Privacy Policy
Effective date: 10 July 2026
Last updated: 12 August 2026
The short version
We collect the stuff we need to fight your parking charge for you — your email, the charge details, the vehicle registration, and any evidence you upload — and we use it to build your challenge and run the Service. We don't sell your data. To help every driver, we also pool de-identified, site-general findings (like "this site's signage doesn't show the price") so other drivers charged at the same place are better armed — never your identity, and you can opt out per challenge (see §4A). We use a small number of trusted providers to host the app, take payments and send email (and, where enabled and with your consent, to understand traffic and run ads). You can see, correct, export or delete your data at any time. When you delete your account, we genuinely erase your personal data — we keep only a one-way scrambled fingerprint of your email so people can't delete-and-rejoin forever to abuse the free service, and even that is time-limited. The full detail is below.
1. Who we are (the data controller)
Natt Workden, trading as "Revenger" ("Revenger", "we", "us") is the controller of the personal data described in this policy. We operate revenger.ai as a sole trader.
- Trading / correspondence address: Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset BH16 6FA
- Data protection contact: Natt Workden, help@revenger.ai
- ICO registration number: ZC220121
We are registered with the UK Information Commissioner's Office (ICO) as a data controller.
2. The personal data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account data | Email address; authentication data; account settings (e.g. your reminder preferences). | You, when you sign up. |
| Challenge data | Details of the parking charge (operator, reference numbers, dates, location, amount); the vehicle registration mark (VRM); your relationship to the vehicle (e.g. registered keeper); the name and postal address used on your letters; the circumstances/notes you provide; the letters, requests and challenge timeline generated for you. | You, and generated by the Service from your inputs. |
| Evidence you upload | Photos and documents (e.g. the charge notice, signage photos, correspondence). These may incidentally contain other people's personal data — number plates, faces. | You. |
| Payment data | A record that you bought a challenge credit or bundle, the amount, a payment reference, and a receipt link. We do not receive or store your full card number — payment card details are handled directly by Stripe. | You + Stripe. |
| Communications | Emails we send you (challenge reminders, service and account emails) and any messages you send us for support. | You + us. |
| Usage & device data | Basic technical data needed to run and secure the app (e.g. IP address, browser type, pages used, timestamps). We use a cookieless product-analytics tool (see §5) to understand how the app is used; advertising tools, if we ever switch them on, additionally collect usage data via cookies with your consent. | Automatically, via your device. |
We try to collect only what we need. Please don't upload special-category data (health, etc.) or third-party data you don't need to — and avoid capturing bystanders in evidence photos where you can.
3. How and why we use your data — and our lawful bases
Under the UK GDPR we must have a lawful basis for each use. Here's the map:
| What we do | Why | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Create and manage your account | To let you use the Service | Contract (Art. 6(1)(b)) |
| Generate your Challenge Materials and run your challenge (deadlines, escalations) | The core service you asked for | Contract (Art. 6(1)(b)) |
| Store the evidence you upload | To build and support your challenge | Contract (Art. 6(1)(b)) |
| Read your uploaded notice/evidence with an AI model to extract facts and draft your letters | To produce your Challenge Materials | Contract (Art. 6(1)(b)) — processed by our AI sub-processor (see §4) on our instructions |
| Take payment for challenge credits/bundles | To sell you the paid service | Contract (Art. 6(1)(b)); payment records also Legal obligation (tax/accounting) |
| Send challenge reminder emails | To help you not miss a deadline | Legitimate interests (Art. 6(1)(f)) — you can turn these off anytime in Settings |
| Send essential service/account emails | To operate the account (e.g. confirm sign-up, password reset) | Contract / Legitimate interests |
| Keep the Service secure, prevent abuse and fraud, enforce our Terms | To protect users and the Service | Legitimate interests (Art. 6(1)(f)) |
| Pool de-identified, site-general findings from your challenge (e.g. that a site's signage omits the price) to help other drivers charged at the same site (see §4A) | To build shared consumer-protection intelligence | Legitimate interests (Art. 6(1)(f)) — on by default; you can opt out per challenge, and object anytime |
| Retain a suppression fingerprint after account deletion (see §8) | To detect and deter abuse of the free service | Legitimate interests (Art. 6(1)(f)) |
| Analytics — understand how the app is used (cookieless; nothing stored on your device) | To improve the Service | Legitimate interests (Art. 6(1)(f)) — you can object at any time (see §10) |
| Advertising / measurement (e.g. Meta Pixel) | To reach and measure potential users | Consent (Art. 6(1)(a)), given via the cookie banner |
| Comply with legal requests and defend legal claims | Legal/regulatory | Legal obligation / Legitimate interests |
Where we rely on legitimate interests, we've weighed them against your rights; you can ask us for our assessment, and you can object (see §10). Where we rely on consent, you can withdraw it at any time without affecting anything we did before you did.
