Privacy Policy
Effective September 20, 2026
PlatePermit is parking permit software provided by Luma Tech Digital (“PlatePermit,” “we”). Schools, homeowner associations, employers, municipalities, and other organizations (“Organizations”) use it to accept permit applications, review them, take payment, and check license plates. This policy explains how we handle personal information across the PlatePermit service and this website.
Our two roles
- Service provider to Organizations. When you apply for a permit on an Organization's PlatePermit site (for example yourschool.platepermit.com), that Organization decides what information is required and how it is used, and it is responsible for those records. We process the information only on the Organization's behalf, under a written agreement, to run the service. That site's own Privacy Policy page describes the specifics for that Organization, including how long documents are kept and whom to contact.
- Operator of this website and of staff accounts. We are directly responsible for information we collect from visitors to platepermit.com, from people who contact us, and from Organization staff who sign in.
Information handled through the service
- Applicants: name, email, optional phone number, and an identifier the Organization asks for (such as an ID number, grade, unit, or department); vehicle plate, state, year, make, model, and color, including any temporary vehicle they register and the dates it stood in for their usual one; documents the Organization requires (such as a driver's license, proof of insurance, or vehicle registration) and their expiration dates; permit status and history. When applicants sign in with Google we receive only their basic profile (name, email address, and profile identifier) to confirm their email address; we request no other Google data and never see their password.
- Payments: the amount, date, and status of a permit payment. We never receive or store card numbers. Card payments are collected by Stripe directly on behalf of the Organization, which is the merchant.
- Organization staff: name, email address, role, and sign-in times. When staff sign in with Google we receive only their basic profile (name, email address, and profile identifier) to confirm who they are. We request no other Google data and never see their password.
- Parking lot checks: an Organization's parking enforcement may scan license plates in its lots with a phone camera. Each photo is used only to read the plate and is never stored on our servers. The plate, the time, the lot, the GPS location where it was photographed, and whether the plate had a valid permit are deleted after 14 days. If a warning is recorded for a plate, the warning itself (the plate, date, and lot) is kept through the permit year so repeat violations can be counted. This applies to every vehicle parked in the lot, including vehicles without a permit.
- Security records: IP addresses and timestamps of actions such as submitting an application or opening a document.
- People who contact us: whatever you choose to send to our support or privacy addresses.
We do not use advertising or analytics trackers. The only cookies we set are those strictly necessary to keep staff signed in and to protect sign-in from forgery.
How we use information
- To provide the service to Organizations: receiving and reviewing applications, issuing and enforcing permits, and sending emails about applications, payments, permits, and expiring documents.
- To authenticate staff and restrict what each role can see.
- To keep the service secure, prevent fraud and misuse, fix problems, and meet legal obligations.
- To bill Organizations, using usage counts that identify no individual (for example, number of documents stored).
We do not sell personal information, share it for advertising, use it to build profiles, or use it to train machine-learning models. We do not combine one Organization's data with another's.
Who can see information
- The Organization's authorized staff see applications and documents for their own Organization only. Every time a staff member opens a document, it is recorded in an audit log.
- The Organization's parking enforcement personnel can look up a plate and see only the plate, whether the permit is valid, the assigned lot, the permit holder's name, and, when a temporary vehicle is registered, both plates and when the temporary one ends — never documents, contact details, or payment information.
- Our service providers, under contract: Amazon Web Services (hosting, storage, email delivery, and reading license plates from camera images), Stripe (card payments, under the Organization's own Stripe account), and Google (sign-in for applicants and staff). All data is stored in the United States.
- PlatePermit personnel, only when needed for support or security.
- As required by law, such as a valid subpoena or court order. Where a request concerns an Organization's records, we direct it to the Organization unless the law prohibits that.
- A successor, if PlatePermit is acquired or merged, subject to the commitments in this policy and in our agreements with Organizations.
How information is protected
- All traffic is encrypted in transit. Uploaded documents and the database are encrypted at rest, and documents are kept in private storage that is not publicly accessible.
- Documents can only be opened through links that expire after five minutes.
- Location data and other hidden metadata are removed from uploaded photos.
- Each Organization's data is isolated from every other Organization's at the database level.
No system is perfectly secure. If we learn of a breach affecting personal information, we will notify the affected Organization without undue delay and support the notifications the law requires.
Retention
Uploaded documents are automatically and permanently deleted after the permit term ends — 30 days after by default; an Organization may set a different period, shown on its own policy page. Other permit records are kept for as long as the Organization's agreement and records policies require, then deleted or returned at its direction. Staff accounts are removed when the Organization removes them. Security logs are kept for as long as needed for security and audit purposes.
Students and minors
Where an Organization is a school, permit records may be education records under the Family Educational Rights and Privacy Act (FERPA). We handle them as a “school official” under the school's direct control, use them only to provide the service, and do not redisclose them except as the school directs or the law requires. Applicants under 18 must have a parent or legal guardian review and agree before applying. The service is not directed to children under 13, and we do not knowingly collect their information.
Your choices and rights
If you applied for a permit, the Organization controls your records: contact its parking office (listed on its site) to see, correct, or delete your information, and we will help it respond. Parents and eligible students may exercise FERPA rights through their school. For information we control directly — staff accounts and messages you sent us — or with any privacy question, contact privacy@platepermit.com. Depending on where you live, you may have additional rights under state privacy law; we honor verified requests as the law requires and never discriminate against anyone for making one.
Changes
If this policy changes in a meaningful way we will change the effective date above, and new permit applications will be asked to agree to the current version. Questions: privacy@platepermit.com.