Privacy Policy

Version 00.15 · updated 2026-09-18

1. Who is responsible for your data

PitchPlan is operated by Daniel Dadashev, a registered sole trader, business no. 303485171, of Haplada 23, Ashkelon, Israel.

For personal data about you as the account holder, we are the controller. For personal data you enter about someone else, such as a client's name, phone number, address, account reference or price on a project, you are the controller and we act as your processor. Clause 7 sets out what that means, and Annex A to the Terms of Use sets out the terms that govern it.

Where this policy cites an article number, GDPR means the General Data Protection Regulation (EU) 2016/679. Citations to any other country's law name that country.

2. What we collect, why, and on what legal basis

2.1 Account and profile

Collected when you register, and editable afterwards in Profile.

What Why Lawful basis (GDPR Art 6) Email address Sign-in, account recovery, service messages 6(1)(b) contract Account and public profile identifiers Identify your account and your public profile address 6(1)(b) contract First and last name Your name to collaborators, on your business card and in messages 6(1)(b) contract Gender, optional Profile display, and internal audience statistics under clause 2.6 6(1)(f) legitimate interest Date of birth Age band for internal statistics and audience selection under clause 2.6 6(1)(f) legitimate interest Job title and short description Your professional profile and business card 6(1)(b) contract Profile photo Your avatar to collaborators 6(1)(b) contract Personal phone, contact email, address, country Contact details you choose to show on your business card; country groups you for internal statistics 6(1)(b) contract, and 6(1)(a) consent for what you choose to publish Business name, business number, phone, fax, email, address, country Your professional business card 6(1)(b) contract

We do not collect a national identity number, a passport number, a government identity document, or payment card details. Card details are entered on Paddle's own checkout and never reach us. See clause 4.

2.2 Your work

Projects, floor plans, layers, assets, uploaded 3D products and textures, project members and roles, annotations, and the collaboration record of who changed what and when. Basis: GDPR Art 6(1)(b), contract.

The collaboration record identifies the device each saved version came from, not only the account. It holds a random device identifier created in your browser or application, described in clause 2.7, and a readable name for that device derived from your browser or handset, such as "Chrome on Mac". This is what lets the project history tell you which of your own devices last saved a plan, and which collaborator's device changed something. Basis: GDPR Art 6(1)(b), contract.

When you publish a room as a showroom, that room stops being private and becomes readable by anyone holding its link, with no account and no sign-in. The same room can be placed inside a website you control, and anyone who reaches that page can open it there. What becomes public is the room, your public handle, your website address if you have given one, the title and description you wrote, the cover picture, and the date it was first published. A visitor is served the geometry of the room and the record of edits made to it, and nothing else from the project it was drawn from. The details you keep about the job, including the client's name, telephone number, address, account reference and price, are not part of what is published and are not readable by a visitor. Basis: GDPR Art 6(1)(a), your consent, given by publishing and withdrawn by unpublishing.

We take nothing from a visitor who opens an embedded showroom. No account is created, no advertising runs there, the payment provider's script is not loaded on that page, and the embedded view is not used to build a profile of the visitor. It reads the published room and the scene file, and nothing else.

2.3 Your plan, and what we count to enforce it

We record which plan your account is on, the Paddle identifiers that connect it to your subscription, and a count of what you are using against that plan: how many projects a free account is holding at once, and whether a plan that allows publishing is still live for the products and showrooms published under it. The count is kept by our server and never taken from what your device reports, because a limit a device can rewrite is not a limit.

Basis: GDPR Art 6(1)(b), contract. This is the agreement itself. The plan you chose sets what the account may do, and the count is how we honour it in both directions: it is equally what stops you being charged for something you did not take.

It cannot be switched off, and the law does not ask us to offer that. The right to object in GDPR Art 21 applies to processing carried out under Art 6(1)(e) or Art 6(1)(f); it does not reach processing that is necessary to perform a contract. Refusing it would mean asking for a subscription and refusing to let us see whether it is being kept. If you do not want it, the account is deletable at any time under clause 6 and the subscription cancellable under the Refund Policy.

2.4 Messages

Chat conversations between you and other users, and broadcast messages from us. Message contents and attachments are stored on our infrastructure. They are not end-to-end encrypted. They are encrypted in transit and at rest, and they are technically readable by us. We read them only where we must: an abuse report, a legal obligation, or a fault you have asked us to investigate. Basis: GDPR Art 6(1)(b) contract, and GDPR Art 6(1)(f) legitimate interest for handling abuse.