4. Who we share your data with
We do not sell your personal data. We share it only with:
- Service providers (processors) who run parts of the Service for us, under contract and only on our instructions:
- Supabase — application hosting, database, authentication and file storage (your account, challenge data and evidence live here).
- Stripe — payment processing (handles your card details directly as a controller of that payment data).
- OpenRouter — routes your uploaded notice/evidence text and challenge inputs to an AI model to extract facts and draft your letters, on our instructions.
- Resend — sending transactional and reminder emails.
- PostHog — product and usage analytics, cookieless and hosted in the EU, on our instructions.
- Meta Platforms (Facebook/Instagram Pixel) — advertising measurement, where enabled and with your consent. Note that advertising pixels typically share limited data with the platform as an independent/joint controller for their own purposes; details will be set out here and in the Cookie Notice when this is switched on.
- Recipients you choose to send to. When you send a letter, appeal, request or complaint, you are the sender — the parking operator, appeals body (POPLA/IAS), regulator (e.g. ICO) or court receives the data because you chose to send it. Unless a specific feature clearly states otherwise, we don't transmit it to them for you.
- Other users, in de-identified form only, via the site-intelligence pool described in §4A.
- Authorities and advisers where we're legally required to, or to establish, exercise or defend legal claims.
- A buyer or successor if the business is reorganised, sold or merged — in which challenge your data would be handled under terms consistent with this policy.
A current list of subprocessors can be provided on request at help@revenger.ai.
4A. Shared site intelligence (pooled, de-identified)
Revenger builds shared intelligence about how parking operators behave at specific sites, so that each driver's challenge can be armed with weaknesses other drivers already found. Here is exactly what that does — and does not — involve.
What we pool. When you have us review a document the operator disclosed to you, and that document is a landowner contract or signage, we may add the finding — the type of document, which element it concerns, whether it looks weak, and a short de-identified note — to a shared pool, tagged to the site (operator + location) and the date your parking event occurred. Other users charged at the same site can see these findings as candidate weaknesses, and we use them to spot when an operator's disclosure is inconsistent between drivers or has changed over time.
What we never pool. We do not share your name, email, vehicle registration, PCN reference, the images or files you upload, or anything that identifies you. Findings from ANPR images and Notice-to-Keeper documents are never pooled at all. Before any note enters the pool it is automatically stripped of things like registration marks, reference numbers, emails and phone numbers. The shared pool contains no field that identifies you.
Why we do it, and your control. We rely on legitimate interests (Art. 6(1)(f)) — the consumer-protection value of pooling how operators actually behave. Contribution is on by default, but you can opt out for any challenge from its Evidence panel, and you can object at any time (see §10). If you delete a challenge or your account, your contributions are removed from the pool too.
Operator intelligence. We also show operator-level information — for example documented defect patterns and official POPLA appeal statistics — compiled from public sources. That is general information about operators, not personal data about you.
We treat all of this as documented patterns and candidate weaknesses — not legally established defects.
4B. Aggregate operator-appeal statistics (de-identified)
We use limited information from an operator's reply to an appeal — such as whether it was a rejection and whether our checked record identified a required second-stage appeal reference — to create aggregated statistics about how operators handle appeals. For example, for eligible BPA cases, we may show the proportion of recorded rejection notices in which Revenger did not identify a POPLA verification code after quality checks.
We create these statistics from case data, but the result we display is designed not to identify you or disclose your correspondence. We publish a named operator statistic only where there are enough eligible recorded cases to meet our privacy and reliability threshold, and we show the sample size and reporting period. We do not publish your name, contact details, vehicle registration, PCN reference, correspondence, individual case, or any site- or date-level breakdown.
We rely on legitimate interests — consumer transparency and helping motorists understand the appeal process. You can opt any challenge out of this use from its Evidence panel, and you can object at any time (see §10). Opted-out, draft and deleted challenges are excluded. A statistic describes Revenger's recorded eligible cases only; it is not a finding that an operator breached a code, or a measure of all of that operator's cases.
5. Cookies, analytics and advertising
We use cookies and similar technologies. Strictly-necessary cookies (for login/session and security) are always on because the app can't work without them. Our product analytics (PostHog, EU) is cookieless — it stores nothing on your device and sets no analytics cookies — so it needs no consent; we rely on legitimate interests and you can object at any time (see §10). Advertising (e.g. Meta Pixel) cookies are non-essential and, if we ever switch them on, are only set after you consent via our cookie banner. Full details are in our [Cookie Notice](/legals).
