Privacy Policy
Last Updated: August 2026
1. Introduction
Planbutlr ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and your rights regarding that data. We operate in accordance with the General Data Protection Regulation (GDPR) and Dutch privacy law.
We do not run ads in the app. We do not track you across other apps or websites.
2. Data Controller
Parity Labs VOF (trading as Planbutlr)
Vennootschap Onder Firma (VOF), registered in the Netherlands
Dutch Chamber of Commerce (KVK) number: 99704862
BTW (VAT) number: NL869098998B01
Registered address: Wipmolenweg 40, 1333GR Almere, Netherlands
Privacy contact: privacy@planbutlr.com
We are a small organisation and have not appointed a Data Protection Officer. Under Article 37 GDPR, we are not required to appoint one because our processing does not involve large-scale monitoring or large-scale processing of special category data. For any privacy question, including those that would normally go to a DPO, write to privacy@planbutlr.com.
3. Information We Collect
We collect only the data necessary to operate the app's features. Below is every category of data we collect.
- AccountEmail address, display name, profile picture, optional bio, and account creation date. Collected when you register. Linked to your identity.
- Sign-in with Apple or GoogleIf you choose to sign in with Apple or Google instead of email and password, that provider returns an identity token to us containing your email address and, where you allow it, your name. We store the same account fields as any other sign-up. We do not receive your password, contact list, or any other data held by Apple or Google. If you use Apple's "Hide My Email" option, we only ever see the relay address Apple generates.
- EventsEvent title, description, cover image, start/end dates, location, currency, and the membership list (who is owner, co-planner, or member). Linked to your identity.
- Date CoordinationDate and time options you propose or vote on (available / maybe / unavailable). Linked to your identity.
- Checklist / ItemsItem names, quantities, categories, notes, URLs, and assignment to members. Linked to your identity.
- PollsPoll questions, options, and the votes you cast. Linked to your identity.
- Expenses & SettlementsExpense descriptions, amounts, currency, payer, split participants, and settlement records (who has paid whom). We do not process payments or store any financial account details. Settlements are tracked by you and other members manually. Linked to your identity.
- CarpoolPickup and drop-off coordinates (obtained from your device location or a typed address via geocoding), departure time, and seat capacity. Location data is used only to resolve addresses for carpool coordination. It is not tracked continuously. Linked to your identity.
- Photos & MediaImages and videos you choose to upload to a shared event album, captions, likes, and basic file metadata (file size, dimensions, MIME type). Photos are stored on our servers and visible only to members of that event. Linked to your identity. Metadata handling: photos uploaded to an event album are automatically re-encoded on your device before upload, which removes embedded EXIF metadata such as device model, capture timestamp, and any GPS coordinates your camera may have tagged. If the re-encode fails, the app refuses to upload the photo so the original file (with its metadata) is not sent to our servers. Profile pictures and event cover images use the same re-encode path but fall back to the original file if the re-encode fails, so in rare cases EXIF may survive for those two image types. Videos are uploaded without re-encoding and retain whatever container metadata was already in the file. If your camera tags videos with location, disable video location tagging in your camera settings or strip the metadata on your device before uploading. We plan to extend automatic stripping to videos in a future update.
- Timeline / ActivitiesActivity descriptions, location (if provided), timestamps, and assigned members. Linked to your identity.
- Device & Notification DataExpo push notification token, device platform (iOS / Android), device type, and OS version. Collected to deliver push notifications to your device. Linked to your account but not shared externally beyond Expo (our push notification provider).
- Notification HistoryA record of the in-app notifications sent to you (type, related event, timestamp, and whether you have read it) so your notification inbox works across devices. Linked to your identity.
- App SettingsLanguage preference, theme preference, and notification preferences. Stored locally on your device and in your account record. Linked to your identity.
- Offline CacheSo the app keeps working without a connection, a copy of the events you belong to and any changes you make while offline are stored on your device and sent to our servers once you reconnect. This cache lives only on your device and is cleared when you sign out or delete the app.
- Crash & Error DataPseudonymised error logs and stack traces produced when the app crashes or encounters an error. This is off until you switch it on: nothing is sent to our error monitoring until you accept it, and if you withdraw that consent the app shuts the connection down and stops sending. When it is on, we also collect performance traces from a sample of sessions and, from a smaller sample, session replays, which reconstruct the screens you saw and the taps you made in the run-up to an error. We configure our error monitoring to exclude your name, email, and event content, and reports are filtered to strip tokens, API keys, and cookies before they are sent. Your user ID and some technical identifiers (such as a session ID) are included so reports from the same session and account can be grouped, which is why we describe these as pseudonymised rather than anonymised. Collected via Sentry (see Section 8).
