ParkPulse · Privacy
Your data, in plain terms
What ParkPulse uses, what stays on your device and how you stay in control.
The Apple account is optional. Online features can use the server even without an account.
ParkPulse contains no targeted advertising and no ad tracking. Your data is not sold. Sync, alerts, the shared day and Apple Wallet each have their own exchanges, detailed below.
Who looks after your data?
Christopher Hardeman is the publisher of ParkPulse and the controller of the processing described here. For a question or a request about your data: christo59@pm.me.
This policy covers the ParkPulse app and its support pages. External sites opened from the app apply their own policies.
The data used, feature by feature
On your device
Visits, rides completed, favourites, encounters, collections, plans, group profiles, passes, bookings, stays, expenses, notes, photos and attachments are stored locally. The backups you export contain personal information; where they go and who you share them with is up to you. iPhone system backups follow your Apple settings.
Parking marker
At your request, ParkPulse keeps on your iPhone the GPS position of your car, its accuracy, the date and your note of the zone or row. This position is not part of account sync and stays stored until it is deleted or replaced in “My car”. Optional reminders use iOS proximity detection, including outside the app with the “Always” permission and notifications enabled. No parking route is recorded. The map and walking directions use Apple services; starting directions sends the destination to Maps.
Apple account and optional sync
Apple sends a sign-in identifier and the technical elements needed to verify and renew access. ParkPulse does not ask Apple for your email address and does not receive your Apple password.
When you sign in, visits, favourites, collections, encounters, names entered in profiles and passes, booking and stay data, expenses, plans and syncable preferences are associated with your account on our server. Item identifiers, versions and deletion markers make it possible to sync changes. Profiles may include the make-up of the group, the height of the youngest, walking, thrill and pace preferences, and the accessibility priority. Photos and attached files are not sent by this sync.
Exchanges go through HTTPS and the synced document is encrypted in the server database. This is not end-to-end encryption: ParkPulse can decrypt it to return it to you.
Restaurants, alerts and notifications
A search sends the restaurant, the date, the number of guests and the meal period wanted. Availability readings are pooled. Alerts and end-of-search notifications also use a random installation identifier, the Apple notification token, the language and delivery information. This data can be processed without an Apple account and stays separate from its sync.
The criteria needed for availability are queried from Disney services. The booking is completed on the official site or app: ParkPulse does not book on your behalf. The Disney maintenance accesses are managed by the publisher; visitors never need to send their Disney password to support.
Location and day guidance
To pause on-site notifications after you leave, version 1.1 sends an “in the park”, “out of the park” or “unknown” state with the date of the reading, without precise GPS coordinates. A presence state expires after 30 minutes without recent confirmation; the last state is replaced on each update and deleted after 30 days without a refresh. Restaurant alerts remain independent of this presence.
With your iOS permission, your position is used for the map, nearby places and on-site progress. The guidance service receives the park concerned, the day’s opening hours, the priority, favourite, skipped, completed or remaining rides and the appointments needed for the plan, with an installation and session identifier. This context reveals your presence in a park, even without precise GPS coordinates.
Notifications and Live Activities use the corresponding Apple tokens and the content needed to display them. Apple maps and directions also fall under Apple services.
Shared day
If you create or join a group, the server keeps the title, the next step, the meeting point, the names of the members and their status. Anyone holding the invitation code can access the group: share it only with the people concerned.
Adding a pass to Apple Wallet
At your request, the pass information (name, type, number, barcode, dates, benefits, relevant visit days and, if present, the image used on the card) is sent to the server to generate and sign the Wallet file. This processing is separate from account sync. The generator does not store it in the database; the added card is then managed by Apple Wallet.
Running the service and support
Connections expose an IP address and network metadata to the host. ParkPulse uses the IP address to limit abuse and logs, among other things, the route called, the date, the result, the duration and errors. If you write to support, your email address, your message and the attachments you choose to send are used to handle your request.
Why this processing?
