Legal

Last updated: September 2026

This is a draft for legal review — not yet effective.

This page describes the security practices we actually follow. We do not claim certifications, audits, or bug bounty programs we do not have — only what is on this page.

Account security

  • OTP sign-in, no passwords. You sign in with a one-time passcode sent to your phone. There is no password to phish, leak, or reuse.
  • Token-based sessions. Your signed-in session uses short-lived, revocable tokens rather than long-lived credentials.

Data protection

  • Encryption in transit. Data moving between your device and our servers is protected with TLS.
  • Encryption at rest. Data stored on our servers is encrypted.
  • In-app chat. Drivers and hosts communicate through the app's chat, so phone numbers stay private unless you choose to share them.

Marketplace safety

  • Every listing is reviewed before it goes live, to catch fraud, duplicates, and obviously fake spots.

Beyond this, our security program is still being built. We will update this page as we add practices — not before.

Report an issue

If you find a security vulnerability in ParkQ, please tell us so we can fix it: email [security email] with a description of the issue and steps to reproduce it. We will acknowledge your report and keep you updated on our progress.