Privacy Notice

PlanProve

Version 1.0 — Last updated: 14 April 2026

Controller:
Make My Plan Ltd
Trading name:
PlanProve
Website:
planprove.com
Contact email:
info@planprove.com
ICO Registration:
ZC114654

1. Who we are and what this notice covers

Make My Plan Ltd (company number 16887298) is the data controller for personal data collected through PlanProve ("we", "us", "our"). PlanProve is an online marketplace connecting homeowners seeking planning permission with qualified planning professionals.

This Privacy Notice explains what personal data we collect, why we collect it, the legal basis we rely on, how long we keep it, who we share it with, and your rights under UK GDPR and the Data Protection Act 2018.

This notice applies to:

  • Homeowners and property owners ("Applicants") who use PlanProve to find planning professionals
  • Planning professionals including architects, architectural technologists, and planning consultants ("Professionals") who subscribe to PlanProve
  • Visitors to planprove.com who have not yet created an account

2. Personal data we collect

2.1 Applicants (homeowners)

When you create an account and use PlanProve as a homeowner, we collect:

  • Identity data: your name and email address
  • Account data: password (stored as a secure hash - we never store passwords in plain text), account creation date
  • Project data: property address, project description, planning application type, project status and outcome
  • Document data: planning documents you upload, including decision notices and condition details
  • Communications: messages exchanged with planning professionals through the platform
  • Usage data: pages visited, features used, search queries, how you interact with the AI Planning Assistant
  • Technical data: IP address, browser type, device type, cookie identifiers (with your consent - see Section 8)

2.2 Professionals (planning specialists)

When you register as a planning professional, we collect:

  • Identity data: your name, email address, professional role, company name (if applicable)
  • Account data: subscription tier, billing date
  • Professional profile data: areas of expertise, service areas, practice details
  • Payment data: billing details processed and held by Stripe - we do not store your full card details
  • Project data: projects created, client project details, enquiries received and sent
  • Communications: messages with clients through the platform
  • Usage data: platform activity, features used, AI Planning Assistant interactions

2.3 Data we collect automatically

When you visit planprove.com, we automatically collect certain technical data including your IP address, browser and device type, referring URL, and pages visited. We use PostHog for analytics. Analytics cookies are only set with your prior consent - see Section 8.

3. Why we process your data and our legal basis

UK GDPR requires us to have a lawful basis for each type of processing. We rely on the following:

PurposeData usedLawful basisApplies to
Creating and managing your accountName, email, password hashContract (Art. 6(1)(b))Applicants & Professionals
Connecting you with planning professionals / homeownersProject details, profile, messagesContract (Art. 6(1)(b))Both
Processing subscription paymentsBilling email, Stripe payment tokenContract (Art. 6(1)(b))Professionals
AI Planning AssistantQueries submitted, project contextLegitimate interests - improving planning outcomes (Art. 6(1)(f))Both
Platform analytics and improvementUsage data, search logs, interaction dataLegitimate interests - product improvement (Art. 6(1)(f))Both
Sending service emails (account, project updates)Email addressContract (Art. 6(1)(b))Both
Marketing emails (newsletters, product news)Email addressConsent (Art. 6(1)(a))Both
Security and fraud preventionIP, device, activity logsLegitimate interests - platform security (Art. 6(1)(f))Both
Legal obligations (accounting, tax records)Billing recordsLegal obligation (Art. 6(1)(c))Professionals

4. Who we share your data with

We do not sell your personal data. We share data only with trusted third-party processors who act under our instruction, each subject to a Data Processing Agreement:

ProcessorPurposeLocationData shared
Supabase Inc.Database hosting - all platform dataUSA (SCCs in place)All user and project data
Anthropic PBCAI Planning Assistant processingUSA (SCCs in place)Queries and project context submitted to the assistant
Stripe Inc.Payment processingUSA (SCCs in place)Billing email, payment token
Resend Inc.Transactional and service email deliveryUSA (SCCs in place)Email address, message content
Vercel Inc.Website hosting and deploymentUSA / EU (SCCs in place)Technical access logs, IP addresses
PostHog Inc.Product analytics (with your consent)EU (Ireland / Germany)Usage data, session data, anonymised event data

All transfers to processors in the USA are protected by Standard Contractual Clauses (SCCs) under UK GDPR Article 46.

