G-308Legal
Planbase Privacy Policy
Companion documents: Subprocessors · Data Retention and Deletion · Cookie Notice · US State Privacy Notice · Data Processing Addendum · Security Overview
Summary in plain language
- Your plans and job files stay on your computer. DimSum Takeoff stores them locally. We don’t receive them unless you send them to us (a diagnostic bundle with “include the job file” ticked) or, later, you use DimSum Cloud.
- We collect what we need to run your account, your license, your payments and your support. That means your name and email, your Workspace, the computers you activate DimSum on, and your subscription status.
- Paddle takes your payment. Paddle is the merchant of record. It holds your card, billing address and tax details; we never see your full card number.
- We don’t sell your data, and we don’t use it for advertising. We use no advertising cookies and no cross-site tracking.
- Website visits are counted without cookies (Cloudflare Web Analytics). The account portal uses cookies only to keep you signed in and secure.
- You can ask us to see, correct, export or delete your data, and to object to some uses. Email privacy@planbaseestimating.com.
This summary is not the whole policy. The numbered sections below are.
1. Who we are
1.1 Planbase Estimating LLC, a Missouri limited liability company based in Kansas City, Missouri, USA (“Planbase”, “we”, “us”, “our”), is responsible for the personal data described in this policy. Under the EU and UK General Data Protection Regulations, Planbase is the controller of that data, except where section 3.3 says we act as a processor for a business customer.
1.2 Contact:
- Privacy questions and requests: privacy@planbaseestimating.com
- Legal notices: legal@planbaseestimating.com
- Support: support@planbaseestimating.com
- Post: Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA
1.3 EU and UK representative. We have not appointed a representative in the EU or the UK. If we appoint one, we’ll name it here.
1.4 Data protection officer. We have not appointed a data protection officer, because our processing does not require one.
2. Definitions
In this policy:
- “Account” means a Planbase account at app.planbaseestimating.com, used to sign in to the portal and to DimSum Takeoff.
- “Workspace” means the account for a company or a single user that holds the license, the seats and the members. Each Workspace has one or more admins.
- “DimSum” or “the app” means DimSum Takeoff, our Windows desktop application for framing takeoff and estimating.
- “Job files” means the files you create or open in DimSum: jobs (
.dsum), tool libraries (.tsum), and the other DimSum file types, plus the plans (PDFs and images) you import. - “DimSum Cloud” means our paid add-on, not yet available, that stores copies of your files online (Cloud Sync) and lets you reach DimSum on your own PC from a browser (the Remote Workstation).
- “Cloud Content” means the files and settings you store with DimSum Cloud.
- “Diagnostic bundle” means a .zip of the app’s logs (and, only if you tick it, the open job file) that you choose to send to us.
- “Sites” means planbaseestimating.com (the website), docs.planbaseestimating.com (the docs), app.planbaseestimating.com (the portal), and our service addresses api.planbaseestimating.com, updates.planbaseestimating.com and admin.planbaseestimating.com.
- “Services” means the Sites, DimSum, Accounts, licensing, updates, support and, when available, DimSum Cloud.
- “Personal data” means information that identifies, relates to, or can reasonably be linked to a person. US state laws say “personal information”; we use the terms the same way.
- “Processor” or “subprocessor” means a company that handles personal data for us and on our instructions. They are listed in subprocessors.md.
3. What this policy covers
3.1 This policy covers personal data we handle through the Services, and when you email us.
3.2 It does not cover:
- Paddle’s handling of your payment, billing address and tax data. Paddle is the merchant of record and decides how it uses that data under its own privacy policy (section 9.3).
- Google’s handling of your Google account when you choose “Continue with Google” (section 9.3).
- Websites and services we link to but don’t run.
3.3 When we act for a business customer. For Cloud Content, Remote Workstation sessions, and customer files inside a diagnostic bundle, we process personal data on behalf of the customer whose Workspace it belongs to. For those, the customer is the controller, we are its processor, and our Data Processing Addendum applies. If you are an employee or client of one of our customers and want to use your rights over that data, contact that customer first; we’ll help them answer.
4. What we collect
The table lists every kind of personal data the Services keep, where it comes from, and whether that part of the Services is running today. Live means it runs now. Built, off means the code exists but is switched off or can’t yet be used. Coming means it isn’t built; we’ll update this policy before it starts.