2.5 Consent and agreement records

For each legal document you accept or decline we store, server-side and append-only: the document key, the version in force, the action you took, a SHA-256 hash of the exact wording you were shown, and the server's timestamp. We deliberately do not record your IP address or your browser user-agent with a consent.

For a purchase we store your express request that the service begin immediately: the price shown, any discount and its source, the refund policy version, the server's timestamp and the wording you agreed to. Basis: GDPR Art 6(1)(c) legal obligation, and GDPR Art 6(1)(f) for evidence in a dispute.

2.6 Product statistics and audiences

We run no third-party analytics. No Google Analytics, Segment, Amplitude, Mixpanel or Sentry is present in the website, the Android application or the server code.

Advertising is a separate question and the answer differs by platform. The website carries no advertising and no advertising software. The Android application carries advertising, described in clause 2.10.

What we do run is first-party:

  • session counts and durations, platform used, and an approximate country derived from your device's timezone, not from your IP address and not from a location permission;

  • daily signup counts;

  • how a session arrived, recorded once per session as a single short word: the utm_source value carried in the link you followed, or invite if you came through an invitation link, or the name of a promotion if you came through a promotion link, or direct if there was none. It records the link, not you, and no advertising network is told anything about it;

  • groupings by plan, country, age band derived from date of birth, gender and job title, used to choose who receives an announcement;

  • what is searched for, what is looked at, what is used, and what is shared, as counts. When you search the product catalogue, the textures or the community, the term you settled on is counted for that day. When you open a catalogue item or place one into a plan, what that item is is counted: its category, its colour, its type and its name. When you publish a room, export a project or open a share sheet, the action is counted.

    What is never counted is who sells it. No supplier, store, owner, business name, catalogue number or price is recorded against any of these figures, and no figure we hold or publish can be traced to one supplier any more than to one person. We hold no data about a specific customer and none about a specific supplier.

  • one coarse grouping attached to those counts: the country, an age band such as 35-44, and gender. All three come from the profile you filled in yourself: the country from the address on your profile, the age band worked out from your date of birth with the date itself never attached, the gender from the field you answered. Nothing in this grouping is read from your device: not your IP address, not a location permission, not your device's timezone or region setting. Every one of the three is optional: if you are signed out, or you left the field empty, that part is recorded as unknown and nothing is guessed to fill it. What leaves your device is the term or the action, the day, whether it came from the website or the application, and that grouping, and no account, session or device identifier. The entry is deleted once counted, and nothing anywhere records that a particular person searched for a particular thing.

What may be done with these counts once they are aggregated is in clause 4, and the minimum count that protects them is stated there.

Why most of this is not personal data at all. A count of what was searched carries no account, no session and no device. There is no key in it that could be joined back to you, and the grouping is one country, one seven-year age band and one letter for gender. It cannot single you out, it cannot be linked to another record about you, and what it supports is a statement about a population, not about a person. On the test the European Data Protection Board sets out in its Guidelines 02/2026 on anonymisation, which asks about record isolation, linkage and inference, these counts are anonymous, and GDPR Recital 26 puts anonymous information outside the Regulation entirely. We therefore do not offer, and are not required to offer, a way to switch them off.

Session summaries used to carry your account id and no longer do. It was never read by anything, so removing it cost no figure and took the last identifier out of these counts. Nothing in the statistics above is about you.

One thing in this clause is still personal data and we say so plainly: while you have PitchPlan open, a live-presence entry carries your account id so the "who is here now" panel counts your open tabs as one person rather than three. It is visible only to us, and it is deleted the moment you disconnect. It is not stored, not aggregated and not part of anything above. Basis: GDPR Art 6(1)(f), our legitimate interest in operating the product. You may object to it under GDPR Art 21; see clause 6.

We send marketing messages only to accounts that have given marketing consent. That consent is optional, it is off unless you turn it on, and you can withdraw it at any time from the agreements section of your preferences, on the website and in the Android application. Withdrawing it does not affect your account or your subscription. Basis for marketing: GDPR Art 6(1)(a) consent.

2.7 Cookies and what is stored on your device

We run no advertising cookies and no analytics cookies, and we show no consent banner. Nothing in our own code writes a cookie, and an automated check enforces that at every build.

