Legal
Privacy Policy
Last updated: 15 July 2026
Operated by Planiverse Intelligence Ltd (Company No. 17159473) · hello@planiverse.uk
01Who we are
Planiverse (planiverse.uk) is a UK planning-intelligence service operated by Planiverse Intelligence Ltd, a company registered in England and Wales.
- Company registration number: 17159473
- Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
- ICO registration number: ZC126236
- Privacy contact: hello@planiverse.uk
Planiverse Intelligence Ltd is the data controller for personal data processed through this site. We do not have, and are not required to appoint, a Data Protection Officer; the named privacy contact above is responsible for handling data-protection enquiries.
This policy explains what personal data we collect, why, what we do with it, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
02Information we collect
We collect the following categories of personal data:
- Contact & purchase data: your email address (for delivery and receipts) and the address and project details you enter to generate a report.
- Property and proposal data you enter: addresses you search, property descriptions, and project details. These are used to generate your one-off report; they are not linked to any account (there is none).
- Payment records: when you purchase a report, the address and selected report type are stored against the Stripe transaction reference. Card details are never seen or stored by Planiverse. They are handled directly by Stripe (see §05).
- Email opt-ins and preferences: newsletter signups, waitlist entries, and unsubscribe state.
- Feedback: any feedback you send us by email.
- Technical and usage data: page views, button interactions, search queries within the app, IP address (transient, not stored long-term against your account), and broad device/browser type.
We do not ask for, and have no need for, special category data (health, religion, ethnicity, and similar) about our customers. Public planning records that we process (see §14) can occasionally reveal such information incidentally — for example, a planning application describing a disabled-access adaptation, or works to a place of worship. We do not seek this information, do not use it for any analytical purpose, and do not draw inferences from it; where it appears, it is present only because the council published it as part of the public planning record.
03How we use your information
- To provide the service: generate reports, deliver purchased reports, and send service emails (receipts).
- To improve the product: understand which features are used, where errors occur, which pages drive engagement. We use this on an aggregated, non-marketing basis.
- To communicate with you: service announcements (security, billing, planned downtime) are sent regardless of marketing preferences. Product updates and new feature emails are sent only if you've opted in; you can unsubscribe at any time using the link in any marketing email.
- To detect and prevent abuse: rate-limiting, spam detection, account-takeover defence, and incident response.
- To meet legal obligations: accounting records (Companies Act, HMRC), responses to lawful information requests, and regulatory enquiries.
We do not sell your data, share it with advertisers, or use it for ad targeting.
04Lawful basis for processing
Under UK GDPR Article 6, we process personal data on the following bases:
- Contract (Art 6(1)(b)): to deliver the report you purchase: report generation and payment processing.
- Legitimate interests (Art 6(1)(f)): to operate, debug, secure and improve the product; to detect abuse; and to keep records for the duration of our customer relationship.
- Legitimate interests (Art 6(1)(f)): to process planning application records obtained from public planning registers, including records relating to properties and applicants other than our customer, in order to provide address-specific planning intelligence. See §14 for a full explanation, the safeguards we apply, and how to object.
- Consent (Art 6(1)(a)): for marketing emails (opt-in when you give us your email, withdrawable at any time) and for analytics cookies (opt-in via the cookie banner, withdrawable at any time, see Cookie Policy).
- Legal obligation (Art 6(1)(c)): for accounting, tax, and regulatory record-keeping.
You can withdraw any consent-based processing at any time without affecting the lawfulness of processing before withdrawal.
05Sub-processors and service providers
We do not sell your data, share it with advertisers, or use it for ad targeting. The providers below process data only on our instructions to deliver our service.
We rely on the following sub-processors. All are bound by data-processing agreements that comply with UK GDPR:
- Vercel Inc. (United States): hosting, edge network, deployment platform. Processes all incoming requests, application logs, and serves static assets. Privacy policy.
- Supabase Inc. (project region: Ireland, eu-west-1): managed Postgres database and object storage. Holds the address and report data you enter, AI-call logs (90-day retention), and report/transaction records. Privacy policy.
- Anthropic, PBC (United States): the Claude API used to generate report narratives. We send the planning question and relevant property data; we do not send your name or email to Anthropic. Anthropic processes API inputs and outputs under their commercial Data Processing Addendum and applies a 30-day input/output retention by default. Privacy policy.
- Resend Inc. (sending region: Ireland, EU): transactional and marketing email delivery. Processes recipient email addresses, names, and email body content. Privacy policy.
- Stripe Payments UK Ltd (United Kingdom): payment processing and fraud prevention (Stripe Radar). Card details are entered on Stripe's hosted checkout page and never reach our servers. We receive only the transaction reference, last 4 digits of the card (where Stripe surfaces it), and billing email. As part of fraud prevention, Stripe processes transaction data, device and browser information, and behavioural signals (Stripe Radar) under their own Data Processing Agreement and privacy policy. Privacy policy.
