Privacy Policy
This policy explains what personal data Planoro collects, why we process it, who we share it with, and the rights you have over it.
1. Who we are
Planoro is a business software platform for planning and coordinating workforce, jobs, scheduling, inventory, and budgets in the events, production, and field-operations industries.
The data controller for the marketing website and for account holders' personal data is Bruno Magalhães (sole trader / empresário em nome individual), registered at Estrada Principal, n.º 20, Casal da Barreirinha, 2560-055 A dos Cunhados, Portugal, NIF/VAT PT271553812. You can reach us at hello@planoro.app.
Two roles. For the personal data of your own account and your company's billing, Planoro is the controller. For the personal data your company enters about its workers, clients, and contacts, your company is the controller and Planoro acts as a processor on your instructions (see section 13).
2. Scope
This policy applies to data processed through:
- The Planoro marketing website.
- The Planoro web and progressive web application.
- Transactional emails, invitations, and notifications we send.
- Support and communication channels connected to Planoro.
3. What data we collect
Depending on how Planoro is used, we process the following categories:
- Account & profile data: name, email address, phone number, profile photo, role, and the company you belong to. Passwords are handled by our authentication provider and stored only as salted hashes — never in plain text and never in our application database.
- Consent records: the version of the Terms and Privacy Policy you accepted and the timestamp of acceptance.
- Company & billing data: company name, industry, timezone, logo, billing email, billing address, VAT identification number, billing currency, and payment/subscription identifiers from our payments provider.
- Worker records: names, emails, phone numbers, profile photos, worker type, roles, skills, languages spoken, certifications, driving-licence categories, whether they have their own vehicle, availability and holiday declarations, reliability metrics, free-text notes, and per-role pay/rate configuration (e.g. hourly or day rates and multipliers). No bank account or card numbers are stored for workers.
- Client (CRM) records: client display and legal names, contact persons, emails, phone numbers, websites, VAT numbers, billing and shipping addresses, tags, lead status, reminders, and notes.
- Operational data: jobs and events (titles, descriptions, venues/locations, dates and times), on-site manager contact details (name, email, phone), role assignments, work segments, schedules, recurring-job series, activity feeds, and change history.
- Financial data: budgets and quotations, line items, tax rates, totals, margins, and frozen finance snapshots that include per-worker cost breakdowns.
- Inventory data: equipment items, categories, quantities, dispatch/arrival/return records, QR scan actors, and condition photos.
- Job Hub communications: the updates, messages, questions, answers, comments, and acknowledgements exchanged on a job, together with the author's name and photo, timestamps, read receipts showing who has opened an update, and records of follow-ups sent when an update goes unread.
- Job expenses: expenses a worker submits against a job — amount, currency, free-text note, receipt images, submission and review timestamps, the reviewer's identity, and any review note. Approved expenses are carried into the job's cost records.
- External portal access data: for workers who use the portal without an account, an encrypted copy and a hash of their personal access link, a hashed access PIN, failed-attempt counts, and lockout timestamps.
- Push notification data: if you enable browser notifications, the push endpoint issued by your browser vendor, the associated encryption keys, your user-agent string, and the time the endpoint was last used.
- Uploaded files: profile/worker/client avatars, company logos, inventory condition photos, files attached to a job or shared in the Job Hub, and expense receipt images.
- Calendar integration data: if a worker connects Google Calendar, an encrypted Google refresh token, the connected Google account email, and the assignment details written to their calendar (see section 7).
- Communications data: the emails, invitations, and notifications we send, plus delivery/open metadata for assignment notifications.
- Technical & security data: IP address, browser/device and user-agent information, authentication and session metadata, security audit events, and server logs. For anti-abuse on promotional codes we may retain an email, payment-card fingerprint, and IP address.
- Preference data: language, theme, notification-sound, and interface view preferences.
- Support messages: if you contact us through the in-app support drawer, the message you write, the category you pick, your name and email, your company name and role, the page you were on, your language, browser information, and the time of sending. These are delivered to our support inbox by email and are not stored in the application database.
4. How we collect it
- Directly from you — registration, profile updates, forms, settings, and file uploads.
- From your organisation's administrators and teammates, who enter your account, worker, or assignment details.
- Automatically through use of the app — server logs, authentication/session technologies, and security telemetry, including approximate location derived from your IP address for company settings.
- From integrations you choose to authorise, such as Google Calendar.
5. Why we process your data
- Provide, operate, and secure the service.
- Create and manage accounts, companies, jobs, workers, clients, schedules, and budgets.
