Legal and policies
Privacy Policy
Version 1 · effective 8 September 2026
1. Who is responsible for your data
1.1 EPlanit Ltd, a company registered in England and Wales under company number 17483076 with its registered office at 50 Sloane Avenue, London SW3 3DD, is the data controller for the personal data described in this policy.
1.2 We are registering with the Information Commissioner's Office and will publish our registration number here as soon as it is issued.
1.3 For anything about your data, contact hello@eplanit.co.uk.
1.4 Our data protection officer is not required for an organisation of our size; privacy questions go to hello@eplanit.co.uk.
2. Where your data comes from
Most of it comes from you: when you create an account, build a supplier profile, post a brief, send a message, or make a booking. We also generate some data about how you use the platform, and we receive confirmation of identity and payment status from Stripe.
There is one exception, and it is set out in full at 3.7. If you run an events business, we may hold a small amount of information about that business before you have ever heard of us, because we found it in a public listing and would like to invite you to join. You can have it deleted in one click, without an account and without giving a reason.
3. What we collect, and why
The table below is organised by what the platform actually stores.
3.1 Account data
| What | Why we have it | Lawful basis |
|---|---|---|
| Email address and password, held by our authentication provider | To create and secure your account and to sign you in | Performance of a contract |
| Your name | To identify you to the people you are dealing with | Performance of a contract |
| Profile photo, if you upload one | To personalise your profile | Consent, by choosing to upload it |
| The date you joined | Account administration and fraud prevention | Legitimate interests |
| Whether you hold an admin or moderator role | To control access to internal tools | Legitimate interests |
3.2 Supplier profile data
| What | Why we have it | Lawful basis |
|---|---|---|
| Business name, category and subcategories, biography | To list you on the marketplace so planners can find you | Performance of a contract |
| Location name, and precise latitude and longitude | To match you to planners searching in your area, and to apply your travel radius | Performance of a contract |
| Travel radius, minimum booking, pricing, deposit policy | To set expectations before an enquiry | Performance of a contract |
| Portfolio images and captions | To show planners your work | Performance of a contract |
| Verification status, and the evidence behind it such as insurance certificates, hygiene ratings and DBS confirmations | To operate the verified badge and keep the marketplace safe | Legitimate interests, and legal obligation where safeguarding applies |
| Identity and bank details held by Stripe | To verify you and pay you | Performance of a contract, and legal obligation under money laundering rules |
3.3 Brief data
| What | Why we have it | Lawful basis |
|---|---|---|
| Event type, date or timeframe, start and end times, alternative dates | To match your brief to available suppliers | Performance of a contract |
| Location of the event | To find suppliers who cover the area | Performance of a contract |
| Categories and subcategories wanted | To route the brief to the right suppliers | Performance of a contract |
| Budget | To help suppliers decide whether to quote | Performance of a contract |
| Free-text description of your event | To let suppliers understand what you need | Performance of a contract |
| Whether the brief is self-served or EPlanit-led, and its status | To route it and to bill correctly | Performance of a contract |
3.4 Messages
| What | Why we have it | Lawful basis |
|---|---|---|
| The content of messages between planners and suppliers | To let you negotiate and agree a booking, and to hold a record of what was agreed | Performance of a contract |
| Who sent what, and when | Same, and to resolve disputes | Performance of a contract, and legitimate interests |
| When you last read a conversation | To show unread indicators | Performance of a contract |
| Monitoring for attempts to take bookings off the platform, abuse, or fraud | To enforce our terms and protect users | Legitimate interests |
3.5 Booking and payment data
When the booking and payment flow goes live we will hold the record of each booking, what was agreed, what was paid and when, and our commission. Card details are handled by Stripe and are never stored on our systems.
3.6 Technical data
IP address, browser and device information, pages visited and actions taken. We use this to keep the service secure, to diagnose faults and to understand how the platform is used. Our lawful basis is legitimate interests, and for any non-essential analytics or marketing cookies, your consent.
3.7 Businesses we invite to join
If you run an events business, we may hold information about that business before you have ever contacted us. This section explains exactly what, why, and how to make it stop.
