Privacy Policy

Last updated: 11 September 2026

Who we are

Beat It ("we", "us", "our") operates usebeatit.com — an AI-powered service that prepares parking appeals. Where the authority accepts appeals by email, we email yours for you and act as your agent in that correspondence. Where the authority uses its own online form, or requires the appeal by post, we prepare it and you submit it yourself.

For privacy queries: privacy@usebeatit.com

Beat It Ltd · Company No. 17198935 · Registered in England & Wales · Registered office: Apartment 104, 3 Wood Crescent, London W12 7GN · On the Information Commissioner's Office (ICO) register of data protection fee payers, registration reference ZC243664.

1. Data we collect

  • Account data: Email address and name when you sign up.
  • Ticket details: PCN/ticket reference, issuing authority, date, time, location, alleged violation, and vehicle registration.
  • Ticket & scene photos: Images you upload of your ticket or the parking scene. Where a council or operator publishes its own photos of the alleged contravention, we may also retrieve those on your behalf so you can review them and so we can check them for you (for example, comparing the photographed vehicle against DVLA records).
  • Accessibility data (optional): If your appeal relies on a disabled person's (Blue) Badge, you may choose to upload a photo of it. This reveals health information, so it is "special category" data — we only process it with your explicit consent and solely to prepare that appeal.
  • Location (only if you turn charge-zone alerts on): If you switch on alerts for toll and charge zones such as the London ULEZ or the Dartford Crossing, your phone tracks your position in the background while you are moving and compares it against a small, fixed list of those zones. All of that comparing happens on your device: your coordinates are never sent to us, or to anyone else. What reaches our servers is only the reminder it produces — the name of the zone you crossed and the date — saved to your account so you can see it and pay in time. Over time that does build up a list of which charge zones you have crossed and when, which you can see in your own inbox. We never receive your route, your speed, or anywhere you go that is not one of those zones. Turning the alerts off stops all of it.
  • IP address: Logged for security, rate-limiting, and fraud prevention.
  • Payment information: Billing details handled by Stripe. We store only a tokenised reference — never your card number.
  • Communications: Appeal letters we prepare for you — including those we email to the authority on your behalf — and any responses received from councils or operators.
  • Usage data: Pages visited and session information to improve the service.

2. How we use your data

  • Generating personalised appeal letters from your ticket details.
  • Emailing those letters to the relevant authority on your behalf, where that authority accepts appeals by email. Where it uses its own online form or requires post, we prepare the letter and you submit it.
  • Sending you email updates about your appeals and account.
  • Processing subscription payments and success fees via Stripe.
  • Detecting fraud and enforcing our rate limits.
  • Improving our service using aggregated, anonymised data.
  • Complying with legal and regulatory obligations.

We do not sell your data. We do not use it for advertising.

3. Our lawful basis for processing

Under UK GDPR we must have a lawful basis for each thing we do with your data. Ours are:

  • Performing our contract with you (Art 6(1)(b)): the core service — creating your account, reading and analysing your ticket and any related photos (including contravention photos we retrieve from the authority) and checking the photographed vehicle against DVLA records, generating appeal letters from your ticket details and vehicle registration, and emailing them to councils and operators on your behalf where those authorities accept email. Without this data we cannot provide the service.
  • Legitimate interests (Art 6(1)(f)): keeping the service secure and reliable — fraud prevention and rate-limiting (IP address), error diagnostics, and product analytics to improve the service; and handling any incidental third-party information (such as bystanders, passengers, or other vehicles) that may appear in ticket, scene, or contravention photos, solely to prepare your appeal. We weigh these interests against the rights of everyone affected and minimise the data used — we only process what the appeal needs, and we strip emails and vehicle registrations out of error reports. You can object to this at any time.
  • Consent (Art 6(1)(a)): optional things you choose to opt into, such as non-essential marketing emails and uploading a disabled (Blue) Badge. You can withdraw consent at any time.
  • Legal obligation (Art 6(1)(c)): keeping payment and tax records for as long as the law requires.

Special category data. A disabled (Blue) Badge reveals health information, which UK GDPR treats as "special category" data needing extra protection. We process it only on the basis of your explicit consent(Art 9(2)(a)), solely to prepare the specific appeal you provide it for. You can withdraw consent at any time and ask us to delete the data from Beat It's systems; withdrawal does not undo processing already carried out (for example, a badge already submitted with an appeal) or data we must keep to meet a legal obligation.

4. Third-party processors (subprocessors)

We use the following subprocessors to deliver the service. Each one receives only the data it needs to perform its function. Where data is transferred outside the UK/EEA, Standard Contractual Clauses (SCCs) apply.

Stripe — Ireland / USA 🇮🇪 🇺🇸

Data received: billing details, card number (handled directly by Stripe — we never see it), email, billing address.

Purpose: payment processing for subscriptions and success fees. PCI-DSS Level 1 compliant.

stripe.com/privacy ↗

Supabase — EU 🇪🇺

Data received: account data (email, hashed password), appeal records, ticket details, uploaded photos.

Purpose: database and authentication. Hosted in the EU. GDPR compliant.

supabase.com/privacy ↗

SendGrid (Twilio) — USA 🇺🇸

Data received: your email address, the content of appeal letters we email to authorities that accept email, and inbound replies received from councils.

Purpose: transactional email delivery and inbound parse for council replies. SCCs apply.

twilio.com/legal/privacy ↗

Anthropic — USA 🇺🇸

Data received: appeal context — ticket details, your answers to clarifying questions, and any narrative you provide — plus vehicle and scene photos: the ticket or scene images you upload, and any contravention photos we retrieve from the council or operator on your behalf.