Storage, sync, searches, alerts, sharing and Wallet generation serve to provide the features you ask for: their basis is the performance of the service. Security, abuse prevention and diagnostics rest on the legitimate interest in maintaining a reliable service. Handling rights requests meets the applicable legal obligations.
The iOS permissions for location, photos and notifications are optional and can be revoked in Settings. Refusing one limits the feature concerned; it does not require you to create an account to use the rest of ParkPulse. Where processing relies on your consent, you can withdraw it without affecting its earlier use.
No advertising profiling and no automated decision producing legal effects is carried out. Day recommendations remain suggestions that you can accept or decline.
Providers, recipients and transfers
The publisher accesses the data needed for operation and support. Cloudflare hosts the server and the database; Apple provides sign-in, notifications, maps and Wallet. Invited members access the information of their group. Proton Mail receives the emails sent to support.
The app also queries ThemeParks.wiki and Queue-Times for park information, and Open-Meteo for the weather at the fixed coordinates of Disneyland Paris. These direct connections transmit the usual network metadata, including your IP address. Opening a Disney site or another external link establishes a connection with that site.
These providers may process data outside the European Economic Area. Cloudflare notably provides standard contractual clauses for the transfers concerned in its data processing agreement. The service is not presented as hosted exclusively in France. You can ask for details of the applicable safeguards at the contact address.
Service policies: Apple · Cloudflare · Disney · Proton.
The support and privacy pages embed no advertising tool, no audience measurement and no application cookie. Hosting may process the technical information needed to deliver and secure them.
How long?
- Local data: until it is deleted on the device. Exports and external backups stay where you saved them.
- Account: for as long as you keep it. Deleting it in the app erases the account, its sessions and its sync document from the active database. A sign-in session expires after 30 days; sign-in challenges after 5 minutes. Expired accesses are then removed by automatic maintenance.
- Restaurants: abandoned one-off searches are cleaned up after 6 hours, unless a notification is still validly awaited. Finished scans are removed after 24 hours and delivered result notifications after 7 days. Saved alerts are removed from 30 days after their last visit date, once their delivery traces have expired. The installation identifier and the notification token are kept to manage notifications; you can ask for them to be erased.
- Shared day: access expires after 48 hours. The group can be deleted before then; expired groups are removed automatically, without waiting for a new group to be created.
- Abuse limitation: counters containing the IP address are cleaned up after 10 minutes during the maintenance pass. The host’s Workers logs are kept for 7 days at most.
- Server history of days and notifications: day contexts are removed from 30 days after the day and their last update. Evaluation and notification traces are removed after 30 days; a recent or still valid delivery is kept until the end of its own period. Cleanup runs every 10 minutes in batches, which can delay erasure in the event of high volume or an incident. This data is separate from the Apple account. You can ask support for earlier erasure with the installation identifier available in the app.
- Support: for the time needed to handle your request and its follow-up; items needed for a legal obligation or to defend a right may be kept for the corresponding period.
Technical backups of the Cloudflare database may contain an earlier state for up to 30 days. They are used for recovery after an incident and are not the active database. An access expiring does not always mean immediate erasure of the data or of these backups.
Your choices and your rights
You can access your data, correct it, ask for its erasure, restriction or portability, and object to processing based on legitimate interest, under the applicable conditions. You can also set out instructions about your data after your death.
- Export: Trip → Backup.
- Delete the account: Trip → Account and synchronization → Delete my account.
- Manage alerts: Restaurants → My alerts. Notifications can also be revoked in iOS Settings.
- Other server data or a lost device: write to christo59@pm.me. If possible, give your installation identifier (Trip → Support and privacy). We will ask only for what is needed to verify the request.
Deleting the account leaves local copies and the installation-related features separate. Signing in again can recreate an account from local data. Deleting the app is not a request to delete the server account.
Rights requests normally receive a reply within one month; a justified extension may be needed depending on their complexity. You can lodge a complaint with the CNIL, the French data protection authority, if you believe your rights are not respected.
Avoid adding unnecessary sensitive information to notes, and enter your companions’ information with their agreement. Any significant change to the processing will be reflected in this policy.