Loading

Privacy Policy

Version 3.0 — Effective August 1, 2026 Parada® by Parada Technologies, Inc.
This Privacy Policy explains how Parada Technologies, Inc. ("Parada", "we", "us") collects, uses, shares, stores, and protects your personal data across the Parada platform, in accordance with Republic Act No. 10173 (the Data Privacy Act of 2012, "DPA"), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC). Read it together with our Terms and Conditions.

1. Introduction & Who We Are

Parada Technologies, Inc. is the Personal Information Controller (PIC) for the personal data processed through the Parada website (www.parada.ph) and mobile apps. Our registered office is 24 Sheridan Towers North, Buayang Bato, Mandaluyong City, Metro Manila, Philippines 1550 (SEC Registration No. 2026060256331-09). We have designated a Data Protection Officer whose contact details are in Section 17.

This is a layered notice: this page is the full text; shorter, "just-in-time" notices appear at the points where we collect data (sign-up, verification uploads, chatbot, checkout). By using Parada you acknowledge this Policy; where the law requires consent, we ask for it separately and specifically.

2. Scope, Verticals & Roles

This Policy covers all Parada Services, across every vertical we operate where available: Shared Residential Parking, Commercial Parking, Peer-to-Peer Car Rental, and Parada Storage. The data we process depends on your role, and a single account may hold more than one role:

  • Renters / Drivers / Guests — users who search, book, and pay.
  • Providers — Parking Owners, Car Hosts, Storage Hosts, and Commercial Operators who list and supply services. Commercial Parking operators may use a separate operator account.
  • PMOs / building administrators — partners who help verify residents.

3. Information We Collect

3.1 Information you provide

  • Account & profile: name/display name, email, password (stored only as a hashed value), phone number, profile photo, home address, and — where you sign in with Google, Facebook, or Apple — the basic profile information those providers share with us.
  • Residency & parking verification documents: government-issued IDs, resident/tenant IDs, proof of billing, lease contracts or titles, slot-assignment or authorization letters, and similar proof needed to confirm residency or a right to list.
  • Car-rental identity (KYC) data: for renting or hosting a vehicle, your driver's license (front and back images), a selfie/liveness photo holding your physical license, your date of birth, license number, type, and expiry, and a billing address.
  • Vehicle & listing data: plate number, make/model/color/type, listing photos, rates, availability, and space or facility details.
  • Booking & transaction data: dates, locations, prices, fees, promo codes, and booking history. Payments are processed on a Xendit-hosted page — Parada does not collect or store your full card number or CVV.
  • Communications: in-app chat messages (stored encrypted at rest), support tickets, chatbot conversations and any files you attach to them, ratings, and reviews.
  • Rental handover records: pickup/return condition photos, which may carry time and location (geo) metadata and a watermark.

3.2 Information we collect automatically

  • Device & log data: IP address, device/browser type, pages visited, and timestamps, used for security, fraud prevention, rate-limiting, and analytics. We track certain page accesses for operational monitoring.
  • Location: when you search an address, your query is sent to our address-suggestion provider (Google) to return suggestions; rental handover photos may include geo metadata as noted above.

4. Lawful Bases for Processing

Under the DPA we rely on the following bases, matched to each purpose:

ProcessingLawful basis
Creating/managing your account; taking and fulfilling bookings; payments and payouts; in-app messagingPerformance of a contract with you (and steps at your request)
Identity, residency, and KYC verificationContract, our legal obligations, and — for sensitive personal information — your specific consent given at the upload screen
Fraud prevention, security logging, safety, dispute handling, service analyticsOur legitimate interests (and legal obligations)
Tax withholding and reporting; responding to lawful requestsCompliance with a legal obligation
Marketing emails and promotional blastsOur legitimate interest in promoting the service, subject to your right to opt out at any time (Section 11)

5. How We Use Your Data

  • To operate the Platform and provide the Services you request.
  • To verify eligibility (identity, residency, license) and prevent fraud and abuse.
  • To process payments through the Payment Processor and to settle Provider payouts, including any tax withholding.
  • To enable communication between Renters and Providers, and to provide customer support (including the AI assistant).
  • To send service messages and, unless you opt out, marketing messages.
  • To maintain security, investigate incidents, resolve disputes, and comply with the law.
  • To analyze and improve the Services (including aggregate, non-identifying analytics).

