Privacy Notice

PlanProve

Version 2.2 — Last updated: 26 August 2026

Controller:
Make My Plan Ltd
Trading name:
PlanProve
Website:
planprove.com
Contact email:
info@planprove.com
ICO Registration:
ZC114654

1. Who we are and what this notice covers

Make My Plan Ltd (company number 16887298) is the data controller for personal data collected through PlanProve ("we", "us", "our"). PlanProve is a case management platform ("CRM") built for planning professionals, helping them manage their caseload, track applications, and collaborate with clients on individual projects.

This Privacy Notice explains what personal data we collect, why we collect it, the legal basis we rely on, how long we keep it, who we share it with, and your rights under UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.

This notice applies to:

  • Planning professionals, including planning consultants and related built-environment professionals ("Professionals"), who use PlanProve to manage their work
  • Clients — homeowners or other individuals invited by a Professional to view progress on a specific project ("Clients"). Clients do not create an independent account; access is granted by a Professional through a Site invite
  • Visitors to planprove.com who have not yet created an account

2. Personal data we collect

2.1 Professionals

When you register and use PlanProve as a planning professional, we collect:

  • Identity data: your name, email address, professional role, company or practice name (if applicable)
  • Account data: subscription tier, billing date, Founding Professional status
  • Professional profile data: areas of expertise, service areas, practice details
  • Payment data: billing details processed and held by Stripe (via Stripe Connect) — we do not store your full card details
  • Site and project data: sites and projects you create, client details you enter, documents you upload, case notes, conditions, and deadlines
  • New Business data: leads you log, fee proposals you send, and invoices you issue
  • Time and billing data: time entries you record against your projects
  • Practice data: if you belong to a shared practice account, your name, email and role, and the sites you're granted access to, may be visible to other authorised members of that practice
  • Contacts data: details of specialists and third parties you save to your Contacts directory
  • Usage data: platform activity, features used, AI Planning Assistant interactions

2.2 Clients (homeowners and others invited to view a project)

PlanProve does not market to or independently recruit Clients. A Client only has access to PlanProve because a Professional has invited them to view progress on a specific project. When a Client accepts an invite, we collect:

  • Identity data: your name and email address, provided by the Professional when the invite is created, or confirmed by you when accepting it
  • Account data: password (stored as a secure hash), date the invite was accepted
  • Access data: which project(s) you've been invited to view, and which documents the Professional has chosen to share with you
  • Technical and usage data: IP address, browser and device type, cookie identifiers (with your consent), pages visited while using your read-only project view

For this category of data, the Professional (or their practice) is the data controller and PlanProve acts as data processor.

2.3 Data we collect automatically

When you visit planprove.com, we automatically collect certain technical data including your IP address, browser and device type, referring URL, and pages visited. We use PostHog for analytics. Analytics cookies are only set with your prior consent — see Section 8.

3. Why we process your data and our legal basis

UK GDPR requires us to have a lawful basis for each type of processing. We rely on the following:

PurposeData usedLawful basisApplies to
Creating and managing your accountName, email, password hashContract (Art. 6(1)(b))Professionals & Clients
Client collaboration (Site invites, read-only project view)Client name, email, invite token, documents marked visibleContract (Art. 6(1)(b)) — on the professional's instructionProfessionals & Clients
Fee proposals and invoicing (via Stripe Connect)Billing details, invoice records, Stripe payment tokensContract (Art. 6(1)(b))Professionals
Shared practice accessName, email, role, site access permissionsContract (Art. 6(1)(b))Professionals
AI-assisted deadline and condition extraction, and the Planning AssistantUploaded documents, queries submitted, project contextLegitimate interests — providing the core service (Art. 6(1)(f))Professionals
Platform analytics and improvementUsage data, search logs, interaction dataLegitimate interests — product improvement (Art. 6(1)(f))Professionals & Clients
Sending service emails (account, project updates)Email addressContract (Art. 6(1)(b))Professionals & Clients
Marketing emails (product news)Email addressConsent (Art. 6(1)(a))Professionals only — we do not market to Clients
Security and fraud preventionIP, device, activity logsLegitimate interests — platform security (Art. 6(1)(f))Professionals & Clients
Legal obligations (accounting, tax records)Billing recordsLegal obligation (Art. 6(1)(c))Professionals

4. Who we share your data with

We do not sell your personal data. We share data only with trusted third-party processors who act under our instruction, each subject to a Data Processing Agreement:

ProcessorPurposeLocationData shared
Supabase Inc.Database and file storage — all platform dataEuropean Union (Ireland, eu-west-1)All user and project data
Anthropic PBCAI Planning Assistant, deadline and condition extractionUSA (UK IDTA / UK Addendum)Documents, queries, and project context submitted to the assistant
Stripe Inc.Payment processing, fee proposals and invoicing (Stripe Connect)USA (UK IDTA / UK Addendum)Billing details, payment tokens, invoice records
Resend Inc.Transactional and service email deliveryUSA (UK IDTA / UK Addendum)Email address, message content
Vercel Inc.Application hosting and deploymentUSA / EU (UK IDTA / UK Addendum)Technical access logs, IP addresses, and authentication session data in transit (not stored)
PostHog Inc.Product analyticsEuropean Union (EU-hosted instance)Usage data, session data, anonymised event data

Supabase and PostHog process data within the European Union, so a UK GDPR Article 46 transfer safeguard is not required for those transfers. Transfers to Anthropic, Stripe, Resend and Vercel in the USA are protected by the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses — the correct UK-specific transfer mechanisms since March 2022, rather than the EU SCCs alone.