4.1 Data you give us
| Data | What exactly | Status |
|---|---|---|
| Account details | Your name and email address; how you sign in (email code, password or Google); your Clerk user ID. Your password is held by Clerk, never by us. | Live |
| Workspace details | Workspace name; members and their role (admin or member); seats; invitations (the invited person’s email, who invited them, when, and whether it was accepted or revoked) | Live |
| Company and location details | If your Workspace fills them in: company details, and for each location its contact and report details, logo, tax rate, suppliers, notes and members | Live |
| EULA acceptance | Which version of the DimSum license agreement you accepted, when, and from which activated computer | Live |
| Terms and Privacy acceptance | When you create an account: which versions of the Terms of Service and this Privacy Policy you accepted, when, where (sign-up), the country your connection came from, and your browser’s user agent | Live |
| Beta sign-up (website form) | Name, work email, company (optional), role, business type, number of estimators, trades, what you use now and when it renews (optional), your note (optional), and the time you sent it | Live |
| Newsletter sign-up | Your email, where on the site you signed up, your confirmation or unsubscribe dates, and which weekly issues we sent you. Double opt-in: we mail you only after you click Confirm. | Live (weekly, from October 2026) |
| Support messages | What you write to us by email, and the notes we keep on your Workspace to help you | Live |
| Correspondence and contact notes | Replies to our emails that come to our reply address (r+…@replies.planbaseestimating.com, received through Cloudflare Email Routing, logged as text, then forwarded to hello@); copies of emails Zac sends you by hand with log@replies.planbaseestimating.com in Bcc; our notes on you or your Workspace, and the date of our next follow-up | Live |
| Diagnostic bundle (only when you send one) | The app’s logs; your note; the email to answer; DimSum version, operating system and update channel; the computer’s ID; and the open job file only if you tick “include the job file” | Live (attached to feedback or a crash report only if you tick it, section 6.4) |
| Feedback and crash reports (only when you send one) | What you write, your name, email and Workspace, DimSum version, operating system and update channel, the computer’s ID; a screenshot or diagnostic bundle only if you tick it; for a crash report, the computer and setup details in section 6.4B | Live |
| Tester programme (only if we invite you to test) | Your name, email and company; the invitation and when it was sent, accepted, revoked or ended; which version of the Beta and Tester Agreement you accepted, and when; your answers to the tester survey; your progress and notes on test task lists | Live |
| Cloud Content | The jobs, tools, reports, settings and plans you choose to sync, and their names, types and sizes | Coming |
| Remote Workstation pairing | Which of your computers you paired and when, and the settings you choose for remote access | Coming |
4.2 Data collected automatically
| Data | What exactly | Status |
|---|---|---|
| Activated computers | For each computer DimSum is activated on: the computer’s name as Windows reports it (often includes a person’s name, e.g. “ALICE-LAPTOP”); a machine fingerprint; operating system; DimSum version; update channel (stable or beta); first-seen, last check-in and deactivation times, and who deactivated it. The fingerprint is a one-way, salted SHA-256 hash of Windows’ machine ID; the raw machine ID never leaves your computer. | Live |
| Sign-in and device security | The one-time codes that hand your sign-in from the browser to DimSum, the device token that keeps DimSum signed in, and short-lived download links. We store each of these only as a SHA-256 hash, with its creation, last-use, expiry and revocation times. | Live |
| License check-ins | DimSum checks in when it starts and about every 4 hours while it runs (sending the computer’s ID, fingerprint, version and channel). Each check-in updates the last check-in time. | Live |
| Update checks | DimSum asks updates.planbaseestimating.com for new versions, sending its version, channel and its signed license file (which contains your user ID, email, Workspace name and the computer’s fingerprint). The update server’s logs never record the license file or key. | Live |
| Account activity (audit) log | Every account change, admin action, license and payment event, and webhook that changed something: when, who or what did it, what it acted on, and details | Live |