- Rate-limit & Security LogsHashed identifiers, timestamps, and counters for login, signup, password reset, and similar sensitive actions, used to block brute-force attacks. Retained for a short period and not shared with anyone.
4. Device Permissions
The app requests the following device permissions. You can grant or revoke these at any time in your device settings.
Taking photos or videos to upload to a shared event album, or photographing a receipt to attach to an expense.
Selecting existing photos or videos from your device to upload as event media, a profile picture, an event cover, or a receipt attached to an expense.
Recording sound as part of a video you add to an event album. Only accessed while you are recording a video.
Resolving your current location to a pickup address for carpool coordination, and showing nearby places first when you search for a pickup point or venue. Only accessed when you actively use those features.
Exporting a finalised event date to your device's native calendar app. Only triggered when you tap "Add to calendar."
Receiving event updates such as new members joining, expenses added, polls created, or photos uploaded. See Section 7 for the difference between transactional and marketing notifications.
5. Legal Basis for Processing (GDPR)
- Contract performance: processing your account, event, expense, settlement, carpool, photo, poll, and timeline data is necessary to deliver the service you signed up for.
- Legitimate interests: rate-limit and security logs are processed to protect the service against brute-force attacks and signup abuse, in a way that does not override your rights. These logs are hashed and exclude content data and direct identifiers.
- Consent: crash and error reporting (via Sentry, including performance traces and session replay) is off until you switch it on, and camera, microphone, photo library, location access, calendar access, push notifications, and any marketing communications are only used when you grant permission. You can withdraw consent at any time in your device or app settings, and withdrawing crash-reporting consent stops collection immediately.
- Legal obligation: where we must retain or disclose data to comply with applicable law (for example, responding to a valid court order or tax record-keeping).
6. How We Use Your Data
- To create and manage your account and event memberships
- To facilitate event coordination, showing group members date votes, expense splits, settlement balances, carpool availability, poll results, shared photos, and the timeline
- To resolve location addresses for carpool pickup and event venues
- To convert expense amounts into the event currency where members record costs in different currencies
- To send transactional push notifications about event activity (new member, expense, poll, activity, photo)
- To detect and fix crashes and errors, keeping the app stable
- To prevent abuse such as brute-force login attempts and signup spam
7. Communications and Notifications
We send two kinds of messages, and we treat them differently under EU law (ePrivacy Directive and the Dutch Telecommunicatiewet).
Account, security, and event-activity messages (email verification, password reset, a co-planner adding you to an event, a new expense, a new poll). These are necessary to deliver the service and cannot be turned off entirely without limiting core functionality, but you can fine-tune which event-activity notifications you receive in Account → Notifications.
Product updates, newsletters, and tips. We only send marketing messages if you have opted in, separately from your account creation. We do not pre-tick consent boxes.
Every marketing email includes a one-click unsubscribe link, and you can also unsubscribe in Account → Notifications or by emailing privacy@planbutlr.com. Opting out of marketing does not affect transactional messages.
8. Third-Party Services
Third parties that receive your data fall into two groups, and the distinction matters for your rights. Processors handle data only on our documented instructions and are bound by a data processing agreement incorporating the Article 28 GDPR terms. Independent controllers decide for themselves what to do with the data they receive, under their own privacy policies, so questions about that processing go to them rather than to us.
Processors acting on our instructions
Each of these is covered by a data processing agreement. They may not use your data for their own purposes.
Database, authentication, file storage, real-time sync, and serverless functions. Hosted in EU-West (Dublin, Ireland). Stores all account, event, expense, settlement, carpool, photo, poll, and timeline data.
Error monitoring and crash reporting, and only if you have switched it on. Our Sentry project runs in Sentry's EU region (Germany), so crash data does not leave the EU. It receives stack traces, performance traces from a sample of sessions, and session replays from a small sample of sessions, which record the screens and interactions leading up to an error. It receives your user ID so reports from one account can be grouped, but it is configured not to send personal data by default, and outgoing reports are filtered to strip tokens, API keys, and cookies. See Section 5 for how to turn this off.
Delivers push notifications to your device. Receives your Expo push token and the notification content only for as long as it takes to route the message. No other personal data is shared.
Delivers over-the-air app updates. Receives your operating system, the project identifier, and a randomly generated token. Expo states this does not include unique device identifiers.