- Google LLC, Google Analytics 4 (United States): anonymous usage analytics, loaded only after you accept analytics cookies. Privacy policy.
- Google LLC, Google Fonts (United States): font CSS and font files served from
fonts.googleapis.com / fonts.gstatic.com on every page. Your browser's IP address is disclosed to Google when fonts load. Privacy policy.
- Mapbox Inc. (United States): interactive map tiles and static map images on the homeowner report flow. Your browser fetches map tiles directly from Mapbox; Mapbox sees your IP address, the tile coordinates requested, and our access token. Privacy policy.
- Ideal Postcodes Ltd (United Kingdom): address autocomplete and resolution against the Royal Mail Postcode Address File (PAF). We send your typed search and the selected address; Ideal Postcodes returns the structured address, postcode, UPRN and coordinates. Privacy policy.
- postcodes.io (United Kingdom, operated by Ideal Postcodes under contract with the Ministry of Housing, Communities and Local Government): postcode and ward lookup using public ONS data. We send postcodes or coordinates only; no personal account data is sent.
06International transfers
Personal data is primarily stored on infrastructure located in the United Kingdom and the European Union. Some sub-processors are based in the United States, which means certain processing involves an international transfer of data outside the UK.
For each US-based sub-processor (Vercel, Anthropic, Google, Mapbox), we rely on:
- The UK International Data Transfer Agreement (UK IDTA), or the European Commission's Standard Contractual Clauses (SCCs) together with the UK Addendum, where applicable; and
- The provider's published security and contractual safeguards under the EU–US Data Privacy Framework where they are certified.
You can request a copy of the safeguards relied on for any specific transfer by emailing hello@planiverse.uk.
07Cookies and similar technologies
We use a small set of cookies and browser local-storage entries. Some are strictly necessary to operate the site (such as remembering your cookie-consent choice); analytics are loaded only after you grant consent via the cookie banner.
Until you click "Accept" on the banner, no Google Analytics scripts are loaded and no analytics requests leave your browser. If you click "Decline" or close the banner, the analytics scripts never load on any page, on any visit, until you change that choice.
For the full list of cookies, what they do, and how long they last, see our Cookie Policy.
08Your rights
Under UK GDPR you have the following rights, free of charge:
- Access: request a copy of the personal data we hold about you (a Subject Access Request, or SAR).
- Rectification: correct inaccurate or incomplete data. Email us to correct any personal data we hold.
- Erasure ("right to be forgotten"): request deletion of the personal data we hold about you (your email and any report or transaction data). Some records (payment receipts, audit logs) are kept for legal and accounting reasons, see §09.
- Restriction: ask us to limit how we process your data while a query is being resolved.
- Portability: receive a copy of the data you provided to us in a structured, machine-readable format (JSON or CSV).
- Object: object to processing based on legitimate interests, including direct marketing. You can unsubscribe from any marketing email via the link in the email footer. If a planning application connected to you appears in our data and you object to us processing it, see §14 — we operate a suppression route and will remove the record from our product.
- Withdraw consent: withdraw any consent you've given (cookie consent via the banner; marketing consent via unsubscribe or by emailing us).
- Complain to the ICO: see §16.
To exercise any right, email hello@planiverse.uk. We aim to respond within 30 days; we may extend this to 60 days for complex requests, in which case we'll tell you within the first 30 days. We may need to verify your identity before responding.
09How long we keep your data
- We do not create customer accounts: a report is a one-off purchase delivered by email, with no login. The personal data from a purchase (your email and the address and details you entered) is retained only within the transaction record (see "Payment records", 6 years) and the generated report (90 days); there is no persistent account to retain or purge.
- AI-call logs (request and response bodies): automatically deleted after 90 days by an enforced retention job. The metadata row in our database is deleted at the same time as the stored body.
- Search history: kept for up to 24 months, then deleted or anonymised for product analytics.
- Generated PDF reports: kept for 90 days in our private storage, after which the file is deleted. The transaction record (address, date, type, payment reference) is kept for 6 years for accounting purposes; you can request a re-issued PDF during that period.
- Payment records and customer billing data: kept for 6 years from the end of the financial year in which the transaction occurred, in line with UK accounting and tax requirements (Companies Act 2006, HMRC).
- Email subscriptions and waitlist entries: kept until you unsubscribe, or 24 months of inactivity, whichever is sooner.
- Server logs: application and access logs are kept for up to 30 days, then rotated.
- Google Analytics data: held by Google for 14 months, the maximum we have configured.
- Third-party planning records: planning application records obtained from public registers (see §14) are retained only for as long as they remain relevant for local comparative analysis. A record is deleted 5 years after the application's decision date; or, where the record has no decision date, 5 years after the date it was validated, received, or (failing those) the date we obtained it. A record is also deleted when we cease covering the local planning authority concerned, or immediately upon a successful objection (see §14).