| Email records | Which one-off emails each person received for a Workspace (e.g. the trial welcome) and the email provider’s message ID; your email choices, including whether you unsubscribed from tips; and, for each email, the delivery events our email provider Resend reports (sent, delivered, delayed, bounced, complained) | Live |
| Portal sign-in data (held by Clerk) | Session records, IP address, browser and device type, and approximate location of sign-ins, used for security and the “active devices” list; bot and fraud checks on sign-up and sign-in (Cloudflare Turnstile and Clerk’s fraud protection) | Live |
| Spam check on forms | When you send the beta or newsletter form, Cloudflare Turnstile checks your browser. We pass your IP address to Cloudflare for that check; we don’t store it. We store only the two-letter country your connection came from. | Live |
| Questions to “Ask the docs” | On the help site (docs.planbaseestimating.com), the questions you type into Ask the docs are sent to Cloudflare (AI Search and Workers AI), which finds the help pages that match and writes a short answer from them. We keep each question, with email addresses and numbers removed, and whether the help pages answered it, for 30 days, to find gaps in the help. We don’t keep your IP address or anything else about you with it. To limit how many questions one visitor can ask each day, we count them against a one-way hash of your IP address made with a random key that changes daily; the count and the key are deleted after two days. Please don’t type personal details into it. | Built, off (being previewed; not yet on the public help site) |
| Server and security logs | IP address, address requested, time, browser type and similar request data, kept by Cloudflare for our Sites, and short-lived application logs | Live |
| Website visit counts | Cloudflare Web Analytics: page views, referrer, browser and country, and page-load timing, without cookies and without identifying you | Live |
| Platform error reports | When our own servers hit an error, Sentry receives the error, the address without its query string, and the host. Never a request body, headers, cookies or anything you typed. | Live |
| Automatic crash reports from DimSum | Not built. DimSum sends a crash report only when you choose to (section 6.4B). If automatic reporting is added, it will be off unless you turn it on, and will never include plan content or job data. | Coming |
| Usage telemetry from DimSum | Not built. If added, it will be off unless you turn it on, anonymous, and never include plan content or job data. | Coming |
| Cloud and Remote Workstation metadata | Storage used; sync times; Remote Workstation connection times, the devices involved and the IP addresses needed to connect them | Coming |
4.3 Data from other companies
| Source | What we receive |
|---|---|
| Clerk (sign-in) | Your Clerk user ID, name and email when you sign up or change them, and a notice when the account is deleted |
| Google (only if you choose “Continue with Google”) | Through Clerk: your name, email address and Google account ID, and your profile picture if Clerk shows it |
| Paddle (payments) | Your Paddle customer and subscription IDs, subscription status, payment status, and the end of the paid period; and for each transaction, refund, credit or chargeback, its date, amount, tax, status and invoice link. Not your card number. |
| Keygen (licensing) | License and machine status changes (e.g. a machine was removed, a license expired) |
4.3A Prospective customers (outreach)
If we email you to introduce DimSum (Communications Policy §4.4), we hold a prospect record: your name, business email, company, trade, city, a short note on why we’re writing (for example, a job or a post of yours we saw), our tags, which emails we sent and when, and whether you replied, bounced or opted out. It comes from people we know or are introduced to, and from business contact details a company publishes (its website or a public business profile). We don’t buy lists. Replies to our outreach come to a reply address (r+…@replies.planbaseestimating.com) through Cloudflare Email Routing; we log their text with the record and forward them to hello@. We also keep our notes on the contact and the date of our next follow-up. See section 8.6.
4.4 What we don’t collect
- We don’t receive your job files or plans unless you send them in a diagnostic bundle or, later, sync them with DimSum Cloud.
- We don’t receive your full card number or bank details; Paddle does.
- We don’t store passwords; Clerk does.
- We don’t keep full license keys; Keygen does. We keep the last 4 characters.
- We don’t store the IP address from the beta or newsletter form; only the country.
- We don’t collect sensitive data (such as health, race, religion or precise location). Please don’t put it in job files you send us or in support messages.
5. Why we use it, and our legal bases
5.1 Under the GDPR and UK GDPR we must have a legal basis for each use.
| Purpose | Data used | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Create and run your Account and Workspace; let admins manage members and seats | Account, Workspace, invitations | Contract (b) |
| License DimSum: activate computers, enforce 2 computers per seat, the 30-day offline grace, deactivation | Activated computers, sign-in and device security, check-ins | Contract (b) |
| Deliver updates, including required critical updates | Update checks, license file | Contract (b) |
| Record which EULA you accepted | EULA acceptance | Contract (b) and legitimate interests (f) in proving the agreement |
| Record that you accepted the Terms of Service and Privacy Policy | Terms and Privacy acceptance | Contract (b) and legitimate interests (f) in proving the agreement |
| Keep billing records (subscriptions, transactions, refunds, credits, chargebacks) | Paddle billing data | Legal obligation (c) (tax and accounting) and contract (b) |
| Know whether our emails arrive, and stop emailing addresses that bounce or complain | Email records and delivery events | Legitimate interests (f) |
| Keep our correspondence, notes and follow-up reminders | Correspondence and contact notes | Legitimate interests (f) in running our business and following up |
| Store your Workspace’s company and location details | Company and location details | Contract (b) |
| Know which Workspaces have paid; react to payment events | Paddle IDs and statuses | Contract (b) |
| Send service emails (invitations, license key, trial and license notices, payment problems) | Account details, email records | Contract (b) |
| Send trial tips (day 3 and day 7), with an unsubscribe link | Account details, email records, email choices | Legitimate interests (f) in helping you use a product you’re trying |
| Send the weekly newsletter | Newsletter sign-up | Consent (a), confirmed by double opt-in |
| Contact beta sign-ups about the beta and Planbase software | Beta sign-up | Consent (a) given by sending the form, and legitimate interests (f) |
| Answer support requests; investigate problems you report | Support messages, feedback and crash reports, diagnostic bundles, notes | Contract (b) and legitimate interests (f) |
| Run the beta and tester programme (invitations, the tester portal, surveys and test task lists) | Tester programme | Contract (b), under the Beta and Tester Agreement |
| Email prospective customers about DimSum (outreach), and honour opt-outs | Prospect records (4.3A) | Legitimate interests (f) in offering a relevant business tool to businesses that may need it; consent where the law requires it (Canada). Keeping the do-not-email entry: legal obligation (c) |
| Keep the Services secure; prevent fraud, spam and abuse; keep an audit trail | Sign-in data, spam checks, server logs, audit log | Legitimate interests (f) |
| Fix bugs in our servers | Platform error reports | Legitimate interests (f) |
| Understand which web pages are useful | Visit counts | Legitimate interests (f) |
| Automatic crash reports and telemetry from DimSum (when built) | As described in 4.2 | Consent (a); you turn them on |
| Provide DimSum Cloud and the Remote Workstation (when available) | Cloud Content, pairing, metadata | Contract (b); for customer content, we act as processor (section 3.3) |
| Keep tax and accounting records; answer lawful requests | Billing status, audit log | Legal obligation (c) |
| Establish, exercise or defend legal claims | Any relevant data | Legitimate interests (f) |
5.2 Legitimate interests. Where we rely on legitimate interests, we have weighed them against your rights. You can ask us for that assessment, and you can object (section 12).
5.3 If you don’t give us data. Account details are needed to create an Account; computer details are needed to activate DimSum. Without them we can’t provide those parts of the Services. Everything marked optional on a form is optional.
5.4 No automated decisions. We don’t make decisions with legal or similarly significant effects about you by automated means alone. Licensing rules (such as the 2-computer limit or the end of a trial) apply automatically to everyone the same way, and you can ask a person to review them at support@planbaseestimating.com.
6. The DimSum app and your job files
6.1 Your job files are stored on your computer. DimSum reads and writes them locally. They are encrypted on disk so other programs can’t open them. They are not sent to us.
6.2 What DimSum sends us. Today the app connects to three addresses only:
- app.planbaseestimating.com, in your browser, to sign in;
- api.planbaseestimating.com, to activate the computer, check in, sign out and deactivate (section 4.2);
- updates.planbaseestimating.com, to check for and download updates.
6.3 Automatic updates. DimSum checks for updates and downloads them in the background. Updates marked critical must be installed to keep using DimSum (see the EULA).
6.4 Diagnostics. DimSum sends a diagnostic bundle only when you choose to, by ticking it in a feedback or crash report (sections 6.4A and 6.4B). The job file is included only if you tick “include the job file”. Bundles are stored in our private storage at Cloudflare and seen only by Planbase staff working on your problem.
6.4A Feedback. When you send a bug report, feedback, a comment or a feature request (in DimSum, Help → Send feedback…, or on your account page), we receive what you write, your name, email and Workspace, the DimSum version, the operating system and update channel, and the computer’s ID. We also receive a screenshot of the DimSum window or a diagnostic bundle, but only if you tick them; the job file is included only if you tick “include the job file”. An email you send us about the app may be added the same way. Feedback and its attachments are stored in our private storage at Cloudflare and seen only by Planbase staff (and the tools we use to fix the problem). We use them to answer you and improve DimSum. We keep the text until the item is closed and then for up to 24 months, and screenshots and bundles for no more than 90 days after it is closed.
