Security and data

Clear information about where Park Share stores workplace data, how access is protected, and the providers involved in delivering the service.

Data location

Park Share uses Cloudflare D1 in the Oceania region. Customer data at rest is stored in Sydney, Australia. Requests may pass through Cloudflare's global network while being delivered to and from the application.

Access and application safeguards

  • Passwordless magic-link authentication, so Park Share does not store account passwords.
  • Optional authenticator-app two-factor authentication, which organisation administrators can require for all members.
  • HTTPS encryption for data transmitted between your browser and the service.
  • Signed session tokens stored in HttpOnly, Secure cookies that are unavailable to browser JavaScript.
  • Organisation-scoped access controls designed to prevent one customer from accessing another customer's records.
  • No advertising trackers and no sale of customer or user information.

Service providers

Park Share shares information only where needed to operate features selected by a customer. The providers currently involved are:

Cloudflare

Application hosting, database, network delivery, and transactional email.

Core service provider.

ClickSend

Delivery of SMS parking notifications.

Only when an organisation enables SMS and a member opts in.

Slack or Microsoft Teams

Delivery of allocation summaries to a customer-configured incoming webhook.

Only when an organisation administrator configures that integration.

Data requests

Account holders may request access, correction, or deletion of personal information. Park Share responds to privacy and deletion requests within 30 days.

Report a security concern

Send suspected vulnerabilities or security incidents to contact@parkshare.work.