girl texting

ePARK Privacy Policy

We at Electronic Parking AB, org. Sen. No. 556871-1450 ("ePARK", "we", "us" and "our"), we care about your privacy and want you to feel confident about how we handle your personal data when you use our parking services and other related services we offer (the "Services"). In this privacy policy, we inform you about how we process your personal data and what rights you have in relation to our processing of your personal data.

Summary – How do we process your personal data?

  • If you use our Services via ePARK Quick, we process your personal data in order for you to be able to use our Services.
  • If you create an account through our mobile application or through our website, we process your personal data to create and administer your account, provide our Services (in logged-in mode), enable the marking of favourite parking zones, save data related to your parking history, payments and parking permits, enable the processing of your payments, and send and analyze customer satisfaction surveys.
  • If you have consented to receive personalized advertisements from us, we process your personal data in order to display personalized advertisements and offers on other websites and social media that you visit.
  • If you receive direct marketing from us, we process your personal data in order to send you mailings and, if you have consented, also to improve and develop our mailings (through analysis of how you open and what you click on in our mailings).
  • If you visit our website and give your consent, we analyse how our website is used and process data for the website to function and to remember your choices.
  • In order to improve and develop our Services, we process your personal data by analyzing how you use various functions on our website and in our mobile app.
  • If you register for one of our events, we process your personal data to administer your participation in the event.
  • To comply with legal requirements, we process your personal data in some cases in order to comply with the requirements of the Marketing Act and the Accounting Act.
  • In order to communicate with you and respond to questions, complaints, legal claims or the like, we process your personal data to handle customer service matters, communicate with you via our AI assistant, handle unpaid invoices, and handle any claims, complaints and similar matters.
  • We also process your personal data to prevent, detect and investigate misuse of your account and our Services.

You have a number of different rights in relation to our processing of your personal data, including the right to object, the right to complain to the Swedish Authority for Privacy Protection, the right to withdraw your consent, and the right of access. More information about these and other rights can be found at the end of this Privacy Policy.

If you have any questions or would like to exercise any of your rights, please contact us (see contact details below).

Data controller and contact details
Electronic Parking AB, org. No. 556871-1450, is responsible for the processing of your personal data (data controller) as described in this privacy policy.

If you have any questions about this processing, or if you want to exercise any of your rights (see "What rights do you have when we process your personal data" below), you are welcome to contact us by emailing privacy@epark.se or sending a letter to: Electronic Parking AB, Anders Carlssons gata 14, 417 55 Gothenburg.

Where do we collect personal data about you from?
The personal data we process about you is primarily data that you provide to us yourself — for example when you create an account with us, use our app or website, or contact us. In some cases we also collect information about you from the state's personal address register (SPAR), in order to ensure that we have correct address information. We also receive personal data from property owners (both municipal and private) and parking operators, in order to check the parking provided against an active parking permit when required.

What happens if you don't provide us with your personal data?
Some of the personal data you provide to us is necessary for us to be able to provide our Services to you and to fulfil our obligations under the Terms of Use. For example, we cannot provide our parking service if you do not provide your registration number. The specific personal data required for each purpose is set out in the detailed sections below.

Who do we share your personal data with?
Your personal data is primarily processed by us at ePARK. In order to provide our Services, we may need to share your personal data with parking operators, so that they can check that your vehicle is parked correctly and that you have paid for the parking. Parking operators process your personal data on our behalf, as our data processor.

In order to offer some of our Services, we also share your personal data with our partner Mysafety, who helps us provide parking insurance.

Depending on your chosen payment method, we also share information about you with our payment service providers and invoice providers, who are independent data controllers for their own processing of your personal data. If an invoice is not paid on time, we may share personal data with our partner Intrum, who helps us handle debt collection; Intrum is an independent data controller for its processing.

We also share your personal data with our external IT suppliers, so that we can manage our obligations to you and conduct our business. Our IT suppliers process your personal data only on our behalf, as our data processor, and only have access to the data needed to fulfil their obligations to us. Because we share data with our IT suppliers for all purposes, this is not repeated separately under "Recipients of your personal data" in each section below.

We also share your personal data with certain other categories of recipients, described in the relevant sections below.

