Effective date: 6 September 2026 · Last updated: 8 September 2026
This policy explains how Kerbie collects, uses, and protects your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Kerbie is operated by SYNTERNEX LTD (company number 17437894), a company registered in England and Wales.
Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
ICO Registration Number: ZC240408
For all data protection enquiries, contact us at: privacy@kerbie.app
Kerbie is a parking management app intended for drivers. You must be at least 18 years of age to create an account and use this service, as using Kerbie (including any paid subscription) forms a binding agreement.
We do not knowingly collect personal data from individuals under 18. If we become aware that a user is under 18, we will delete their account and all associated data without delay.
In compliance with the UK Children's Code (Age Appropriate Design Code), we apply privacy-by-default settings for all users and do not use personal data for profiling or targeted advertising.
Account data:
Location data:
Parking session data:
Parking search records:
Sign scan images:
Payment data:
Enforcement reports:
Feedback:
Device data:
We process your personal data under the following legal bases as defined by UK GDPR:
When you scan a parking sign, the image is sent to Anthropic (Claude AI) and/or Google Cloud Vision for analysis. This processing occurs in real time.
Images are used solely for the purpose of interpreting the parking sign and are not used to train AI models. Images are not stored by Kerbie at all. They are processed in memory to extract the sign's text and discarded immediately afterwards — this is true whether or not the scan is linked to an active parking session. Only the extracted text and the resulting parking rules are saved to your account.
We process scan images because it is necessary to provide the sign-scanning feature you have asked us to perform (Article 6(1)(b)). If you would rather your images were not sent to these providers, simply do not use the scanner — every other part of Kerbie works without it.
Location data is considered sensitive personal data and is handled with care. We collect your location only when you actively use features that require it (e.g., finding parking or starting a session).
The personal link to your parking‑session location data is removed after 12 months, or immediately when you delete your account. The remaining de‑identified location and outcome data cannot be traced back to you and is retained to improve parking recommendations for everyone.
To improve our parking recommendations we also record usage and parking‑outcome events (for example, which spots were recommended and whether parking succeeded), which can include the location involved. The link between these events and your account is removed after 12 months, or immediately when you delete your account. The remaining de‑identified data cannot be traced back to you and is kept to improve the service for everyone.
We do not sell or share your location data with advertisers or data brokers.
We share your data only with the third-party service providers necessary to operate Kerbie:
| Provider | Purpose | Country | Safeguard |
|---|---|---|---|
| Stripe | Payment processing | USA / EEA | SCCs + Adequacy |
| Anthropic | AI sign analysis | USA | Standard Contractual Clauses |
| Google Cloud | Image analysis | USA / EEA | SCCs + Adequacy |
| Nominatim (OpenStreetMap Foundation) | Address search & geocoding | UK / EEA | UK adequacy (EEA) |
| Photon (Komoot) | Search autocomplete | Germany / EEA | UK adequacy (EEA) |
| Railway | Server hosting & database | USA | Standard Contractual Clauses |
| Vercel | Frontend hosting | USA | Standard Contractual Clauses |
| Brevo | Transactional email delivery | France / EEA | UK adequacy (EEA) |
| Firebase (Google) | Push notifications | USA / EEA | SCCs + Adequacy |
| Sentry | Error monitoring (text masked, media blocked) | Germany / EEA | UK adequacy (EEA) |
| PostHog | Product analytics — only with your consent | USA | Standard Contractual Clauses |
When you search for a destination, the text you type and your approximate location are sent to our address-search providers (Nominatim and Photon) solely to return matching places — they do not receive your account details.
We do not sell your personal data to any third party.
Some of our service providers are based outside the UK. Where data is transferred internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner's Office, or transfers to countries with an adequacy decision.
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Parking sessions | Personal link removed after 12 months (or on account deletion); de-identified location/outcome retained |
| Sign scan images | Not stored — processed in memory only, never saved to disk |
| Payment records | Not held by Kerbie — retained independently by Stripe under its own legal obligations |
| Feedback | 2 years |
| Enforcement reports | 30 days |
| Parking search history | 13 months |
| Usage & parking outcomes | Account link removed after 12 months (or on account deletion); de-identified data retained |
| Password reset tokens | 1 hour from generation |
| Trust & safety reports (Community Spaces) | Retained indefinitely; survives account deletion (moderation/anti-abuse record) |
You have the following rights regarding your personal data:
To exercise any of these rights, contact us at privacy@kerbie.app. We will respond within 30 days.
You can also delete your account directly in the app via Profile → Delete Account. This deletes your account and immediately removes the link between you and your parking sessions, searches, scans and usage records. Three things survive deletion: your Stripe payment records, which Stripe (not Kerbie) retains independently under its own legal obligations; de-identified location and outcome data that can no longer be traced back to you; and, if you have used Community Spaces, any trust and safety report filed about your account, which is retained to prevent repeat contact with the person who reported you. All three are described in section 10.
Strictly necessary: Kerbie stores session tokens in your browser's local storage to keep you logged in. These are essential for the service to function and require no consent.
Analytics (optional, opt-in): with your consent, we use PostHog to understand how the app is used (pages visited, features used). Analytics never run unless you accept the consent prompt, and you can decline with no loss of functionality. To withdraw consent later, clear the site/app data for Kerbie or contact us at privacy@kerbie.app. Analytics data is not used for advertising and is never sold.
Error monitoring: we use Sentry to capture crashes and errors so we can fix them. Error reports have all text masked and media blocked — they do not contain what you typed or viewed.
We do not use advertising cookies and we do not sell or share data with advertisers or data brokers.
Push notifications require explicit consent from your device operating system and can be withdrawn at any time via your device settings.
We take the security of your personal data seriously:
If you believe your account has been compromised, contact us immediately at privacy@kerbie.app.
We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page and, where changes are significant, notify you by email.
Your continued use of Kerbie after any changes constitutes your acceptance of the updated policy.
If you are unhappy with how we handle your personal data, you have the right to lodge a complaint with the UK's data protection regulator:
We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first at privacy@kerbie.app.
© 2026 SYNTERNEX LTD. All rights reserved.
Questions? privacy@kerbie.app