Privacy Policy
Last updated: August 15, 2026This Privacy Policy explains how Planning Ops LLC, a South Carolina limited liability company (“we,” “us,” “Planning Ops”), collects, uses, and shares information when you use our software-as-a-service platform, the Planning Ops Platform (the “Service”), which includes the Place & Finish, Manpower, Project Schedule, and Daily Reports views, the Planning Ops application for iPhone and iPad, and any related websites, APIs, and services. For the purposes of applicable data-protection law (including GDPR, UK GDPR, and CCPA), Planning Ops LLC is the data controller for the personal information it processes through the Service.
By using the Service, you consent to the practices described here. If you do not agree, please do not use the Service.
1. Information we collect
Information you provide directly.
- Account details: name, email address, company name, password (stored as a salted hash, never in plaintext), and the workspace URL slug you choose.
- Payment details: Payment is processed entirely by Stripe, both during the 14-day trial and afterwards. We accept credit and debit cards, Apple Pay, and Google Pay. Wallet methods tokenize the underlying card inside the wallet provider; in every case we only see a Stripe customer ID and the last four digits of the underlying card for receipt display — we do not see, store, or transmit full card numbers. Your payment method is collected at signup but not charged during the 14-day trial period; the first charge attempts on day 15 if you have not canceled. If you cancel within the first 14 days you are not charged a cent. Cancellation is self-service from the Billing page inside your hub (Control Panel ▸ Billing); cancellation takes effect at the end of the current billing period (no refund for the current period), and you can resume anytime before then.
- Operational data you upload: employee names, project information, schedule entries, pour details, regions, contact details (names, emails, and phone numbers) of crew members and third parties you add for email/SMS notifications, and any other content you enter into the Service. If an administrator enables the optional Daily Reports module, this also includes the daily field reports your crews file — work performed, crew on site, equipment, deliveries, delays, safety and injury/incident records, foreman sign-off, and any photos captured or uploaded with a report. If an administrator enables the optional Time Tracking feature, this also includes employee time and payroll data — hours worked by pay type (straight, overtime, double-time, holiday, and PTO), the per-employee EE IDs and payroll IDs you enter, and the earning codes you configure for payroll exports. Payroll-system exports (for systems such as QuickBooks, ADP, or Paychex) are generated as files you download and import yourself; Planning Ops does not transmit your time or payroll data to any payroll provider. If an administrator enables the optional Certifications module, this also includes worker certification records — certification type, credential/certificate number, issue and expiry dates, and any notes you enter — together with any copies of certificates (PDF or image files) you upload, which may themselves contain personal information such as license numbers, dates of birth, signatures, or photographs, and which are stored in a private, tenant-isolated storage bucket and served only through short-lived signed links. To show weather forecasts on the schedule, the project location you enter (ZIP code, or city and state) is sent to third-party weather and geocoding APIs (Open-Meteo, Zippopotam.us, and the OpenStreetMap/Nominatim service) to resolve the location and fetch a forecast; no personal identifiers are sent.
- Communications: if you email us, we keep the message and your reply chain to support our response.
Information collected automatically.
- Authentication and session data: session tokens (JWTs) issued at login, and the IP address used to obtain the session — stored by our authentication provider (Supabase) for fraud detection and rate limiting. Planning Ops platform-administrator (staff) accounts are additionally protected by mandatory TOTP-based two-factor authentication (2FA); the TOTP secret is stored by Supabase. Customer-account two-factor authentication is on our roadmap.
- Security and license-compliance signals: for each session we record technical signals associated with the account — including the session token, IP address, coarse (approximate) location derived from the IP, device and browser characteristics (user agent), and concurrent-session activity. We use these signals to secure your account, detect and stop fraud and account takeover, and enforce rate limits, and we may use them to verify license compliance — including detecting when a single paid working seat credential is shared and used by more than one person at the same time (for example, simultaneous active sessions from different devices or locations). This anti-sharing enforcement is described in our Terms of Service. We do not use these signals for advertising, and we do not derive precise GPS location from them.
- Audit log: the Service maintains an in-app audit log of who created, modified, or deleted records within your workspace.
