Plan The Day

Privacy Policy

Last updated: 12 August 2026

Version: v0.6

Privacy at a glance

A short summary of how Plan The Day handles personal data. It does not replace the full Privacy Policy below.

  • Information we collectAccount, Event-planning, Supplier/contact, Contract and billing-related information.
  • How we use itTo operate and secure Plan The Day, support authorised collaboration, manage payments and understand product use.
  • Who we share it withNecessary providers, plus people an authorised user gives access to.
  • How long we keep itOnly as long as necessary to provide the service or meet legal obligations.
  • Your rightsYou can ask us to access, correct or delete your personal data.

10BIT LABS LTD, trading as Plan The Day ("Plan The Day", "we", "us" or "our"), explains in this Privacy Policy how we collect, use, store and share personal data when you use Plan The Day, contact us, purchase a Plan The Day product or otherwise interact with us.

The information we collect

Information you provide

Depending on how you use Plan The Day, you may provide account information, including your email address and optional first and last name; Event information, such as an Event name, type, date, location, Timeline Items and notes; Supplier and contact information; Contract files and associated details; access-sharing and invitation information; support correspondence; and payment-related information, such as the product purchased, payment status, amount, currency, Stripe customer or subscription identifiers, and renewal date.

Payments are processed by Stripe. We do not receive or store your full payment-card details.

Information collected automatically

When you use Plan The Day, we and our service providers may process limited technical and security information, such as IP address, browser and device information, pages or features used, authentication and security events, and diagnostic information necessary to operate, protect and troubleshoot the service.

We use Sentry for error monitoring only when it is enabled in the relevant environment. Our implementation is designed to remove user identity, form values, cookies, credentials, query-string values and other private content from error reports before transmission.

The Analytics category runs unless you turn it off, and uses PostHog to understand how Plan The Day is used and improve it. PostHog receives the screen you are on, how you reached us - the website that referred you and any utm_ campaign labels on the link you followed - and limited technical browser information needed to deliver analytics. A pseudonymous identifier is stored in your browser so repeat visits from one device count as one visitor. It is not your account, and no profile is built from it.

If you separately turn on Account-linked analytics, that activity is connected to a pseudonymous account identifier, and PostHog additionally receives successful authentication and setup outcomes and the creation category of a first Supplier, Contract or Timeline item. Turning it on also links the activity already measured on that device, including from before you turned it on and before you signed in. The paragraphs below describing outcomes, context, refusals and purchases apply only while it is on.

PostHog also receives that you interacted with a control and where on the screen you tapped or scrolled. The wording of what you tapped is deliberately hidden, because a control in Plan The Day often carries a Supplier or a person's name, so we receive the kind of control and its position rather than its label.

So that we can tell whether a change helps one kind of customer and not another, PostHog receives a small amount of context alongside those outcomes: the type of Event you are planning, such as a wedding or a birthday; roughly how far away it is, expressed as a broad band rather than a date; whether you are planning your own Event or working as a planner; which plan you are on; and, for planners, a broad band of how many Events you have access to. Where you invite an Event Organiser or an Event Planner to work with you, we receive that an invitation was created, accepted, revoked or ended, and which of those two roles it concerned.

Where Plan The Day stops you doing something, PostHog receives that it happened and the reason category - for example that you reached a limit of your plan, or that a form was incomplete. It does not receive what you typed or the message you were shown.

If you buy Event Pass or Planner Pro, PostHog receives that you reached an upgrade prompt, that you started checkout and which of the two products it was for, and that the purchase was applied to your account. We use this to understand which parts of Plan The Day people find worth paying for. No payment detail is involved: no card details, no amount, no price, no currency and no Stripe reference. Those remain with Stripe.

Performance measurement runs unless you turn it off, and collects four standard web timings that describe how quickly a screen loaded and how stable it was while loading. This is kept deliberately apart from Analytics: it carries no account identifier, it is not linked to your Analytics activity, and it stores no identifier in your browser, so it tells us that a screen is slow without telling us who found it slow.

If you separately choose Session Replay, we may record a masked playback of a screen while a named investigation is open, limited to the screens that investigation concerns and to a fixed end date set before it starts. All text and everything you type is hidden in a recording. Session Replay is off unless you turn it on, and it also requires the Analytics choice.

Where a web address contains a reference to one of your records, we replace that reference before sending, so we can see that a Contract screen was opened without seeing which Contract. PostHog does not receive your name, email address, your Event's name, date or location, Supplier or contact details, Contract content or names, payment details, form values, free text, query-string values or credentials, and we do not collect advertising click identifiers such as gclid or fbclid. Where you have turned on Account-linked analytics, we use the account identifier to link that activity across browsers and sessions. We do not use Analytics for advertising, automated decisions or profiling for marketing.

Information about other people

If you add Supplier contacts, collaborators, invitation recipients or information within a Contract or note, you may provide personal data about other people. You must ensure that you have a lawful basis to provide that information and that you give those people any privacy information required by law.