6.5 Automatic crash reports and usage telemetry are not built. If we add them, they’ll be off until you turn them on in Settings → Account & License → Privacy, and this policy will be updated first.
6.4B Crash reports. When you send a crash report (in DimSum, the Crash report button or Help → Send a crash report…), DimSum shows you what it contains and sends it only after you tick “I agree to send this crash report, including my computer and setup details, to Planbase”. It contains what a bug report does (§6.4A), plus details of your computer and setup: the operating system’s version, build, language and time zone; the processor, memory, graphics card and its driver; each monitor’s size, scaling, refresh rate and arrangement, and where DimSum’s window is; free disk space; how DimSum is installed (version, update channel, install location and type, other copies found, update state, versions of its components, its start-up options and the size of its data folder); DimSum’s memory use; the license mode and status (never your license file, keys or sign-in codes); DimSum’s settings; the last lines of DimSum’s logs; any crash files DimSum’s own processes wrote on your computer; and the open job’s size and counts. Your Windows user name, your computer’s name, email addresses, sign-in codes, tokens and keys are hidden before it leaves your computer. The job file and a screenshot are included only if you tick them. After DimSum closes unexpectedly it may ask whether you want to send one; it never sends one by itself. Crash reports are stored, seen and kept as feedback is (§6.4A).
6.6 Things kept only on your computer. DimSum keeps local logs, your settings, and a copy of your license file on your computer. They stay there unless you send a diagnostic bundle.
7. DimSum Cloud and the Remote Workstation (coming)
7.1 Cloud Sync will store copies of your jobs, tools, reports, settings and plans in our storage at Cloudflare (Cloudflare R2), so they’re available on every computer you sign in on. Cloud Sync will be off until you turn it on, and you’ll choose which kinds of files it syncs.
7.2 The Remote Workstation will let you use DimSum on your own PC from a browser. Our servers introduce your browser and your PC to each other. The picture and your mouse and keyboard then travel directly between the two, encrypted end to end (WebRTC with DTLS-SRTP). When a direct connection isn’t possible, Cloudflare relays the encrypted traffic but can’t read it. We see when a session starts and ends, the devices involved, and the network addresses needed to connect them, but not what’s on the screen. A PC can only be reached after someone at that PC turns on remote access and confirms a pairing code.
7.3 After you cancel DimSum Cloud we keep your Cloud Content for 3 months. We email you straight away with a link to download it, and again 7 days before it’s deleted. If your DimSum license lapses, DimSum Cloud has a 2-month grace period before those 3 months start.
7.4 Over your storage limit, new uploads pause. Nothing is deleted because you’re over the limit.
7.5 We’ll update this policy, the Subprocessors list and the Data Processing Addendum before DimSum Cloud starts.
8. Emails
8.1 Service emails (transactional): Workspace invitations, the license key, the trial welcome, trial ending and ended, license active, seat assigned, payment problems, license ending and ended. These are part of the Services and you can’t unsubscribe from them while you have an Account. Clerk sends the sign-in and verification codes.
8.2 Trial tips (day 3 and day 7 of a trial) are optional. Every one has an unsubscribe link and one-click unsubscribe headers. Unsubscribing stops tips and our other marketing email (it puts your address on our do-not-email list); service emails continue.
8.3 The newsletter comes out once a week, with that week’s new DimSum versions and website news; a week with nothing new has no issue. It’s double opt-in: you sign up on our website, confirm by email, and can unsubscribe with one click from any issue (the link at the bottom, or your mail app’s unsubscribe button).
8.4 Paddle sends its own receipts and payment emails as merchant of record.
8.5 Commercial emails include our postal address, as US law (CAN-SPAM) requires: 3418 East 104th Street, Kansas City, MO 64137.
8.6 Outreach. Zac may email contractors and estimators one to one from hello@ to introduce DimSum, with at most one follow-up and one last note (Communications Policy §4.4). Every outreach email has a one-click Unsubscribe link and asks you to reply “no thanks” if you’re not interested; either one puts your address on our do-not-email list, honoured straight away and always within 10 business days. You can also object at any time by writing to privacy@planbaseestimating.com.
