Privacy policy
Last updated: 15 August 2026
This privacy policy explains how Kerbnow ("we", "us", or "the app") collects, uses, stores, and protects your information when you use our mobile app and website.
Who we are
Kerbnow is built and run by SHACKSOLUTIONS LTD, a UK-registered private company. We are not affiliated with any council, government body, or parking enforcement authority. We built Kerbnow because we got tired of squinting at confusing parking signs.
Information we collect
We collect the minimum data needed to provide and improve Kerbnow. Here is what we collect:
Sign photos
When you point the camera at a sign and scan it:
- Sent for reading: To read a sign, the app sends a single still image to Google Gemini, a third-party AI service acting as our processor under contract. The image is used only to read the sign and is not used to train Google's models. It is processed securely and is never sold or used for advertising.
- Saved to your scan history: The scanned sign photo is saved to your scan history so you can reference it later. You can delete any scan from your history at any time - see Data retention for what "delete" means.
- Building our parking-sign database: We also keep the sign's location, the rules we decoded from it, and the photo indefinitely - even after you delete the scan or your account - to build and improve a database of UK parking signs. Before this happens, we remove the link to your account, so this data no longer identifies you; see Data retention below for exactly when.
- Anonymous submission: If you choose to submit a sign for training-set review, we strip any incidental personal data (number plates and faces visible in the frame) before storage.
Because sign photos are taken in public places, they may incidentally include other people, vehicles, or number plates in the background. We don't currently run any process to remove or obscure this incidental content from the photos we retain internally to build the database above - we rely instead on removing the link to your account (see Lawful basis for processing). We do not currently sell or share this retained scan data with third parties. If that ever changes, we will first process anything shared or sold outside Kerbnow to remove or obscure identifiable third-party content, such as faces and other vehicles' number plates.
Account information
When you create an account or sign in:
- Authentication data: If you sign in with Apple or Google, we receive your email address and name from these providers. We store your email for account management. You can choose to hide your email when signing in with Apple.
- Anonymous accounts: If you use the app without signing in, we create an anonymous account with a random identifier. No personal information is collected.
- Display preferences: Optional display name and notification preferences.
Vehicle information
Adding a vehicle is optional - the sign scanner works without one. If you add a vehicle, we store:
- Registration plate
- Make, model, colour, fuel type, CO2 emissions, and weight/dimensions (where available)
- Whether the vehicle is registered as a taxi or private hire vehicle
We use this to tailor the parking rules we show you to your vehicle - for example diesel surcharges, EV bay eligibility, permit and controlled parking zone pricing, and taxi/PHV rules. Vehicle details are retained for as long as your account exists, or until you remove the vehicle from Settings.
Today, vehicle details are entered by hand - we don't look them up automatically. We can look up some of these details from the DVLA's Vehicle Enquiry Service (VES) using your registration, but that lookup is currently switched off. If we turn it on, VES would only be used to pre-fill the fields above from your plate, and we'll update this policy and the third-party table below first.
Special category data (Blue Badge)
If you tell us you hold a Blue Badge, we store that status along with the issuing council and expiry date you provide. This reveals disability-related information, which UK GDPR treats as "special category data". We only collect and store it with your explicit consent - given by confirming a clear opt-in prompt when you turn on "Blue Badge holder" in the app - which is the Article 9 condition we rely on. It's entirely optional: you can decline, and you can remove your Blue Badge status at any time by turning the toggle off or removing your vehicle in Settings, which deletes it immediately.
Device and technical information
When you use the app, we may collect technical details such as:
- Device model and platform
- Operating system version
- App version and build number
- Push notification token (if notifications are enabled)
Usage analytics
We use PostHog (EU-hosted) for product analytics and debugging:
- Which screens you view and features you use
- Scan counts, postcode lookups, scan-history interactions (aggregated)
- App performance and stability signals
- Session replay with text inputs masked
Session replay helps us identify bugs and UX issues. Your typed text is masked before capture, and the camera viewfinder is not recorded.
Preferences
We store your:
- Recent postcode lookups
- App preferences and settings
- Notification timing for "move the car" reminders
Your preferences are stored on your device. If you sign in, your scan history syncs across your devices through our servers, encrypted in transit and at rest.
Permissions and data
The app may request optional permissions when you use specific features:
- Camera: Required for the sign scanner. The still image you capture is sent to our scanning service to read the sign, then saved to your scan history so you can reference it later. You can delete any scan at any time - see Data retention for what "delete" means.