- Send essential operational notifications, invitations, and transactional emails.
- Process subscriptions, billing, invoices, and prevent payment abuse.
- Sync assignments to a connected calendar when you enable it.
- Maintain audit trails and investigate security incidents, misuse, or fraud.
- Improve reliability, performance, and user experience.
- Comply with legal obligations and enforce our Terms.
6. Legal bases (GDPR)
We rely on the following legal bases under the EU General Data Protection Regulation:
- Performance of a contract — to provide the service you or your organisation signed up for, and to bill for it.
- Legitimate interests — to secure the platform, prevent abuse and fraud, maintain audit logs, and improve the product, balanced against your rights.
- Consent — for optional integrations you enable (such as Google Calendar) and where else legally required. You can withdraw consent at any time.
- Legal obligation — to meet tax, accounting, and other statutory duties.
7. Service providers and international transfers
We do not sell personal data. We share it only with the service providers (sub-processors) needed to run Planoro, each bound by a data-processing agreement and appropriate safeguards:
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage, and realtime | All account, company, worker, client, job, finance, and inventory data; credentials; uploaded files | EU region (see note below) |
| Stripe | Subscription payments and billing | Billing name, email, address, VAT ID, and payment-card data (held by Stripe, not by us) | United States |
| Resend | Transactional email — invitations, billing, and worker assignment notifications | Recipient and manager names, emails and phone numbers, job schedule, location, and travel details | United States |
| Optional, per-worker Google Calendar sync | Connected account email, job title, location, times, and manager contact written to the calendar | United States | |
| Vercel | Application hosting and content delivery | Request metadata and served assets | United States / global edge |
| Vercel Web Analytics | Aggregate traffic measurement for the website and app | Page path, referrer, country, device and browser type, and a short-lived one-way hash derived from IP address and user-agent. No cookies, no cross-site identifier, no advertising use | United States / global edge |
| Upstash | Rate limiting and abuse protection (Redis) | IP addresses and request identifiers used as short-lived counter keys, typically expiring within minutes | Configured region |
| Browser push services | Delivery of browser notifications — operated by your own browser vendor (for example Google, Mozilla, or Apple) | The push endpoint your browser issued and the encrypted notification payload | Depends on your browser vendor |
| GeoNames, Photon (OpenStreetMap), Open-Meteo | Venue, address, and city search suggestions | The location text typed into a search box. No account or worker identifiers | European Union / Germany |
| Amazon Web Services | Underlying infrastructure for our database, authentication, and file storage, as Supabase's own sub-processor | The data listed for Supabase above | EU region (eu-west-1) |
Google API data — Limited Use. Planoro's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We use Google Calendar access solely to create and update the connecting worker's own job-assignment events; we do not sell this data, use it for advertising, transfer it to others except to provide or improve this feature, or let humans read it — except with your consent, for security, or to comply with law.
International transfers. Our primary database and files are hosted in the European Union. Some providers above are based in the United States, so certain data is transferred internationally. Where this happens we rely on Standard Contractual Clauses and equivalent safeguards. The exact hosting region of some providers is configured at deployment — contact us at support@planoro.app for the current sub-processor details.
Changes to this list. Before we add or replace a sub-processor that handles personal data your company controls, we will update this page and give reasonable advance notice to account owners, so you have the opportunity to object.
We may also disclose data to legal authorities where required by law, and to a buyer or investor in connection with a merger, acquisition, or asset sale, subject to this policy.
Note on public files. Profile/worker/client avatars and company logos are stored in publicly readable buckets, meaning anyone with the file URL can view the image. Do not upload sensitive images as avatars or logos. Inventory condition photos are stored privately.
8. Data retention
We keep personal data only as long as necessary for the purposes in this policy and to meet legal, contractual, and operational requirements.
- Active account and workspace data is retained while your account is active.
- Inactive and lapsed accounts: if a subscription lapses, your workspace data is preserved so you can resume. We do not keep dormant workspaces indefinitely: where an account stays inactive — no sign-in and no subscription — for 24 months, we may erase the workspace, having first given the account owner at least 30 days' notice at the address on file.
- In-app deleted items (trash): records you delete inside the app are soft-deleted and remain recoverable; those that contain personal data — jobs and worker records — are permanently erased 90 days after deletion.
- Job Hub content: updates, questions, comments, acknowledgements, and read receipts are kept for the life of the job they belong to and are erased with it. Deleting an update removes it from the feed; it and any attached file are permanently erased 30 days later. When a worker's record is erased, their name and photo are removed from the messages they wrote, and the message itself is shown as coming from a removed user.