We do store information on your device in your browser's local and session storage, and the application does the same on your handset. That is the same kind of act as setting a cookie, so we list it rather than rely on the word "cookie" doing the work.

Website, kept until you clear your browser storage:

Key What it holds @pitchplan/device_id A random identifier generated the first time you open PitchPlan in this browser. It means nothing outside PitchPlan and is not shared with anyone. It is stored alongside your projects so the history can say which device saved a version. See clause 2.2 pitchplan-theme, pitchplan-language The theme and language you chose pitchplan_input_mode, pitchplan_camera_control, pitchplan_camera_sensitivity, pitchplan_movement_speed How you prefer to drive the 3D view pitchplan_project_defaults The defaults you set for a new project olympus_report_currency The currency you chose to read figures in pitchplan_tutorial_disabled, pitchplan_tutorial_suppressed Which tutorials you have turned off pp_my_invite_link Your own invitation link, so it does not have to be issued again Keys beginning ss_ Short-lived state while you are signing in, such as which plan you clicked before registering. They expire an hour after they are written pp.debugBridge, pp.debugBridgeVerbose, pp.debugCollab Developer diagnostics. They stay unset unless a developer sets them

Website, cleared when you close the tab:

Key What it holds @pitchplan/session_id An identifier for one browsing session, used to keep concurrent edits in order pp_invite_ref, pp_invite_token If you arrived through an invitation link, the reference carried in it, so the invitation can be honoured when you register pp_campaign If you arrived through a promotion link, the promotion's short name, so the benefit it offered can be applied when you finish registering. It is removed as soon as it is used. See clause 2.13 vcard_<identifier> A copy of a public business card you have just opened, so that returning to it does not fetch it again @pitchplan/chunk_reload A flag set once if part of the site fails to load and has to be retried

We use no IndexedDB. Your sign-in session is stored separately by the Firebase Authentication library under its own keys.

Android application, kept until you uninstall or clear the app's data:

Key What it holds @pitchplan/device_id The same kind of random device identifier as the website's, generated once per installation. It is stored alongside your projects so the history can say which device saved a version. See clause 2.2 @pitchplan/device_name_override A device name you have chosen to use in place of the one your handset reports @pitchplan/projects Your projects, held on the device @pitchplan/isLoggedIn, @pitchplan/userStatus Whether you are signed in, and whether the account is registered or temporary @pitchplan_theme, @pitchplan_language The theme and language you chose @pitchplan_input_mode, @pitchplan_camera_control, @pitchplan_camera_sensitivity, @pitchplan_movement_speed, @pitchplan_indicator_style, @pitchplan_rotation_lock How you prefer to drive the 3D view @pitchplan_project_defaults The defaults you set for a new project @pitchplan/tutorial_mode_disabled, @pitchplan/tutorial_suppressed Which tutorials you have turned off @pitchplan/saved_bt_devices Bluetooth measuring devices you have paired with the app, so they reconnect without being paired again pp:noteAvatarPhotos:v3 A cache of the profile pictures of people collaborating on a project you have open, so the app does not fetch them repeatedly @pitchplan/seen_before A flag set after your first session, so that a session summary can be counted as a first visit or a return. It holds no identifier @pitchplan/devLogs Developer diagnostics. It stays unset unless a developer sets it

Three of these are worth naming separately, because they are not settings you chose. The device identifier is described above and in clause 2.2. The first-visit flag exists to count new against returning sessions. The avatar cache holds pictures of other people, kept on your device only, and cleared with the app's data.

The advertising components in the Android application store their own values on your handset, outside the list above and under keys we do not choose: your answer to the consent form, and what Google's advertising library needs in order to work. Clause 2.9 describes what they are for. Your device's advertising identifier is provided by Android itself and is not ours; you can reset it or turn off personalisation in your device settings, and neither of those affects your PitchPlan account.

One third-party script runs on our public pages. So that prices appear in your own currency with your local tax already applied, the pricing section loads Paddle's checkout library from Paddle's servers. It loads on the landing page whether or not you are signed in and whether or not you ever buy anything. Paddle therefore sees your network address and browser when that page loads, and stores what its own library needs on your device. It is not an analytics or advertising script, it does not profile you, and it reports nothing to us about you. Clause 4 covers what Paddle does with what it holds.

