Last updated · 19 Aug 2026
Privacy Policy
This explains what Talli records when you use the site, why we are allowed to, and what you can make us do about it. It covers tallipark.com and nothing else.
§ 1
Who is responsible
Talli operates this site and decides what happens to the personal data described below. In the language of the GDPR — Regulation (EU) 2016/679, known in Poland as RODO — we are the controller of it.
Anything in this document, and any request under it, goes to hello@tallipark.com. A person reads that address.
§ 2
What we record
Only what a given feature needs to work. Most of the site — searching, the map, district prices, the live city-lot counts and the rental-agreement generator — runs without an account and records nothing that identifies you.
With an account, this is the complete list:
- Your account: name, email address, chosen language, whether the address has been confirmed, and your password stored only as a hash that cannot be turned back into the password. Signing in with Google adds the profile picture Google returns.
- Your sessions: a session token, and the IP address and browser user-agent of the device you signed in from. This is what keeps you signed in, and what lets us end a session that is being abused.
- Your reservations: which spot, the dates, the number of months, the amount, the currency, the status, and the reference Przelewy24 gives the transaction.
- Listings you publish: title, description, address, map location, price, photos, and the contact phone number you give for enquiries.
- Things you write: reviews and ratings, messages to other users, and the names and filters of the alerts you save.
- Spots you save to your favourites.
- Usage events — which pages and which steps of the booking flow were reached. There is a section on those below, because how they are built is the part that matters.
§ 3
What we deliberately do not record
Four of these are worth stating outright, because the obvious assumption about each one is the wrong one.
- Card numbers and banking credentials never reach Talli. You enter them on Przelewy24’s own page; we are handed a transaction reference and a result, and nothing else.
- The rental-agreement generator runs entirely inside your browser. Names, PESEL numbers, addresses and bank account numbers typed into it are saved on your own device and are never sent to us — that is a design decision, not a promise about our servers.
- We do not take phone numbers or email addresses out of the advertisements we index from other sites, even where one appears in the text.
- There is no advertising network, no tracking pixel, no social plugin and no third-party profile of you on this site.
§ 4
Listings we index from other sites
Part of what you can search here is public advertisements published on OLX and Otodom. We record the advertisement’s own content — title, description, price, district, photos and a link back to where it was published — so that somebody looking for parking in Warsaw can search all of it at once instead of site by site.
If you published one of those advertisements and you want it off Talli, send the link to hello@tallipark.com. We take it down on receipt and keep it suppressed, so a later indexing run does not quietly restore it.
§ 5
How we measure use of the site
We count events ourselves rather than embedding somebody else’s analytics product, and the counter is built so that it cannot identify you.
- Each browser tab is given a random identifier held in that tab’s session storage. It is thrown away when the tab closes, and it is never joined to a device, an IP address or a person.
- An event records what happened — a search run, a listing opened, a step of the booking flow reached — alongside a district, a spot type or a price band. It never carries a phone number, an email address, a street address, an exact price or a listing title.
- If you are signed in when it happens, the event is linked to your account. If you are not, nothing about it can be traced back to you, and we have no way to change that afterwards.
§ 6
Why we are allowed to hold it
Every category above rests on one of the grounds in Article 6(1) of the GDPR.
- Performing our contract with you — Article 6(1)(b). Your account, your reservations, your listings, your messages, and the emails those generate.
- Our legitimate interests — Article 6(1)(f). Keeping the site secure, enforcing rate limits, preventing abuse, and understanding in aggregate which parts of the site get used. We have weighed each against your interests and use the least identifying data that answers the question.
- A legal obligation — Article 6(1)(c). Accounting records for money taken through the site.
- Your consent — Article 6(1)(a). The listing alerts you choose to receive. Every alert email carries a way to stop them, and an alert can be switched off in your account at any time.
§ 7
Who else sees it
We do not sell personal data and we do not hand it to anybody for their own marketing. It reaches the following companies because the site cannot function without them, and each one processes it on our instructions except where noted.
