Privacy Policy
Last updated: August 14, 2026 Effective date: June 18, 2026
1. Introduction
This Privacy Policy explains how Backlot Labs LLC, a Florida limited liability company doing business as Parkboxd ("Parkboxd," "we," "us," or "our"), collects, uses, shares, and protects information when you use the Parkboxd mobile and web application (the "Service"). Parkboxd is operated from the United States.
By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
Contact: contact@parkboxd.com
2. Information we collect
2.1 Information you provide
| Data | Examples | Why |
|---|---|---|
| Account identity | Email and authentication identifiers handled by Clerk | Create and secure your account |
| Date of birth | Your birth date, provided once at sign-up | Age verification (13+ and Florida minor gating). Retained with your account; not shown on your profile and not returned in raw form to the app |
| Profile | Username (handle), display name, bio, avatar, banner image | Build your public profile |
| Trip logs & activities | Visit dates, titles, written reviews, star ratings, parks/rides/food, notes, tags | Core journaling feature |
| Photos | Images you attach to trip logs, activities, or your profile. Location metadata (EXIF/GPS) embedded in a photo is stripped when the image is uploaded and is not stored. | Display your content |
| Social actions | Follows, likes, saves, comments | Power the social feed |
| Reports & enforcement | Content you flag and the reason given; enforcement records on your account (warnings, strikes, suspension status) | Moderation and safety |
| Communications | Messages you send us (e.g., support, privacy requests) | Respond to you |
2.2 Information collected automatically
| Data | Source | Why |
|---|---|---|
| Push notification token | Expo, when you enable notifications | Send you notifications |
| Device/platform | iOS, Android, or web indicator tied to your push token | Deliver platform-appropriate notifications |
| Approximate location | Device location, only if you grant permission | Find nearby parks / relevant content |
| Usage & technical data | Standard app/backend logs (e.g., timestamps, error logs, coarse device/app info) | Operate, secure, and debug the Service |
| Product analytics events | First-party, account-linked usage events recorded by our own backend when you are signed in (e.g., screen views, feature usage, session start/end, session duration, device model, OS/app version, coarse locale/time zone) | Understand how the Service is used and improve it |
| Pre-sign-in analytics events | First-party, anonymous usage events recorded before you create an account or sign in, identified only by a random, resettable on-device identifier and session identifier (e.g., app open, screen views, and signup started/completed/abandoned, plus coarse screen-route patterns). Contains no name, email, or IP address; your IP is used only transiently for rate limiting | Understand pre-signup usage and improve onboarding |
| Campaign attribution | The first utm_source/medium/campaign/content/term parameters and referring site's hostname seen at your first app open, stored on-device and attached to the anonymous pre-sign-in events above; if you create an account, stored once on your account |
Understand which channels bring people to Parkboxd |
| Platform performance & reach telemetry | Anonymous, per-install metrics sent to Expo (EAS Insights/Observe): app installs, store/app versions, embedded-vs-OTA update adoption, and cold/warm launch and render timings. Tagged only with an anonymous per-install identifier generated by Expo (no account ID, email, or name) | Measure update reach and app performance |
| Device locale & units | Your device's language/region, measurement system (metric/imperial), and 12/24-hour clock preference, read from the operating system | Show dates, distances, and times in your local format |
| Crash & error diagnostics | Crash reports and performance data via Sentry, including device model, OS/app version, error stack traces, and an SDK-generated identifier | Diagnose crashes and stabilize the Service |
Location is optional. The app requests location permission only to surface nearby or relevant parks and, if you choose, to log a park day while you're there. You can decline or revoke it in your device settings at any time without losing core functionality. Depending on your device and the permission you grant, location may be precise at the moment of use; we use it transiently to find nearby parks and to detect which park you're in, and we do not build a location history.