How we use your information

We use personal data to create and secure accounts, authenticate users and provide the service; create, manage and display Events, Timelines, Suppliers, contacts and Contracts; provide access-sharing and collaboration features at the direction of authorised users; process purchases and manage subscriptions; respond to support requests; maintain security; prevent fraud and misuse; investigate faults; improve the reliability of Plan The Day; understand product use, unless you have turned Analytics off; and comply with legal, accounting and regulatory obligations.

We do not currently use personal data for targeted advertising or sell personal data.

Our lawful bases

Under UK data-protection law, we rely on the following lawful bases:

  • Contract - where processing is necessary to provide Plan The Day, manage your account, provide paid products or take steps at your request before entering into a contract.
  • Legitimate interests - where necessary to secure, operate, support and improve Plan The Day, provided that these interests are not overridden by your rights and freedoms. This covers Analytics and Performance measurement, which measure how the service is used rather than who is using it. You can object to either at any time, and the switches on the Cookie Policy page are how you do it: no reason is needed and nothing else about your account changes.
  • Legal obligation - where we need to retain or disclose information to meet legal, tax, accounting or regulatory requirements.
  • Consent - where we ask for it for a specific optional purpose, which is Account-linked analytics and Session Replay. You can withdraw consent at any time, but this will not affect processing that occurred before withdrawal.

Who we share information with

We share personal data only where necessary to provide the service, including with Supabase for authentication, database and private file storage; Stripe for hosted payment checkout and subscription management; Sentry, when enabled, for limited error monitoring and diagnostics; PostHog, unless you have turned the Analytics category off; hosting, infrastructure, security and professional service providers; and authorised Event Organisers, Event Planners, Event Team Members and Suppliers where an authorised user has granted or shared access to an Event.

We may also share information with public authorities, professional advisers or transaction counterparties where required by law or necessary to protect our rights, users or business, including in connection with a merger, investment, sale, restructuring or other business transaction.

International transfers

Our service providers may process personal data outside the United Kingdom. Where this is a restricted transfer under UK data-protection law, we will use a lawful transfer mechanism, such as UK adequacy regulations or appropriate contractual safeguards. Contact us for further information about the safeguards relevant to your data.

Retention

We keep personal data only for as long as necessary for the purposes described in this policy.

  • Account and Event data is retained while your account or Event remains active.
  • If an eligible account holder requests profile deletion, access ends immediately and permanent deletion is scheduled 28 days after the request is accepted. Signing in again during that period cancels the request.
  • Event data and private Contract files are deleted when the relevant Event is deleted, subject to any limited retention required for security, backups or legal obligations.
  • Payment, subscription and transaction records are retained for as long as needed to administer billing and meet legal, tax and accounting obligations.
  • Security and diagnostic information is retained only for the period necessary to protect and operate the service.
  • Where Analytics or Performance measurement is running, the PostHog events and any person profiles they produce are retained for 90 days. Neither Performance measurement nor Analytics on its own creates a person profile; only Account-linked analytics does. We reset browser analytics on withdrawal or sign-out. Before Analytics is enabled in production, the profile-deletion process will also delete the associated PostHog person data.

Cookies and similar technologies

Plan The Day uses strictly necessary cookies and similar technologies to maintain secure authentication and restricted access-sharing or invitation sessions. These are necessary for the service to function.

Where enabled, Plan The Day also uses Analytics, Account-linked analytics, Performance measurement and Session Replay technologies. Each is separate from the others. Analytics and Performance measurement run unless you turn them off, under an exemption in the Privacy and Electronic Communications Regulations for statistics collected solely to improve a service. Account-linked analytics and Session Replay are off until you turn them on, and we ask for your affirmative choice before using either. You can change any of these at any time through the Cookie Policy page. Turning a category off stops its future capture and leaves the others unchanged; see our Cookie Policy for further detail.

We do not currently use advertising or targeted-marketing cookies. Stripe may use cookies or similar technologies on its hosted checkout pages in accordance with Stripe's own privacy and cookie notices.

You can manage cookies through your browser settings. Blocking necessary cookies may prevent parts of Plan The Day from working correctly.

Your rights

Subject to applicable law, you may have the right to request access to your personal data, ask us to correct inaccurate or incomplete data, request deletion of your personal data, ask us to restrict our use of your data, receive data you have provided in a portable format, object to processing based on our legitimate interests, and withdraw consent where we rely on consent.

To exercise a right, contact us using the details below. We may need to verify your identity before responding.

You also have the right to complain to the UK Information Commissioner's Office.

Security

We use appropriate technical and organisational measures to protect personal data. These include access controls, authenticated sessions, restricted sharing credentials, row-level access controls for application data, private storage for Contract files and signed URLs for file access.

No system is completely secure. Please keep your account access details private and contact us promptly if you believe your account has been compromised.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to Plan The Day, our data practices or legal requirements. We will post the updated version on this page and update the "Last updated" date.

Contact us

For questions, privacy requests or complaints about this Privacy Policy, use the contact details below.

10BIT LABS LTD
13 Dunmow Close, Loughton, Essex, IG10 3AS
legal@plantheday.co.uk

We use analytics and performance measurement to understand and improve Plan The Day. These run by default. You can also choose optional account-linked analytics. You can change this at any time.