We may also share data with: law enforcement or regulatory authorities where legally required; professional advisers (lawyers, accountants) under confidentiality obligations.

5. How long we keep your data

We do not keep personal data longer than necessary for the purpose for which it was collected:

Data typeRetention periodReason
Account and profile dataDuration of account, plus 30 days after deletionContract performance; time for account recovery
Project data and documentsDuration of account, plus 30 days after deletionContract performance
Billing and payment records7 years from transaction dateLegal obligation - HMRC / Companies Act
AI assistant conversation history90 days from last interactionLegitimate interests - service quality
Analytics / usage dataUp to 7 years (in line with our analytics processor's retention policy)Legitimate interests - product improvement
Search logs (identifying period)90 daysLegitimate interests, security and audit
Search logs (anonymised)A further 9 months (12 months total from creation)Legitimate interests, product analytics with personal identifiers removed
Security and access logs90 daysLegitimate interests - fraud prevention
Marketing consent recordsUntil consent withdrawn, plus 3 yearsLegal obligation - demonstrating consent

Search logs are personal data while they include your user identifier. After 90 days we remove your identifier from each search log row, keeping only the anonymised search content for aggregate product analytics. The fully anonymised rows are then deleted entirely after 12 months.

6. Your rights

Under UK GDPR you have the following rights. To exercise any of them, contact us at info@planprove.com. We will respond within one month.

Right of access: You can request a copy of all personal data we hold about you (a Subject Access Request).

Right to rectification: You can ask us to correct inaccurate or incomplete data.

Right to erasure: You can request deletion of your data where we no longer have a legal basis to hold it. Note: billing records must be kept for 7 years.

Right to data portability: You can request your data in a machine-readable format via your account settings.

Right to restrict processing: You can ask us to pause processing your data while a complaint is investigated.

Right to object: You can object to processing based on legitimate interests (e.g. analytics). We will stop unless we have compelling legitimate grounds.

Right to withdraw consent: Where processing is based on consent (e.g. marketing emails, analytics cookies), you can withdraw it at any time.

Right to complain: You have the right to lodge a complaint with the ICO: ico.org.uk or 0303 123 1113.

7. Automated decision-making and AI

PlanProve uses an AI Planning Assistant powered by Anthropic's Claude API. This assistant provides information and guidance about the UK planning system. It does not make automated decisions that have legal or similarly significant effects on you - it is an information tool only.

Queries you submit to the AI Planning Assistant are processed by Anthropic as a data processor acting under our instruction. We do not use this data to profile users or make automated decisions about eligibility for services.

8. Cookies and tracking

We use the following categories of cookies:

CategoryExamplesConsent required?Purpose
Strictly necessarySupabase session cookie, Stripe sessionNo - essential for the site to functionAuthentication, security, payment processing
AnalyticsPostHog analytics cookiesYes - opt-in consent requiredUnderstanding how users use the platform to improve it

You can manage your cookie preferences at any time via the cookie banner on our website.

9. How we protect your data

We implement appropriate technical and organisational measures including:

  • All data stored in Supabase with Row Level Security (RLS) enforced
  • Passwords stored as bcrypt hashes - never in plain text
  • HTTPS encryption in transit via Vercel
  • Two-factor authentication on all administrator accounts
  • Rate limiting and security headers on all platform endpoints
  • Access to user data restricted to authorised personnel and no third parties beyond the processors listed in Section 4
  • Regular security reviews as part of the development process

In the event of a personal data breach that is likely to result in a risk to individuals, we will notify the ICO within 72 hours and affected individuals without undue delay.

10. Changes to this notice

We may update this Privacy Notice from time to time. We will notify you of material changes by email or via a notice on the platform. The date at the top of this document reflects the most recent version.

11. Contact us and complaints

For any questions about this notice or to exercise your rights:

If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF