Legal and policies

Privacy Policy

Version 1 · effective 8 September 2026

1. Who is responsible for your data

1.1 EPlanit Ltd, a company registered in England and Wales under company number 17483076 with its registered office at 50 Sloane Avenue, London SW3 3DD, is the data controller for the personal data described in this policy.

1.2 We are registering with the Information Commissioner's Office and will publish our registration number here as soon as it is issued.

1.3 For anything about your data, contact hello@eplanit.co.uk.

1.4 Our data protection officer is not required for an organisation of our size; privacy questions go to hello@eplanit.co.uk.

2. Where your data comes from

Most of it comes from you: when you create an account, build a supplier profile, post a brief, send a message, or make a booking. We also generate some data about how you use the platform, and we receive confirmation of identity and payment status from Stripe.

There is one exception, and it is set out in full at 3.7. If you run an events business, we may hold a small amount of information about that business before you have ever heard of us, because we found it in a public listing and would like to invite you to join. You can have it deleted in one click, without an account and without giving a reason.

3. What we collect, and why

The table below is organised by what the platform actually stores.

3.1 Account data

WhatWhy we have itLawful basis
Email address and password, held by our authentication providerTo create and secure your account and to sign you inPerformance of a contract
Your nameTo identify you to the people you are dealing withPerformance of a contract
Profile photo, if you upload oneTo personalise your profileConsent, by choosing to upload it
The date you joinedAccount administration and fraud preventionLegitimate interests
Whether you hold an admin or moderator roleTo control access to internal toolsLegitimate interests

3.2 Supplier profile data

WhatWhy we have itLawful basis
Business name, category and subcategories, biographyTo list you on the marketplace so planners can find youPerformance of a contract
Location name, and precise latitude and longitudeTo match you to planners searching in your area, and to apply your travel radiusPerformance of a contract
Travel radius, minimum booking, pricing, deposit policyTo set expectations before an enquiryPerformance of a contract
Portfolio images and captionsTo show planners your workPerformance of a contract
Verification status, and the evidence behind it such as insurance certificates, hygiene ratings and DBS confirmationsTo operate the verified badge and keep the marketplace safeLegitimate interests, and legal obligation where safeguarding applies
Identity and bank details held by StripeTo verify you and pay youPerformance of a contract, and legal obligation under money laundering rules

3.3 Brief data

WhatWhy we have itLawful basis
Event type, date or timeframe, start and end times, alternative datesTo match your brief to available suppliersPerformance of a contract
Location of the eventTo find suppliers who cover the areaPerformance of a contract
Categories and subcategories wantedTo route the brief to the right suppliersPerformance of a contract
BudgetTo help suppliers decide whether to quotePerformance of a contract
Free-text description of your eventTo let suppliers understand what you needPerformance of a contract
Whether the brief is self-served or EPlanit-led, and its statusTo route it and to bill correctlyPerformance of a contract

3.4 Messages

WhatWhy we have itLawful basis
The content of messages between planners and suppliersTo let you negotiate and agree a booking, and to hold a record of what was agreedPerformance of a contract
Who sent what, and whenSame, and to resolve disputesPerformance of a contract, and legitimate interests
When you last read a conversationTo show unread indicatorsPerformance of a contract
Monitoring for attempts to take bookings off the platform, abuse, or fraudTo enforce our terms and protect usersLegitimate interests

3.5 Booking and payment data

When the booking and payment flow goes live we will hold the record of each booking, what was agreed, what was paid and when, and our commission. Card details are handled by Stripe and are never stored on our systems.

3.6 Technical data

IP address, browser and device information, pages visited and actions taken. We use this to keep the service secure, to diagnose faults and to understand how the platform is used. Our lawful basis is legitimate interests, and for any non-essential analytics or marketing cookies, your consent.

3.7 Businesses we invite to join

If you run an events business, we may hold information about that business before you have ever contacted us. This section explains exactly what, why, and how to make it stop.

Where it comes from. Public sources: business directories, public listings, business websites and public social media pages. We record the source against every record, so if you ask us how we found you, we can tell you rather than guess.

WhatWhy we have itLawful basis
Business name, trading area and categoryTo know whether you would be useful to the people planning events on EPlanitLegitimate interests
A business email address or contact name, where publicly listedSo we can write to you to invite youLegitimate interests
A website or social media handleTo confirm you are a working business, and to write about your actual work rather than send a form letterLegitimate interests
A draft profile written from your public listingSo that joining takes a couple of minutes rather than an eveningLegitimate interests
A company number, where one has been given to usTo confirm the company against the Companies House public registerLegitimate interests

Our legitimate interests, and the balance we have struck. Our interest is in building a marketplace with enough suppliers on it to be useful. We have weighed that against your interests, and these are the limits we hold ourselves to: we do not keep writing if you do not reply; the message tells you where we found you; we hold nothing that was not already publicly available; we never buy contact data; and we never sell or share it.

How to stop it, in one click. Every invitation carries a link that removes you. It needs no account, no sign-in, and no reason. When you use it we delete your email address, your contact name, and the description and prices we had drafted for you. We keep only the fact that your business was approached and said no, so that a later search cannot put you back in the queue. Your email address is kept as a one-way fingerprint rather than as the address itself, purely so that we recognise you and stop.

You can also email hello@eplanit.co.uk and ask, and we will do the same thing.

If you never reply. An invitation expires. Ninety days after that we automatically delete the contact details and the draft profile, keeping only the record that your business was approached and when.

Nothing is published without you. A profile we have drafted for you is not visible to anybody until you claim it and choose to publish it. Until then it exists only in our own systems.

3.8 Account security records

When something important changes on your account, we write down what changed and tell you, so that the one time it was not you, you find out the same day.

WhatWhy we have itLawful basis
The field that changed, with its previous and new valueSo you can see exactly what happened on your own accountLegitimate interests
The date and time, the IP address and the browser the change was made fromSo you can recognise whether it was youLegitimate interests
Whether the change was made by somebody at EPlanit rather than from your accountSo an administrative change is never mistaken for a strangerLegitimate interests

Phone numbers and addresses are masked before they are written into this record, so that the record cannot itself become a source of your contact details. Your password is never recorded, only the fact that it changed.

You can read this record at any time in your account settings. We keep it for twelve months and then delete it automatically.

3.9 Grant applications

If you apply for an EPlanit grant, we hold what you tell us in the application so we can judge it fairly and pay the winner.

WhatWhy we have itLawful basis
Your name, business name, email address and, if you give it, phone numberTo identify the application, contact you about it and stop duplicate entriesPerformance of our agreement with you
Your answers, the amount you ask for and any picture you uploadTo judge the application against the published criteriaPerformance of our agreement with you
The panel's scores and notesTo make a fair decision and to explain it if you askLegitimate interests
Whether you agreed we may publish your name and story if you winSo we only publish what you allowedConsent, which you can withdraw at any time
Payment details for the winnerTo pay the grantPerformance of our agreement with you

Who sees it. The EPlanit team and the judging panel. We do not share applications with anyone else and we do not use them for marketing. If you win and agreed to it, we publish your name or business name and what the grant is for; nothing else from your application is published.

How long we keep it. Applications are kept for two years after the round closes and then deleted. The winner's payment record is kept for six years, because we are required to keep financial records.

4. Sensitive information in briefs and messages

This section exists because of what an events platform inevitably collects. Briefs and messages are free text, and the nature of events means they will sometimes reveal information that UK GDPR treats as special category data, needing stronger protection.

  • Religious or philosophical belief: a christening, a bar mitzvah, an Eid celebration, a Hindu wedding, or a request for halal or kosher catering.

  • Health: allergies and dietary requirements told to a caterer or cake maker, accessibility needs, or the circumstances behind a memorial event.

  • Sexual orientation: a same-sex wedding.

  • Data about children: a child's name, age or photograph in a brief for a children's party.

We do not ask for any of this, and you should not include more of it than a supplier needs. Where it is present, we hold it only to pass it to the suppliers you are dealing with and to keep the record of your booking, and we do not use it for any other purpose.

