Privacy Policy
Last updated: 28 June 2026
1. Who We Are
UAB Lorantas is the data controller for the personal data described in this Privacy Policy.
2. Personal Data We Collect
| Category | Examples | Why we need it |
|---|---|---|
| Account and contact details | Name, email address, phone number, Firebase account ID | Account access, booking communication, customer support, security |
| Profile and contract details | Address, emergency contact, stored item type, description, registration or hull number, declared value | Storage agreement, check-in, emergency contact, deposit and liability handling |
| Booking details | Selected bay(s), dates, duration, arrival window, price, add-ons, booking status, cancellation/refund events | Providing and administering the parking/storage service |
| Payment data | Stripe customer/payment identifiers, payment status, deposit charge/refund records | Taking payments, handling deposits and refunds. We do not store full card numbers. |
| Identity and check-in data | ID type, document reference recorded at check-in, Stripe Identity verification status, verified name or date of birth where returned by Stripe | Fraud prevention, facility security, contract enforcement, confirming the person collecting or storing the item |
| Legal acceptance and signatures | Accepted document versions, acceptance time, IP address, user agent, online or on-site signature record | Proving acceptance of the Terms, Privacy Policy, and storage agreement |
| Vehicle access and security data | Vehicle plate(s), gate access-list entries, ANPR/access events, entry/exit time, direction, decision, camera/gateway identifiers, CCTV or camera snapshots where configured | Operating the gate, protecting the facility, investigating incidents, preventing unauthorised access |
| Photos and documents | Contracts, storage agreement PDFs, condition photos of stored items or bays, signature images | Booking records, check-in/check-out evidence, claims handling |
| Technical data | IP address, browser/device data, authentication/session information, security logs | Keeping the website secure, diagnosing issues, preventing abuse |
3. Why We Use Your Data and Our Legal Basis
- Contract performance: to create your account, process bookings, take payment, manage your storage period, generate contracts, and provide customer support.
- Legal obligations: to keep accounting, tax, legal, and dispute records where required by law.
- Legitimate interests: to secure the site, prevent fraud and unauthorised access, manage the gate/ANPR/CCTV system, investigate incidents, protect property, improve reliability, and enforce our agreements.
- Consent: only where we ask for a separate, specific consent. Ordinary booking, payment, security, and contract processing does not rely on consent.
If you do not provide information that is required for a booking, payment, identity check, or gate access, we may be unable to complete the booking or allow check-in/access.
4. How We Use Your Data
- Provide the Lorantas parking and storage service.
- Send operational messages such as booking confirmations, receipts, pre-check-in links, contract notices, cancellation/refund updates, and service alerts.
- Verify identity and maintain security at check-in, check-out, and gate entry.
- Process payments, deposits, refunds, invoices, and accounting records.
- Manage access to the facility using authorised vehicle plates and gate logs.
- Handle support, disputes, insurance or damage claims, safety incidents, and legal requests.
5. Who We Share Data With
We do not sell your personal data. We share it only where necessary with trusted providers and authorities, including:
- Stripe for card payments, deposits, refunds, and Stripe Identity verification.
- Firebase / Google Cloud for hosting, authentication, database, storage, and cloud functions.
- Azure Communication Services for operational email delivery.
- Gate, CCTV, ANPR, and IT service providers where needed to operate or maintain the facility and access systems.
- Insurance providers, legal advisers, accountants, banks, and payment processors where needed for claims, accounting, or legal matters.
- Public authorities or law enforcement where required by law or where necessary to protect rights, safety, or property.
6. International Transfers
Some providers, including Stripe, Google/Firebase, and Microsoft/Azure, may process data outside Lithuania or the European Economic Area. Where this happens, we rely on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, and the providers' data processing terms.
7. Data Retention
| Record type | Retention |
|---|---|
| Account/profile data | While your account or customer relationship is active, then as long as needed for legal, accounting, dispute, or security purposes. |
| Booking, contract, payment, invoice, and refund records | Normally up to 7 years after the booking or accounting period, unless a longer period is required for a dispute or legal claim. |
| Legal acceptance records and signatures | As long as needed to prove acceptance of the relevant agreement and defend legal rights. |
| ID/check-in verification records | For the booking period and then as long as reasonably needed for security, legal, accounting, or dispute purposes. |
| ANPR access events and camera snapshots | Up to 30 days, unless needed longer for an incident, investigation, dispute, legal claim, or law-enforcement request. |
| Gate access plates on active bookings | For the booking lifecycle and then as long as needed for access/security audit purposes. |
| Technical security logs | For as long as reasonably needed to secure, debug, and protect the service. |
When data is no longer needed, we delete it, anonymise it, or keep it only where a legal exception applies.
8. Cookies and Local Storage
We use essential authentication/session technologies and local storage needed for the website and booking flow to work. We do not use advertising or third-party tracking cookies on the customer booking website.
9. Automated Processing
Our ANPR/gate system may automatically recognise an authorised vehicle plate and open the barrier within an active booking window. Unknown or blocked plates may be denied and logged for review. We do not use automated decision-making that produces legal or similarly significant effects without human review. Payment and identity checks are handled through Stripe systems and may require manual review if something does not match.
10. Security
We use technical and organisational measures designed to protect personal data, including TLS encryption in transit, Firebase Authentication, role-based admin access, closed storage for contracts and booking photos, audit logs, and restricted access for staff and service providers.
11. Your GDPR Rights
Subject to applicable limits, you have the right to request:
- access to your personal data;
- correction of inaccurate or incomplete data;
- deletion of data;
- restriction of processing;
- data portability;
- objection to processing based on legitimate interests;
- withdrawal of consent where processing is based on consent.
To exercise your rights, email northstreem@gmail.com. We may need to verify your identity before acting on a request.
You also have the right to complain to the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija): vdai.lrv.lt.
12. Changes to This Policy
We may update this Privacy Policy when our services, systems, or legal requirements change. The date at the top shows the latest version. Significant changes will be highlighted on the website or sent by email where appropriate.
<- Back to Lorantas