Do we transfer your personal data outside the EU/EEA?
As a general rule, we and our data processors process your personal data within the EU/EEA. However, when we use the services of Google, LinkedIn, Meta, Intercom, ActiveCampaign (which provides the Postmark service) or Zendesk, your personal data is transferred to the United States. These transfers are based on the European Commission's adequacy decision under Art. 45 GDPR — the EU-US Data Privacy Framework. This means the European Commission has assessed that the US offers an adequate level of protection for businesses certified under the framework. You can look up Google's, LinkedIn's, Meta's, Intercom's, ActiveCampaign's and Zendesk's certifications by searching for their respective companies.

In some cases (specified in the relevant sections below), we use service providers who transfer your personal data outside the EU/EEA to a country without an adequacy decision, or to service providers in the USA that are not certified under the framework. In these cases, transfers are instead based on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). Different modules apply depending on the roles of the sender and recipient — most often Module 3 (Processor to Processor), otherwise Module 1 (Controller to Controller) or Module 2 (Controller to Processor). Where legislation in the recipient country affects how the standard contractual clauses work, we and/or our suppliers take additional protective measures to ensure adequate protection of your personal data.

If you would like more detailed information about transfers of personal data outside the EU/EEA, please contact us.

Detailed description of how we process your personal data
Below, for each purpose, you'll find: what we do, what personal data is processed, the legal basis, the storage period, and who receives the data.

If you use our Services via ePARK Quick
Many of our Services require an account. However, with limited functionality, our Services can also be used without an account, via ePARK Quick. If you use our Services while logged in instead, the processing described under "If you create an account with us" applies instead.

Purpose: To provide our Services to you, manage your purchase of our Services, and process your payments.

Personal data processed: Registration number; geographic location; contact details (name, mobile number, postal address and email address); choice of payment method; payment details; parking data (e.g. date and time of completed parking and choice of parking zone).

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR). The processing is necessary to provide our Services via ePARK Quick to you and thereby fulfil our agreement with you.

Storage period: We process your personal data for the duration of your use of our Services via ePARK Quick, and for 12 months from your last activity.

Recipients:We share your personal data with our payment service providers and with parking operators, who process it as independent data controllers (they will inform you separately about their own processing). Depending on which Service you use, your data may also be shared with Mysafety.

If you create an account with us
If you choose to create an account, we need to process your personal data to create and administer your account and provide you with our Services. If you don't provide the information required in our registration form, we cannot create an account for you.

To create and administer your account
Purpose: Create a login to your account; manage your account; verify your identity via BankID; communicate with you about your account (e.g. password resets).

Personal data processed: Name; personal identity number (where applicable, for BankID identification); user details for your account, including login password (stored encrypted); contact details (name, mobile number, postal address and email address).

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) — necessary to create and administer your account under our Terms of Use. Processing of your social security number is necessary for secure identification via BankID. If you don't provide your name, social security number and contact information, we cannot fulfil our obligations and must deny you an account.

Storage period: For as long as you have an account with us. If your account is inactive for at least 12 months, we stop processing your data and delete your account. If you deregister, your account details are deleted 30 days after deregistration.

To provide our Services (in logged-in mode)
Purpose: Verify whether you are eligible to use our Services (e.g. whether you hold a parking permit within a certain zone); provide our Services to you; manage your purchase of our Services and process payments.

Personal data processed: Login details; registration number; contact information (mobile number, postal address, email address); geographic location; choice of payment method; payment details; employment data (if applicable, when using ePARK Business); parking data (date/time of completed parking, chosen parking zone); address details, vehicle owner details and other information needed to verify your right to access our Services, such as a parking permit.

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) — necessary to provide our Services and fulfil our agreement with you.

Storage period: For the duration of your use of our Services and 12 months from your last activity. If you deregister, your data is stored for 30 days after deregistration.

Recipients: Our payment service providers (independent data controllers, who will inform you separately). Depending on the Service used, data may also be shared with parking operators, property owners and Mysafety, who process it as independent data controllers.

To enable favouriting of parking zones
Purpose: Let you save parking zones as favourites.

Personal data processed: UserID; information about the parking zones you have marked as favourites.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in offering this function.

Storage period: For as long as you have an active account and the favourited zone(s) remain active.

To save information related to your parking history, payments and parking permits
Purpose: Show you information about your parking history, payments made and parking permits.

Personal data processed: Name; registration number; UserID; user account details (including encrypted login password); contact details (mobile number, postal address, email address); geographic location; parking data (date/time of completed parking); payment method, payment history and similar payment details; active parking permits.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in offering this function.