5. Who we share your data with

WhoWhat they getWhere
The other party to your enquiryPlanners see supplier profiles. Suppliers see the brief and messages sent to them, including your name and event details.Within the platform
Supabase, our database, authentication and file storage providerAll platform dataIreland, EU (eu-west-1)
Stripe, our payment processorPayment and identity dataIreland and the United States
Lovable, our development platformAccess to the application environmentEuropean Union and United States
Our email providerYour email address and the content of notificationsResend, United States
Professional advisers, and authorities where the law requiresOnly what is necessaryUnited Kingdom
A buyer, if the business is soldPlatform data, subject to the same protectionsAs applicable

We do not sell your personal data, and we do not share it with advertisers.

6. Sending data outside the UK

6.1 Our database and files are hosted in Ireland. Transfers from the UK to the EEA are permitted under the UK adequacy regulations.

6.2 Stripe may process data in the United States. Those transfers rely on the UK extension to the EU-US Data Privacy Framework, or on the International Data Transfer Agreement, together with appropriate safeguards.

6.3 Where we use any other provider outside the UK or EEA, we put appropriate safeguards in place before doing so.

7. How long we keep it

DataRetention
Account and profile dataWhile your account is open, then 12 months
Supplier verification evidence such as insurance certificates and DBS confirmations3 years after the profile closes, so we can show what we checked and when
Briefs24 months after the event date or the brief closing
Messages6 years from the booking, matching the limitation period for a contract claim
Booking and payment records6 years after the end of the tax year, as tax law requires
Technical logs12 months
Marketing preferences and unsubscribesKept indefinitely so we honour your choice

Two retention rules apply to the data described at 3.7 and 3.8. An invitation that expires or is withdrawn has its contact details and draft profile deleted ninety days later, leaving only the record that the business was approached. A record that a business declined is kept indefinitely, as a business name and a one-way fingerprint of the email address only, because it is what stops us contacting them again. Account security records at 3.8 are kept for twelve months.

8. Your rights

Under UK GDPR you have the right to:

  • be told how your data is used, which is what this policy does;

  • get a copy of the data we hold about you;

  • have inaccurate data corrected;

  • have data deleted, where we no longer need it and no legal obligation requires us to keep it;

  • restrict or object to how we use it, including objecting to processing based on legitimate interests;

  • receive your data in a portable format;

  • withdraw consent at any time, where we relied on consent;

  • object to direct marketing at any time, with no exceptions.

To exercise any of these, email hello@eplanit.co.uk. We respond within one month, and will tell you if we need longer because the request is complex. There is no charge.

Deleting your account does not delete everything immediately. We keep booking, payment and message records for the periods in section 7, because tax law requires some of it and because the other party to a booking has rights too.

9. Cookies

We use cookies that are strictly necessary to run the site and keep you signed in, which do not need your consent. Any analytics, performance or marketing cookies are used only with your consent, given through the cookie banner, and you can change your choice at any time.

10. Security

Data is encrypted in transit and at rest. Access to the production database is limited to those who need it. Row-level security is enabled on every table so users can reach only their own records. Payment card details never touch our systems.

If a breach occurs that risks your rights and freedoms, we will report it to the ICO within 72 hours and tell you where the risk to you is high.

11. Marketing

We send service messages about your account, briefs and bookings, which are part of the service and not marketing. We send marketing only where you have agreed, or where you are an existing user and we are telling you about similar services, and every marketing message has an unsubscribe link.

12. Children

EPlanit is for adults. You must be 18 or over to hold an account. We do not knowingly collect data from children, but a planner may include information about a child in a brief for a children's party. Please include only what the supplier needs.

13. Changes to this policy

We will update this policy when the platform changes, in particular when the booking and payment flow goes live. Where a change is material we will tell you by email. This is version 1, last updated 27 August 2026.

14. Complaints

Tell us first at hello@eplanit.co.uk and we will try to put it right. You also have the right to complain to the Information Commissioner's Office at ico.org.uk, or on 0303 123 1113.