Hosting for the Planbutlr website (planbutlr.com). Standard server request logs (IP address, browser, URL) are retained briefly for security purposes. We also run Vercel Analytics and Speed Insights on the website to count page views and measure loading performance. Both are cookieless and assign no persistent identifier, so visits cannot be linked to you or followed across sites. Neither runs in the mobile app.
Address geocoding and place search for carpool pickup points and event venues, used as the fallback when the Google Places lookup below is unavailable. When you search for or confirm an address, the typed string or coordinates are sent to this service. No account data is shared.
Independent controllers
These parties determine their own purposes for the data they receive. They are not acting on our instructions, and their own privacy policies govern what they do with it.
Place search and autocomplete when you look up a carpool pickup point or an event venue. Your typed search text is sent, along with a coarse location to bias results towards places near you if you have granted location access. This is the first lookup the app tries; if it is unavailable the app falls back to Photon / Nominatim above. No account data, event content, or identifiers are attached to the query. Google operates under its own controller-to-controller data protection terms.
Authenticates you if you sign in with your Apple account, in which case Apple learns that you signed in to Planbutlr and returns an identity token to us. Apple also holds any App Store account and purchase data in its own right, and Apple Push Notification service carries notifications to iOS devices. We send Apple no event content.
Authenticates you if you sign in with your Google account, in which case Google learns that you signed in to Planbutlr and returns an identity token to us. Google also holds any Play Store account and purchase data in its own right, and Firebase Cloud Messaging carries notifications to Android devices. We send Google no event content.
Supplies daily exchange rates when an event has expenses in more than one currency. The app requests a rate table for a base currency and caches it on your device. We send no amounts, no event content, and no account data. The request exposes your device's IP address to the CDN serving the rate file, as any web request would.
Typography (Inter, Plus Jakarta Sans) used on the website. Fonts are loaded at build time. No user data is sent to Google when you visit the site.
If we add, replace, or materially change a processor, we update this page and, where the change involves a new category of data or a transfer to a new jurisdiction, give at least 30 days' notice in advance through an in-app message or email before the change goes live. You can object to a material processor change by deleting your account.
9. International Data Transfers
Everything you create in the app stays in the EU. Your account, event, expense, carpool, photo, poll, and timeline data is stored by Supabase in Dublin, Ireland (EU-West), and crash reports go to Sentry's EU region in Germany. Neither is transferred to the United States. The services below sit outside the EU and receive the limited data described above. For each, we rely on a transfer mechanism approved under Chapter V of the GDPR.
- Expo (United States)EU Standard Contractual Clauses (SCCs), Module 2 (controller to processor). Receives push token and notification payload, plus the OS and project identifier for app updates.
- Google Maps Platform (United States)EU-US Data Privacy Framework certification (Google LLC), backed by Standard Contractual Clauses. Applies when you search for a place or pickup point. Google receives your search text and, if you have granted location access, a coarse location to bias results.
- Apple (United States)EU Standard Contractual Clauses. Applies to Sign in with Apple, App Store account data, and push delivery to iOS devices.
- Google (United States)EU-US Data Privacy Framework certification (Google LLC). Applies to Google Sign-In, Play Store account data, and push delivery to Android devices.
- Photon / NominatimGeocoding instances are hosted in the EU. If we ever fall back to a non-EU instance, only the address string is sent and we rely on SCCs.
This is a description of where the data sits, not a claim that it is end-to-end encrypted. It is not. Data is encrypted in transit and at rest, but we hold the keys, which means a small number of authorised personnel can technically access stored content, including uploaded images, when operating or debugging the service.
10. Authentication & Session Security
- You can sign in with an email address and password, with Sign in with Apple, or with Google Sign-In
- Social sign-in uses an identity token exchanged directly with Apple or Google. We never see or store your Apple or Google password
- Email verification is required when you sign up with an email address and password, before you can use the app
- Password reset is delivered via a time-limited email link
- Login, signup, and password reset are rate-limited to prevent abuse
- Sessions are stored using hardware-backed secure storage (iOS Keychain / Android Keystore)
- Passwords must meet a minimum complexity requirement (length and character variety)
- Changing your password automatically signs you out of all other devices
11. Security Measures
- All data is transmitted over HTTPS (TLS)
- Sensitive data on your device is stored in hardware-backed secure storage (iOS Keychain / Android Keystore)
- Database access is restricted by row-level security so you can only access data for events you belong to
- Photo storage is access-controlled per event. Only members can view or download an event's photos
- All user-provided input is validated and sanitised
- Access to production infrastructure is restricted to essential personnel only
12. Data Breach Notification
Even with the safeguards above, no system is fully immune to incidents. If we discover a personal data breach within the meaning of Article 4(12) GDPR, we will:
- Investigate the scope and impact promptly and contain the incident
- Notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours of becoming aware of the breach, unless the breach is unlikely to result in a risk to your rights and freedoms (Article 33 GDPR)
- Notify affected users without undue delay when the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR), describing what happened, what data was affected, what we are doing about it, and what you can do to protect yourself
- Maintain an internal incident log documenting the facts of the breach, its effects, and the remedial action taken
13. Your Rights (GDPR)
Under the GDPR, you have the following rights. To exercise any of them, contact privacy@planbutlr.com. We respond within 30 days.