- Neon — the managed Postgres database everything is stored in.
- Vercel — hosting, and the storage that photos on submitted listings are kept in.
- Przelewy24, operated by PayPro S.A. of Poznań — payments. They are a separate controller for the payment itself and apply their own privacy policy to it.
- Resend — sending email: booking confirmations, password resets, address verification and alert digests.
- Mapbox — map tiles. Your browser fetches those directly, so Mapbox sees your IP address whenever a map is on screen.
- Google — only if you choose to sign in with a Google account.
- The owner of a spot you reserve — your name, your email address and your booking dates, so that they can arrange handover with you. That transfer is the entire point of a reservation.
§ 8
Data leaving Europe
Some of the companies above are established outside the European Economic Area or use infrastructure that is. Where data reaches them, the transfer rests on the European Commission’s standard contractual clauses or on an adequacy decision covering that country.
Write to hello@tallipark.com if you want to know which mechanism covers a particular one, and we will tell you.
§ 9
How long we keep it
Nothing is kept indefinitely by default, and the one exception is imposed on us rather than chosen.
- Account data: until you ask us to delete the account.
- Reservations and their payment references: five full years from the end of the year the payment was made in, which is the retention Polish tax and accounting law requires. This one survives the deletion of an account, reduced to what the law actually demands.
- Sessions: until they expire or you sign out.
- Messages and reviews: for as long as the account exists. A review stays visible after a listing is taken down, under the reviewer’s name.
- Usage events: kept as counts. Deleting an account cuts the link to it and leaves the event behind as an anonymous number, so historical figures do not silently rewrite themselves.
- Photos on a listing: deleted with the listing. Photos uploaded and never attached to a published listing are swept automatically.
§ 10
What you can ask us to do
The GDPR gives you all of the following, and exercising any of them is free. Write to hello@tallipark.com — from the address on your account where you can, since that is the fastest way for us to be satisfied it is really you.
- Get a copy of the personal data we hold about you and an explanation of what we do with it (Article 15).
- Have anything wrong corrected (Article 16). Your name, email address and language are editable in your account without asking us.
- Have your account and the data attached to it deleted (Article 17). We will, except for the payment records accounting law obliges us to keep — those are reduced to the legal minimum and used for nothing else.
- Have us pause processing while a dispute about accuracy or legitimacy is open (Article 18).
- Receive the data you gave us in a machine-readable file, or have it sent to another service (Article 20).
- Object to anything we do on the basis of legitimate interests (Article 21), including the usage counting described above.
- Withdraw consent at any moment. That stops the processing going forward and does not make what happened before it unlawful.
§ 11
If you think we have got this wrong
Tell us first, at hello@tallipark.com — most of it is fixable the same week. That is not a precondition for anything: you can complain to the Polish supervisory authority whatever we say, and at any point.
Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa — uodo.gov.pl
We answer requests and complaints within one month. If a request is genuinely complicated we may take up to two further months, and we will tell you inside the first month if that happens.
§ 13
Keeping it safe
Passwords are stored as hashes and cannot be recovered by anybody, us included. Traffic to and from the site is encrypted in transit.
An owner’s phone number is deliberately absent from the listing page itself — it is not in the HTML, not in the data the page ships, and not reachable by reading the page. It is served only to a signed-in account, at most twenty times an hour, with every request recorded. That does not make bulk collection impossible; it makes it slow, expensive and attributable, which is the achievable goal.
No system is perfect. If you find a weakness, write to hello@tallipark.com. We will treat it seriously, and credit you if you want to be credited.
§ 14
Age
Talli is not for children. You need to be at least 16 to hold an account and at least 18 to make a reservation, because a reservation is a contract.
We do not knowingly collect data from anybody younger. If you believe we have, write to hello@tallipark.com and we will remove it.
§ 15
Changes to this policy
When this document changes, the date at the top changes with it. If a change materially alters what we do with data we already hold, account holders are emailed before it takes effect rather than after.