Anthropic, Stripe, Resend and Vercel all incorporate the UK International Data Transfer Agreement or the UK Addendum into their standard commercial terms — confirmed directly from each vendor's published Data Processing Addendum. This applies automatically as a customer on their normal terms, with nothing separate to request or sign.

We may also share data with: law enforcement or regulatory authorities where legally required; professional advisers (lawyers, accountants) under confidentiality obligations; and, where you are part of a shared practice, other authorised members of that practice for the sites and data your practice administrator has given you access to.

5. How long we keep your data

We do not keep personal data longer than necessary for the purpose for which it was collected:

Data typeRetention periodReason
Account and profile dataDuration of account, plus 30 days after deletionContract performance; time for account recovery
Site, project data and documentsDuration of account, plus 30 days after deletionContract performance
Client (homeowner) access dataDuration of the invite plus the professional's own account retentionProcessed on the professional's instruction as controller for this data
Billing and payment records6 years from the end of the relevant accounting periodLegal obligation — HMRC / Companies Act
AI assistant activity (documents processed, queries)90 days from last interactionLegitimate interests — service quality
Analytics / usage data12 months (anonymised thereafter)Legitimate interests — product improvement
Security and access logs90 daysLegitimate interests — fraud prevention
Marketing consent recordsUntil consent withdrawn, plus 3 yearsLegal obligation — demonstrating consent

A more detailed Data Export and Retention Policy is published on this site, setting out the full retention schedule and export process, particularly for practice customers who require this as part of their own due diligence.

6. Your rights

Under UK GDPR you have the following rights. To exercise any of them, contact us at info@planprove.com. We will respond within one month.

Right of access: You can request a copy of all personal data we hold about you (a Subject Access Request).

Right to rectification: You can ask us to correct inaccurate or incomplete data.

Right to erasure: You can request deletion of your data where we no longer have a legal basis to hold it. Note: billing records must be kept for 7 years.

Right to data portability: You can request your data in a machine-readable format via your account settings.

Right to restrict processing: You can ask us to pause processing your data while a complaint is investigated.

Right to object: You can object to processing based on legitimate interests (e.g. analytics). We will stop unless we have compelling legitimate grounds.

Right to withdraw consent: Where processing is based on consent (e.g. marketing emails, analytics cookies), you can withdraw it at any time.

Right to complain directly to us: Under the Data (Use and Access) Act 2025, you have the right to raise a complaint about how we've handled your personal data directly with us, before or instead of going to the ICO. Email info@planprove.com with "Data Complaint" in the subject line. We will acknowledge your complaint within 30 days and keep a record of how it was resolved.

Right to complain to the ICO: You also have the right to lodge a complaint with the Information Commissioner's Office: ico.org.uk or 0303 123 1113.

7. Automated decision-making and AI

PlanProve uses an AI Planning Assistant powered by Anthropic's Claude models, available to Professionals. It is used to extract deadlines and planning conditions from documents you upload, and to answer questions about your own sites and projects. It does not draft planning statements or provide professional planning judgement — that remains entirely with you.

The AI Planning Assistant does not make automated decisions that have legal or similarly significant effects on any individual — it is a productivity tool for Professionals only. Clients do not interact with the AI Planning Assistant.

Content you submit to the AI Planning Assistant is processed by Anthropic as a data processor acting under our instruction. We do not use this data to profile users or make automated decisions about eligibility for services.

8. Cookies and tracking

We use the following categories of cookies:

CategoryExamplesConsent required?Purpose
Strictly necessarySupabase session cookie, Stripe sessionNo — essential for the site to functionAuthentication, security, payment processing
AnalyticsPostHog analytics cookiesYes — opt-in consent requiredUnderstanding how users use the platform to improve it

You can manage your cookie preferences at any time via the cookie banner on our website.

9. How we protect your data

We implement appropriate technical and organisational measures including:

  • All data stored in Supabase with Row Level Security (RLS) enforced
  • Passwords stored as bcrypt hashes — never in plain text
  • HTTPS encryption in transit via Vercel
  • Optional two-factor authentication (TOTP-based) available to all Professional accounts, not just administrators, with a recovery path through a practice admin
  • Rate limiting and security headers on all platform endpoints
  • Access to user data restricted to the data controller (Joel Grist, Director of Make My Plan Ltd) and no third parties beyond the processors listed in Section 4
  • Regular security reviews as part of the development process

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay.

10. Changes to this notice

We may update this Privacy Notice from time to time. We will notify you of material changes by email or via a notice on the platform. The date at the top of this document reflects the most recent version.

11. Contact us and complaints

For any questions about this notice or to exercise your rights:

If you are unhappy with how we have handled your data, you can raise it with us directly first (see Section 6), or complain to the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF