Privacy Policy
Planz Last Updated: June 14, 2026
1. Introduction / Who We Are
1.1. This Privacy Policy ("Policy") explains how Planz ("we," "us," or "our") collects, uses, shares, and protects your personal data when you use the Planz mobile application and any associated services (collectively, the "Service").
1.2. Planz is a hobby-native social platform for group plan coordination and venue booking. We operate in the United Arab Emirates and are in the process of registration under Meydan Freezone, Dubai, UAE. Our website is accessible at planz.ae.
1.3. We are committed to protecting your personal data in accordance with UAE Federal Decree-Law No. 45/2021 on the Protection of Personal Data ("PDPL"), the DIFC Data Protection Law where applicable, and any implementing regulations issued thereunder.
1.4. By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.
2. What Data We Collect
We collect the following categories of personal data:
2.1. Account and Profile Information
- Full name
- Date of birth / age
- Neighborhood or general location
- Interests and hobby preferences
- Instagram handle (optional)
- Profile avatar or photo
- Email address
- Phone number (if provided for authentication)
2.2. Authentication Data
- Account credentials managed through our authentication provider
- Login timestamps and session information
2.3. Location Data
- Approximate location (neighborhood-level) as provided by you during profile setup
- Device-level location data, collected only with your explicit consent, used for venue discovery and group plan coordination
2.4. Usage and Behavioral Data
- Interactions with the Service (e.g., groups joined, plans created, features used)
- Session duration and frequency of use
- In-app navigation and feature engagement
- This data is collected only with your consent and is used solely to improve the Service
2.5. Chat and Communication Data
- Messages sent within group chats and direct messages on the platform
- Media shared within conversations
2.6. Booking and Payment Data
- Venue booking details (date, time, venue, group size)
- Payment transaction records (processed securely by our PCI-compliant payment processor)
- We do not store full credit or debit card numbers on our servers
2.7. Device and Technical Data
- Device type, model, and operating system
- Push notification tokens
- App version
- Crash reports and diagnostic logs
- IP address
2.8. Data You Choose to Provide
- Feedback, support requests, or other communications you send to us
- Content you voluntarily share through the Service
3. How We Use Your Data
We process your personal data only where we have a lawful basis to do so under the PDPL. The table below sets out our purposes for processing and the corresponding legal bases.
3.1. Performance of the Service (Contractual Necessity)
- Creating and maintaining your account
- Displaying your profile to other users for group activity matching based on shared interests
- Facilitating group plan creation, coordination, and venue booking
- Processing payments for bookings
- Delivering push notifications related to your plans, groups, and bookings
- Providing customer support
3.2. Consent
- Collecting and processing device-level location data for venue discovery
- Collecting usage and behavioral analytics to improve the Service
- Sending promotional or marketing communications (you may withdraw consent at any time)
3.3. Legitimate Interests
- Improving, optimizing, and developing the Service
- Detecting, preventing, and addressing fraud, abuse, and security issues
- Moderating content to maintain community safety
- Analyzing aggregated, de-identified usage trends
3.4. Legal Obligations
- Complying with applicable UAE laws, regulations, and lawful government requests
- Retaining financial and transaction records as required by UAE commercial law
- Responding to valid legal processes
3.5. Anti-Dating Commitment
We do not use your personal data for romantic matching, dating suggestions, or any form of individual-to-individual compatibility scoring. Profile data, including interests and neighborhood, is used exclusively for commonality-based group activity matching. This is a core design principle of the Service.
4. How We Share Your Data
4.1. With Other Users. Your profile information (name, avatar, interests, neighborhood, and Instagram handle if provided) is visible to other users within the context of group plans and shared activities. You control what you share in your profile.
4.2. With Venues and Booking Partners. When you make a booking, we share necessary details (such as group size, date, and time) with the relevant venue to fulfill your reservation. We share only the minimum data required.
4.3. With Service Providers. We share data with third-party service providers who process data on our behalf, as described in Section 5 below. These providers are contractually bound to process your data only for the purposes we specify and in accordance with this Policy.
4.4. For Legal Reasons. We may disclose your data if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others, or to detect, prevent, or address fraud, security, or technical issues.
4.5. Business Transfers. In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data.
4.6. No Sale of Personal Data. We do not sell your personal data to third parties.
5. Data Processors and Third Parties
We use the following third-party data processors to operate the Service. Each processor is bound by a data processing agreement that requires them to protect your data in accordance with applicable law.
| Processor | Purpose | Data Processed |
|---|---|---|
| Supabase | Database hosting, user authentication, file storage, and real-time messaging infrastructure | Account data, profile data, chat messages, uploaded media |
| Stripe | Payment processing (PCI DSS compliant) | Payment and transaction data (card details are handled directly by Stripe and are not stored on our servers) |
| PostHog | Product analytics | Usage and behavioral data (consent-gated; collected only with your explicit opt-in) |
| Sentry | Crash reporting and error monitoring | Device information, diagnostic logs, error traces (no personal profile data) |
| Resend | Transactional email delivery | Email address, email content for account-related communications |
5.1. We conduct due diligence on all processors to verify they maintain appropriate technical and organizational security measures.