Background location (Auto check-in). By default we do not collect background location. If, and only if, you turn on Auto check-in in Settings (which prompts for the "Always" permission), the app uses your device location in the background to detect when you arrive at a supported park; the park-day draft is then started the next time you open the app (arrival is only detected, not acted on, in the background). We use park geofence entry events for this purpose only; we do not continuously track or store your background location, and turning Auto check-in off (or revoking the permission) stops it immediately.
2.3 Authentication data (Clerk)
Sign-up and sign-in are handled by Clerk. We store a Clerk user identifier to link your account to your activity. Your password and the primary handling of your login credentials are managed by Clerk under Clerk's privacy policy.
2.4 Information we do not collect
We do not require or intentionally request payment-card information, government identifiers, biometric identifiers, facial-recognition data, or special-category/sensitive personal information, and we do not perform facial recognition or build background-location profiles. (We do collect your date of birth once at sign-up for age verification, as described in Section 2.1: a birth date is not a government identifier, and we retain it with your account rather than exclude it here.) Because trip logs, photos, and notes are free-form, your User Content could contain sensitive information (for example, accessibility, dietary, health, or religious details, or images of identifiable people), so please share only what you are comfortable making visible. We do not use that content to infer sensitive characteristics about you, and we do not sell your personal information or use it for cross-context behavioral advertising.
3. Cookies and tracking technologies
Parkboxd is not an advertising-driven service and does not use third-party advertising cookies or cross-site tracking.
- Mobile app: We use on-device storage (for example, Expo Secure Store) to keep you signed in and remember preferences. This is essential to operating the app.
- Web: If you use the web version, we use only essential cookies/local storage needed for authentication and core functionality.
We use first-party product analytics, platform performance/reach telemetry (Expo/EAS), and crash/error reporting (Sentry) to understand how the Service is used, measure app performance, and diagnose problems. None of these is used for advertising or cross-site tracking:
- First-party analytics. When you are signed in, our own backend records usage events (for example, screen views, feature usage, and session start/end) linked to your account. We use this internally only, to understand product usage and improve the Service. We do not sell it, share it for advertising, or use it to make automated decisions that have legal or similarly significant effects about you. The raw event and session records are kept for a limited window (about 90 days), after which only aggregated, non-identifying metrics remain; all of your analytics records are deleted when you delete your account.
- Pre-sign-in analytics. Before you create an account or sign in, the app
records a small set of anonymous usage events (app open, screen views,
and signup started/completed/abandoned) identified only by a random,
resettable device and session identifier stored on-device, with no cookies,
name, email, or IP address recorded. We also capture first-touch campaign
attribution (the
utm_parameters and referring site's hostname present at your first app open) and attach it to these anonymous events; if you go on to create an account, that attribution is stored once on your account so we can tell which channels bring people to Parkboxd. Raw anonymous events are deleted after about 90 days; only aggregates are retained. - Platform telemetry (Expo/EAS). The app reports anonymous performance and reach metrics to Expo (our build/update platform) via its EAS Insights and Observe layers, for example, app installs, app/store versions, embedded-vs-OTA update adoption, and launch/render timings. These are tagged only with an anonymous, per-install identifier generated by Expo; they are not linked to your account, and they carry no email, name, precise location, or diary content.
- Sentry records crash reports and performance diagnostics (for example, device model, OS/app version, error stack traces, and an SDK-generated identifier). Crash reports are intended to be technical and are not designed to include your trip content; limited technical data such as IP address may be processed transiently to deliver and debug a report.
Our marketing site (parkboxd.com) separately uses Cloudflare Web Analytics, a cookieless, non-tracking page-view counter; it does not use a device identifier and is not linked to your Parkboxd account.
If we add or change analytics or diagnostics providers, we will update this Policy and, where required, request your consent.
