The short version (plain language)
The full details are below. This summary is for convenience and does not replace it.
1. Who we are
This Privacy Policy explains how PlanO Events, a sole proprietorship in Lipa City, Philippines(“PlanO,” “we,” “us”) handles personal information, in line with the Data Privacy Act of 2012 (RA 10173), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC).
2. The information we collect
a. Waitlist information. The email address you submit on our website, used only to send you updates about PlanO.
b. Account information. When you create an account: your name, work email, business details, and login credentials.
c. Onboarding and usage information. During setup we may collect operational details about your business (for example, events per week, busy and slow months, typical inquiry volume) and how you use the Service. Some of this is stored for our internal product and analytics purposes to improve PlanO and is not necessarily displayed back to you.
c-1. Incomplete signup information. If you begin creating an account but do not complete payment, we keep the account details you entered (such as your name and email) in a pending state so you can return and finish, and so we can send you a reminder to complete signup. See Sections 3 and 5b.
g. Tax and invoicing details (optional). If you want a BIR-compliant service invoice for your subscription, you can give us your registered business name, Taxpayer Identification Number (TIN), registered business address, and a finance or accounts-payable email. Providing these is entirely optional — the Service works without them — and we use them only to prepare, issue, and keep records of your invoices. We do not use them for marketing, profiling, or any other purpose. If you are a sole proprietor, note that your TIN and registered details are also personal information about you, and they are held under the same protections as everything else in this Policy. See §10 for how long invoicing records are kept.
d. Customer Data you provide. As a coordinator, you input information to run your workflow, including the personal information of your own clients and suppliers (names, contact details, message contents, event details, supplier categories, and pricing). For this information, you are the controller and PlanO is your processor — we process it on your instructions to provide the Service.
e. Connected messaging data (Meta). If you connect a Meta (Facebook/Instagram) account, we access and process the message threads and related data you authorize, solely to provide the Service to you.
f. Connected calendar data (Google) — optional. If you choose to connect Google Calendar, we access your calendar to read your availability and to write events for booked discovery calls. This integration is entirely optional. We request the minimum access needed and you can disconnect at any time. See Section 6a for how we handle Google user data.
3. How we use information, and our lawful basis
| Purpose | Lawful basis (RA 10173) |
|---|---|
| Send waitlist/launch updates | Your consent |
| Provide and operate the Service | Performance of our contract with you |
| Process your Customer Data | On your instructions, as your processor |
| Process client event details that qualify as sensitive personal information (see §3a) | Consent obtained by you from your client, specific to the purpose and prior to processing (RA 10173 §13(a)); PlanO processes only as your processor |
| Schedule calls via your connected calendar (if enabled) | Performance of our contract with you |
| Secure the Service, prevent abuse | Our legitimate interests |
| Improve the Service using internal analytics and de-identified patterns | Our legitimate interests, in a way that does not identify any individual |
| Notify suppliers referenced by coordinators (Section 7) | Our legitimate interests, balanced against supplier rights |
| Remind you to complete an incomplete signup (Section 5b) | Our legitimate interests |
| Collect your tax and invoicing details (§2g) | Your consent, given at the point you provide them |
| Issue and retain BIR-compliant invoices and books of account | Legal obligation (National Internal Revenue Code and BIR regulations) |
| Comply with law | Legal obligation |
We do not sell your personal information, and we do not share it for others’ independent use.
3a. Sensitive personal information in client event details
Event work involves categories that RA 10173 §3(l) treats as sensitive personal information — including marital status, age, and religious affiliation. A wedding brief will ordinarily contain at least one of these, and event details may also reference a child celebrant or minors attending.
This matters because sensitive personal information cannot be processed on the basis of legitimate interest. Under §13, processing is prohibited unless a narrow exception applies, and the applicable one here is the data subject’s consent, specific to the purpose and given before processing.
How we handle this:
- You obtain the consent, not us. Your client is your client. As controller, you are responsible for informing them and obtaining their consent for their event details to be processed by a service provider like PlanO. Your Terms of Service §4b sets out this obligation.
