PlanProve
Version 2.2 — Last updated: 26 August 2026
Make My Plan Ltd (company number 16887298) is the data controller for personal data collected through PlanProve ("we", "us", "our"). PlanProve is a case management platform ("CRM") built for planning professionals, helping them manage their caseload, track applications, and collaborate with clients on individual projects.
This Privacy Notice explains what personal data we collect, why we collect it, the legal basis we rely on, how long we keep it, who we share it with, and your rights under UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
This notice applies to:
When you register and use PlanProve as a planning professional, we collect:
PlanProve does not market to or independently recruit Clients. A Client only has access to PlanProve because a Professional has invited them to view progress on a specific project. When a Client accepts an invite, we collect:
For this category of data, the Professional (or their practice) is the data controller and PlanProve acts as data processor.
When you visit planprove.com, we automatically collect certain technical data including your IP address, browser and device type, referring URL, and pages visited. We use PostHog for analytics. Analytics cookies are only set with your prior consent — see Section 8.
UK GDPR requires us to have a lawful basis for each type of processing. We rely on the following:
| Purpose | Data used | Lawful basis | Applies to |
|---|---|---|---|
| Creating and managing your account | Name, email, password hash | Contract (Art. 6(1)(b)) | Professionals & Clients |
| Client collaboration (Site invites, read-only project view) | Client name, email, invite token, documents marked visible | Contract (Art. 6(1)(b)) — on the professional's instruction | Professionals & Clients |
| Fee proposals and invoicing (via Stripe Connect) | Billing details, invoice records, Stripe payment tokens | Contract (Art. 6(1)(b)) | Professionals |
| Shared practice access | Name, email, role, site access permissions | Contract (Art. 6(1)(b)) | Professionals |
| AI-assisted deadline and condition extraction, and the Planning Assistant | Uploaded documents, queries submitted, project context | Legitimate interests — providing the core service (Art. 6(1)(f)) | Professionals |
| Platform analytics and improvement | Usage data, search logs, interaction data | Legitimate interests — product improvement (Art. 6(1)(f)) | Professionals & Clients |
| Sending service emails (account, project updates) | Email address | Contract (Art. 6(1)(b)) | Professionals & Clients |
| Marketing emails (product news) | Email address | Consent (Art. 6(1)(a)) | Professionals only — we do not market to Clients |
| Security and fraud prevention | IP, device, activity logs | Legitimate interests — platform security (Art. 6(1)(f)) | Professionals & Clients |
| Legal obligations (accounting, tax records) | Billing records | Legal obligation (Art. 6(1)(c)) | Professionals |
We do not sell your personal data. We share data only with trusted third-party processors who act under our instruction, each subject to a Data Processing Agreement:
| Processor | Purpose | Location | Data shared |
|---|---|---|---|
| Supabase Inc. | Database and file storage — all platform data | European Union (Ireland, eu-west-1) | All user and project data |
| Anthropic PBC | AI Planning Assistant, deadline and condition extraction | USA (UK IDTA / UK Addendum) | Documents, queries, and project context submitted to the assistant |
| Stripe Inc. | Payment processing, fee proposals and invoicing (Stripe Connect) | USA (UK IDTA / UK Addendum) | Billing details, payment tokens, invoice records |
| Resend Inc. | Transactional and service email delivery | USA (UK IDTA / UK Addendum) | Email address, message content |
| Vercel Inc. | Application hosting and deployment | USA / EU (UK IDTA / UK Addendum) | Technical access logs, IP addresses, and authentication session data in transit (not stored) |
| PostHog Inc. | Product analytics | European Union (EU-hosted instance) | Usage data, session data, anonymised event data |
Supabase and PostHog process data within the European Union, so a UK GDPR Article 46 transfer safeguard is not required for those transfers. Transfers to Anthropic, Stripe, Resend and Vercel in the USA are protected by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — the correct UK-specific transfer mechanisms since March 2022, rather than the EU SCCs alone.