4. How we use information
We use your information to:
- Provide and operate the Service (display your profile, trip logs, and feeds);
- Authenticate you and keep your account secure;
- Calculate derived, aggregated metrics such as crowd levels, trending parks, and wait-time context (these use catalog and aggregate data, not your private diary content);
- Send push notifications you have enabled;
- Respond to your communications and support requests;
- Enforce our Terms of Service, investigate abuse, and moderate reported content;
- Diagnose problems, prevent fraud, and improve the Service;
- Comply with legal obligations.
Legal bases (where applicable, e.g., for EU/UK users): we process information based on your consent (e.g., notifications, location), to perform our contract with you (providing the Service), to comply with a legal obligation, and for our legitimate interests (security, abuse prevention, and product improvement).
Analytics, profiling, and automated decisions. We keep account-linked usage analytics (see Sections 2.2 and 3), which we use internally only to understand product usage and improve the Service. We do not use your personal information for advertising profiling or cross-context behavioral advertising, and we do not use it for automated decision-making that produces legal or similarly significant effects about you. Our internal analytics may include derived, product-focused signals (for example, an internal engagement or churn-risk indicator used to prioritize product work); these are used to operate and improve the Service and to inform support, not to make decisions with legal or similarly significant effects about you.
5. How information is shared
We share information only as described here. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5.1 With other users
Your public content (username, profile, public trip logs, activities, comments, likes, and follow relationships) is visible to other users of the Service. Content you mark private is not shown to other users in the app, but it is not encrypted from us: we and our service providers can access it to operate, secure, support, and moderate the Service and to comply with law. Uploaded images are served from a content-delivery URL keyed to each file, so anyone who obtains that URL may be able to view the image regardless of the trip log's visibility setting. Choose your visibility, and what you upload, accordingly; public content can be viewed and re-shared by others. When an image is deleted, or hidden or removed through moderation, it stops being served from its URL shortly afterward (brief delivery-network caching may apply).
5.2 With service providers (subprocessors)
We rely on these providers to run the Service. Where they process data on our behalf, they do so as processors under written contracts/data-processing terms. App stores (Apple, Google) generally act as independent controllers for the data they collect about your download and use, under their own policies:
| Provider | Purpose | Data involved |
|---|---|---|
| Clerk | Authentication & account management | Identity, login credentials |
| Convex | Backend, database, hosting | All app data |
| Cloudflare R2 | Image/object storage | Photos you upload |
| Expo (EAS) | Push notifications, app updates, and anonymous performance/reach telemetry | Push token, device platform; anonymous per-install performance/reach metrics (EAS Insights/Observe) |
| FreeScout | Support ticketing (self-hosted at support.parkboxd.com) | When you contact support: your message, your account email, app version, OTA update ID, and platform/OS |
| Resend | Email delivery (account and product email, and marketing email if you opt in) | Your email address, your name if you provided one, email engagement events (delivery, opens, bounces, spam complaints), and transactional email logs |
| Sentry | Crash & error reporting | Crash/diagnostic data, device/app info, SDK-generated identifier, transient IP |
| Apple App Store / Google Play | App distribution | Per their own policies |
Push-notification delivery networks. To deliver push notifications, the
relevant push token or subscription endpoint and the notification content are
routed through the platform push services for your device: Apple Push
Notification service (APNs) for iOS, Google Firebase Cloud Messaging (FCM,
fcm.googleapis.com) for Android, and your browser's web-push service
(for example, Google FCM or Mozilla's autopush at
updates.push.services.mozilla.com) for web. These services receive your push
token/endpoint (a device identifier) and the notification payload in order to
deliver the message.
We also pull non-personal park, attraction, wait-time, and weather data from
third-party sources (for example, themeparks.wiki, queue-times.com, and
Open-Meteo (api.open-meteo.com) for weather). These requests use park
coordinates, not your device location, and we do not send your personal
information to those data sources.
5.3 Legal and safety
We may disclose information if required by law, subpoena, or legal process, or when we believe in good faith that disclosure is necessary to protect our rights, enforce our Terms, ensure the safety of users or the public, or investigate fraud or security issues.
