Last updated: 7 July 2026
1. Who this notice applies to
This privacy notice explains how Metropark Ltd trading as PARKULTRA® collects and uses personal information when you use our website, apply for a permit, register visitor parking, pay or appeal a Parking Charge Notice, submit evidence, report nuisance parking, use a customer portal, contact us, or park at a site managed by us.
It also explains how personal information may be processed in connection with ANPR, CCTV, body-worn camera footage, patrol evidence, uploaded photographs, nuisance parking reports, self-ticketing evidence, customer portal records and related parking-management activity.
2. Controller details
Metropark Ltd trading as PARKULTRA® is the controller for personal information processed through our website and parking-management services unless another arrangement is stated in a customer agreement or site-specific notice.
Metropark Ltd is registered in England and Wales under company number 03235898. Our registered office is 27 Old Gloucester Street, London WC1N 3AX. Our ICO registration number is Z9687436.
Data protection contact: dataprotection@metropark.co.uk
General contact: info@metropark.co.uk
3. Information we may collect
- name, postal address, email address and telephone number;
- vehicle registration mark, vehicle make/model, colour and parking location;
- permit application details, bay/property information and eligibility evidence;
- visitor parking session details, site-location codes, authorisation references and scan-in/scan-out records;
- PCN reference, date/time/location information, payment status, payment references and appeal details;
- photographs, documents and evidence submitted through appeals, permit applications, visitor parking, nuisance parking reports, customer enquiries or self-ticketing;
- ANPR images, CCTV images, vehicle movement records, patrol photographs, body-worn camera evidence and other parking-control records where used at a site;
- resident permit account details, application status, approval or rejection records, renewal records, account messages and related audit history;
- customer account details, authorised user details, training/certificate status, site permissions and portal audit logs;
- technical information such as IP address, browser type, device information, page access records and security logs.
4. Surveillance, ANPR, CCTV and evidential images
At some sites managed by Metropark Ltd trading as PARKULTRA®, parking control may be supported by ANPR cameras, CCTV, body-worn cameras, attendant patrols, uploaded photographs, customer evidence submissions or other parking control technology.
These systems may capture vehicle registration marks, vehicle images, date and time information, location information, images of vehicles and surrounding context, and other evidence relevant to the management and enforcement of parking terms and conditions.
We use this information for parking management, permit control, visitor parking management, investigation of breaches of site parking terms, issuing and administering Parking Charge Notices, dealing with appeals, responding to complaints, supporting legal or regulatory obligations, fraud prevention, audit purposes and protecting the rights of landowners, residents, visitors and authorised users.
Where ANPR, CCTV or other surveillance systems are used, signage at the relevant site will identify that camera or parking control systems may be in operation and will direct users to further privacy information. We do not use facial recognition as part of our standard parking enforcement process unless this is expressly stated in a separate site-specific privacy notice.
We seek to operate parking-control systems in a proportionate way. Images and vehicle data are reviewed before enforcement action is taken, and where evidence is unclear, incomplete or insufficient, we may decide not to issue or pursue a Parking Charge Notice. Where appropriate, we may use privacy by design measures, including careful camera positioning, restricted access, secure storage, encryption, audit controls and limited retention periods.
5. Why we use personal information
We use personal information to manage parking sites, administer permits and visitor parking, process PCNs, handle payments, review appeals, assess nuisance parking reports and self-ticketing evidence, provide customer support, maintain audit trails, prevent misuse, improve our services, comply with legal and regulatory obligations and establish or defend legal claims.
6. Lawful bases
Depending on the circumstances, we may rely on contract, legitimate interests, legal obligation, consent, or the establishment, exercise or defence of legal claims. For example, we may rely on legitimate interests to manage parking controls, protect private land, administer permit systems, review evidence and pursue unpaid parking charges where appropriate. We may rely on contract to provide customer services, legal obligation to comply with regulatory requirements, and consent for non-essential cookies or marketing where used.
7. DVLA and keeper details
Where a Parking Charge Notice needs to be progressed and we have a lawful basis and reasonable cause to do so, vehicle keeper details may be requested or processed in accordance with applicable DVLA requirements, accredited trade association rules and data protection law.