Purpose: reading and analysing your ticket and related photos (the images you upload and any contravention photos we retrieve), generating appeal letters, and checking the photographed vehicle against DVLA records (make and colour) to flag a possible misread or cloned plate. API data is not used to train models per Anthropic's data usage policy. SCCs apply.

anthropic.com/legal/privacy ↗

OpenAI — USA 🇺🇸

Data received: ticket details and clarifying answers for some AI features.

Purpose: supplementary AI processing. OpenAI does not use API data to train models per their data usage policy. SCCs apply.

openai.com/policies/privacy-policy ↗

Cloudflare — USA / global 🇺🇸 🌍

Data received: anonymous abuse-prevention signals via Turnstile CAPTCHA (no cookies, no personal identifiers).

Purpose: bot and abuse prevention on signup and appeal submission. SCCs apply.

cloudflare.com/privacypolicy ↗

Sentry — USA 🇺🇸

Data received: error stack traces, browser/device info, and IP address (which may identify you).

Purpose: error reporting and diagnostics so we can fix bugs. SCCs apply.

sentry.io/privacy ↗

PostHog — USA / EU 🇺🇸 🇪🇺

Data received: product events (pages viewed, actions taken) and anonymous identifiers.

Purpose: product analytics to understand how the service is used. SCCs apply where data is processed in the USA.

posthog.com/privacy ↗

Vercel — USA 🇺🇸

Data received: request metadata (IP, user agent) for the web frontend and edge network.

Purpose: hosting and content delivery. SCCs apply.

vercel.com/legal/privacy-policy ↗

5. International data transfers

Several of our subprocessors (Stripe, SendGrid, Anthropic, OpenAI, Cloudflare, Sentry, PostHog, Vercel) process data outside the UK and EEA, primarily in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum, which provide equivalent protections to UK and EU data protection law.

6. Data retention

  • Active accounts: Data retained while your account is open.
  • Deleted accounts: When you delete your account in the app or on the website, your account, your appeals and the rest of your data are deleted from our database immediately, and we delete the files held with them — what you uploaded, and the documents attached to your appeals. Two things can survive that step: a message from an authority that was never linked to one of your appeals, and some files — particularly on a very large account, or if something goes wrong while they are being removed. Email us and we will remove anything of yours that is left. If you ask us to delete your account by email instead, we do it within one month of receiving your request or, if later, any identity information we reasonably asked you for — we do not take the extra time the law allows for deletion requests. Anonymised appeal outcome data may be retained for service improvement.
  • Payment records: Retained for 7 years for tax and accounting compliance.

7. Your rights (UK GDPR)

Under UK GDPR, you have the right to:

  • Access — request a copy of your personal data.
  • Deletion — ask us to delete your account and all associated data.
  • Portability — receive your data in a machine-readable format (JSON export available in account settings).
  • Rectification — correct inaccurate data we hold.
  • Objection — object to how we process your data.
  • Restriction — limit how we use your data while a dispute is resolved.

Email privacy@usebeatit.com to exercise any right. We will respond without undue delay, and within one month. If we have to check who you are before we can deal with your request, that month starts when we receive what we asked you for. If you have asked for a copy of your data and we need more detail to find it, the clock pauses between our question and your answer. If your request is complex, or you make several, we can take up to two months longer — if that happens, we will tell you why within the first month.

Complaining to us: if you are unhappy with how we have handled your personal data, you can complain to us directly. Email privacy@usebeatit.com or support@usebeatit.com — both reach the same people. Putting "Data protection complaint" in the subject line helps us spot it, but you do not have to: any message telling us you are unhappy with how we have handled your data counts, and you do not need to have contacted us before.

We will acknowledge your complaint within 30 days of receiving it. We will then look into it without undue delay, keep you posted on how it is going, and tell you the outcome.

Being straight with you about what receives it: that inbox is read and handled by a person, and we do not yet have a complaint form or automated tracking. What we promise above applies regardless.

You can also complain to the ICO ↗.

8. CCPA — California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • The right to know what personal information we collect and how it is used.
  • The right to delete your personal information.
  • The right to opt out of the sale of your personal information. We do not sell personal information.
  • The right to non-discrimination for exercising your CCPA rights.

To exercise CCPA rights, email privacy@usebeatit.com.

9. Cookies & local storage

We use only essential cookies, to keep you signed in. Cloudflare Turnstile protects signup and appeal submission from bots without setting cookies or identifying you. We set no advertising cookies, and no third-party cookies that track you across other websites.

Our product analytics (PostHog) stores a first-party identifier in your browser's local storage rather than in cookies, so we can understand how the service is used. It stays first-party and is never used for cross-site advertising. We rely on legitimate interests for this (see section 3); to opt out, switch on your browser's "Do Not Track" setting, or contact us using the details in section 7.

Published tribunal decisions we collect

Separately from the information our customers give us, we collect published parking-appeal decisions from public tribunal registers to learn which arguments win. Some of those published decisions are about identifiable people. That collection has its own notice, which explains what we hold, what has gone wrong and been fixed, and the rights you have: usebeatit.com/privacy/tribunal-records.

10. Changes

We will notify you by email of any material changes. The latest version is always at usebeatit.com/privacy.

Contact

Privacy questions, requests to use your rights, and data protection complaints: privacy@usebeatit.com (or support@usebeatit.com, which reaches the same place).

Get the Beat It app

Download on theApp StoreGET IT ONGoogle Play