- Cookies / local storage: we store session tokens and small preferences (last visited week, UI toggles) in your browser’s local storage. These are strictly necessary to run the Service. On our public marketing and signup pages we also use the LinkedIn Insight Tag for ad conversion measurement and retargeting of our LinkedIn advertising, and PostHog for product analytics. These are not strictly necessary, and they set or read cookies and similar identifiers. If you are in the EEA, the UK, or Switzerland, neither loads until you accept them in the cookie notice shown on your first visit — declining leaves them switched off, and your choice is remembered for 180 days across planningops.com and signup.planningops.com. You can change it at any time via Cookie settings in the footer of any page. Everywhere else these load by default and you may opt out at any time by the same control. We also honor the Global Privacy Control (GPC) browser signal in every region, which switches both off regardless of any earlier choice. See the Product analytics entry below, the sub-processor table in Section 4, and Section 10.
- Product analytics: we use PostHog to record page views, button clicks, and a small set of business events (e.g. signup started, signup completed, hub login) so we can understand how the Service is used and improve it. The email address you use to sign in is sent to PostHog only as a SHA-256 hash (one-way), not in plaintext, so we can attribute events to an account without exposing the raw email to our analytics processor. To opt out, use Cookie settings in the footer of any public page (in the EEA, the UK, and Switzerland, analytics does not load at all until you accept it), or email admin@planningops.com. We honor the Global Privacy Control (GPC) browser signal, and also your browser’s Do Not Track setting where supported by our analytics processor — see Section 8.
- Server logs: our hosting providers (Netlify, Supabase) log standard request metadata (timestamp, IP, user agent, requested URL, response code) for operational and security purposes. These logs are retained per the providers' policies.
Mobile application.
If you use the Planning Ops app for iPhone and iPad (available on the App Store), the app is a version of the same Service and collects and uses information as described elsewhere in this policy. Two things are specific to the app:
- Biometric sign-in (Face ID / Touch ID). If you choose to unlock the app with Face ID or Touch ID, the biometric match is performed entirely by your device’s operating system. We never receive, see, or store your face or fingerprint data, and no biometric information ever leaves your device. Turning the feature on stores only your existing login token — never your password — in your device’s secure keychain, released only after that biometric (or device-passcode) check. You can turn it off at any time in My Account, which deletes the stored token from your device.
- On-device storage. So you can keep working when your connection drops, the app keeps a working copy of your in-progress daily report and your login session on your device, and syncs your report to our servers automatically when you reconnect. Data stored on your device is protected by your device’s own security — including any Face ID, Touch ID, or passcode lock you have set — and is removed when you delete the app. (Because it is held in your device’s secure keychain, the biometric login token described above can remain on the device until you turn the feature off in My Account.)
- Distribution through the App Store. The app is distributed by Apple. When you download or update it, Apple collects its own information about that transaction — and, if you have opted in to sharing analytics with app developers in your device settings, may share aggregated usage and crash diagnostics with us. That collection is governed by Apple’s privacy policy, not this one, and happens under Apple’s control rather than ours. We do not send Customer Data to Apple, and Apple has no access to your workspace, your schedules, or anything else you store in the Service — which is why Apple does not appear in the sub-processor table in Section 4. Your subscription is billed by us through Stripe, not by Apple, and the app contains no in-app purchases.
2. How we use information
- To operate, maintain, and provide the Service to you and your team.
- To authenticate users and enforce per-tenant data isolation (row-level security).
- To process payments and deliver receipts (via Stripe).
- To send transactional email — welcome, password reset, access-granted, invoice receipts, payment failure notices, security alerts, subscription cancellation confirmations, plan-change and reactivation confirmations, and schedule distribution emails (via Resend). Transactional email is always sent, regardless of marketing opt-out status, because it relates to your active subscription or account.
- To send marketing-class email — trial reminders, weekly digests, and product announcements (via Resend). You can opt out of all marketing-class email at any time via the one-click Unsubscribe link in any such email or at planningops.com/unsubscribe. Opt-outs are stored in a cross-tenant suppression list keyed only by email address.
- To send SMS / text-message notifications — concrete pour confirmations, cancellations, schedule changes, and reminders (via Twilio) — to recipients who have opted in. See the SMS / text-message notifications subsection below for details and opt-out.