2.8 Logs

Server logs are written by Google Cloud Logging. Log output passes through a redaction step that replaces values under keys containing password, token, secret, apiKey, email, phone, idNumber, creditCard or ssn, and truncates user identifiers to their first four characters.

Two log stores exist. Operational logs are kept 30 days. Administrative activity audit logs are kept 400 days; that period is fixed by the platform and we cannot shorten it. If a log line carries personal data that survived redaction, 400 days is its retention period.

2.9 What you write to us, and what we send you

The addresses we publish in this policy deliver into a Google Workspace mailbox that we control. When you write to us, your email address, your subject line, your message and anything you attach are held in that mailbox and can be read by the people who run the service. That includes a request to exercise any of the rights in clause 6, because clause 6 asks you to write to us to make one.

We read this mail to answer you, to meet a legal duty such as a rights request or a refund, and to keep a record that we answered. Basis: GDPR Art 6(1)(b) contract for support about your account, GDPR Art 6(1)(c) legal obligation for a rights request or a consumer right, and GDPR Art 6(1)(f) legitimate interest in keeping a record of what we were asked and what we replied.

When we send an announcement or a marketing message to a group of accounts, we keep a record of it: the subject and text sent, which group it went to, whether it was sent as marketing, who sent it, how many accounts it reached, and the address of any account the message could not be delivered to together with the reason. That record does not contain the recipients who did receive it.

2.10 Advertising in the Android application

The website carries no advertising. The Android application does.

Advertisements are shown between actions in the Android application to accounts that are not on a paid plan. A paid subscription removes them, and that is a term of the plan rather than a preference. They are not shown to a signed-out visitor, and they are never shown in place of something you were doing: if no advertisement is available, or you declined one, the action simply continues.

The advertisements come from Google AdMob. When one is requested, Google receives technical information about your device and the advertising identifier your Android device provides, which you can reset or switch off in your device settings. We send Google nothing from your account and nothing from your projects: not your name, not your email address, not your plans, not your messages. We collect no location data ourselves, and nothing we send Google tells it where you are. Google itself determines an approximate location from the network address your device connects from, and may use that both to select advertisements and to decide which consent form to show you. That processing is Google's, under Google's own terms and privacy notice; we do not receive it and we do not direct it. Google receives no report from us about who you are, and we receive no personal data back from Google.

Consent, and what happens without it. Before any advertisement can be requested, the application asks Google's User Messaging Platform, a certified consent management platform, whether the law where you are requires your consent. Where it does, which includes the European Economic Area, the United Kingdom and Switzerland, you are shown a consent form and your answer is kept by that platform. Deciding whether a form is needed takes one call to Google when the application starts.

The application shows an advertisement only where that platform says one may be requested. If the platform gives no answer, because the form was closed, the request timed out, there was no network, or something failed that we did not anticipate, nothing is requested and the action you were taking simply continues. The safe direction is the only direction the application takes when the answer is missing.

A refusal is not always the end of advertising, and we say so rather than imply otherwise. Where you refuse consent, Google's platform may still permit a limited advertisement, one selected without using your advertising identifier and without building a profile of you. The application does not override that verdict in either direction: it asks the platform whether an advertisement may be requested and obeys the answer. What it never does is request a personalised advertisement from somebody who refused one.

Changing your mind. Where you were shown a consent form, the Settings screen of the Android application carries a Privacy options row that reopens that form, so withdrawing consent is as easy as giving it, which is what GDPR Art 7(3) requires. The row appears exactly when the consent platform says a way back is required, which is the European Economic Area, the United Kingdom and Switzerland. There is no switch that turns advertising off altogether on a free plan; a paid subscription removes advertising, and that is described in clause 4 of the Terms of Use.

What Google does with what it collects for advertising is governed by Google's own terms and its own privacy notice, and for that purpose Google is not simply acting on our instructions. Basis for advertising to accounts in the European Economic Area, the United Kingdom and Switzerland: GDPR Art 6(1)(a), consent, obtained through the form described above. Where consent is refused and a limited advertisement is nonetheless served, that advertisement is selected without your advertising identifier and without profiling, and Google is responsible as controller for the basis on which it does so.

