Privacy Policy

How we collect, use, and protect personal data -- for venues using CrowdPlan, and for visitors to this website.

Last updated 9 October 2026. "CrowdPlan", "we" and "us" mean CrowdPlan.app, the operator of the service -- see our Terms & Conditions for how the service itself works.

1. Who this covers, and who's responsible for what

CrowdPlan is used by venues ("tenancies") to schedule their own staff and manage their own rooms, shows, and bookings. For data a venue enters about its own staff -- names, emails, phone numbers, rota and shift records -- that venue is the data controller, and CrowdPlan is a data processor acting only on that venue's instructions. If you're a member of staff whose data appears in a CrowdPlan account, your own employer (the venue) is who to contact about it in the first place; we process it only to provide the service to them.

For the account-holder relationship itself (billing contacts, support conversations, this website), CrowdPlan is the data controller.

2. What we collect

Depending on how a venue uses CrowdPlan, this can include:

We don't use tracking or advertising cookies, and we don't sell personal data to anyone.

3. Why we process it

To provide the service a venue has subscribed to (rota, bookings, reporting); to keep accounts secure (detecting suspicious sign-ins, rate-limiting); to bill the account holder; to respond to support requests; and to meet our own legal obligations (e.g. accounting records). Where a venue switches on an optional integration (Microsoft 365, Google, TicketSource), that's done on the venue's own instruction and consent, not ours.

4. Who we share it with

We use a small number of other companies to help run the service, each only for what they need to do their part:

We don't share data with anyone else, and never for their own marketing purposes.

5. Where data is stored, and international transfers

CrowdPlan's own servers, database and backups are in the United Kingdom (London). Some of the processors above (Stripe, SMTP2GO, Microsoft, Google) may process data outside the UK/EU as part of running their own services; where that happens, it's covered by their own standard contractual clauses or equivalent safeguards recognised under UK/EU data protection law.

6. How long we keep it

For as long as a venue's subscription is active, plus 90 days after cancellation (so data can still be exported or the subscription resumed -- see our Terms), after which it's deleted. Backups are kept on a rolling 30-day basis and age out automatically. Support correspondence is kept for as long as reasonably needed to resolve the matter and for our own records.

7. How we protect it

Encrypted in transit (HTTPS everywhere). Passwords are hashed, never stored in plain text. Any third-party credentials CrowdPlan itself holds (e.g. an integration's access token) are encrypted at rest. Backups are automated, encrypted, and access to them is restricted. We don't claim perfection -- no service can -- but this reflects what we actually do, not a generic promise.

8. Your rights

Under UK GDPR you have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have it deleted, to restrict or object to some processing, and to receive it in a portable format. If your data was entered by your employer (a venue using CrowdPlan), ask them first -- they control it; we'll support them in responding. For anything CrowdPlan itself controls (see section 1), contact us directly at [email protected]. You can also complain to the UK's data protection regulator, the Information Commissioner's Office (ICO), at any time.

9. Cookies and browser storage

Nothing here tracks you: no advertising, analytics or tracking cookies, on this website or in the app. What we do use is listed below; it's what the service needs to work, plus one small note so the website's opening animation only plays once.

Push notifications (where a staff member enables them) are a browser permission, not a cookie. Paying by card happens on Stripe's own checkout pages, under Stripe's privacy policy.

10. Children

CrowdPlan is a business tool used by venues to manage their own staff; it isn't directed at or marketed to children, and we don't knowingly collect data about children through this website.

11. Changes to this policy

We may update this policy from time to time. Material changes are notified by email to account holders at least 30 days before they take effect, same as changes to our Terms.

Contact

[email protected]