- To analyze usage trends in aggregate (via PostHog) to improve the Service.
- To monitor for abuse, fraud, or security incidents.
- To enforce license compliance — which may include detecting shared working-seat credentials (concurrent sessions) — using the security signals described in Section 1.
- To respond to your support requests.
- To comply with legal obligations.
We do not use your operational data (employee names, schedules, pours, time and payroll records, etc.) for advertising, machine learning training, or any purpose unrelated to providing the Service to you.
SMS / text-message notifications.
If you provide a mobile phone number and consent to receive text messages, Planning Ops may send you operational SMS notifications — such as concrete pour confirmations, cancellations, schedule changes, and reminders. These messages are transactional and are sent only to recipients who have opted in. We never send marketing or promotional text messages, and we do not buy, rent, or message purchased phone-number lists.
How you opt in. You can opt in yourself on our public web form at planningops.com/sms: enter your mobile number and actively check a consent box (unchecked by default) agreeing to receive these messages. You may also be enrolled by the Planning Ops customer coordinating the work (your employer, the general contractor, or the company running the pour), who shows you the same program terms and obtains your agreement before your number is enabled. In substance you agree: “Planning Ops will text you concrete pour confirmations, cancellations, and schedule updates. Message frequency varies. Message and data rates may apply. Reply STOP to opt out or HELP for help. See our Terms (planningops.com/terms) and Privacy Policy (planningops.com/privacy).” Consent to receive text messages is not a condition of any purchase. (If you are a Planning Ops customer sending texts to your own contacts through the Service, you are responsible for obtaining their consent — see our Terms of Service.)
Opt-out and help. Reply STOP to any message at any time to unsubscribe; you will receive a single confirmation and then no further texts. Reply HELP for help, or email admin@planningops.com. Message frequency varies. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages.
No sharing of mobile opt-in data. No mobile information — including your phone number and SMS consent — will be shared with third parties or affiliates for marketing or promotional purposes. The information-sharing categories described elsewhere in this policy exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties. We use Twilio solely as our SMS delivery provider to transmit the messages you requested.
3. Platform administrator access
Planning Ops staff (the “platform administrator”) may, in limited circumstances, sign in to a workspace under a masked support identity shown as “Planning Ops (Admin)” — never under an individual staff member’s own name — to provide technical support, investigate a reported issue, or respond to a security or legal obligation. We take the following safeguards every time this happens:
- Recorded in an audit log. Every support sign-in is written to our audit log — recording the individual Planning Ops staff account that performed the session (identified by its email address, which is not one of your own user accounts), the workspace, and the timestamp. These support-session records are maintained by Planning Ops in our platform administration console; a customer-facing view of them is not yet available in the app, but you can request the details for your workspace at any time by contacting us.
- Time-limited. Each support session is capped at 30 minutes by an automatic client-side timeout. The session also expires according to your workspace’s normal inactivity rules.
- Single-use sign-in link. The link used to access your workspace is single-use — it is consumed on first use and cannot be replayed.
- Visible banner. When platform support is signed into your workspace, an orange banner is displayed at the top of the screen identifying the session as a platform support session, with the remaining time shown.
- No background access. We do not maintain standing background access to your workspace. The platform administrator must explicitly initiate a session, which is logged. Routine operations (backups, monitoring) use service-level credentials that read only metadata, not your operational data.
- Termination on your request. Workspace administrators can revoke all active sessions for their workspace at any time. Email us at admin@planningops.com and we will end any active support session immediately.
The platform administrator does not use this capability to read, export, or use your operational data for any purpose other than the specific support or maintenance task that prompted the session. We do not share data accessed during a support session with third parties, except as required by law.