Storage period: For the duration of your account and 12 months from your last activity. If you deregister, data is stored for 30 days after deregistration.

To enable the processing of your payments
Purpose: Provide a quick and easy way for you to manage and complete your payments.

Personal data processed: Name; registration number; personal identity number (for BankID identification, where applicable); employment data (if applicable, via ePARK Business); information about your chosen payment method; payment details; user account details (including encrypted login password); contact details (mobile number, postal address, email address).

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) — necessary to fulfil our agreement with you, including enabling payment for parking. Processing of your social security number is necessary for secure identification via BankID.

Storage period: For the duration of your account and 12 months from your last activity. If you deregister, data is deleted 30 days after deregistration.

Recipients: Our payment service providers and invoice provider, who process your data as independent data controllers (they will inform you separately).

To send and analyze customer satisfaction surveys
Purpose: Send customer satisfaction surveys by email, giving you the opportunity to influence our service offering, and analyze survey results.

Personal data processed: Email address; your survey responses; which parking operator you used the first time you used our Services, and which city/zone that operator is affiliated with.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in sending and analyzing surveys to improve our offering.

Storage period: Until we have analysed the survey results (normally 3–6 months after your response), plus 12 months thereafter.

If you have consented to receive personalized ads from us
Purpose: Promote our Services with advertisements and offers tailored to you, shown on LinkedIn, Google, Facebook and/or Instagram as well as other websites you visit, based on information these parties have about you and information we have collected. We may use Google, LinkedIn and/or Meta marketing services, collecting data via cookies and similar technologies.

Personal data processed: IP address; your geographic location; search results and advertising banners shown to you, based on analysis of how you use our website and information the marketing services already hold about you (e.g. which website referred you to us).

Legal basis: Consent (Art. 6(1)(a) GDPR) — we obtain your consent to provide customized marketing based on collected information. You may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal. You can manage your marketing choices via Google, LinkedIn, Instagram and Facebook's respective ad settings.

Storage period: You will see marketing from us for 90 days from your last visit to our website.

Recipients: If you consent, we share your personal data with Google, LinkedIn and Meta (Facebook and Instagram), who process it both on our behalf (as data processors) and as independent data controllers for their own purposes. They will inform you separately about their own processing — see Google's, LinkedIn's and Meta's (Facebook and Instagram) privacy policies for details, including retention periods.

If you receive direct marketing from us
We collect personal data directly from you and through analysis of how you interact with our marketing mailings.

Purpose (part 1): Send direct marketing (e.g. newsletters) by post, email, text message, social media or similar channels, in cases where you have not opted out of direct marketing when creating your account (soft opt-in).

Personal data processed: Name; postal address; email address; mobile number; zone.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in sending direct marketing to those who have not declined it (soft opt-in).

Purpose (part 2): Improve and develop our mailings (including newsletters) by analyzing how you open and interact with them, using cookies and similar technologies.

Personal data processed: IP address; email address; information about how you open our mailings and what you click on.

Legal basis: Consent (Art. 6(1)(a) GDPR). You may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Storage period: Until you unsubscribe or otherwise ask us to stop sending direct marketing. If you opt out, your data is kept in our deregistration register until further notice.

Recipients: MailChimp and InTime, who help us send email and SMS marketing and act as our data processors. Through MailChimp, your data is transferred to the United States; as MailChimp is not certified under the EU-US Data Privacy Framework, this transfer is based on the EU Commission's Standard Contractual Clauses (Module 2: controller to processor).

If you visit our website
If you agree, we analyse how our website is used. We also process personal data so the website functions and remembers your choices. Data is collected from your device (mobile, computer or tablet) when you visit; Google also uses information it already holds about you to carry out this analysis. We use cookies and similar technologies to collect this data — see our cookie information page for details.

Analyse how our website is used
Purpose: Analyse website usage via cookies, to improve functionality and adapt the website to visitors, using Google Analytics (which assigns a random ID to distinguish your device and identify usage patterns).

Personal data processed: Your IP address (processed only on an aggregated level — we cannot link it to you individually); information about how you use the website (clicks, time spent); which area of the country you're browsing from; number of visits (for total visitor counts); device/browser information (e.g. screen resolution); other information Google holds about you, such as the referring website or channel.

Legal basis: Consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time; this does not affect the lawfulness of prior processing. You can avoid Google Analytics by installing a browser opt-out extension, or by adjusting your browser's cookie settings.