6. Sharing & Disclosure

We do not sell your personal data. We share it only as described here:

6.1 With the other party to your booking

Completing a booking necessarily reveals some information to your counterpart:

  • Shared & Commercial Parking: the Owner/Operator sees the Driver's name and vehicle details for an approved booking; the Driver sees the space/facility and access details.
  • Car Rental: to let the Host decide on and prepare for a booking, the Host progressively sees the Guest's information — the Guest's home address from the time a request is made, the Guest's email and phone once the booking is approved, and the Guest's driver's-license document once the booking is Paid/Active. A Host's access to a Guest's contact and license data ends about 30 days after the rental completes (extended while a dispute is open). The separate window for a Guest to file a post-trip dispute is shorter (see the Car Rental Agreement).
  • Storage: the Host and Renter exchange the information needed to arrange access and handover, including through in-app chat.

6.2 With service providers (processors)

We use the third-party processors listed in Section 8 to run the Platform. Some receive personal data strictly to perform their function (for example, the payment gateway, cloud hosting, email and SMS delivery, and the AI assistant).

6.3 Operational notifications

We route internal operational alerts (for example, new signups, bookings, refunds, and support touchpoints) to our team's Slack workspace. Email addresses in these alerts are masked, but the alerts may include names and booking, refund, or support details so our team can act on them.

6.4 Legal, safety & corporate

We may disclose data to comply with a law, regulation, subpoena, or lawful government request (including to the DTI or BIR where required); to protect the rights, safety, or property of Parada, our Users, or the public; to enforce our Terms; or in connection with a merger, acquisition, or sale of assets, subject to this Policy.

7. Verification & KYC Documents

Verification documents (Section 3.1) are sensitive personal information under Section 13 of the DPA. We ask for your specific, informed consent at the point of upload, and we apply data-minimization: we collect only what a given check needs. These documents are:

  • transmitted over encrypted channels (TLS) and stored in a private, access-controlled object store with server-side encryption;
  • accessible only through admin-only routes and short-lived signed links, by reviewers operating under role-based access and a documented purpose limitation;
  • never used for marketing or profiling; and
  • never placed, in raw or full form, into emails, operational chat alerts, or client-visible URLs.

8. Processors & International Transfers

We engage the following categories of processors. Some are based outside the Philippines (notably in the United States), so operating Parada involves cross-border transfers. Under Section 21 of the DPA, Parada remains accountable for personal data transferred to a processor and uses contractual and technical safeguards (including processors' data-processing agreements and standard contractual clauses where applicable) to require a comparable level of protection.

ProcessorPurposeData involved
XenditPayment processingPayment and booking metadata (no card data stored by Parada)
Amazon Web Services (S3, CloudFront, SNS)File storage, content delivery, notificationsUploads, photos, documents; delivery metadata
MongoDB AtlasApplication database hostingAccount, booking, and message records
Google (Sign-in, Places, Firebase)SSO, address autocomplete, remote configurationSSO profile; address search queries (Firebase config carries no personal data)
Facebook (Meta) & AppleSingle sign-onBasic SSO profile you authorize
Anthropic (Claude)AI support assistantYour chatbot messages and any images/PDFs you attach (see Section 10)
OpenAISearch / recommendation embeddingsNon-identifying listing/search text used to compute matches
Email delivery (GoDaddy / secureserver.net SMTP)Transactional & marketing emailEmail address and message content
SMS gateway (CloudSMS) / AWS SNSSMS notificationsPhone number and message text
SlackInternal operational alertsNames and booking/support details; emails masked

9. Cookies & Sessions

Parada uses cookies that are strictly necessary to run the Services — principally a session cookie to keep you logged in and a CSRF token to protect form submissions. Necessary cookies do not require consent. If we introduce analytics or marketing cookies that are not strictly necessary, we will seek your consent first and update this Section. We do not use your data for third-party advertising networks.

10. Automated Tools & AI

Our support assistant is powered by a third-party AI service (Anthropic's Claude). When you use it, the text you type and any images or PDFs you attach are sent to that service to generate a reply; attachments are stored in our object store and referenced through short-lived signed links. The assistant's answers may be imperfect and are not professional advice; you can always escalate to a human. We do not use your chatbot inputs to train third-party AI models, consistent with the provider's default API terms.