4. Third-party processors
We share data only with vendors strictly necessary to operate the Service. Each is bound by their own privacy commitments and applicable data-protection laws.
| Vendor | Purpose | Data shared |
|---|---|---|
| Supabase | Database, authentication, edge compute | All Customer Data and account info |
| Stripe | Payment processing | Email, name, billing details, last4 of card |
| Netlify | Static site hosting | Request logs, IP addresses |
| Resend | Transactional and marketing email | Recipient email, name, message content |
| Twilio | SMS / text-message notifications | Recipient mobile number, message content |
| PostHog | Product analytics (page views, button clicks, custom business events) | SHA-256 hash of email, anonymized user ID, tenant slug, role, browser metadata, event properties. Raw email is not sent. |
| LinkedIn (Microsoft Corp.) | Ad conversion measurement & retargeting | IP address, browser/device metadata, page-visit events |
| Google (Google LLC) | Ad conversion measurement (Google Ads) | IP address, browser/device metadata, page-visit and signup-conversion events |
| Open-Meteo | Weather forecasts shown on the Place & Finish schedule | Project ZIP code / approximate location only — no personal identifiers |
| Zippopotam.us | ZIP-to-coordinates geocoding for the weather forecast | Project ZIP code only — no personal identifiers |
| OpenStreetMap Foundation (Nominatim) | ZIP-to-location geocoding (fallback) for the weather forecast | Project ZIP code only — no personal identifiers |
We do not sell, rent, or trade your information with any third party for marketing purposes.
5. Data location and transfers
The Service is hosted on infrastructure located in the United States. By using the Service, you consent to the transfer of your information to the United States, which may have data-protection laws different from your country of residence.
6. Data retention
While your subscription is active, we retain your Customer Data — including your full history of daily reports and their attached photos — for the life of your subscription. We do not delete your records on a fixed age-based timer, and there is no set number of years after which a daily report is automatically purged while your account is in good standing. You can export a complete copy of your records at any time (see Your rights below and the archive export in the Terms), and you should export before you cancel. Retention after a trial ends or a paid subscription lapses is described below. Note that some source records — for example OSHA injury and illness logs, payroll, and tax records — carry their own legal retention periods that are your responsibility to observe.
Free trial tenants.
If you cancel your 14-day trial before it converts to a paid subscription (no charge incurred), access to your tenant is locked and your Customer Data is retained for at least 30 days in case you change your mind and reactivate. After 30 days of inactivity following a canceled trial, we may permanently delete trial-tenant Customer Data; we will send a reminder email to the administrator’s email address before deletion.
Paid subscription lapses.
If a paid subscription lapses (cancellation by the customer or repeated failed payment), access to your tenant is locked for up to 30 days, after which Customer Data may be permanently deleted. Backups may retain data for up to 90 days for disaster-recovery purposes.
Manual deletion.
The workspace owner can permanently and immediately delete the entire workspace and all of its data, self-service, from Control Panel ▸ Billing ▸ Danger Zone (irreversible, requires a typed confirmation, and cancels the subscription). This deletes all Customer Data — including your full daily-report history, uploaded worker-certification files, and every other uploaded photo and file — from both our database and our file storage, immediately and permanently. Deleted data is not recoverable (no undo, no backup restore), so you should export anything you wish to keep before deleting. When a workspace or account is deleted this way, its data is removed right away rather than held for the retention windows described above; only records we are required to keep by law (e.g., financial records related to your subscription) are retained. You may also request deletion at any time by emailing admin@planningops.com. We will honor verified deletion requests within 30 days, except where retention is required by law.
Individual account deletion.
Any signed-in user can permanently delete their own account — their login, role grants, and profile — self-service from the My Account menu in the hub. Confirmation requires re-entering your current password and typing your email address. This removes only your personal account; it does not delete your workspace’s operational data or any other user. To prevent a workspace from being orphaned, the workspace owner and the last remaining administrator cannot remove themselves this way — they use the workspace deletion above or the email request path instead.
7. Security
- Tenant isolation: per-tenant row-level security in the database means another customer cannot read or write your data, regardless of any application bug.
- Encryption in transit: all traffic is served over HTTPS with HSTS preload.
- Encryption at rest: our database provider encrypts all data at rest.
- Password hashing: passwords are hashed with bcrypt (industry standard) via Supabase Auth. Plaintext passwords are never stored.
- Two-factor authentication (2FA): Planning Ops platform-administrator (staff) accounts are protected by mandatory TOTP-based 2FA (authenticator app), enforced at every sign-in. Customer-account 2FA is on our roadmap.