Where it comes from. Public sources: business directories, public listings, business websites and public social media pages. We record the source against every record, so if you ask us how we found you, we can tell you rather than guess.
| What | Why we have it | Lawful basis |
|---|---|---|
| Business name, trading area and category | To know whether you would be useful to the people planning events on EPlanit | Legitimate interests |
| A business email address or contact name, where publicly listed | So we can write to you to invite you | Legitimate interests |
| A website or social media handle | To confirm you are a working business, and to write about your actual work rather than send a form letter | Legitimate interests |
| A draft profile written from your public listing | So that joining takes a couple of minutes rather than an evening | Legitimate interests |
| A company number, where one has been given to us | To confirm the company against the Companies House public register | Legitimate interests |
Our legitimate interests, and the balance we have struck. Our interest is in building a marketplace with enough suppliers on it to be useful. We have weighed that against your interests, and these are the limits we hold ourselves to: we do not keep writing if you do not reply; the message tells you where we found you; we hold nothing that was not already publicly available; we never buy contact data; and we never sell or share it.
How to stop it, in one click. Every invitation carries a link that removes you. It needs no account, no sign-in, and no reason. When you use it we delete your email address, your contact name, and the description and prices we had drafted for you. We keep only the fact that your business was approached and said no, so that a later search cannot put you back in the queue. Your email address is kept as a one-way fingerprint rather than as the address itself, purely so that we recognise you and stop.
You can also email hello@eplanit.co.uk and ask, and we will do the same thing.
If you never reply. An invitation expires. Ninety days after that we automatically delete the contact details and the draft profile, keeping only the record that your business was approached and when.
Nothing is published without you. A profile we have drafted for you is not visible to anybody until you claim it and choose to publish it. Until then it exists only in our own systems.
3.8 Account security records
When something important changes on your account, we write down what changed and tell you, so that the one time it was not you, you find out the same day.
| What | Why we have it | Lawful basis |
|---|---|---|
| The field that changed, with its previous and new value | So you can see exactly what happened on your own account | Legitimate interests |
| The date and time, the IP address and the browser the change was made from | So you can recognise whether it was you | Legitimate interests |
| Whether the change was made by somebody at EPlanit rather than from your account | So an administrative change is never mistaken for a stranger | Legitimate interests |
Phone numbers and addresses are masked before they are written into this record, so that the record cannot itself become a source of your contact details. Your password is never recorded, only the fact that it changed.
You can read this record at any time in your account settings. We keep it for twelve months and then delete it automatically.
3.9 Grant applications
If you apply for an EPlanit grant, we hold what you tell us in the application so we can judge it fairly and pay the winner.
| What | Why we have it | Lawful basis |
|---|---|---|
| Your name, business name, email address and, if you give it, phone number | To identify the application, contact you about it and stop duplicate entries | Performance of our agreement with you |
| Your answers, the amount you ask for and any picture you upload | To judge the application against the published criteria | Performance of our agreement with you |
| The panel's scores and notes | To make a fair decision and to explain it if you ask | Legitimate interests |
| Whether you agreed we may publish your name and story if you win | So we only publish what you allowed | Consent, which you can withdraw at any time |
| Payment details for the winner | To pay the grant | Performance of our agreement with you |
Who sees it. The EPlanit team and the judging panel. We do not share applications with anyone else and we do not use them for marketing. If you win and agreed to it, we publish your name or business name and what the grant is for; nothing else from your application is published.
How long we keep it. Applications are kept for two years after the round closes and then deleted. The winner's payment record is kept for six years, because we are required to keep financial records.
4. Sensitive information in briefs and messages
This section exists because of what an events platform inevitably collects. Briefs and messages are free text, and the nature of events means they will sometimes reveal information that UK GDPR treats as special category data, needing stronger protection.
-
Religious or philosophical belief: a christening, a bar mitzvah, an Eid celebration, a Hindu wedding, or a request for halal or kosher catering.
-
Health: allergies and dietary requirements told to a caterer or cake maker, accessibility needs, or the circumstances behind a memorial event.
-
Sexual orientation: a same-sex wedding.
-
Data about children: a child's name, age or photograph in a brief for a children's party.