6. International transfers
Some of our providers process data outside the UK. Where they do, we make sure appropriate safeguards are in place — for example a UK/EU adequacy decision, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. You can ask us for details of the safeguards for a specific provider.
7. How long we keep it (retention)
- Active account: we keep your account, challenge data and evidence for as long as your account is open, so your challenges stay available to you.
- After you delete a challenge or your account: we erase the personal data as described in §8, and remove your contributions from the site-intelligence pool.
- Pooled findings: de-identified findings in the shared pool are fully anonymised, so they fall outside the scope of the UK GDPR and are retained indefinitely for statistical/intelligence purposes. Findings tied to a challenge are removed if you delete the source challenge or account.
- Operator-appeal statistics (§4B): we retain only the successfully anonymised aggregate outputs while they remain useful; we review the methodology annually and delete or suppress any output that falls below its threshold following a removal or recalculation. Your underlying case records stay subject to the retention and deletion rules above.
- Payment/accounting records: kept for as long as required by law (typically 6 years).
- Suppression fingerprint (§8): kept for 24 months, then deleted.
- Backups: residual copies in secure backups are overwritten on our normal backup cycle.
8. Deleting your account — and the one small thing we keep, honestly explained
You can delete your account at any time from Settings. When you do, we erase your personal data — your challenges, letters, uploaded evidence, name, address and account details are genuinely removed from the live system (and age out of backups on the normal cycle), and your login is deleted. Your de-identified contributions to the site-intelligence pool are removed too.
There is one exception, and we want to be upfront about it. If you've used the free part of the Service (the free appeal), we keep a single one-way, irreversible cryptographic fingerprint (a "peppered hash") of your email address in a suppression list. We can't reverse it into your email, it isn't linked to any of your erased challenge data, and it exists to help us detect and deter abuse of the free service — for example, someone repeatedly deleting and re-creating accounts to evade a suspension or to run up free appeals at scale (each free appeal has a real cost to us). Before hashing, we normalise the email (e.g. removing Gmail dots and +tags) so trivial variations resolve to the same fingerprint.
We rely on legitimate interests for this (fraud/abuse prevention), it's minimised (a single hash, nothing else) and it's time-boxed — we delete the fingerprint after 24 months. This does not stop you exercising your data-protection rights, and if you have a specific concern you can contact us.
9. How we keep your data secure
Access to challenge data and evidence is restricted to your own account through database row-level security, evidence files are held in a private store (not public), data is encrypted in transit, and access by our providers is governed by contract. The site-intelligence pool is held in a separate store that contains no identifying fields. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we'll comply with our breach-notification duties if anything goes wrong.
10. Your rights
Under UK data-protection law you have the right to:
- access a copy of your data (you can also self-serve an export from Settings);
- have inaccurate data corrected;
- have your data erased (see §8);
- restrict or object to certain processing, including processing based on legitimate interests — this covers the site-intelligence pooling in §4A, the aggregate operator-appeal statistics in §4B, and our cookieless product analytics — and any processing for direct marketing. Objecting to the §4B use, or opting a challenge out from its Evidence panel, stops that challenge being used for the statistic; we recompute and refresh within 24 hours and confirm it to you;
- withdraw consent where we rely on it (e.g. advertising cookies, if enabled); and
- data portability for data you provided, where applicable.
To exercise any of these, email help@revenger.ai. We'll respond within one month. You won't usually be charged, and we may need to verify your identity first. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ico.org.uk; helpline 0303 123 1113) — though we'd appreciate the chance to put it right first.
11. Children
Revenger is not intended for anyone under 18, and we don't knowingly collect data from under-18s. If you believe a child has given us data, contact us and we'll delete it.
12. Other people's data in your uploads
Because evidence photos can contain number plates and faces, you may be providing us with other people's personal data. Please only upload what's necessary for your challenge, and avoid capturing bystanders where you can. We process that data solely to provide the Service to you; if a third party contacts us about data in an upload, we'll handle it in line with the law (and without exposing your challenge to them).
13. Changes to this policy
We may update this policy. If we make a material change we'll take reasonable steps to tell you (e.g. by email or an in-app notice). The "last updated" date at the top always reflects the current version.
14. Contact
Data protection contact: Natt Workden
Natt Workden, trading as Revenger, Lytchett House, 13 Freeland Park, Wareham Road, Poole, Dorset BH16 6FA
Email: help@revenger.ai
Revenger is an entertainment product and not a law firm. This policy explains how we handle your data; it is not legal advice.