- Strict CSP and security headers: the Service ships with a strict Content Security Policy, HSTS preload, X-Frame-Options DENY (frame-ancestors 'none'), Permissions-Policy, Referrer-Policy, and other defense-in-depth headers.
No system is perfectly secure. While we apply reasonable safeguards, we cannot guarantee absolute security. You are responsible for protecting your login credentials and notifying us of suspected unauthorized access.
8. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data — you can edit your own display name at any time from the My Account menu in the hub;
- Delete your account and personal data — any user can self-delete their own account from the My Account menu, or email us (subject to legal retention exceptions);
- Export your data — the Service provides PDF exports for schedules and projections; a complete daily-report archive (one compiled PDF of your entire daily-report history) plus individual report PDFs when the Daily Reports module is enabled; payroll exports (a branded Excel timesheet and per-system import files, mostly CSV, for common payroll systems) when Time Tracking is enabled; a Certification Report (a branded PDF, optionally embedding copies of certificate documents) plus a certifications roster Excel export when the Certifications module is enabled; and Excel for roster import; and we will export account and audit-log data on request;
- Object to certain processing or withdraw consent where we rely on consent;
- Opt out of marketing email at any time via the one-click Unsubscribe link in any marketing email or at planningops.com/unsubscribe. Transactional email related to your active subscription will continue;
- Opt out of product analytics by emailing admin@planningops.com. We honor browser Do Not Track signals where supported by the analytics processor;
- Lodge a complaint with a data-protection authority if you believe we have violated your rights.
To exercise any of these rights, email admin@planningops.com from the email address associated with your account.
9. Children’s privacy
The Service is not directed to children under 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, contact us and we will delete it.
10. California, EU/UK, and Canadian residents
If you reside in California, the EU, the UK, Canada, or another jurisdiction with specific privacy laws (CCPA, GDPR, UK GDPR, PIPEDA), the rights described in Section 8 apply to you, plus any additional rights granted by your jurisdiction’s law. For Canadian residents, we handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA); as described in Section 5, information is processed and stored in the United States. Contact us to exercise any such right. We do not sell personal information for money.
Do Not Sell or Share My Personal Information.
We do not sell your personal information for money, and we never sell or share your operational data. However, the cookie-based advertising tools on our public marketing pages — the LinkedIn Insight Tag (ad conversion measurement and retargeting) and our PostHog analytics — may involve disclosures of online identifiers (such as your IP address, device/browser metadata, and page-visit events) that can be considered a “sale” or “share” for cross-context behavioral advertising under the CCPA/CPRA and similar laws. To opt out of this “sale/share,” use Cookie settings in the footer of any public page — this switches both tools off in your browser and is the fastest route. You may also email admin@planningops.com with the subject line “Do Not Sell or Share”. We treat a Global Privacy Control (GPC) signal as a valid opt-out and honor it automatically, in every region and regardless of any earlier choice you made in the cookie notice; we also respect tracking-cookie blocking and Do Not Track where supported by our analytics processor. Opting out of advertising cookies does not affect your access to the Service.
Cookie consent in the EEA, the UK, and Switzerland.
If you are in the EEA, the UK, or Switzerland, we ask for your consent before any non-essential cookie or similar identifier is set. On your first visit to our public marketing or signup pages you will see a cookie notice offering Accept and Reject as equally available choices; the LinkedIn Insight Tag and PostHog analytics described above do not load unless and until you accept. Strictly necessary cookies — your session token, the record of your cookie choice, and basic interface preferences — are used without consent, as permitted by law. Your choice is stored for 180 days and applies across planningops.com and signup.planningops.com, after which we ask again. You may withdraw consent at any time, as easily as you gave it, via Cookie settings in the footer of any page; withdrawing also clears the analytics identifiers already stored in your browser. Declining or withdrawing has no effect on your access to the Service.
11. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or via a notice in the Service. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact
Privacy questions or requests: admin@planningops.com.
Postal mail (registered agent for service of process):
Planning Ops LLC
c/o Registered Agents Inc
6650 Rivers Ave., Suite 100
Charleston, SC 29406, USA