8. Who we may share information with
We may share relevant information with landowners, managing agents, customer contacts, payment providers, IT/cloud providers, postal and print providers, ANPR or camera-system providers, parking-industry bodies, independent appeals bodies, debt recovery agents, legal advisers, courts, regulators, law enforcement, the DVLA, or other parties where necessary for parking management, dispute handling, compliance, enforcement or legal claims.
Where information is disclosed to a third party for its own legal or regulatory purpose, that third party may become a controller of the copy disclosed to it. We do not sell personal information.
9. Retention
We keep personal information only for as long as necessary for the purpose for which it was collected. Retention periods may vary depending on the type of data, the site, the service provided, the status of any permit application, visitor session, PCN, appeal, complaint, report, audit requirement or legal obligation.
Resident Permit Accounts. Permit applicants create a Resident Permit Account as part of the online permit application process. The account may be used to track the application, receive updates, provide further evidence, download approved permits, manage renewals and use resident-controlled visitor parking where enabled for the site.
If a permit application is rejected or further evidence is required, the Resident Permit Account will ordinarily remain active for 30 days so the applicant can view the decision, amend the application where permitted or provide further evidence. After that period, if there is no approved permit, active application, renewal window, dispute, appeal, payment issue, investigation or other lawful reason to retain access, the account may be closed.
When an account is closed, access to the account will be disabled. Uploaded proof documents and supporting evidence connected with a closed or unsuccessful permit application will ordinarily be deleted or anonymised within 30 days after account closure, unless we have a continuing lawful reason to retain them.
Minimal transaction, payment, VAT, audit, application outcome, permit history, compliance, complaint, regulatory and legal records may be retained for up to six years where this is necessary for accounting, tax, audit, legal claims, regulatory compliance, fraud prevention, dispute resolution or business records.
Raw camera footage and images may be retained for a limited period depending on the system and site. Where footage, images, documents or other evidence become part of a Parking Charge Notice, appeal, complaint, nuisance parking report, self-ticketing submission, regulatory enquiry, debt recovery process or legal claim, they may be retained for longer where necessary for enforcement, audit, dispute resolution, fraud prevention, legal obligations or regulatory compliance.
10. Data protection impact assessments and safeguards
Where appropriate, we carry out or maintain data protection and surveillance assessments to help identify and reduce privacy risks connected with ANPR, CCTV, camera systems, nuisance parking reports, self-ticketing evidence, portal uploads and related processing. These assessments may consider necessity, proportionality, signage, retention, data-sharing, security, review processes and user training.
Detailed DPIAs, asset registers, customer agreements, site schedules and operational security information are not normally published on the public website, but may be held internally or made available through the relevant customer portal or contractual process where appropriate.
11. Security
We use technical and organisational measures designed to protect personal information. Portal access, payment records, uploaded evidence, camera evidence and audit records should only be accessed by authorised users with a legitimate reason. Security measures may include access controls, encryption, secure storage, audit logs, restricted disclosure and staff or user training.
Where passwords are used, PARKULTRA does not require routine password changes for standard accounts. Users may be required to change their password where there is a suspected compromise, security incident, administrator reset, unusual account activity or other security concern. Customer administrator, self-ticketing, warden and internal accounts may be subject to additional security controls, including multi-factor authentication where enabled or required.
Users must keep their login details secure and must not share portal access codes, passwords or account links with anyone else. We may suspend, disable or reset account access where we believe this is necessary to protect users, customer sites, personal data or the integrity of the PARKULTRA® platform.
12. International transfers
Some service providers may process information outside the UK. Where this happens, we will take appropriate steps designed to protect personal information in line with applicable data protection law.
13. Your rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, request portability, or withdraw consent where processing is based on consent. You also have the right to complain to the Information Commissioner’s Office.
We do not charge a standard fee for subject access requests. We may charge a reasonable fee or refuse to act where permitted by data protection law, for example where a request is manifestly unfounded or excessive.
14. Cookies
Information about cookies and similar technologies used on this website is set out in our Cookie Information page.
15. Contact us
To make a privacy request or ask a question about this notice, email dataprotection@metropark.co.uk.