Data Retention Schedule
Draft — pending solicitor review
This document is a working draft prepared in-house. It reflects how Parkntel actually handles your data today, but it has not yet been reviewed or approved by a qualified solicitor, and it may change before launch.
Version 2026-07-28 · Last updated 28 July 2026
UK GDPR's storage limitation principle says personal data must not be kept longer than it is needed for the purpose it was collected for. Most privacy policies satisfy that with a sentence saying periods are “set per category”. This page is the actual list.
These periods are enforced by a scheduled job that runs against the database on its own restricted account, not by anyone remembering to tidy up. Every purge is recorded in the audit log. The one thing that pauses a period is a legal hold — if data is subject to an active legal claim or a law-enforcement request, it is excluded from deletion until the hold is released.
| Data | Kept for |
|---|---|
Photos you take to scan a number plate The plate is read on your own device and only the text you confirm is sent to us. The image never leaves your phone. | Not kept at all |
Messages in a conversation you marked resolved Deleted. You are warned before you resolve a thread, and told again in your notifications. | 24 hours |
Messages in a conversation nobody resolved Deleted. Unresolved threads get a longer window because there was no clear end point. | 7 days after the thread expires |
Evidence you uploaded to prove you own a vehicle Deleted. The grace period exists so you can reinstate a vehicle or dispute a decision. | 90 days after you remove the vehicle |
Your identity verification result Anonymised. We keep the outcome and your date of birth, not your ID document — that is held by Stripe and redacted immediately after the check. | 5 years |
Your account profile after you ask us to delete it Anonymised. The grace period covers accidental deletion and lets us finish any dispute already in progress. | 30 days |
Routine activity logs Deleted. | 2 years |
Security-sensitive logs (sign-ins, permission changes, data access) Deleted. Six years matches the limitation period for bringing a legal claim in England and Wales. | 6 years |
Sign-in and device records Removed. Their purpose — spotting an unusual sign-in — expires quickly. | 1 year |
Records of data requests you made to us Deleted. Kept as evidence that we handled your request properly. | 3 years |
Records of consent you gave Deleted. Kept so we can show what you agreed to and when. | 3 years |
Billing records Deleted. This is a statutory accounting requirement, so we cannot delete these earlier on request. | 6 years |
Support conversations Deleted. | 2 years |
Encrypted backups Deleted as each backup ages out. A deletion request reaches backups within this window rather than instantly. | 90 days |
Asking for something earlier
You can ask us to delete your data before these periods expire, and we will unless we are legally required to keep it — billing records and some security logs being the main exceptions, which we will tell you about if they apply. Email privacy@parkntel.com; we respond within 30 days. Your other rights are set out in the Privacy Policy.