- We give you the wording. PlanO provides ready-made notice and consent text inside the intake and brief flow so you do not have to draft it. Using it is how you meet §4b in practice.
- We minimize what we hold. We do not store raw message threads beyond what is needed to produce and maintain your brief, and we keep only the fields the brief requires.
- We never use it for our own purposes. Client event details are processed solely to provide the Service to you. They are not used for analytics, product training, or any purpose you have not instructed.
4. How your private workspace data is handled (the two-layer model)
We separate two kinds of information and treat them differently:
- Your private relational data — which suppliers you use, your negotiated tie-up rates, and who is in your workspace — is visible only to you within your workspace. It is not shared with other coordinators or with your clients, and we do not use it to identify you to anyone outside the platform.
- De-identified, aggregate signals — for example, that a supplier category is referenced often across the network — may be used to improve discovery and platform quality in a way that never traces back to you or to your specific relationship with any supplier.
5. Supplier profiles — the two-layer model
Supplier information sits in two layers. All of it comes from coordinators — we do not scrape Facebook, Instagram, or other platforms.
Layer 1 — shared business facts. Business name, service category, service area, and publicly advertised pricing. PlanO is the controller for this layer. It is marked community-contributed and unverified until the supplier claims it.
Layer 2 — each coordinator’s private record. A coordinator’s negotiated rate, notes, and booking history. The coordinator is the controller and PlanO is their processor. It is visible only to that coordinator, never shown to others, and a negotiated rate is never placed on the shared layer.
Personal identifiers — a supplier’s personal name, personal mobile, or personal social account — do not cross workspaces on the shared layer.They stay in the private layer, or wait for the supplier’s own claim and consent.
Our lawful basis for the shared layer.Many Philippine suppliers are sole proprietors, so their business details can also be personal information. We therefore do not rely on the argument that business facts fall outside the law. We rely instead on legitimate interest under RA 10173 §12(f) — our interest, and coordinators’ interest, in maintaining accurate records of the suppliers they work with. We keep this narrow, and the limits below are what keep it fair. We keep the shared layer strictly to business-facing fields, which is what keeps this layer clear of the sensitive categories described in §3a, where legitimate interest would not be available. We do not rely on consent for this layer; consent applies only at the point a supplier claims and lists a profile.
- An unclaimed profile is not public and not discoverable by coordinators who did not add the supplier. We do not show a supplier’s logo before they claim it.
- A profile becomes public only if the supplier claims it, verifies their identity, and opts in (Section 5a).
- Suppliers can see, correct, object to, or delete their information whether or not they have claimed a profile. In the private phase, a request about one coordinator’s private record goes to that coordinator; requests about the shared layer, and all requests after a claim, are handled by PlanO. See the Supplier Data Notice and Section 8.
5a. Supplier verification and accounts
Suppliers may hold their own PlanO account, whether they claim an existing profile or sign up directly.
Before a profile is publicly listed, the supplier completes an identity check — a business document or government ID, plus a phone or GCash confirmation. We use this only to confirm identity and protect coordinators from impostors.
5b. Recovering incomplete signups
If you start signing up but do not complete payment, we keep what you entered so you can finish, and we may email you a reminder. You can ask us to delete a pending account anytime via privacy@planoevents.site, and we delete pending accounts left inactive after 90 days.
6. Who we share information with (sub-processors)
We share information only with service providers that help us run PlanO, under appropriate safeguards:
- AI provider (Google)— our AI features run on Google’s Gemini models through a single, paid Google Cloud project. See Section 6a for what this means for your data;
- Hosting/infrastructure (Vercel and our database provider) — to store and serve the Service;
- Payment (PayMongo, our payment gateway; PlanO is the seller of record) — to process subscription payments;
- Meta — only as needed to operate the messaging integration you connect;
- Google — also used, separately, to operate the optional calendar integration you connect.
We do not allow these providers to use your information for their own unrelated purposes.
6a. AI provider — no training on your data
PlanO runs its AI features on Google’s paid enterprise tier under the Google Cloud Data Processing Addendum. Under those terms, your prompts and the data we process for you are not used to train Google’s models, and we do not use any free or consumer-tier AI service anywhere in the Service. If we change AI providers or add another one, we will update this Policy and the sub-processor list in §6 before the change takes effect.
