt.
9. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy as needed in order to reflect changes to the legal situation or to the service. Registered users will be informed by email of material changes. The current version is always available in the app and on this page.