2.11 Permissions the Android application asks for

Android asks your permission before an application can use certain features of your handset. These are the ones PitchPlan asks for, what each one is for, and what we do with what it gives us. You can grant or withdraw any of them at any time, in the Permissions screen inside the application or in your Android settings, and the application keeps working without them, with the feature that needs the permission unavailable.

Permission Why the application asks What we collect Microphone Recording a voice message in a project chat, while you hold the record button The recording you chose to send, stored and delivered as a chat attachment under clause 2.4. Nothing is recorded before you press, and nothing is recorded after you release Nearby devices, which Android calls Bluetooth scan and Bluetooth connect Finding and connecting a Bluetooth laser measuring device, so a measurement goes straight into a plan The identity of a device you paired, kept on your handset so it reconnects without pairing again, and the measurements it sends. See clause 2.7 Contacts Only when you choose to import your contacts from the chat's Contacts tab, after a notice in the application that says what will be read and why The names, phone numbers and email addresses of the contacts you imported, kept as described in clause 2.14. Nothing is read before you press Import, and nothing is read again unless you import again Location, on Android 11 and older only Nothing to do with where you are. Until Android 12, Android would not let any application scan for Bluetooth devices without the location permission, so on those versions it is the price of the measuring-device feature Nothing. We do not read your location, we do not store it and we do not send it anywhere. On Android 12 and newer the application does not ask for this permission at all, and our Bluetooth scan is declared to Android with the neverForLocation flag, which tells the system it must not be used to derive a location

We collect no location data on any platform. The website asks for no location permission. The approximate country in clause 2.6 is derived from your device's timezone setting, and nothing else.

We do not send push notifications, and the application asks for no notification permission.

2.12 Where we get your data from

Almost everything in this policy comes from you, or is generated by your use of the product. Two things do not:

  • Paddle tells us that a subscription was paid, changed, refunded or cancelled, and the country Paddle determined for tax. We receive no card number and no bank details. See clause 4.

  • Google tells our sign-in service that a Google account authenticated successfully, and gives us the email address and, where you have one, the name and profile picture on that account, if you chose to sign in with Google.

We buy no personal data, and we receive none from a data broker, an advertising network or a list provider.

2.13 Invitations and promotions

Two things can attach a benefit to a new account, and both leave a record on it.

An invitation. Someone already using PitchPlan sends you their link. If you register through it and later subscribe, they receive free time. We store, on your account, which invitation you arrived through, so that the reward can be paid to the right person and paid once.

A promotion. A promotion link opens a page at an address of the form /promo/ followed by the promotion's short name. If you register through it, your account may receive either a period of a paid plan as a gift or a discount held against a future purchase. We store, on your account, the promotion's short name, which of the two kinds it was, and the moment it was claimed. A promotion can be claimed once per account, only by an account that has just registered, never paid before and not already carrying a promotion.

These records exist so that a benefit is granted once and to the right account, and so that a question about a missing reward can be answered. They are kept as long as the account exists and are deleted with it. Basis: GDPR Art 6(1)(b), contract, because the benefit is part of what you were offered. Counts of how many accounts a promotion produced are kept as figures about the promotion and carry nothing about you.

2.14 Contacts you import

The chat's Contacts tab lets you bring in your own contacts, from the Google account you signed in with (on the website and in the Android application) or from the handset's address book (in the Android application). Nothing is imported until you ask for it. Google shows its own consent screen for its contacts before we receive anything; Android asks its permission after a notice from us.

What we keep is the names, email addresses and phone numbers of the contacts you imported, in a document under your own account that only you can read, and which you can delete from the same tab at any time. It is used for two things: to show you which of your contacts already hold a PitchPlan account, by checking their email addresses and phone numbers against registered accounts on our server, which keeps no copy of what it checked; and to give you an invitation you can send to the others yourself. We do not message your contacts, we do not share them, and we do not use them for anything else. Deleting your account deletes them.

The people in your contacts have not agreed to anything with us and are not our users. Clause 7 applies: you are responsible for having the right to hold their details, and the lawful basis on our side is GDPR Art 6(1)(b), running the feature you asked for. Basis for the import itself: your instruction.

3. Where your data is stored

Store What it holds Region Cloud Firestore Accounts, projects, messages, consents, billing records European Union multi-region Firebase Realtime Database Live collaboration, presence, locks Belgium Cloud Storage Project assets, uploads, images Belgium Cloud Functions All server-side processing Belgium Firebase Authentication Email address and sign-in identifiers Google-managed; no region is selected by us

Every store for which a region can be chosen is in the European Union. Until 21 August 2026 the file store and the server functions were in the United States, and we moved them.