We do not ask for any of this, and you should not include more of it than a supplier needs. Where it is present, we hold it only to pass it to the suppliers you are dealing with and to keep the record of your booking, and we do not use it for any other purpose.
5. Who we share your data with
| Who | What they get | Where |
|---|---|---|
| The other party to your enquiry | Planners see supplier profiles. Suppliers see the brief and messages sent to them, including your name and event details. | Within the platform |
| Supabase, our database, authentication and file storage provider | All platform data | Ireland, EU (eu-west-1) |
| Stripe, our payment processor | Payment and identity data | Ireland and the United States |
| Lovable, our development platform | Access to the application environment | European Union and United States |
| Our email provider | Your email address and the content of notifications | Resend, United States |
| Professional advisers, and authorities where the law requires | Only what is necessary | United Kingdom |
| A buyer, if the business is sold | Platform data, subject to the same protections | As applicable |
We do not sell your personal data, and we do not share it with advertisers.
6. Sending data outside the UK
6.1 Our database and files are hosted in Ireland. Transfers from the UK to the EEA are permitted under the UK adequacy regulations.
6.2 Stripe may process data in the United States. Those transfers rely on the UK extension to the EU-US Data Privacy Framework, or on the International Data Transfer Agreement, together with appropriate safeguards.
6.3 Where we use any other provider outside the UK or EEA, we put appropriate safeguards in place before doing so.
7. How long we keep it
| Data | Retention |
|---|---|
| Account and profile data | While your account is open, then 12 months |
| Supplier verification evidence such as insurance certificates and DBS confirmations | 3 years after the profile closes, so we can show what we checked and when |
| Briefs | 24 months after the event date or the brief closing |
| Messages | 6 years from the booking, matching the limitation period for a contract claim |
| Booking and payment records | 6 years after the end of the tax year, as tax law requires |
| Technical logs | 12 months |
| Marketing preferences and unsubscribes | Kept indefinitely so we honour your choice |
Two retention rules apply to the data described at 3.7 and 3.8. An invitation that expires or is withdrawn has its contact details and draft profile deleted ninety days later, leaving only the record that the business was approached. A record that a business declined is kept indefinitely, as a business name and a one-way fingerprint of the email address only, because it is what stops us contacting them again. Account security records at 3.8 are kept for twelve months.
8. Your rights
Under UK GDPR you have the right to:
-
be told how your data is used, which is what this policy does;
-
get a copy of the data we hold about you;
-
have inaccurate data corrected;
-
have data deleted, where we no longer need it and no legal obligation requires us to keep it;
-
restrict or object to how we use it, including objecting to processing based on legitimate interests;
-
receive your data in a portable format;
-
withdraw consent at any time, where we relied on consent;
-
object to direct marketing at any time, with no exceptions.
To exercise any of these, email hello@eplanit.co.uk. We respond within one month, and will tell you if we need longer because the request is complex. There is no charge.
Deleting your account does not delete everything immediately. We keep booking, payment and message records for the periods in section 7, because tax law requires some of it and because the other party to a booking has rights too.
9. Cookies
We use cookies that are strictly necessary to run the site and keep you signed in, which do not need your consent. Any analytics, performance or marketing cookies are used only with your consent, given through the cookie banner, and you can change your choice at any time.
10. Security
Data is encrypted in transit and at rest. Access to the production database is limited to those who need it. Row-level security is enabled on every table so users can reach only their own records. Payment card details never touch our systems.
If a breach occurs that risks your rights and freedoms, we will report it to the ICO within 72 hours and tell you where the risk to you is high.
11. Marketing
We send service messages about your account, briefs and bookings, which are part of the service and not marketing. We send marketing only where you have agreed, or where you are an existing user and we are telling you about similar services, and every marketing message has an unsubscribe link.
12. Children
EPlanit is for adults. You must be 18 or over to hold an account. We do not knowingly collect data from children, but a planner may include information about a child in a brief for a children's party. Please include only what the supplier needs.
13. Changes to this policy
We will update this policy when the platform changes, in particular when the booking and payment flow goes live. Where a change is material we will tell you by email. This is version 1, last updated 27 August 2026.
14. Complaints
Tell us first at hello@eplanit.co.uk and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113.