- Job expenses and receipts: kept for the life of the job. Where an approved expense has been carried into accounting records, the underlying accounting entry follows the billing retention period below.
- Uploaded files: when the job, worker, or company a file belongs to is erased, the file is removed by a daily cleanup task, normally within 24 hours and at most within a few days.
- Push notification endpoints: kept while notifications are enabled, and deleted as soon as your browser reports the endpoint is no longer valid or you turn notifications off.
- External portal credentials: the encrypted access link and PIN hash are kept while the worker's record exists, and are erased with it. Regenerating a worker's link immediately invalidates the previous one.
- Account deletion: when you delete your account, your jobs, worker and client records, user accounts, and company are erased immediately, and your authentication account and public avatars and logos are removed. Files held in private storage are removed at the same time, with a daily cleanup task as a backstop.
- Billing and accounting: payment-card data is held by Stripe under its own retention policy and is never stored by us; invoices and accounting records are kept for at least 10 years to meet Portuguese tax and commercial-law obligations.
- Security, audit, and activity logs: retained for up to 24 months for security, fraud prevention, and accountability — with company links removed when your account is deleted — and not removed when an individual record is deleted.
- Anti-abuse records: the email, payment-card fingerprint, and IP address retained for promotional-code abuse prevention are kept for up to 12 months.
- Google Calendar token: the encrypted refresh token is kept while the integration is connected, cleared automatically if Google reports that access was revoked, and removed when your account is deleted.
- Support messages: kept in our support mailbox for up to 24 months so we can follow up on the same issue, then deleted.
9. Security
We apply administrative, technical, and organisational safeguards designed to protect data against unauthorised access, alteration, disclosure, or loss. These include row-level access controls scoping data to your company, encrypted storage of integration credentials, signature-verified payment webhooks, rate limiting, and security audit logging. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
If something goes wrong. Where Planoro processes personal data on your company's behalf, we will notify your company of any personal-data breach affecting that data without undue delay after becoming aware of it, whatever its severity, and give you the information you need to meet your own reporting duties. Where Planoro is the controller, we will notify the competent supervisory authority as required and will inform you directly without undue delay if the breach is likely to result in a high risk to your rights and freedoms.
10. Your rights
Under the GDPR and applicable law, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority — in Portugal, the Comissão Nacional de Proteção de Dados (CNPD).
If your data was entered into Planoro by an organisation (for example, as a worker or client), that organisation is the controller. We will refer your request to them or act on their instructions. To exercise your rights, contact support@planoro.app; we may need to verify your identity first. We respond to requests within one month; for complex or numerous requests we may extend this by up to two further months and will let you know if we do.
11. Automated decisions and profiling
Planoro calculates a small number of indicators about workers from their activity in the workspace — most notably a reliability indicator derived from how many assignments a worker has completed and how many they have declined. These indicators are shown to the managers in the worker's own company to help them plan.
A person always decides. These indicators are decision support only. Planoro does not make automated decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. Who is offered a job, engaged, or paid is decided by the people in your company, not by the software. If you believe an indicator about you is wrong, you can ask the company that holds your record to correct it, and you may contest a decision that relied on it.
12. Children's privacy
Planoro is a business tool not directed to children. We do not knowingly collect personal data from children under 16 (or the minimum age set by local law). If you believe a child has provided us data, contact us and we will delete it.
13. Processing on behalf of your organisation
When your company enters personal data about its workers, clients, and contacts, your company decides why and how that data is processed and is therefore the controller. Planoro processes it solely to provide the service, on your documented instructions, and does not use it for unrelated purposes.
These processor commitments apply to every customer automatically — you do not have to ask for them. They are that we act only on your instructions; that everyone we allow to access the data is bound by confidentiality; that we keep appropriate security measures; that we engage sub-processors only as described in section 7 and hold them to equivalent obligations; that we assist you with data-subject requests, security, breach notification, and impact assessments; that we delete or return the data when the service ends; and that we make available the information you need to verify our compliance.
These commitments are set out in full in our Data Processing Agreement. If your organisation needs it as a separately signed document, or requires its own form of DPA, contact support@planoro.app.
14. Third-party sites
Planoro may link to third-party websites or services. Their privacy practices are governed by their own policies, not this one.
15. Changes to this policy
We may update this policy from time to time. We will revise the date at the top and, where the change is material, provide additional notice or ask you to re-accept.
16. Contact
For privacy questions, requests, or complaints, email support@planoro.app.