Three things about that are worth stating plainly rather than leaving to be discovered.

  1. The file store we used before the move still exists in the United States and still holds copies of files uploaded before that date. The product no longer writes to it, and the only thing still read from it is a set of images in the public product catalogue, which are public by their nature. We have not yet deleted it.

  2. Firebase Authentication is not offered to us with a region choice, so we have not made one. It holds your email address and sign-in identifiers.

  3. Advertising in the Android application involves Google outside the European Economic Area, as clause 2.10 describes, and only where you have consented.

Each of those is an international transfer under Chapter V of the GDPR.

We are established in Israel, and the European Commission recognises Israel as providing an adequate level of protection, so a transfer from the European Economic Area to us needs no additional safeguard.

For the United States leg our processor is Google. Google LLC holds an active certification under the EU-US Data Privacy Framework, its UK Extension and the Swiss-US framework, covering Google and its wholly-owned US subsidiaries unless explicitly excluded. Google's Cloud Data Processing Addendum incorporates the European Commission's standard contractual clauses for its cloud services. The Commission's adequacy decision for the Data Privacy Framework was upheld by the EU General Court on 3 September 2025 in Case T-553/23, Latombe v Commission, and remains in force; an appeal is pending before the Court of Justice as Case C-703/25 P.

4. Who else receives your data

Five companies receive your data in the ordinary running of the service, and no others do. Clause 4.1 and clause 4.2 describe the only two situations in which anybody else could ever receive it.

Recipient What they receive Why Google LLC and Google Ireland Ltd (Firebase, Google Cloud) Everything described in clause 2, because they host it Hosting, database, authentication, file storage, server execution, logging Google Maps Platform (Places) The address text you type into an address field, sent from your browser as you type Address autocomplete on registration, profile and project forms Google Workspace (Gmail API) Your email address and the contents of every message we send you, and, if you write to us, your message as it sits in our mailbox Sending service email, sending announcements and marketing email to accounts that have consented, and holding the mailbox our published addresses deliver into. See clause 2.9 Paddle.com Market Ltd Your email address, billing address and payment details, which you give to Paddle directly. Separately, and before any purchase, the network address and browser of anyone who opens a page showing prices, because Paddle's library is loaded there to convert prices. See clause 2.7 Merchant of record for every purchase. Paddle takes the payment, issues your invoice, appears on your bank statement and processes refunds. It also localises the prices shown before you buy Google AdMob In the Android application only, and only for an account without a paid plan that has consented where consent is required: technical information about your device and your device's advertising identifier. Nothing from your account and nothing from your projects. See clause 2.10 Showing advertisements, and measuring them

Paddle is the merchant of record and decides for itself how it handles the payment transaction. Its own privacy notice governs that. Google likewise decides for itself what it does with what it collects for advertising.

We do not sell personal data and we do not share it with data brokers. We do not pass your name, your email address, your projects or your messages to any advertising network.

Aggregate figures are a different thing, and we may give them away, publish them or sell them. They are drawn from the counts in clause 2.6, for example how many times a category, a colour or a type of product was searched for, looked at or used in a month, and how those counts break down by country, age band and gender. They contain no personal data, they are never broken down to a person, and any figure counted fewer than ten times is left out entirely. That minimum applies to the whole figure including its grouping, not to the product alone: a colour searched four thousand times is published, and the same colour in one country by one age band four times is not.

They likewise say nothing about any individual supplier: the counts record what a product is, never who sells it, so no report can show one supplier's performance to another.

The one advertising relationship we have is the one in clause 2.10, it exists only inside the Android application, and it is described there in full.

We also read foreign-exchange reference rates from the European Central Bank. No personal data is sent there.

4.1 When the law compels us

We may disclose personal data to a court, a regulator, a tax authority or a law enforcement body where a binding legal obligation requires it, and to our own lawyers or insurers where we need to establish, exercise or defend a legal claim. The lawful basis is GDPR Art 6(1)(c) for the first and GDPR Art 6(1)(f) for the second.

We disclose only what the demand actually covers. We check that the demand is binding on us before we answer it, and we refuse an informal request that carries no legal force. Where we are lawfully permitted to tell you that a demand was made, we will tell you.