9. Who we share data with
9.1 We don’t sell personal data, and we don’t share it for cross-context behavioural advertising (targeted advertising).
9.2 Subprocessors. Companies that run parts of the Services for us process personal data on our instructions under written terms: Cloudflare (hosting, databases, storage, email routing for replies to our emails, spam checks, web analytics, and the help site’s Ask the docs answers), Clerk (sign-in), Keygen (licensing), Resend (email), Sentry (error reports), and Google (Google Workspace, the mailbox behind our email addresses). The full list, with what each handles and where, is in subprocessors.md.
9.3 Independent controllers. Some companies decide for themselves how they use the data:
- Paddle (Paddle.com Market Limited and its affiliates) is the merchant of record. It collects your name, email, billing address, payment details, IP address and tax information at checkout, and handles payments, tax, invoices, refunds and fraud checks under its own privacy policy (https://www.paddle.com/legal/privacy).
- Google, if you choose “Continue with Google”, under Google’s privacy policy (https://policies.google.com/privacy).
9.4 Your Workspace. Admins of your Workspace can see the members’ names, emails, roles and activated computers (by name), and can deactivate computers. Members can see their own computers.
9.5 Other disclosures. We may disclose personal data:
- if the law requires it, or to answer a valid legal request (we’ll tell you unless the law forbids it);
- to protect the rights, property or safety of Planbase, our customers or others, including to prevent fraud;
- to professional advisers (lawyers, accountants) under confidentiality;
- to a buyer or successor if Planbase is sold, merged or reorganised, who must keep this policy’s promises for data collected under it.
10. International transfers
10.1 Planbase is based in the United States, and most of our subprocessors store data in the United States. Cloudflare serves our Sites from data centres around the world. If you’re outside the US, your data is transferred to and handled in the US and other countries whose laws may differ from yours.
10.2 For personal data from the EEA, UK and Switzerland, we rely on:
- the EU-US Data Privacy Framework, its UK Extension and the Swiss-US framework, where the recipient is certified; and otherwise
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum and the Swiss amendments, in our contracts with subprocessors and, for business customers, in our Data Processing Addendum.
10.3 You can ask for a copy of the safeguards at privacy@planbaseestimating.com.
11. How long we keep data
We keep personal data only as long as we need it for the purposes in section 5, then delete or anonymise it; tester-programme records are the one exception, kept indefinitely as below. The full schedule is in data-retention-and-deletion.md. In short:
- Account, Workspace and license data: while your Account is open, then 90 days after it closes;
- Billing records (subscriptions, transactions, refunds, credits, chargebacks): 7 years, for tax and accounting; Paddle keeps its own records;
- Agreement records (your Terms of Service, Privacy Policy and EULA acceptances): while your Account is open, then up to 10 years, as proof of what was agreed;
- Email records and delivery events: while your Workspace is open, then 90 days;
- Correspondence and contact notes: with the record they belong to (customers: 3 years from the last message; prospects: as below);
- Company and location details: while your Workspace is open, then 90 days;
- Feedback and crash reports (if you’re not a tester): while your Account is open, then 90 days;
- Diagnostic bundles: until the issue is closed, and no more than 90 days after it’s closed, and 12 months at most;
- Cloud Content: 3 months after DimSum Cloud is cancelled;
- Beta sign-ups: until the beta ends plus 12 months, or sooner if you ask;
- Tester programme (only if we invite you to test): your tester checklists, the feedback and crash reports you send as a tester, and the record that you accepted the Beta and Tester Agreement are kept indefinitely, as the history of how DimSum was tested; you can ask us to delete it at any time, and we will unless we must keep it, e.g. the record that you accepted the tester agreement (an attached diagnostic bundle still follows the diagnostic bundle period above);
- Questions typed into Ask the docs on the help site: 30 days, with emails and numbers removed and nothing about who asked.
- Prospect records (outreach): while useful for telling you about DimSum, and deleted when you ask; after an opt-out, only the do-not-email entry is kept, so we never email you again.
When you ask us to delete your data, we delete or anonymise it, except that agreement records (the EULA, Terms of Service and Privacy Policy, and tester agreement acceptances), billing records and the do-not-email entry are kept; a computer named in a kept EULA acceptance keeps its row without its name, fingerprint or license ID. The full schedule, row by row, is in data-retention-and-deletion.md.