Request a copy of the personal data we hold about you
Correct any inaccurate or incomplete data
Delete your account and all personal data, in-app or via email request
Receive a copy of your data in a structured, commonly-used, machine-readable JSON format (Article 20 GDPR; export available in-app)
Ask us to limit how we use your data in certain circumstances
Object to processing based on legitimate interests, including any direct marketing
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.
If you live in another EU member state, you may also lodge a complaint with your local data protection authority. A directory is available at edpb.europa.eu.
14. Data Export & Account Deletion
You can export or delete your data at any time, directly in the app:
Account → Account & privacy → Your data → Download my data. We email a secure download link for a JSON file containing your profile, events, expenses, polls, votes, activities, items, and photo records. The download link expires after 7 days.
Account → Account & privacy → Your data → Delete account. Your account is deactivated immediately and you are signed out. All personal data is permanently removed within 30 days. During that 30-day window you can sign in again to cancel the deletion if you change your mind.
Full deletion instructions →15. Data Retention and Inactive Accounts
We retain your data for as long as your account is active. Once you request deletion, your account is deactivated immediately and a 30-day grace period begins, during which you can cancel the deletion. After the grace period, all personal data is permanently removed from our active databases. Automated database backups expire within 7 additional days. Pseudonymised Sentry error logs may be retained for up to 90 days for debugging purposes.
If your account has shown no sign-in activity for 24 consecutive months, we will send you a reminder email. If we receive no response within 90 days of that reminder, we delete your account and the personal data tied to it, applying the same procedure as a user-initiated deletion. Events you participated in remain visible to other members but your personal name, email, and profile picture are removed from those records (see Terms of Service, Section 14).
16. Automated Decision-Making and Profiling
We do not make any decisions about you based solely on automated processing, and we do not perform profiling that produces legal or similarly significant effects on you. Features such as place search and expense splitting are simple lookups and calculations based on the inputs you provide, and do not analyse your behaviour or preferences.
17. Children's Privacy
Planbutlr is not directed at children under the age of 13 (or 16 in jurisdictions where that is the applicable minimum age under GDPR, including the Netherlands). Meeting the minimum age is a condition of using the app, set out in our Terms of Service. We do not currently ask for your date of birth or verify your age at signup, so we rely on you meeting that condition and on reports from parents, guardians, and other users. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, contact privacy@planbutlr.com and we will delete the account and associated data promptly.
When we receive a credible report that an account belongs to a child below the applicable minimum age, we suspend the account immediately, contact the email address on file to request parental confirmation, and delete the account and associated data if we cannot verify that consent has been given by a parent or guardian. We do not request copies of identity documents to verify age; we rely on the user's representation and on credible reports from parents, guardians, or other users.
18. Disclosure to Law Enforcement and Authorities
We do not voluntarily disclose your personal data to law enforcement, government agencies, or other third parties. We will only disclose data when we are legally compelled to do so under Dutch or EU law (for example, a valid court order, a binding request from the Autoriteit Persoonsgegevens, or a similar instrument from another competent authority), or when disclosure is strictly necessary to prevent an imminent threat to life or physical safety. Where the law allows, we will notify the affected user before disclosure and will challenge requests that we believe are overbroad or unlawful. We do not run a transparency report at our current scale; if that changes we will publish one.
19. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, including changes that expand the categories of data we collect, the purposes for which we use it, or the parties with which we share it, we give at least 30 days' advance notice by posting the updated policy on this page, updating the "Last Updated" date, and sending an in-app notification or email. Non-material changes (such as clarifying wording or fixing typos) take effect when posted. The previous version remains available on request.
20. Contact Us
For privacy-related questions or to exercise your rights, email us. Postal correspondence can also be sent to the registered address below.
Legal entity: Parity Labs VOF (trading as Planbutlr)
KVK: 99704862
BTW (VAT) number: NL869098998B01
Postal address: Wipmolenweg 40, 1333GR Almere, Netherlands
Email: privacy@planbutlr.com
Response time: Within 30 days, as required by GDPR.