Privacy Policy
Updated / November 2025
1. Introduction
Planby Technologies Inc. (“Company,” “we,” “us,” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Plana platform (the “Service”). This Privacy Policy applies to all users of our Service worldwide. We comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) for California residents, the Personal Information Protection Act (PIPA) for users in South Korea, and other applicable privacy laws.
2. Data Controller Information
The data controller responsible for your personal data is:
Planby Technologies Inc.
Email: contact@planby.us
U.S. Address: 3003 North 1st Street #221, San Jose, CA 95134, USA
Korea Address: 2F, 18 Yeoksam-ro 12-gil, Gangnam-gu, Seoul, Republic of Korea
3. Information We Collect
3.1 Information You Provide
We collect information that you provide directly to us, including:
Account Information: Name and email address when you create an account.
Payment Information: Billing details and payment card information (processed securely through Stripe).
Design Files: Images, designs, and other files you upload to use with our Service.
3.2 Information Collected Automatically
When you use our Service, we automatically collect certain information, including:
Device and Access Information: IP address, browser type, operating system, device identifiers, and access times.
Usage Data: Information about how you interact with the Service, including features used, actions taken, and session duration.
Analytics Data: User behavior patterns collected through Microsoft Clarity and similar analytics tools.
3.3 Information from Third Parties
We may receive information about you from third-party services you use to log in or connect to our Service, subject to your authorization.
4. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain the Service | Performance of contract |
| Process payments | Performance of contract |
| Improve and develop the Service | Legitimate interests |
| Send service-related communications | Performance of contract / Legitimate interests |
| Analytics and usage monitoring | Legitimate interests / Consent |
| Comply with legal obligations | Legal obligation |
| Marketing communications | Consent |
5. Third-Party Service Providers
We share your information with the following categories of third-party service providers:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Payment details, billing info |
| Google Cloud | Cloud infrastructure | Service data |
| OpenAI | AI image generation | Prompts, uploaded images |
| Google Gemini | AI processing | Prompts, uploaded images |
| Microsoft Clarity | Analytics | Usage data, session recordings |
| Amazon Web Services | Data storage | All service data |
Each third-party service provider is contractually obligated to protect your data and use it only for the purposes specified.
6. Data Storage and International Transfers
6.1 Data Storage Location
Your data is stored on servers located in the United States, operated by Amazon Web Services (AWS). AWS maintains robust security measures and compliance certifications.
6.2 International Data Transfers
If you are located outside the United States, please note that your data will be transferred to and processed in the United States. For transfers from the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission or other valid transfer mechanisms. For transfers from South Korea, we comply with PIPA requirements for cross-border data transfers.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
Account Information: Retained while your account is active and for a reasonable period thereafter.
Design Files: Retained while your account is active. Deleted upon account deletion or as per your request.
Payment Records: Retained for the period required by tax and accounting laws (typically 5-7 years).
Usage Data: Retained for up to 24 months for analytics purposes.
Legal Compliance: Data may be retained longer if required by law or to protect our legal interests.
8. Your Rights
8.1 Rights Under GDPR (EEA Users)
If you are located in the European Economic Area, you have the following rights:
Right of Access: Request a copy of your personal data.
Right to Rectification: Request correction of inaccurate data.
Right to Erasure: Request deletion of your personal data.
Right to Restrict Processing: Request limitation of data processing.
Right to Data Portability: Receive your data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interests.
Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
8.2 Rights Under CCPA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
Right to Know: Request disclosure of categories and specific pieces of personal information collected.
Right to Delete: Request deletion of personal information.
Right to Opt-Out: Opt out of the sale or sharing of personal information. Note: We do not sell personal information.
Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights.
8.3 Rights Under PIPA (Korean Users)
If you are located in South Korea, you have the following rights under the Personal Information Protection Act:
Right to Access: Request access to your personal information.
Right to Correction: Request correction or deletion of inaccurate data.
Right to Suspend Processing: Request suspension of personal information processing.
Right to Withdraw Consent: Withdraw consent for optional data collection.
8.4 How to Exercise Your Rights
To exercise any of these rights, please contact us at contact@planby.us. We will respond to your request within the timeframe required by applicable law (typically 30 days for GDPR, 45 days for CCPA, 10 days for PIPA). We may ask you to verify your identity before processing your request.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about your use of the Service:
Essential Cookies: Required for the Service to function properly.
Analytics Cookies: Help us understand how users interact with the Service (Microsoft Clarity).
Preference Cookies: Remember your settings and preferences.
You can manage cookie preferences through your browser settings. Note that disabling certain cookies may affect the functionality of the Service.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls, regular security assessments, and employee training. However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us immediately at contact@planby.us, and we will take steps to delete such information.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service prior to the effective date of the changes. We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
13. Do Not Track Signals
Some browsers have a “Do Not Track” feature that signals to websites that you do not want to have your online activity tracked. Our Service does not currently respond to “Do Not Track” signals. However, you can manage your privacy preferences through the cookie settings in your browser.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, or if you wish to exercise your data protection rights, please contact us at:
Planby Technologies Inc.
Email: contact@planby.us
U.S. Address: 3003 North 1st Street #221, San Jose, CA 95134, USA
Korea Address: 2F, 18 Yeoksam-ro 12-gil, Gangnam-gu, Seoul, Republic of Korea
For EEA users, you also have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.