6b. Google user data — Limited Use (Calendar)
For the separate, optional Google Calendar integration, PlanO’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Calendar data only to provide the scheduling features you enable, we do not use it for advertising, we do not sell it, and we do not allow humans to read it except where you explicitly request support, where required for security or to comply with law, or in aggregated, de-identified form.
7. Notifying suppliers referenced by coordinators
As PlanO grows, when a supplier has been independently added by several different coordinators, we may send that supplier a one-time email invitation to claim a profile on PlanO.
- This invitation is coordinator-anonymized: it tells the supplier that several coordinators have referenced them, but it does not name which coordinators, and it never discloses any coordinator’s rates, client details, or workspace contents. (The supplier is identified to themselves on their own profile; what stays hidden is the identity of the coordinators who vouched.)
- We rely on our legitimate interest in connecting vouched-for professionals to a tool that benefits them, balanced against supplier rights.
- Every invitation explains how to opt out, object, or request deletion — a supplier can simply reply to the email. We honor those requests promptly and keep a minimal suppression record so we do not contact them again.
- Supplier outreach is conducted by email only.
8. Your rights under the Data Privacy Act
You have the right to be informed, to object to processing, to access your personal information, to correct it, to erasure or blocking, to data portability, to damages, and to lodge a complaint with the National Privacy Commission. To exercise any of these, contact privacy@planoevents.site. We will respond within the period required by law. These rights are available to coordinators, clients whose data is processed, and suppliers (including those with unclaimed profiles).
9. Cross-border transfers
Some service providers process data outside the Philippines. Our AI provider does so under the Google Cloud Data Processing Addendum (Section 6a), which bars training on your data. Hosting and calendar providers process abroad under their own terms. For all cross-border transfers, we take the steps RA 10173 requires to ensure comparable protection, including contractual safeguards. By using the Service, you are informed of these transfers.
Client event details cross the border too. Producing your brief means sending client message content to our AI provider outside the Philippines, and that content can include the sensitive categories described in §3a. We remain accountable for it under RA 10173 §21 wherever it is processed.
10. Data retention
We keep personal information only as long as needed for the purposes above or as required by law. Waitlist emails are kept until you ask us to delete them. Account and Customer Data are kept for the life of your account and deleted or returned within 30 days of account closure, except where law requires longer retention.
Unclaimed supplier profiles are deleted on a valid request from the supplier; after an opt-out we retain only a minimal suppression record so we do not re-contact them, and we may retain anonymized, aggregate signals that do not identify any individual.
11. Deleting your data
Account deletion: Request deletion of your account and associated personal information by emailing privacy@planoevents.site or using the in-app deletion option.
Meta data deletion: If you connected a Meta account, you can disconnect it in-app at any time. To request deletion of message data we processed, follow the instructions at planoevents.site/data-deletion.
Google Calendar: You can disconnect Google Calendar in-app at any time, which stops further access. You may request deletion of any calendar-derived data we hold via privacy@planoevents.site.
13. Security
We use reasonable technical and organizational measures to protect personal information, including access controls and encryption in transit. No system is perfectly secure; we will notify affected data subjects and the NPC of a personal data breach as required by law.
14. Children
PlanO is a business tool for professional event coordinators. It is not directed at children, children are not our users, and no part of the Service is designed for or made available to them. We do not knowingly collect the personal information of minors as account holders. Because children do not access the Service, the age-appropriate notice requirements that apply to products and services likely to be accessed by children are not applicable to PlanO.
15. Changes to this Policy
We may update this Policy. We will post the new version with a revised “Last updated” date and, for material changes, give reasonable notice. Where a change materially alters the purpose for which already-collected personal information is used, we will seek fresh consent where the law requires it rather than relying on notice alone.
16. Contact
PlanO Events
Lipa City, Philippines
Privacy / DPO: dpo@planoevents.site · General: info@planoevents.site
National Privacy Commission: privacy.gov.ph