Storage period: 24 months after your website visit.

Recipients: Google, who provides Google Analytics and processes your data both as our data processor and as an independent data controller, informing you separately about its own processing. See Google's privacy policy for details and retention periods.

To make the website work and remember your choices
Purpose: Use cookies and similar technologies to ensure the website functions properly and securely, and to remember your choices (e.g. your consent). We and our suppliers do not manually track your usage — this happens automatically via technical functions.

Personal data processed: Information about how you use the website; information about your choices.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in providing a well-functioning, secure website.

Storage period: 90 days.

Recipients: Service providers used on the website (e.g. our consent management tool), listed as "necessary" in our cookie policy. These act as our data processors.

To improve and develop our Services
We use a range of features across our website and app. To improve and develop these, we analyse how you use them.

Purpose: Analyze how you use our Services and features on the website and mobile app, in order to improve and develop them, using cookies or similar technologies.

Personal data processed: Your IP address (aggregated level only); times you have used our Services; extent of usage (e.g. loading frequency); the website you were linked from; pages you visit, links you use and other content viewed; information about your device and other technical information provided by your browser.

Legal basis: Consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing. You can decline non-essential cookies via your browser settings.

Storage period: Up to 24 months.

Recipients: If you consent, Google, who provides the Firebase tool used to analyse Service usage, acting both as our data processor and as an independent data controller (informing you separately). See Google's privacy policy for details and retention periods.

If you register for one of our events
Purpose: Send you event invitations and administer your participation.

Personal data processed: Name; email address; phone number.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in inviting you to events and administering participation.

Storage period: 24 months after you attended the event.

To comply with legal requirements
We must comply with certain legal requirements, such as the Marketing Act's prohibition on emailing anyone who has objected, and the Accounting Act's requirement to retain accounting records. We receive this data directly from you.

To comply with requirements of the Marketing Act
Purpose: If you've indicated you don't want direct marketing from us, we keep a record in our unsubscribe register to ensure we don't market to you.

Personal data processed: Email address.

Legal basis: Legal obligation (Art. 6(1)(c) GDPR) — required under the Marketing Act (SFS 2008:486), which prohibits marketing to those who have objected. You must provide this data, or we cannot guarantee you won't receive further marketing.

Storage period: Until further notice, in our "deregistration register."

To comply with the requirements of the Accounting Act
Purpose: Register, account for and archive payments and other transactions between us and you, in compliance with accounting legislation.

Personal data processed: Name, payment history and other information constituting accounting documentation.

Legal basis: Legal obligation (Art. 6(1)(c) GDPR) — required under the Accounting Act (SFS 1999:1078). You must provide this data, or we cannot comply with our legal obligations.

Storage period: 7–8 years, in accordance with the Accounting Act — up to and including the seventh year after the end of the calendar year to which the data relates.

To communicate with you and respond to questions, complaints, legal claims, or the like
to handle customer service issues

Purpose: Communicate with you; respond to customer service questions; identify you when you contact customer service; investigate complaints and support cases (including technical support).

Personal data processed: Name; registration number; geographic location; IP address; contact details (address, email, mobile number); your correspondence with customer service; information about your activity when using our Services (e.g. charging frequency, or parking service usage data).

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in communicating with you and handling customer service matters. You must provide this data, or we cannot help you with your case.

A related purpose — ensuring high quality in customer service, training staff, and verifying what was said in a call — involves processing audio recordings of phone calls, based on your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time (without affecting the lawfulness of prior processing).

Storage period: For the duration of an ongoing customer service case, plus 24 months thereafter.

Recipients: Zendesk, who help us handle customer service requests and act as our data processor.

To communicate with you via our AI assistant
Purpose: Communicate with you and answer questions via our chat function.

Personal data processed: Information needed to assist with your case/questions (e.g. registration number, payment method, email address, address information); information you provide via our AI assistant.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in offering prompt assistance for common customer questions.

Storage period: For the duration of your ongoing conversation with our AI assistant.

Recipients: Intercom, provider of the AI assistant, acting as our data processor.

To handle unpaid invoices
Purpose: Check for unpaid invoices; send payment reminders; transfer data to debt collection agencies if a collection process is initiated.

Personal data processed: Name; personal identity number (for BankID identification, where applicable); registration number; chosen payment method; payment details; contact details (mobile number, postal address, email address).

