Legal

Privacy Policy

Last updated
August 12, 2026
Version
v1.0

This policy explains what personal information AuthenCore AI Parking collects, how location, vehicle, and payment data are handled, who it is shared with, and your rights under PIPEDA.

1. What we collect

Account details (name, email, mobile number), registered vehicle details, device and session diagnostics, location signals, and payment metadata.

We collect only what is needed to open, confirm, and settle parking sessions and to support and secure the service.

2. How location data is used

Location signals are used to confirm entry to and exit from geofenced parking zones. Confirmation requires multiple readings; single readings are never acted on.

Location history is not sold, and is not used for advertising or for profiling outside parking session determination.

3. Vehicle and licence plate data

Plate, province or territory, and vehicle description are stored to link a session to the correct vehicle identity.

Plates are normalized for matching and are visible to the operator of a facility where your vehicle has parked.

4. Payment data and tokenization

Card details are captured by our payment processor and stored as tokens. We retain only the brand, last four digits, and expiry.

Full card numbers and security codes never reach AuthenCore systems and are never stored by us.

5. Data shared with parking operators

Operators can see sessions, vehicles, and payment outcomes for their own facilities only, together with the minimum customer detail needed to resolve a session.

Operator changes to sessions, rates, or payments are recorded in an audit log with the actor and a reason.

6. Data shared with municipalities

Municipal data sharing is off by default, is enabled per zone, and is field-level opt-in.

Where enabled, only the fields explicitly selected for that zone are transmitted, and each transmission is logged.

7. Retention and anonymization

Personal information is retained only as long as needed for the purposes described here, or as required by law.

On account deletion, identifying fields are anonymized while financial records are retained for the statutory retention period.

8. Your rights under PIPEDA

You may access, correct, or request deletion of your personal information, and withdraw consent, subject to legal and contractual limits.

You may also complain to the Office of the Privacy Commissioner of Canada if you are not satisfied with our response.

9. Cookies

We use strictly necessary cookies for authentication and session security.

Analytics or preference cookies, if introduced, will be described here and made optional.

10. Security

Data is encrypted in transit and at rest, access is role-scoped, and privileged actions are logged.

We review access controls regularly and restrict staff access to what their role requires.

11. Contact and our Privacy Officer

Privacy requests and questions can be sent to privacy@authencore.ai, attention Privacy Officer.

AuthenCore AI, Ontario, Canada.