4.2 If the business changes hands

If PitchPlan is sold, merged into another business, restructured, or if its assets are transferred, your data may pass to the buyer or the successor as part of that transaction, because the service you hold an account with would then be run by them. The lawful basis is GDPR Art 6(1)(f), our legitimate interest in being able to transfer the business as a going concern.

Three things are fixed and are not left to the buyer's discretion:

  • We will tell you before it happens, or as soon as we lawfully can if the transaction itself is confidential until it completes.

  • The buyer is bound by this policy as it stands on the day of the transfer, until they give you a new one and you have had the chance to react to it.

  • You may delete your account instead. Clause 6 applies unchanged, and a pending sale is not a reason for us to delay an erasure request.

Before a transaction completes, a prospective buyer examining the business receives aggregate figures and contract terms. It does not receive your account, your projects, your messages or your email address.

5. How long we keep it

Data Kept for Account, profile, projects, messages As long as your account exists A sign-up you started and did not finish 7 days, then the name and email address Google gave us are deleted with the unfinished account. We send you a reminder on the third day and on the sixth; cancelling the sign-up deletes everything at once and ends the reminders Cloud project copies after a paid plan ends 30 days, with a reminder 7 days before deletion. The deletion runs on a nightly pass, so it happens on the first pass after the 30 days are up Products and showrooms you published, after a plan that allowed publishing ends The showrooms come down from the community that day and the products are hidden from it. The product records and their files are kept 30 days on their own clock, with the same reminder, then deleted Project deletion records Until every device that held a copy has acknowledged, and at most 90 days of device silence Payment provider event records 90 days, then deleted automatically Invitation reward credits They lapse 24 months after they are earned Which invitation or promotion your account arrived through As long as your account exists, and deleted with it. See clause 2.14 Consent and agreement log As long as your account exists. It is append-only The raw entry behind a usage count (clause 2.6) Until the next roll-up, which runs every 15 minutes. It is deleted as it is counted, and it carries no account, session or device at all: the database itself refuses an entry that tries to The live-presence entry (clause 2.6) While the page or app is open. Deleted on disconnect, by the database, not by a job that might not run The usage counts themselves, and their country / age band / gender grouping Kept indefinitely, deliberately. They are counts, they are subject to the ten-count minimum in clause 4, and there is nothing in them to delete for one person, which also means deleting your account does not change them, because none of them is about you Operational server logs 30 days Administrative audit logs 400 days, fixed by the platform Invoices and tax records Held by Paddle as merchant of record under its own statutory duty, not by us Email you send us, and our replies Kept in our mailbox while the matter is open and afterwards as our record that we answered. It is not deleted when you delete your account, because it is our side of a correspondence and may be evidence that we met a deadline Records of announcements and marketing messages we sent Kept as our record of what was sent, to whom as a group, and on what basis

Deleting your account does not empty our mailbox. If you want the correspondence itself removed, say so and we will treat it as an erasure request under clause 6 and answer it on its own terms.

When you delete your account we delete your user record and everything under it, every project you own and its stored files, your uploaded products and lists, your chat participation, your entry in other users' favourites, and your authentication record; your Paddle subscription is cancelled and its local copy removed. This is a hard delete, not a flag.

6. Your rights

Under the GDPR, the UK GDPR and Israel's Privacy Protection Law 5741-1981 you may (article numbers below are the GDPR's; the UK GDPR mirrors them, and Israeli law grants the equivalent core rights in its own sections):

  • access the personal data we hold about you (Art 15);

  • correct it (Art 16);

  • erase it (Art 17);

  • restrict or object to processing (Arts 18 and 21). The statistics in clause 2.6 are outside this right and outside the GDPR altogether, because they are anonymous; see the note there. The live-presence entry described in the same clause is not, and you may object to it;

  • port your data to another service (Art 20);

  • withdraw consent at any time, without affecting what was lawful before you withdrew it;

  • complain to a supervisory authority. See clause 13.

What that looks like in practice today, stated plainly:

  • Erasure is self-service. Settings, then Security and Privacy, then Delete Account. It performs a complete deletion.

  • Correction is self-service. Most of your profile is directly editable.