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in handling unpaid invoices. Processing of your social security number is necessary for secure identification via BankID.

Storage period: Until the invoice is paid or the case is handed over to Intrum for further processing.

Recipients: Intrum, who help with debt collection management if this becomes relevant. Intrum is an independent data controller for its own processing.

To handle any claims, complaints and similar matters
Purpose (claims): Handle any claims made against us.

Personal data processed: Name; registration number; contact details (address, email, mobile number); information from communications with you regarding your claim (e.g. time of use of the relevant service).

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in being able to defend ourselves against a possible legal claim.

Purpose (complaints): Handle complaints or other similar issues.

Personal data processed: Name; registration number; contact details (address, email, mobile number); information about your use of our Services, app or website; information from communications regarding your claim.

Legal basis: Legal obligation (Art. 6(1)(c) GDPR) — compliance with mandatory consumer law and other mandatory rules.

Storage period: For as long as the case is ongoing, plus 24 months thereafter.

To prevent, detect and investigate misuse of your account and our Services
Purpose: Control your account and activities and your use of our Services; investigate suspicious activity or Terms of Use violations; identify accounts with previously documented abuse or fraud; provide relevant authorities with information in case of suspected crime.

Personal data processed: Name; UserID; login details; activities associated with your account; information about your use of our Services, app or website.

Legal basis: Balancing of interests (Art. 6(1)(f) GDPR) — our legitimate interest in preventing and investigating misuse of your account and our Services, and in establishing legal claims.

Storage period: For the duration of your account and 12 months from your last activity. If you deregister, data is deleted 30 days after deregistration.

How have we carried out our balancing of interests when the legal basis is our legitimate interest (Art. 6(1)(f) GDPR)?
For certain purposes, we process your personal data based on a balancing of interests. We have assessed that our legitimate interest in the processing outweighs your interest and fundamental rights in not having your data processed. Our specific legitimate interest for each purpose is stated under "Legal basis" in the relevant section above. Contact us if you'd like more information about how we made these assessments.

Consent
In certain situations, we process your personal data based on your consent — these situations are described above. You can withdraw your consent at any time by contacting us. If you withdraw all or part of your consent, we will stop processing your data for that purpose. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

What rights do you have when we process your personal data?
In accordance with the GDPR, you have the following rights. Contact us (see details above) with any questions or to exercise your rights. The Swedish Authority for Privacy Protection also provides detailed information on these rights and their exceptions.

Right to complain (Art. 77 GDPR) — You may lodge a complaint with the competent supervisory authority if you believe our processing infringes the GDPR. In Sweden, this is the Swedish Authority for Privacy Protection.

Right to withdraw consent (Art. 7(3) GDPR) — You may withdraw your consent at any time by contacting us.

Right of access / "register extract" (Art. 15 GDPR) — You may request confirmation of whether we process your personal data, and if so, receive a copy of that data along with information about the processing (purposes, retention periods, etc.).

Right to object (Art. 21 GDPR) — You may object at any time to processing for direct marketing purposes (including profiling), and to processing based on a balancing of interests.

Right to rectification (Art. 16 GDPR) — You may have inaccurate personal data corrected, or incomplete data completed.

Right to erasure / "right to be forgotten" (Art. 17 GDPR) — Under certain conditions, you may have your personal data deleted — for example if you withdraw consent and there is no other legal basis for processing, or if the data is no longer necessary for the purpose it was collected for.

Right to restriction of processing (Art. 18 GDPR) — Under certain conditions, you may demand that we restrict processing — for example if you contest the accuracy of the data, or if the processing is unlawful and you oppose deletion but request restricted use instead.

Right to data portability (Art. 20 GDPR) — If we process your data based on your consent or to fulfil an agreement, you have the right to receive the data concerning you, in a structured, commonly used, machine-readable format, and to transfer it to another data controller where technically feasible.

This privacy policy was established by ePARK / Electronic Parking AB on April 1, 2026.

News

News

Malmö City signs agreement with ePARK Group for digital short-term and residential parking

Read more

News

Nääs Castle implements digital parking platform

Read more

News

ePARK wins procurement in Eskilstuna municipality – new digital parking permit system

Read more

News

Meet Hugo – our new Senior App Developer

Read more

News

Skansen digitizes staff parking with ePARK Group

Read more

Handle parking app
Use our mobile parking app today
Download now