Privacy Policy

This policy covers heyparking.de and the pre-registration offered there. The HeyParking app and the later booking platform are not yet in operation; a separate policy will be published for them when they launch. Nothing is booked and nothing is paid for here.

Controller
ManglerViragHeyland UG (haftungsbeschränkt)
Address
Lena-Christ-Str. 12, 85579 Neubiberg, Germany
Contact
hey@heyparking.de
Last updated
17 September 2026
Legal bases
Art. 6(1)(a) and (f) GDPR
Storage location
Azure Container Apps and PostgreSQL on Microsoft Azure, EU region
Supervisory authority
Bavarian Data Protection Authority (BayLDA), Ansbach
Deletion
Self-service link at the foot of every e-mail we send

1. Controller and contact

The controller is ManglerViragHeyland UG (haftungsbeschränkt), Lena-Christ-Str. 12, 85579 Neubiberg, Germany, registered at the Munich local court under HRB 311836, represented by its managing directors Robin Mangler, Tomas Virag and Maximilian Heyland.

For any privacy question, and for access, rectification, erasure or withdrawal, write to hey@heyparking.de. No data protection officer has been appointed; the thresholds in Art. 37 GDPR and § 38 BDSG are not currently met.

2. What the pre-registration stores

The form on the homepage asks for two required details: your e-mail address and your postcode. Everything else is optional. We do not ask for and do not store a phone number, a name, a street address or payment details.

Exactly the following is stored in a dedicated waiting-list table:

Your e-mail address is treated as the unique key: registering again with the same address updates the existing entry rather than creating a second one.

Registrations made before 16 August 2026 may additionally hold a name, a number of parking spaces and a private-or-commercial flag, left over from an earlier version of the form. Those fields are no longer collected. We will delete them individually on request, without you having to give up your place on the list.

  • e-mail address
  • postcode
  • which side you are on: offering a space, or looking for one
  • only if you are offering and ticked them: parking space or garage, wallbox, solar system
  • whether you asked to be notified at launch
  • the language you registered in
  • the time of registration, of your e-mail confirmation and of the last change

3. What we use this for

The postcode answers the only question this list exists for: where enough supply and demand meet for a launch there to be worth it. We evaluate it in aggregate only — how many offers and how many seekers per postcode.

The parking space, wallbox and solar entries tell us what equipment exists in an area. These too are only ever looked at in aggregate.

We use your e-mail address to confirm your registration and to notify you once, when HeyParking launches in your area. There is no newsletter, no promotional mail, and your address is never passed on for advertising purposes.

There is no profiling and no automated decision-making within the meaning of Art. 22 GDPR. We do not sell data.

4. The confirmation e-mail and the links in it

After you submit the form you receive exactly one e-mail, containing a confirmation link. Only once you click it is your address confirmed and due to be notified at launch. If you do not confirm, we do not write to you again.

The same e-mail carries a second link that deletes your registration and everything stored with it, immediately and without follow-up questions. Our e-mails also carry the RFC 8058 unsubscribe header, which many mail clients render as their own unsubscribe button.

Both links contain a signed token holding your e-mail address, the language, the link's purpose and an expiry date. The confirmation link expires after 24 hours; the deletion link deliberately lasts a year, because it has to still work months later. The tokens are not stored in the database — they are verified cryptographically on each use.

E-mails are sent via Brevo. We use no tracking pixels and no open or click tracking.

5. Server logs, IP address and abuse protection

When you open the site, the hosting provider records the usual connection data: IP address, time of access, the address requested, the volume transferred, and browser and operating-system identifiers. This is technically necessary to deliver the site and keep it secure. The legal basis is Art. 6(1)(f) GDPR.

The registration form additionally limits submissions to five per minute per IP address. The timestamps this needs live only in the server's memory, are never written to the database, and are gone at the next restart at the latest.

The form contains a field invisible to humans that only automated scripts fill in. If it is filled in, we discard the submission entirely and store nothing.

6. Cookies and storage on your device

This site sets exactly one cookie: NEXT_LOCALE. It remembers the language you chose, so the site does not greet you in a different one on your next visit. It holds only a language code such as de or en — no identifier, and nothing by which a person could be recognised.

That cookie is strictly necessary for the service you requested and therefore exempt from consent under § 25(2) no. 2 TDDDG. Which is exactly why you see no cookie banner here: there is nothing we would need to ask you about.

Beyond that, the site puts nothing in your browser — no local storage, no session storage, no advertising or recognition cookies, no embedded social media widgets.

There is no audience measurement or web analytics on this site. We do not know who opened which page, and we do not measure it.

7. Who processes the data on our behalf

We use the following providers as processors under Art. 28 GDPR. Data processing agreements are in place with all of them. The website and the database are operated inside the EU; only the e-mail dispatch leaves it.

The waiting-list table sits in its own database schema, separate from the systems of the later product platform. The website's credentials are technically confined to that one table and cannot read anything else. The database connection is TLS-encrypted throughout.

Within the company, access is limited to the people who look after the pre-registration and the launch communication. We pass data to no other third party unless legally obliged to.

  • Microsoft Azure (Microsoft Ireland Operations Ltd.) — website hosting on Azure Container Apps and the database, both in a data-centre region inside the EU
  • Brevo SAS, France (EU) — delivery of the confirmation and launch e-mails; no third-country transfer, as Brevo processes this data within the EU

8. How long we keep it

Registrations whose e-mail address is not confirmed within 90 days are deleted in full. Without confirmation there is no valid consent, and the entry is of no use to us.

Confirmed registrations are kept until the market launch in your area, and for no more than 24 months from registration. After that we delete them, unless a contractual relationship has arisen.

If you withdraw your consent or use the deletion link, we delete the entry immediately and completely — no residual copy and no suppression list is left behind.

Server log data at the hosting provider is deleted under that provider's retention periods, once it is no longer needed for operation and security.

9. Your rights

You have the following rights. An informal message to hey@heyparking.de is enough for all of them; we ask for proof of identity only where there is reasonable doubt. We reply within one month.

You may withdraw your consent at any time with effect for the future. The lawfulness of processing carried out until then is unaffected.

You also have the right to lodge a complaint with a data protection supervisory authority. Ours is the Bayerisches Landesamt für Datenschutzaufsicht, Promenade 18, 91522 Ansbach, Germany.

  • access to the data held about you (Art. 15 GDPR)
  • rectification of inaccurate data (Art. 16 GDPR)
  • erasure (Art. 17 GDPR) — immediately and by yourself, via the link in any of our e-mails
  • restriction of processing (Art. 18 GDPR)
  • receipt of your data in a portable format (Art. 20 GDPR)
  • objection to processing based on legitimate interests (Art. 21 GDPR)
  • withdrawal of consent already given (Art. 7(3) GDPR)

10. Whether you have to provide the data, and changes to this policy

Providing an e-mail address and postcode is neither legally nor contractually required. Without them, though, we cannot put you on the list or notify you at launch — there is no other consequence.

This policy describes the site as it stands today. As soon as the booking platform goes into operation, or the providers we use change, we will publish an amended version here. The date above states which version is in force.

In short: two required details, one cookie for the language, one confirmation e-mail and a deletion link that works for a year. No audience measurement, no newsletter, no cross-site tracking, no selling of data.