  • Portability is partial. You can download any single project as a .pitchplan archive, free of charge and without a subscription. We provide no one-click export of your whole account covering profile, messages, consents and billing history. Ask us and we will produce it by hand.

  • Access is by request. We provide no download-my-data screen. Write to the address in clause 1.

To exercise a right, write to support@pitch-plan.com. We answer within one month as GDPR Art 12(3) requires, extendable by two further months for complex requests, and we will tell you if we extend.

7. Data you enter about other people

When you record a client's name, phone number, address, account reference or price on a project, that person did not sign up with us and may never have heard of us.

  • You decide to collect it and for what purpose. You are the controller.

  • We store it and serve it back to you. We act as your processor, on your instructions, on the terms in Annex A to the Terms of Use, which sets out what we may do with it, who else holds it, where it sits, how you get it back and when it is deleted.

  • You owe that person the information duties in GDPR Art 14. They have a right to know that you put their details into a tool.

We do not use this data for any purpose of our own. It is not included in the statistics in clause 2.6, and it is never sent to an advertising network.

8. Security

  • Encrypted in transit, and encrypted at rest by Google.

  • Access control enforced at the database itself, in Firestore, file storage and realtime database rules, not only in the interface.

  • Application integrity checks on every server function our own applications call, so that a request has to come from a genuine copy of the website or of the Android application, not only on the administrative publishing path.

  • Server-side rate limiting on sensitive operations.

  • Redaction of sensitive field names in logs.

  • A record of unusual events, kept for review.

We claim no end-to-end encryption and no security certification. Chat messages are readable by us, as clause 2.4 states. GDPR Art 32 requires measures appropriate to the risk, and these are the measures we take.

9. Age

PitchPlan is built for professionals and adults planning building work. It is not directed at children.

The service is for people aged 18 and over. Your date of birth is an optional field, and the registration form on the website and in the Android application offers only dates at least 18 years in the past, so it cannot be used to record a younger age. We do not verify the date you give: we ask for no identity document and we run no age-estimation of any kind. A date that is not yours is a false statement to us, and its consequences are yours.

So the rule is enforced on the answer you give and not on your identity. If you believe that a child has registered, write to support@pitch-plan.com and we will delete the account.

10. Automated decision-making

We make no decision producing legal or similarly significant effects about you by automated means, within the meaning of GDPR Art 22. Audience selection for announcements groups accounts by country, plan, age band, gender and job title. It decides who receives a message, and nothing about your rights or your money.

Which advertisement Google selects in the Android application is decided by Google, on what Google holds, and not by us. It decides what you are shown for a few seconds, and nothing about your account, your subscription or your work.

11. Changes to this policy

We may update this policy. Every version is archived with its number, and the version in force is shown at the top of the published page. Where a change is material we will tell you before it takes effect.

12. Which laws reach us, and which do not yet

We sell in the European Economic Area, the United Kingdom, the United States and Israel, and we hold ourselves to the strictest applicable rule in one set of documents rather than four. Where a law does not reach us we say so with the threshold, so you can see for yourself when it would.

Regime Applies to us The threshold, and where we stand GDPR (EU/EEA) Yes It applies to any EEA person's data whatever our size. Everything above is written to it UK GDPR Yes A separate regime since Brexit, materially the same rights. Our contact details in clause 1 serve both Israel: Privacy Protection Law 5741-1981, as amended by Amendment 13 (in force 14 August 2025) Yes We are established in Israel. We do not meet the registration threshold for a database holding sensitive information on more than 100,000 people, nor are we a public body. We do not today run a direct-marketing database of more than 10,000 people; if we do, we will register it before we cross that line US state privacy laws (California CCPA/CPRA and the state laws modelled on it) Not yet California reaches a business only above one of three thresholds: annual gross revenue over $25 million, buying or selling the personal information of 100,000 or more consumers or households, or deriving 50% or more of revenue from selling or sharing personal information. We are below all three. Aggregate figures that identify nobody are not personal information for this purpose

If any of that changes, this clause changes with it, and before the fact, not after. Growing past a threshold is a planned event, not a surprise.

13. Complaints

Write to us first, at support@pitch-plan.com. If we cannot resolve it, you may complain to a supervisory authority: in Israel, the Privacy Protection Authority; in the European Economic Area, the authority where you live, where you work, or where the alleged infringement took place (GDPR Art 77); in the United Kingdom, the Information Commissioner's Office.