- Location: Used to look up postcode rules around you. We do not continuously track your location in the background - only when the app is actively in use. Each time you scan a sign, we store the precise location of that scan (latitude/longitude) tied to your account, so we can show you the rules that apply nearby and help you find your way back to your car. This stays tied to your account for as long as the scan is in your history; afterwards we retain it as anonymised data for our parking-sign database - see Data retention below.
- Notifications: Used for "move the car" reminders before a restriction starts. Scheduled locally on the phone.
- Face ID / biometrics: Used by the operating system to protect your authentication session stored in the device keychain. We do not receive or store biometric data.
Feedback and support data
If you send feedback through the app, we store:
- Your feedback message and category (misread sign, missing sign type, feature request, etc.)
- Optional sign photo and scan log (only if you attach it)
- Device context (platform, OS version, app version, model)
- A PostHog identifier/session reference used for debugging
Website cookies and local storage
On kerbnow.com, we use cookies and local storage for analytics, consent preferences, and advertising. This includes PostHog (analytics), and Meta, Google Ads, and TikTok (advertising cookies, used to measure and improve the performance of our ad campaigns). We use a cookie banner so you can opt out of this tracking.
If you opt out, we store that preference and disable PostHog, Meta, Google Ads, and TikTok tracking for the site.
Advertising
We run ad campaigns on Meta (Facebook/Instagram), Google Ads, and TikTok to reach new drivers. To measure and improve these campaigns we share limited data with those platforms:
- On the website: a cookie-based pixel from each platform, and which store button you clicked.
- In the app: TikTok's SDK reports app installs and purchases (no personal details beyond a hashed device/account identifier).
- From us: when you buy Kerbnow Pro, we report the purchase to Meta using a one-way hashed version of your email address and account id (never your email in plain text) so Meta can measure ad performance. This is separate from and never shared with the AI model that reads your signs.
We don't show ads inside the app itself, and we don't sell your data to advertisers. Website visitors can opt out of advertising cookies via the cookie banner; account holders can request deletion of any data these platforms hold about them by contacting the platform directly, or by asking us to stop future reporting.
Information we do not collect
- Your driving licence number
- Your credit card numbers, billing address, or bank details (Kerbnow Pro is purchased through the Apple App Store or Google Play, who handle the payment)
- Your contacts, calendar, or photos beyond what you actively share
- Continuous background location tracking - we only capture your location at the moment of each scan, not in between (see Permissions and data above)
- Identifying details about people or property visible in photos submitted for training-set review (we strip these before storage) - see Sign photos above for how photos saved to your regular scan history are handled instead
We do collect your vehicle's registration plate if you add a vehicle, and the precise location of each sign you scan - see Vehicle information and Permissions and data above.
How we use your information
- To provide the service: Scanning signs, syncing your scan history, scheduling move-the-car reminders.
- To improve sign reading: Misread reports help us retrain the model so the same sign reads correctly next time.
- To improve reliability: Understanding usage patterns helps us prioritise features and fix issues.
- To communicate: Sending service notifications and important product updates.
- To build our parking-sign database: After a scan (or your account) is deleted, we keep the anonymised location, decoded rules, and photo to build and improve a UK-wide map of parking signs - see Sign photos above.
We never:
- Sell your data to anyone.
- Show ads inside the app.
- Use your scan history or sign photos for advertising.
- Share your scan history or sign photos with third parties without your explicit permission - this doesn't cover the anonymised internal retention described in Sign photos above, which no longer identifies you.
We do use limited advertising tools (Meta, Google Ads, TikTok) to measure ad campaign performance - see Advertising below.
Lawful basis for processing
Under UK GDPR, here's the legal basis we rely on for each main use of your data:
- Providing the service (scanning signs, syncing your history, move-the-car reminders): performance of a contract with you.
- Improving sign reading and reliability (misread reports, usage analytics, session replay): our legitimate interests in making Kerbnow more accurate and reliable - you can opt out of analytics at any time (see Your rights).
- Blue Badge status: your explicit consent, since this is special category data (see Special category data).
- Fraud prevention and dispute resolution (keeping a deleted scan linked to your account for up to 90 days before anonymising it): our legitimate interests in keeping the service safe from abuse.
- Building our parking-sign database (retaining anonymised sign locations, decoded rules, and photos indefinitely after a scan or account is deleted): our legitimate interests in building and improving a UK-wide map of parking signs.
- Advertising cookies and pixels: your consent, given or withheld via the cookie banner, in line with PECR.
- Account and legal records: compliance with our legal obligations (e.g. tax and accounting) where applicable.