12. Your rights
12.1 Everyone may ask us, at no charge, to:
- Access: confirm whether we hold personal data about you and give you a copy;
- Correct it (you can change your name and email in the portal yourself);
- Delete it (subject to 12.4);
- Export it in a structured, machine-readable form (portability): ask us for Download all my data, one download of everything we hold about you (and, for a Workspace Admin, the Workspace), which we send within 30 days of your request.
- Object to our use of it based on legitimate interests, and to direct marketing at any time;
- Restrict our use of it while a complaint is resolved;
- Withdraw consent where we rely on consent (e.g. the newsletter, crash reports). This doesn’t affect what we did before.
12.2 How to ask. Email privacy@planbaseestimating.com from the address on your Account, or write to us (section 1.2). We’ll confirm it’s you, usually by email from that address, and may ask for more if we can’t. An authorised agent may ask for you (see the US State Privacy Notice).
12.3 When we’ll answer. Within one month under the GDPR and UK GDPR (extendable by two months for complex requests, and we’ll tell you), and within 45 days under US state laws (extendable by 45 days).
12.4 Limits. We may keep data we must keep by law (such as tax records), need to establish or defend legal claims, or need to keep a security record (such as a minimal audit entry that an account existed and was deleted). We’ll tell you what we kept and why.
12.5 Workspace members. For Cloud Content and other data your company controls (section 3.3), we may refer you to your Workspace admin.
12.6 Complaints. If you’re in the EEA or UK, you can complain to your data protection authority (in the UK, the Information Commissioner’s Office). We’d appreciate the chance to fix it first.
12.7 No discrimination. We won’t treat you differently for using your rights.
13. US state privacy rights
Residents of California and other US states with privacy laws have the rights in our US State Privacy Notice, including the categories of data we collect, how to make requests, appeals, and authorised agents. We don’t sell personal information or share it for targeted advertising, so there’s nothing to opt out of; we treat a Global Privacy Control signal as a valid opt-out request anyway.
14. Cookies and similar technologies
The website and docs set no cookies of our own; visits are counted without cookies. The portal uses cookies that are strictly necessary to sign you in and keep it secure, plus a few browser-storage entries that remember, for example, which Workspace you last chose. We use no advertising or cross-site tracking cookies. Details for each site are in the Cookie Notice.
15. Security
15.1 We protect personal data with measures that fit what we hold, including: HTTPS everywhere; no passwords, full card numbers or full license keys on our systems; sign-in codes, device tokens and download links stored only as hashes; license files signed with Ed25519; our admin tools behind Cloudflare Access with every admin action recorded in the audit log; and secrets kept out of our code. The Security Overview describes them.
15.2 No system is perfectly secure. If a breach affects your personal data, we’ll tell you and the authorities as the law requires (under the GDPR, the authority within 72 hours where required).
16. Children
The Services are for businesses and professionals, and the Terms of Service (section 2.6) require every User to be at least 18. They are not directed at children under 16, and we don’t knowingly collect personal data from anyone under 16. If you think a child has given us personal data, email privacy@planbaseestimating.com and we’ll delete it.
17. Changes to this policy
17.1 We’ll post changes on this page and update the “Last updated” date and version.
17.2 For a material change, we’ll tell Account holders by email or in the app at least 30 days before it takes effect. Where the law requires your consent to a change, we’ll ask for it.
17.3 Earlier versions are available on request.
18. Contact
Planbase Estimating LLC · 3418 East 104th Street, Kansas City, MO 64137, USA Privacy: privacy@planbaseestimating.com · Legal: legal@planbaseestimating.com · Support: support@planbaseestimating.com
Change log
| Date | Version | Change |
|---|---|---|
| 2026-10-07 | 1.0 | Published. Same day: section 11 says tester-programme records are kept indefinitely, with the right to ask for deletion. |
| 2026-10-07 | 1.0 | Same day, added after attorney review (show at the next review): prospective customers and outreach emails (4.3A, the section 5 table, 8.6, section 11). |
| 2026-10-07 | 1.0 | Same day, added after attorney review (show at the next review): Terms and Privacy acceptance, company and location details, correspondence and contact notes (4.1), Resend delivery events (4.2), Paddle billing records (4.3), outreach replies (4.3A), the section 5 table, Cloudflare Email Routing (9.2), retention and what a deletion keeps (section 11), Download all my data on request (section 12). |
Planbase Estimating LLC, 3418 East 104th Street, Kansas City, MO 64137, USA. Questions: legal@planbaseestimating.com.All legal documents.