Privacy Policy
Last updated: 13 August 2026
ParkPilot is an independent app that shows Lightning Lane and standby wait times for the Walt Disney World theme parks and sends you a notification when a ride you are watching becomes available. This policy explains what we collect, why, and what you can do about it. It applies to the ParkPilot mobile apps for iOS and Android and to the ParkPilot website.
What we collect
- Your username and password. Required to create an account so your ride alerts follow you between devices. Passwords are stored only as a salted BCrypt hash — we cannot read them, and neither can anyone who obtains a copy of the database.
- Your ride alerts. Which attractions you asked to be notified about.
- A push notification token for each device you sign in on. This is an anonymous identifier issued by Apple, Google, or Expo that lets us deliver a notification to that specific installation. It is not tied to your phone number, advertising identifier, or hardware serial.
- An optional device name (for example "Tyler's iPhone"), only so you can recognise your own devices.
We do not ask for an email address, phone number, real name, payment details, contacts, photos, or location. The app never requests location permission — it does not need to know where you are to tell you a Lightning Lane opened.
What we do not do
- We do not sell or rent your personal information to anyone.
- We do not track you across other apps or websites.
- We do not use advertising identifiers, and we serve no advertising.
- We do not build advertising or marketing profiles about you.
How we use it
Only to run the service: to sign you in, to remember which rides you are watching, and to deliver the notifications you asked for. A background job on our server checks the parks roughly every 45 seconds and sends a push when one of your watched rides opens up.
Who we share it with
- Expo (Expo Application Services) relays our notifications to Apple and Google. It receives your push token and the text of the notification (the ride name and its wait time). See Expo's privacy policy.
- Apple Push Notification service and Firebase Cloud Messaging deliver the notification to your device, as they do for every app on the platform.
- Our hosting provider, which stores the database on our behalf.
That is the complete list. We disclose information otherwise only if legally compelled to.
Where wait times come from
Wait times and Lightning Lane availability are gathered from publicly available park data feeds. This is information about rides, not about you, and nothing about your account is sent to those sources.
How long we keep it
Your account and alerts are kept until you delete them. Push tokens are removed when you sign out, and automatically when the push service tells us an app has been uninstalled.
Deleting your account
You can delete your account and all associated data from inside the app: Settings → Delete account. This is immediate and permanent. It removes your username, password hash, every ride alert, and every registered device. No copy is retained.
If you can no longer access the app, email support@softwarebydavis.com from a device signed in to the account and we will delete it for you.
Security
All traffic between the app and our servers uses HTTPS. Your sign-in token is stored in the iOS Keychain or Android Keystore, not in plain application storage.
Children
ParkPilot is not directed at children under 13 and we do not knowingly collect information from them. If you believe a child has created an account, contact us and we will remove it.
Your rights
Depending on where you live you may have the right to access, correct, export, or delete your personal information. Deletion is available directly in the app; for anything else, contact us at the address below and we will respond within 30 days.
Changes
If this policy changes materially we will update the date at the top and note the change in the app.