5.2. We limit the data shared with each processor to only what is necessary for the specific service they provide.
6. International Data Transfers
6.1. Some of our data processors operate infrastructure outside the United Arab Emirates. In particular, Supabase and Stripe may process data in jurisdictions outside the UAE.
6.2. Where personal data is transferred outside the UAE, we ensure that adequate safeguards are in place in accordance with Article 22 of the PDPL, including:
- Data processing agreements with all processors that include data protection obligations consistent with the PDPL
- Verification that receiving jurisdictions maintain an adequate level of data protection, or that appropriate contractual safeguards are implemented
- Technical security measures, including encryption in transit and at rest
6.3. You may contact us at the address in Section 12 to obtain further information about the specific safeguards applied to international transfers of your data.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.
| Data Category | Retention Period |
|---|---|
| Account and profile data | Retained while your account is active. Upon account deletion, a 30-day grace period applies during which you may reactivate your account. After the grace period, data is permanently and irreversibly deleted from our systems. |
| Chat messages | Retained while your account is active. Upon account deletion, chat messages are retained for an additional 90 days for safety and content moderation review purposes, after which they are permanently deleted. |
| Payment and transaction records | Retained for five (5) years from the date of the transaction, in compliance with UAE commercial and financial record-keeping requirements. |
| Usage and analytics data | Retained in aggregated or de-identified form. Identifiable analytics data is deleted within 12 months of collection or upon account deletion, whichever is sooner. |
| Crash reports and diagnostic logs | Retained for up to 90 days for debugging and service improvement, then automatically deleted. |
7.1. When data is no longer required, it is securely deleted or irreversibly anonymized so that it can no longer be associated with you.
8. Your Rights Under UAE PDPL
Under the PDPL, you have the following rights with respect to your personal data:
8.1. Right of Access. You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data.
8.2. Right to Correction. You have the right to request correction of inaccurate or incomplete personal data. You can also update most profile information directly within the app.
8.3. Right to Deletion / Erasure. You have the right to request deletion of your personal data, subject to our legal obligations to retain certain records (e.g., financial transaction records). Account deletion can be initiated directly within the app settings.
8.4. Right to Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible.
8.5. Right to Withdraw Consent. Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. You can manage consent preferences within the app settings.
8.6. Right to Restriction of Processing. You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data or where you have objected to processing.
8.7. Right to Object to Automated Decisions. You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. Planz does not currently make solely automated decisions of this nature.
8.8. Exercising Your Rights. To exercise any of these rights, please contact us at privacy@planz.ae. We will respond to your request within thirty (30) days. We may request verification of your identity before processing your request.
8.9. Right to Lodge a Complaint. If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the UAE Data Office or the relevant data protection authority in your jurisdiction.
9. Data Security
9.1. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL
- Encryption of data at rest
- Secure authentication mechanisms, including support for multi-factor authentication
- Role-based access controls limiting employee and contractor access to personal data on a need-to-know basis
- Regular security assessments and monitoring
- PCI DSS-compliant payment processing through Stripe (we never store, process, or transmit full card numbers on our infrastructure)
- Incident response procedures for identifying, reporting, and addressing data breaches
9.2. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the relevant authorities and affected individuals in accordance with the PDPL's breach notification requirements.
9.3. While we take commercially reasonable steps to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
10. Children's Privacy
10.1. The Service is intended for users aged eighteen (18) years and older. We do not knowingly collect, solicit, or process personal data from individuals under the age of 18.
10.2. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data as promptly as possible.
10.3. If you are a parent or guardian and believe that your child has provided personal data to us, please contact us at privacy@planz.ae so that we can take appropriate action.
11. Changes to This Policy
11.1. We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will:
- Update the "Last Updated" date at the top of this Policy
- Notify you through the app or by other appropriate means (such as email) before the changes take effect
- Where required by law, obtain your consent to material changes
11.2. We encourage you to review this Policy periodically. Your continued use of the Service after the effective date of any updated Policy constitutes your acknowledgment of the changes.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@planz.ae
- Entity: Planz (Meydan Freezone, Dubai, UAE)
- Website: https://planz.ae
We aim to respond to all inquiries within thirty (30) days.
Governing Law. This Policy is governed by the laws of the United Arab Emirates, including the PDPL (Federal Decree-Law No. 45/2021), and shall be interpreted in accordance with the same.