Last updated 9 October 2026. "CrowdPlan", "we" and "us" mean CrowdPlan.app, the operator of the service -- see our Terms & Conditions for how the service itself works.
1. Who this covers, and who's responsible for what
CrowdPlan is used by venues ("tenancies") to schedule their own staff and manage their own rooms, shows, and bookings. For data a venue enters about its own staff -- names, emails, phone numbers, rota and shift records -- that venue is the data controller, and CrowdPlan is a data processor acting only on that venue's instructions. If you're a member of staff whose data appears in a CrowdPlan account, your own employer (the venue) is who to contact about it in the first place; we process it only to provide the service to them.
For the account-holder relationship itself (billing contacts, support conversations, this website), CrowdPlan is the data controller.
2. What we collect
Depending on how a venue uses CrowdPlan, this can include:
- Staff account data entered by a venue: name, email address, phone number, role, and (if uploaded) a profile picture.
- Rota, booking, and reporting data: shifts, room/resource bookings, show and contra details, end of shift reports -- whatever the venue itself records.
- Login and security data: sign-in timestamps, IP address and approximate country (used only to flag unusual sign-in activity and enforce rate limits against repeated failed logins), and browser session identifiers.
- Billing contact data for the account holder, processed on our behalf by Stripe -- see section 4. We never see or store full card details ourselves.
- Push notification subscriptions, only if a staff member chooses to enable notifications on their own device -- this is a device-level subscription identifier, not tied to browsing activity.
- Support correspondence if you contact us or raise a support ticket.
- Third-party sign-in data, only for a venue that has switched on Microsoft 365 or Google sign-in: the name, email, and (best-effort) profile photo Microsoft or Google shares when a staff member signs in that way, matched to their existing CrowdPlan login by email. We never receive their Microsoft/Google password.
We don't use tracking or advertising cookies, and we don't sell personal data to anyone.
3. Why we process it
To provide the service a venue has subscribed to (rota, bookings, reporting); to keep accounts secure (detecting suspicious sign-ins, rate-limiting); to bill the account holder; to respond to support requests; and to meet our own legal obligations (e.g. accounting records). Where a venue switches on an optional integration (Microsoft 365, Google, TicketSource), that's done on the venue's own instruction and consent, not ours.
4. Who we share it with
We use a small number of other companies to help run the service, each only for what they need to do their part:
- Stripe -- payment processing for subscriptions. We never store full card details ourselves.
- SMTP2GO -- sending the transactional emails CrowdPlan sends (sign-in links and codes, notifications, show reports a venue chooses to email out). CrowdPlan uses SMTP2GO's EU service, so sending is processed on servers in the EU/UK. Each message passes through SMTP2GO in order to be delivered, and SMTP2GO keeps delivery logs (recipient address, subject, delivery status) for its own retention period.
- Microsoft and Google -- only for a venue that has switched on their own Microsoft 365 or Google integration (sign-in, room calendar sync, the Google Sheet import, or sending a venue's own customer emails from its own Microsoft 365 mailbox). Nothing is sent to either unless a venue turns that feature on. Some CrowdPlan notification and support emails are also sent through CrowdPlan's own Microsoft 365 mailbox.
- TicketSource -- only for a venue that has connected its own TicketSource account for ticket sales figures.
- Anthropic -- only for a venue using the Smart Import add-on: the technical rider it uploads is sent to Anthropic, a US company, so its requirements can be read out. Nothing is sent unless a venue uses that feature.
- DigitalOcean -- hosting: the servers and managed database CrowdPlan runs on, in its London data centre.
- Microsoft -- cloud storage for our nightly backups, in the UK.
- Cloudflare -- a security and delivery layer in front of the website and app. Web traffic passes through its network, which can handle it at locations outside the UK.
We don't share data with anyone else, and never for their own marketing purposes.
5. Where data is stored, and international transfers
CrowdPlan's own servers, database and backups are in the United Kingdom (London). Some of the processors above (Stripe, SMTP2GO, Microsoft, Google) may process data outside the UK/EU as part of running their own services; where that happens, it's covered by their own standard contractual clauses or equivalent safeguards recognised under UK/EU data protection law.
6. How long we keep it
For as long as a venue's subscription is active, plus 90 days after cancellation (so data can still be exported or the subscription resumed -- see our Terms), after which it's deleted. Backups are kept on a rolling 30-day basis and age out automatically. Support correspondence is kept for as long as reasonably needed to resolve the matter and for our own records.
7. How we protect it
Encrypted in transit (HTTPS everywhere). Passwords are hashed, never stored in plain text. Any third-party credentials CrowdPlan itself holds (e.g. an integration's access token) are encrypted at rest. Backups are automated, encrypted, and access to them is restricted. We don't claim perfection -- no service can -- but this reflects what we actually do, not a generic promise.
8. Your rights
Under UK GDPR you have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have it deleted, to restrict or object to some processing, and to receive it in a portable format. If your data was entered by your employer (a venue using CrowdPlan), ask them first -- they control it; we'll support them in responding. For anything CrowdPlan itself controls (see section 1), contact us directly at [email protected]. You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time.
9. Cookies and browser storage
Nothing here tracks you: no advertising, analytics or tracking cookies, on this website or in the app. What we do use is listed below; it's what the service needs to work, plus one small note so the website's opening animation only plays once.
- This website (crowdplan.app) sets no cookies of its own. It keeps two small things in your browser: a note that you've seen the opening animation, so it only plays once (kept until you clear your browser's site data), and the room count you picked, so it carries from the home page to Pricing (cleared when you close the browser). Neither identifies you or leaves your browser.
- The CrowdPlan app (your venue's address, such as yourvenue.crowdplan.app) sets one cookie,
PHPSESSID, to keep you signed in. It ends when you close your browser, unless you tick "Remember me", in which case it lasts until you sign out or it expires. The app also keeps some screen state in session storage (which sections you had open, a short-lived copy of your to-do list), cleared when you close the browser. - Cloudflare, which protects the site and the app from attacks, may set short-lived security cookies (such as
__cf_bmorcf_clearance) to tell people from bots.
Push notifications (where a staff member enables them) are a browser permission, not a cookie. Paying by card happens on Stripe's own checkout pages, under Stripe's privacy policy.
10. Children
CrowdPlan is a business tool used by venues to manage their own staff; it isn't directed at or marketed to children, and we don't knowingly collect data about children through this website.
11. Changes to this policy
We may update this policy from time to time. Material changes are notified by email to account holders at least 30 days before they take effect, same as changes to our Terms.