# What the official ParkSmarter app does with your privacy *A plain-language look at the official **ParkSmarter** app for Android (`com.ipsgroupinc.parksmarter`, version 4.4.0), and how **BigBrainParking** — this open-source alternative — is different.* This was written by inspecting the official app's own files (its permission list and its program code). It's meant to be readable by anyone, not just programmers. Where we're **sure**, we say so; where we're making an educated guess, we say that too. --- ## The short version - **Your exact location is sent to ParkSmarter's servers whenever you look at the map** in the official app — automatically, just by opening it, not only when you ask it to "find parking near me." - **The app also carries a stack of tracking tools** (Segment, Amplitude, Firebase, Sentry) that quietly report what you do and your device's identity to outside companies. - **It can read a permanent hardware ID from your phone and send it to ParkSmarter.** - **Good news:** it **cannot** track your location while the app is closed. - **BigBrainParking removes the tracking entirely** and only sends your location when *you* deliberately tap "My location" and search. --- ## First, why does this matter? "Location data" is a record of where you physically are. On its own, one location isn't a big deal. But a *stream* of them — collected quietly and often — reveals where you live, work, worship, and who you visit. When that's combined with a permanent ID for your phone and shared with advertising/analytics companies, it becomes a profile of you that can be sold, leaked, or subpoenaed. So the questions that matter are: **who collects it, how often, is it tied to your identity, and does it leave in ways you didn't ask for?** --- ## When does the official app send your location to ParkSmarter? **To ParkSmarter's own servers, your GPS is used for one thing: finding nearby meters.** There are exactly two requests that carry your coordinates (finding meters near a point); your location is **not** attached to logging in, starting a parking session, or paying. That part is reasonable. **The catch is *when* it happens.** The official app is built to grab your live GPS and ask ParkSmarter "what meters are near me?" **automatically when you open the map** — you don't have to tap anything. So simply browsing the app quietly sends your precise location to ParkSmarter's servers. > **How sure are we?** *Fairly sure.* The code clearly reads your current GPS and has a > "nearby meters" feature wired to the map. Confirming the exact moment it fires would take > watching the app's live network traffic, which we haven't done yet. **BigBrainParking does the opposite on purpose:** it opens on your **last parking lot** (from your own history, not your GPS), and it only sends your location when you *explicitly* tap **"My location"** and then search. --- ## The bigger privacy concerns These are things the official app *can* do beyond the parking API itself. They're taken from the app's official permission list and the tracking libraries built into it. ### 1. Hidden tracking/analytics companies (the biggest one) The app bundles four separate tracking/telemetry toolkits: - **Segment** — a "customer data platform." Its whole job is to collect what you do in the app and fan it out to many other companies. - **Amplitude** — product-analytics; records your actions to study behavior. - **Firebase** (Google) and **Sentry** — Google's analytics/crash tools and an error tracker. These typically collect: **which screens you visit and when, your device model, and your IP address** (which reveals your rough city/neighborhood), and often an **advertising ID** (a code used to follow you across different apps). Even without your exact GPS, this is a detailed behavioral profile shared with outside companies. > **BigBrainParking has none of these.** No Segment, no Amplitude, no Firebase, no Sentry, > no ad-ID, no Google services at all. ### 2. A permanent hardware ID sent to ParkSmarter The app is allowed to **read phone/device identifiers** (the "read phone state" permission), and it has a feature that sends your device's **IMEI number** — a permanent serial number for your phone — to ParkSmarter. Unlike a password you can change, this ID is fixed, so it can be used to recognize your specific phone forever. > **BigBrainParking never reads or sends this.** ### 3. Other capabilities worth knowing about - **Install tracking** — records how you found/installed the app (via the Google Play "install referrer"), tied to your Play account. - **Wi-Fi scanning permission** — can see the Wi-Fi networks around you, which can be used to *estimate your location even without GPS*. - **Microphone permission** — unusual for a parking app. It may be an unused leftover from a library, but the app is allowed to access your microphone. - **Google push messaging (FCM)** — notifications are routed through Google, which links your device to Google and to ParkSmarter's messaging system. --- ## To be fair — what it does *not* do - **No background location tracking.** This is important: the app can only see your location **while you have it open and are using it**. It has the everyday location permission but **not** the special "all the time / in the background" one, so it can't follow you around when the app is closed. - Your location going to ParkSmarter is genuinely limited to the "find nearby meters" feature — it isn't stapled onto payments or your account details. --- ## Side-by-side | | Official ParkSmarter app | BigBrainParking | | --- | --- | --- | | Sends GPS to ParkSmarter | **Automatically** when you open the map | **Only** when you tap "My location" and search | | Opens the map on… | Your current GPS location | Your **last parking lot** (not your GPS) | | Hidden analytics/tracking SDKs | Segment, Amplitude, Firebase, Sentry | **None** | | Advertising ID / cross-app tracking | Likely collected | **Never** | | Sends a permanent device ID (IMEI) | Yes (feature exists) | **Never** | | Google services required | Yes (Firebase, FCM) | **None** (runs on GrapheneOS) | | Background location | No | No | | Source code you can inspect | No (closed) | **Yes** (this repo) | --- ## How we checked (for the curious) - **Permissions** come from the app's own `AndroidManifest` (the official list Android shows). Confirmed present: precise + approximate location, read-phone-state, Wi-Fi state, microphone, camera, Google push, install-referrer. Confirmed **absent**: background location. - **Tracking libraries** and the **location-bearing requests** (`getMetersByLocation` / `getLimitedMetersByLocation`) and the **IMEI-sending** device-registration request come from reading the app's decompiled program code (version 4.4.0). - **Educated guesses** (clearly labeled above) are the auto-send-on-open behavior and the advertising-ID collection — code strongly suggests them, but a live network capture would make them certain. We can do that capture if you want proof. *Not affiliated with or endorsed by IPS Group / ParkSmarter. This is an independent, good-faith analysis of a publicly distributed app for the purpose of building a privacy-respecting alternative. Findings reflect version 4.4.0 and could change in later versions.*