We do not make decisions that produce legal or similarly significant effects about you solely by automated means. Address autocomplete and search suggestions are conveniences and do not, by themselves, decide any outcome.

11. Marketing Choices

We may send promotional emails about Parada — including targeted promo campaigns to verified Renters — unless you have opted out. Every marketing email contains a working unsubscribe link, and you can also manage your preference in your account settings. We honor opt-outs promptly; once you opt out we stop marketing to you but continue to send essential service messages (booking confirmations, security notices, and the like).

12. Children's Privacy

Parada is intended for users who are at least 18 years old. We do not knowingly collect personal data from children. If you believe a minor has provided us data, contact our DPO and we will take appropriate steps.

13. Data Retention & Deletion

We keep personal data for as long as your account is active and, after that, for the periods needed to meet legal, tax, accounting, dispute, and fraud-prevention obligations. Our target retention periods are:

CategoryTarget retention
Account & profile dataWhile active; retained after closure for the periods below, then deleted or anonymized
Booking, payment & payout recordsUp to 10 years (BIR / accounting requirements)
Verification & KYC documentsWhile the account/role is active; removed or anonymized within a defined window after closure, subject to legal holds
In-app chat & support recordsRetained for reference and dispute resolution; chat sessions close shortly after a booking ends and remain read-only
Device & security logsRetained for a limited period for security and fraud purposes
How account deletion works today. When you delete your account, we deactivate it (it can no longer sign in or transact) and it is removed from active use. For the retention periods above, some records and uploaded documents are kept in back-end storage to meet our legal, tax, and dispute obligations, and are then deleted or anonymized. You may request erasure of data we are not required to keep at any time (Section 16); we honor valid requests and are continuing to strengthen automated deletion on the schedule above.

14. Data Security

We apply organizational, physical, and technical measures appropriate to the risk, including:

  • encryption in transit (TLS) and at rest, including server-side encryption for stored files and AES-256-GCM encryption of chat message bodies;
  • hashed passwords (bcrypt) — we never store passwords in plain text;
  • short-lived, signed links for private files, and admin-only access routes;
  • role-based access controls and audit logging of sensitive access (including views of verification documents and administrator access to chat);
  • CSRF protection, request rate-limiting, and temporary account lockout after repeated failed logins to deter brute-force attacks; and
  • masking of email addresses in operational alerts.

No method of transmission or storage is completely secure, but we work to protect your data and to improve our controls over time.

15. Data-Breach Notification

We maintain a breach-response process aligned with NPC Circular 16-03. Where a personal-data breach is likely to give rise to a real risk of serious harm, we will notify the NPC and the affected data subjects within 72 hours of knowledge of, or reasonable belief in, the breach, and cooperate with the NPC as required.

16. Your Rights as a Data Subject

Under the DPA you have the rights to:

  • be informed about how your data is processed;
  • access your data and obtain a copy;
  • rectify inaccurate or outdated data;
  • object to processing, including for marketing;
  • erasure or blocking of data we are not required to keep;
  • data portability for data you provided, in a usable format;
  • damages for a violation of your rights; and
  • lodge a complaint with the NPC.

To exercise any right, email our DPO at [email protected]. We may need to verify your identity before acting, and we will respond within the period required by law.

17. Data Protection Officer

Data Protection Officer, Parada Technologies, Inc.
Email: [email protected]
Address: 24 Sheridan Towers North, Buayang Bato, Mandaluyong City, Metro Manila, Philippines 1550

18. Complaints to the NPC

If you believe your data-privacy rights have been violated and we have not resolved your concern, you may file a complaint with the National Privacy Commission (5th Floor, Delegation Building, PICC Complex, Pasay City; privacy.gov.ph). We ask that you contact our DPO first so we can try to resolve the matter directly.

19. Updates to this Policy

We may update this Policy to reflect changes in our Services or the law. We will post the updated version here with a new effective date and, for material changes, notify you by email or in-app. Prior versions are archived.

20. Contact Information

  • Privacy / DPO: [email protected]
  • General support: [email protected]
  • Parada Technologies, Inc. (SEC Registration No. 2026060256331-09), 24 Sheridan Towers North, Buayang Bato, Mandaluyong City, Metro Manila, Philippines 1550
  • Telephone: +63 (02) 7273 1125 · Website: www.parada.ph

See also our Terms and Conditions, Refund & Cancellation Policy, and Community Guidelines.