Data storage and security
- Where: App data is stored using AWS and Neon infrastructure providers, primarily in UK and EU regions.
- Encryption: Data is encrypted in transit (TLS) and at rest. Storage protections are managed by our infrastructure providers.
- Access: Access is limited to authorised maintainers and service providers who need it to operate the service.
- Security: We apply reasonable technical and organisational safeguards, but no system is completely risk-free.
Third-party services
We use these third-party services:
| Service | Purpose | Privacy policy |
|---|---|---|
| AWS | App hosting, file storage and delivery, and scheduled tasks | aws.amazon.com/privacy |
| Neon | Database hosting | neon.tech/privacy |
| Google Gemini | Reading parking signs from the still image you capture | policies.google.com/privacy |
| PostHog | Analytics and session replay | posthog.com/privacy |
| DVLA Vehicle Enquiry Service | Vehicle lookup from your registration plate - currently inactive; not used by the live app | gov.uk VES privacy notice |
| Expo | Mobile app framework and push notifications | expo.dev/privacy |
| Apple Sign In | Authentication (if you choose) | apple.com/legal/privacy |
| Google Sign In | Authentication (if you choose) | policies.google.com/privacy |
| Apple Maps | Map rendering and reverse geocoding for postcode lookup | apple.com/legal/privacy |
| Slack | Internal operations and alerting (misread reports, model issues) | slack.com/privacy-policy |
| Meta (Facebook) | Advertising - website pixel and server-side purchase reporting (hashed data only) | facebook.com/privacy/policy |
| Google Ads | Advertising - website conversion tracking | policies.google.com/privacy |
| TikTok | Advertising - website pixel and in-app install/purchase reporting | tiktok.com/legal/privacy-policy |
Your rights
Under UK GDPR, you have the following rights over your data:
- Access: View your scan history and settings any time in the app.
- Correction: Update your display name and preferences in settings.
- Deletion: Delete your account from within the app. You're signed out immediately; if you sign back in within 30 days the deletion is cancelled and your account is restored exactly as it was.
- Portability: Tap "export my data" in settings to receive a JSON dump.
- Opt-out: You can use the app anonymously without an account. In the app, go to More → Preferences → Analytics to turn in-app product analytics off at any time. Website visitors can opt out of analytics and advertising cookies via the cookie banner.
- Complain: If you're unhappy with how we've handled your data, you can complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at ico.org.uk. We'd appreciate the chance to put things right first - contact us using the details below.
Data retention
- Active accounts: Data is retained while your account exists.
- Deleted accounts: When you delete your account you're signed out immediately and your account enters a 30-day recovery window. Signing back in during that window cancels the deletion and restores everything. If you don't sign back in, all personal information (email, name, push token, preferences) is permanently and irreversibly deleted within 30 days, in line with UK GDPR's right to erasure. Your scan records are handled separately - see below.
- Scanned sign photos and scan records: Saved to your scan history while your account exists. Deleting a single scan removes it from your visible history immediately; the record stays linked to your account for up to 90 days for fraud prevention and dispute resolution, and is then anonymised - we remove the link to your account rather than deleting the record. Deleting your account anonymises any of your remaining scans as soon as the 30-day recovery window lapses, rather than waiting the further 90 days. Once anonymised, we retain the sign's location, the decoded parking rules, and the photo indefinitely to build and improve our database of UK parking signs - see Sign photos above.
- Vehicle details and Blue Badge status: Retained while the vehicle stays on your account, or until you remove it or delete your account.
- Misread reports: Anonymised after the model update lands, then retained for 12 months as a regression test.
- Feedback submissions: Retained for up to 24 months, including any device/debug information you (or the app) attach. Because our feedback records are only linked to your identity while your account exists, they are not deleted when you delete your account - deleting your account removes the link, but the feedback content itself is kept for the period above.
- Other analytics logs: Retained according to provider settings and operational/legal needs.
Children's privacy
Kerbnow is intended for licensed drivers (18+). We do not knowingly collect data from anyone under 18. If you believe a minor has provided data to us, contact us and we will remove it.
International data transfers
Your data may be processed in countries outside your residence, including through our third-party providers. We rely on provider safeguards (standard contractual clauses, UK adequacy decisions) for international transfers where required.
Changes to this policy
We may update this privacy policy from time to time. Significant changes will be announced through the app or website. The "Last updated" date at the top shows when this policy was last revised.
Contact us
Questions about this privacy policy or your data? Email us at [email protected].