Privacy policy
- Version
- 1.1
- Last updated
- 6 August 2026
Notice Draft pending legal review. This document is published for transparency and will be reviewed by counsel before it is relied upon.
This policy explains what ValoPal does with information about guests, valet staff and visitors to this website.
1.Who we are and our role
ValoPal provides digital valet ticketing, payment and record-keeping software to parking operators and to the hotels, restaurants and venues they serve. We are reachable at privacy@valopal.ai.
For information about guests and staff, the parking operator is the controller and ValoPal is the processor. The operator decides which stands run ValoPal, which payment methods are offered, what notice is posted at the stand, and how long records are kept within the limits we support. We process that information only to run the service on the operator's instructions.
For this website — valopal.ai — ValoPal is the controller of the limited log and analytics data described below.
2.What we collect and why, by person
Guests
- Name, if the guest or the attendant provides one. Used to match a guest to a ticket at pick-up.
- Mobile number, if the guest chooses to provide one. Used only to send status texts about their own vehicle and to issue an Apple Wallet pass. It is optional and the pass works without it.
- Vehicle description — make, model, colour. Used to identify the vehicle on the rack.
- Licence plate. Used to locate a ticket when a guest loses access to their pass.
- Vehicle photographs taken at drop-off and, where the operator enables it, at pick-up. Used to record the condition of the vehicle at hand-off.
- Payment status and method — paid by card, or recorded at the booth. Used to release the vehicle correctly and to reconcile a shift.
- Ticket and scan timestamps: when the ticket was created, when the pass, key tag or spot was scanned, when the car was requested and when it was released.
We do not collect card numbers. Card payments are processed by Stripe on Stripe's own systems, and we receive only a status and a reference.
Attendants and managers
- Name and staff identifier, so an action can be attributed to a person.
- Device identifier, so a shift can be bound to the device it was worked on.
- PIN, stored only as a cryptographic hash and used to sign in for a shift.
- Action timestamps: sign-in and sign-out, tickets created, photos taken, overrides applied and verifications completed.
Website visitors
- Standard server log data: IP address, user agent, requested page, timestamp and referrer, retained for security and abuse prevention.
- Aggregate, cookieless analytics: page views, referrer, country, device type and clicks on our main calls to action. No cross-site tracking and no advertising profiles.
- If you submit the pilot request form: your name, email, organisation and what you tell us about your stand, plus a hashed form of your IP address used for rate limiting.
3.How we use it
- To create and maintain the ticket record for a vehicle, from drop-off to release.
- To show a guest the live status of their vehicle and, where a number was given, to text them about it.
- To take payment through Stripe, or to record a payment taken at the booth for a manager to verify.
- To record vehicle condition at hand-off and to make photographs available if a claim is raised.
- To let a manager verify exceptions and audit who did what, when and on which device.
- To produce operational reporting for the operator — arrival patterns, stay length, request-to-ready time, payment mix and throughput.
- To keep the service secure, prevent abuse, and meet our legal obligations.
- To respond to enquiries submitted through this website.
5.What we never do
- We do not sell personal information.
- We do not share mobile numbers or SMS consent with third parties for marketing purposes. Numbers are used only to text a guest about their own vehicle.
- We do not send guests marketing messages.
- We do not use vehicle photographs to build advertising profiles.
- We do not run third-party advertising or cross-site tracking on this website.
6.Retention
- Guest personal information — name, mobile number, plate — is deleted after the ticket closes plus the dispute window the operator configures.
- Vehicle photographs and AI findings follow the same schedule as the ticket they belong to.
- Non-identifying operational events — timestamps, durations, counts, payment method without the payer — are retained so reporting stays intact after personal data is removed.
- Staff records are retained for the duration of the operator's account and a limited period afterwards for audit purposes.
- Website enquiry submissions — pilot requests sent through this site — are deleted automatically 24 months after they are received.
Where an operator instructs a shorter or longer window within the range we support, the operator's setting governs.
7.Security
- Data is encrypted in transit and at rest.
- Guest passes are short-lived signed links scoped to a single ticket; they cannot reach staff functions or another operator's data.
- Staff sign in with a PIN bound to one device for one shift, and every action is attributed.
- The audit log is append-only. Corrections are new entries with a reason, not edits over the top of the old value.
- No card data is stored on our systems.
- Access to production data by our team is limited, logged and used only for support and incident response.
8.Your rights and how to exercise them
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and not to be discriminated against for exercising those rights.
If you are a guest or a staff member, the operator is the controller, so the fastest route is to contact the property or operator. You may also write to privacy@valopal.ai and we will either action the request or pass it to the operator and tell you that we did. We will respond within the time your law requires, and we will ask for enough information to confirm who you are before we act on a request.
9.Children's data
ValoPal is a business service used by adults handing over a vehicle. We do not knowingly collect personal information from children under 13. If you believe a child's information has reached us, write to privacy@valopal.ai and we will delete it.
10.International transfers
The valet service and the subprocessors that run it are operated in the United States. Two website-only providers sit elsewhere: our analytics provider is hosted in the European Union, and web fonts are delivered by Google. If you use ValoPal from outside these regions, your information will be transferred to and processed there. Where a transfer requires a safeguard, we rely on the standard contractual clauses or another lawful transfer mechanism in our agreements with subprocessors.
11.California privacy rights (CCPA/CPRA)
This section applies to California residents. In most cases ValoPal acts as a service provider to the parking operator, and the operator is the business.
Categories of personal information collected
- Identifiers — name, mobile number, licence plate, email for website enquiries, IP address.
- Commercial information — payment status and method, ticket history at a property.
- Visual information — photographs of a vehicle taken at hand-off.
- Internet or network activity — pages viewed on this website, scan events within the service.
- Professional or employment information — for attendants and managers, staff identifier and shift activity.
Purposes
To operate the valet workflow, take or record payment, record vehicle condition, verify exceptions, produce operational reporting for the operator, keep the service secure, and respond to business enquiries.
Categories of recipients
The parking operator, and the service providers listed in section 4 — payment processor, SMS provider, cloud hosting and object storage, Wallet pass provider, AI vision provider, website analytics provider and web font provider.
Retention
As described in section 6.
Sale and sharing
We do not sell personal information and we do not share personal information for cross-context behavioural advertising, as those terms are defined by the CCPA as amended by the CPRA. We have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of consumers under 16.
Sensitive personal information
We do not use or disclose sensitive personal information for purposes beyond those permitted for a service provider performing the service.
Submitting a request and appealing a denial
Email privacy@valopal.ai with the subject line "California privacy request" and tell us what you want and which property or stand you visited. An authorised agent may submit on your behalf with written permission. If we deny a request, our response will explain why; you may appeal by replying to that response with the subject line "Appeal", and a different reviewer will respond in writing.
12.Changes to this policy
When we change this policy we update the version number and date at the top of this page. Material changes affecting operators are notified to the operator's account contact. Because consent records point at a specific version, superseded versions remain identifiable by their version number.
13.Contact
Privacy questions: privacy@valopal.ai. Security reports: security@valopal.ai. Anything else: hello@valopal.ai.