5.4 Business transfers
If Parkboxd is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information, and the successor will be bound by this Policy or provide equivalent protection.
6. Data retention
We retain your information only as long as needed for the purposes in this Policy. Typical periods:
| Data | Retention |
|---|---|
| Account & content (active account) | Kept while your account is active |
| Account & content after deletion | Removed or de-identified within 30 days of your deletion request. Exception: photos you contributed to the shared catalog (e.g., approved cover suggestions) may remain in the catalog under the license in the Terms of Service §4.3. Exception: content and related account information preserved for child-safety reporting is kept for the period described in the row below, even after deletion. |
| Record of account deletion | When you delete your account, we keep a minimal permanent record of the deletion itself: an internal account identifier and the date of deletion, and nothing else — no name, no email address, no content, and no activity. We keep this record indefinitely, including a copy in our backup storage, so that if we ever restore data from a backup, your deletion is re-applied instead of your account reappearing. The record cannot be used to reconstruct your account or identify you outside our systems. |
| Uploaded images never attached to content | Automatically purged within ~24 hours |
| Email records held by our email provider | When you delete your account, we delete your contact record at our email provider. Delivery logs for messages already sent (including the recipient address and engagement events) stay with the provider until they expire under its own retention settings — we cannot delete individual log entries. If an address previously hard-bounced or reported a message as spam, it may stay on the provider's suppression list so we do not email it again. |
| Push notification tokens | Removed when you disable notifications, sign out, or the token becomes invalid |
| Approximate location | Used transiently to find nearby parks; not stored as a history |
| Technical/usage logs | Retained for a limited period (typically up to 90 days) for security and debugging |
| Moderation reports, enforcement records & admin/audit logs | Retained longer (typically up to 2 years) for safety and accountability |
| Content reported for child safety (and related account information) | Preserved for 1 year from the report or submission, as 18 U.S.C. §2258A(h) requires, and longer where NCMEC, law enforcement, or other applicable law requires or permits. Preservation continues after the content is removed and after the account is deleted; the material is stored securely, accessed only as needed to comply with the law, and used for no other purpose. |
| Backups | Routine database backups expire on rolling cycles: daily snapshots within 30 days, monthly archival snapshots within 12 months. Media you delete (or that is removed from the Service) is purged from media backups within ~30 days of removal. |
We may retain limited information beyond these periods where required for legal compliance, to resolve disputes, or to prevent fraud or abuse (a "legal hold").
7. De-identified and aggregated data
We may create aggregated or de-identified data (such as crowd levels and trending metrics) that does not identify you. We may use and share this data for any lawful purpose, and we will not attempt to re-identify it except to test our de-identification processes.
8. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccurate information (much of which you can edit in-app);
- Delete your account and associated data (available in-app);
- Object to or restrict certain processing;
- Port your data to another service;
- Withdraw consent for notifications or location at any time.
How to make a request. Email contact@parkboxd.com. We will verify your request by confirming control of your account (for example, the email associated with it) and respond within the time required by applicable law. An authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising these rights. If we deny a request, you may ask us to reconsider by replying to our response.
9. California privacy disclosures (CCPA/CPRA)
If you are a California resident, this section supplements the rest of this Policy. If we are not a "business" covered by the CCPA/CPRA, we offer these rights voluntarily where feasible. The categories below are illustrative; the labels track the CCPA's statutory categories and the examples show how they map to Parkboxd. In the past 12 months we have collected the following categories of personal information:
| CCPA category | Collected? | Examples | Sources | Business purpose | Disclosed to |
|---|---|---|---|---|---|
| Identifiers | Yes | Username, email, account ID, push token, date of birth | You, Clerk | Account, auth, notifications, age verification | Service providers |
| Customer records | Yes | Profile details, photos | You | Provide the Service | Service providers; other users (public content) |
| Internet/network activity | Yes | App usage and error logs; account-linked first-party usage analytics; anonymous platform performance/reach telemetry; crash diagnostics | Automatic (our backend); Expo/EAS, Sentry | Security, debugging, product improvement | Service providers |
| Geolocation (approximate) | Only with permission | Coarse location | Your device | Show nearby parks | Service providers |
| Visual & similar information | Yes | Photos you upload | You | Core features | Service providers; other users (public content) |
| Commercial/usage information | Yes | Trip logs, reviews, comments, ratings | You | Core features | Service providers; other users (public content) |
Sensitive personal information: We do not collect or process sensitive personal information as defined by the CPRA, and we do not use any information for purposes that require a "limit the use of my sensitive personal information" option.