10Security
- All connections are encrypted in transit using HTTPS / TLS 1.2+. Strict-Transport-Security (HSTS) is enforced.
- Database access is restricted to authorised application servers via short-lived credentials. Row Level Security is enabled on all application-data tables.
- Secrets (API keys, database credentials) are stored as encrypted environment variables and rotated when staff change or on a periodic schedule.
- We log all report-generation activity for security and quality review, with the 90-day retention described above.
- If we detect a personal data breach that risks your rights, we will notify the ICO within 72 hours and contact you directly without undue delay.
11Children
Planiverse is intended for property owners. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, please email hello@planiverse.uk and we will delete it promptly.
12Automated decision-making
Planiverse uses AI to generate planning intelligence reports. These outputs are analytical and informational: they do not produce legal or similarly significant decisions about you as an individual, and they are clearly labelled as AI-generated.
We do not use automated decision-making (within the meaning of UK GDPR Article 22) for credit, eligibility, insurance, employment, or anything else that would have a legal or similarly significant effect on you.
13Where our data comes from
The personal data we hold about you comes from:
- You directly: what you enter to generate a report (address, project details), at checkout (email), and through any forms on our site.
- Public planning data sources: we obtain planning application records from the public planning registers maintained by local planning authorities in England (directly and via aggregation services such as PlanIt.org.uk), and planning constraint data from national datasets published by government (including planning.data.gov.uk). These records describe planning applications and decisions at specific properties. Because a planning application is made by a person, these records can relate to identifiable individuals — see §14 for how we handle that.
- Address-resolution providers: when you select an address, Ideal Postcodes / postcodes.io return structured address details (UPRN, postcode, coordinates, ward) that we store against your search.
14Planning records relating to other properties
This section explains how we process information about planning applications at properties other than the one a customer is asking about — because those records can relate to identifiable people. If a planning application connected to you appears in our data, this section is addressed to you.
What we process, and where it comes from. English councils are required by law to maintain a public planning register: every planning application and its outcome is published so that development can be publicly scrutinised. We obtain planning records from those public registers. For each application we may hold the property address, the description of the proposed work, the application type, the decision and its date, and reference numbers.
Why we process it. Our reports tell a homeowner what the planning data suggests about their own property. That necessarily involves looking at what has happened at comparable properties nearby: what was applied for, and what was approved or refused. Without those neighbouring records there is no analysis.
Our lawful basis. We rely on legitimate interests (Article 6(1)(f) UK GDPR). Our legitimate interest is operating a commercial service that helps homeowners understand the planning position of their property before committing to professional fees, using records that councils already publish for public scrutiny. We have carried out and documented a Legitimate Interests Assessment weighing that interest against the rights and interests of the individuals concerned.
The safeguards we apply.
- We do not retain or display applicant or agent names in dedicated fields.
- Where personal names appear incidentally within free-text proposal descriptions extracted from the public register, we apply an automated redaction filter at the display layer to materially reduce incidental name exposure where technically feasible.
- Raw unredacted descriptions are held securely, access-restricted, solely as the underlying source records from which the customer-facing display is derived; they are never served or disclosed.
- We do not name individual planning officers on our public pages.
- Third-party planning records appear within the paid report; we do not publish identifiable comparable records on our public marketing pages.
- We correct known errors in decision outcomes for any council whose data we use before that data is shown.
- Where a customer wants the full application, including any named individuals, they follow an outbound link to the council's own public register, where the council discloses that information under its own statutory duty and lawful basis.
Why we have not contacted you individually. Where personal data is obtained from a source other than the individual, UK GDPR normally requires the individual to be informed. We rely on the exemption at Article 14(5)(b): the records we process relate to a very large number of planning applications across England, and we hold no contact details for the individuals concerned. Obtaining contact details to individually notify each person would involve disproportionate effort and necessitate gathering additional personal data, which contradicts the principle of data minimisation. This published notice serves as the transparency measure instead, ensuring the processing is open and your rights can be exercised.
Your right to object and have your record suppressed. If a planning application connected to you appears in our data and you do not want it to, email hello@planiverse.uk with the property address or application reference. We will suppress that record from our product — it will no longer appear in any report or on any of our services — and confirm to you in writing. We aim to action objections promptly and will respond within one month at the latest.
How long we keep these records. See §09: records are retained only while they remain relevant for local comparative analysis, and are deleted when they age out of our analytical window, when we cease covering the authority concerned, or immediately upon a successful objection.
15Changes to this policy
We may update this policy to reflect changes to our service, our sub-processors, or our legal obligations. Any material changes will be posted on this page and reflected by the "last updated" date at the top before they take effect.