Anthropic, Stripe, Resend and Vercel all incorporate the UK International Data Transfer Agreement or the UK Addendum into their standard commercial terms — confirmed directly from each vendor's published Data Processing Addendum. This applies automatically as a customer on their normal terms, with nothing separate to request or sign.
We may also share data with: law enforcement or regulatory authorities where legally required; professional advisers (lawyers, accountants) under confidentiality obligations; and, where you are part of a shared practice, other authorised members of that practice for the sites and data your practice administrator has given you access to.
We do not keep personal data longer than necessary for the purpose for which it was collected:
| Data type | Retention period | Reason |
|---|---|---|
| Account and profile data | Duration of account, plus 30 days after deletion | Contract performance; time for account recovery |
| Site, project data and documents | Duration of account, plus 30 days after deletion | Contract performance |
| Client (homeowner) access data | Duration of the invite plus the professional's own account retention | Processed on the professional's instruction as controller for this data |
| Billing and payment records | 6 years from the end of the relevant accounting period | Legal obligation — HMRC / Companies Act |
| AI assistant activity (documents processed, queries) | 90 days from last interaction | Legitimate interests — service quality |
| Analytics / usage data | 12 months (anonymised thereafter) | Legitimate interests — product improvement |
| Security and access logs | 90 days | Legitimate interests — fraud prevention |
| Marketing consent records | Until consent withdrawn, plus 3 years | Legal obligation — demonstrating consent |
A more detailed Data Export and Retention Policy is published on this site, setting out the full retention schedule and export process, particularly for practice customers who require this as part of their own due diligence.
Under UK GDPR you have the following rights. To exercise any of them, contact us at info@planprove.com. We will respond within one month.
Right of access: You can request a copy of all personal data we hold about you (a Subject Access Request).
Right to rectification: You can ask us to correct inaccurate or incomplete data.
Right to erasure: You can request deletion of your data where we no longer have a legal basis to hold it. Note: billing records must be kept for 7 years.
Right to data portability: You can request your data in a machine-readable format via your account settings.
Right to restrict processing: You can ask us to pause processing your data while a complaint is investigated.
Right to object: You can object to processing based on legitimate interests (e.g. analytics). We will stop unless we have compelling legitimate grounds.
Right to withdraw consent: Where processing is based on consent (e.g. marketing emails, analytics cookies), you can withdraw it at any time.
Right to complain directly to us: Under the Data (Use and Access) Act 2025, you have the right to raise a complaint about how we've handled your personal data directly with us, before or instead of going to the ICO. Email info@planprove.com with "Data Complaint" in the subject line. We will acknowledge your complaint within 30 days and keep a record of how it was resolved.
Right to complain to the ICO: You also have the right to lodge a complaint with the Information Commissioner's Office: ico.org.uk or 0303 123 1113.
PlanProve uses an AI Planning Assistant powered by Anthropic's Claude models, available to Professionals. It is used to extract deadlines and planning conditions from documents you upload, and to answer questions about your own sites and projects. It does not draft planning statements or provide professional planning judgement — that remains entirely with you.
The AI Planning Assistant does not make automated decisions that have legal or similarly significant effects on any individual — it is a productivity tool for Professionals only. Clients do not interact with the AI Planning Assistant.
Content you submit to the AI Planning Assistant is processed by Anthropic as a data processor acting under our instruction. We do not use this data to profile users or make automated decisions about eligibility for services.
We use the following categories of cookies:
| Category | Examples | Consent required? | Purpose |
|---|---|---|---|
| Strictly necessary | Supabase session cookie, Stripe session | No — essential for the site to function | Authentication, security, payment processing |
| Analytics | PostHog analytics cookies | Yes — opt-in consent required | Understanding how users use the platform to improve it |
You can manage your cookie preferences at any time via the cookie banner on our website.
We implement appropriate technical and organisational measures including:
In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay.
We may update this Privacy Notice from time to time. We will notify you of material changes by email or via a notice on the platform. The date at the top of this document reflects the most recent version.
For any questions about this notice or to exercise your rights:
If you are unhappy with how we have handled your data, you can raise it with us directly first (see Section 6), or complain to the Information Commissioner's Office (ICO):