Sale/sharing: We do not sell or share (for cross-context behavioral advertising) personal information, and we have not done so in the past 12 months.
California residents have the right to know, delete, correct, and to be free from discrimination for exercising these rights. Submit a request via contact@parkboxd.com.
10. Do Not Track and Global Privacy Control
Because we do not track users across third-party websites for advertising, we do not respond differently to "Do Not Track" browser signals. Where required by law, we will treat a recognized Global Privacy Control (GPC) signal as a valid opt-out request to the extent it applies.
11. Children's privacy
The Service is intended for users 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact contact@parkboxd.com and we will delete it. This complies with the U.S. Children's Online Privacy Protection Act (COPPA).
12. Security and breach notification
We use reasonable technical and organizational measures to protect your information, including authentication via Clerk, access controls, rate limiting, and reputable infrastructure providers. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. Help protect your account by keeping your login credentials confidential.
If we become aware of a data breach affecting your personal information, we will notify you and any relevant authorities as required by applicable law.
13. International users and cross-border data
Theme-park fans come from all over the world, and Parkboxd welcomes users globally. Parkboxd is operated from the United States, and your information will be processed and stored in the United States and in other regions used by our service providers. Data-protection laws in those locations may differ from those where you live. Where we transfer personal information across borders, we rely on appropriate safeguards as described below.
13.1 Consent to transfer
If you access the Service from outside the United States, you understand that your information will be transferred to, processed, and stored in the United States and other countries. Except where stronger local-law rights apply (see 13.2), you consent to that transfer.
13.2 EEA, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, the following applies to you:
- Controller. Backlot Labs LLC (Parkboxd) is the controller of your personal information. Contact: contact@parkboxd.com.
- Legal bases. We process your information on the bases described in Section 4: your consent (e.g., notifications, location, and analytics where required), performance of our contract with you, compliance with a legal obligation, and our legitimate interests (security, abuse prevention, and product improvement).
- Your rights. You may request access, rectification, erasure, restriction, and portability of your personal information, and you may object to processing based on legitimate interests and withdraw consent at any time (without affecting processing already carried out). Submit requests to contact@parkboxd.com.
- International transfers. When we transfer your information from the EEA/UK/Switzerland to the United States or other countries, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (with the UK Addendum / Swiss equivalents where applicable) or another lawful transfer mechanism.
- Complaints. You have the right to lodge a complaint with your local data protection supervisory authority. We'd appreciate the chance to address your concern first, so please consider contacting us before you do.
13.3 Other U.S. state privacy rights
If you reside in a U.S. state with a comprehensive privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others, you may have rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. We do not sell personal information, serve targeted advertising, or use profiling that produces legal or similarly significant effects. To exercise any available right, email contact@parkboxd.com; you may appeal a denied request by replying to our response.
14. Third-party links and services
The Service may reference or link to third-party sites, content, or services (for example, park information). We are not responsible for the privacy practices of those third parties; review their policies separately.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for material changes, provide notice in the app or by email where appropriate. Your continued use of the Service after changes take effect constitutes acceptance.
16. Contact
Questions or privacy requests? Email contact@parkboxd.com. A postal address for formal legal notices is available on request at that email.