Privacy Notice
Last updated: August 2026
This notice explains what personal data EventsPlans collects, why we collect it, who else sees it, and what you can ask us to do with it. It covers this website and the services on it.
1. Who we are
The data controller is EventsPlans, registered at 485 The Avenue, Cambridge, CB44 5HN. For anything in this notice, including a request about your own data, email [email protected] or write to us at that address.
2. What we collect, and why
We collect only what a marketplace needs to work. We do not buy personal data, we do not sell it, and we do not use it for advertising.
If you create an account
- Your email address, name, and a password. The password is stored only as a bcrypt hash, so we cannot read it and cannot tell you what it is.
- Optionally, your phone number, company name, postal address, date of birth, and a profile photo, if you choose to add them.
- Whether your account is a customer account or a vendor account.
We use this to give you an account, to sign you in, and to show your name on anything you post. Without it there is no account.
If you sign in with Google or Facebook
- Your email address and name from that provider, and the identifier it gives us for your account there.
- Your profile photo, if the provider supplies one. We copy the image into our own storage rather than linking to it, so the provider does not see every page you view.
We do not receive your password from the provider, and we do not post anything to your account there. If you upload your own photo, it replaces the copied one and we do not fetch the provider’s again.
If you send a vendor an enquiry
- Your name, email address, phone number, your message, and the event date and place, if you give them. You do not need an account to send an enquiry.
- We email all of that to the vendor. They reply to you directly. We are not in the middle of that conversation, and after the email is sent your details are the vendor’s to hold under their own privacy practices.
- We keep a record of the enquiry so we can count how many the site produces. That record deliberately holds no contact details — it stores which listing was contacted, the event date, the outcome, and when it happened, and nothing that identifies you.
- We also keep a copy of the enquiry for the vendor, so they can read it in their account as well as in their inbox. It holds what you typed — your name, email address, phone number, message, and the event date and place — and is removed two years after it arrives. It belongs to the listing rather than to an account: if the business later claims the listing, or it is transferred to them, they see the enquiries it received.
If you write a review
- Your star rating and your comment, shown publicly beside the listing with your first name only. Your surname and email address are never shown.
If you use the messaging facility
- The messages you send and receive, and when they were sent and read. These are private between you and the other party, and we do not publish them.
If you pay for a listing plan
- Payments are taken by Stripe, on Stripe’s own pages. We never see your card. We hold a Stripe customer reference, which plan each of your listings is on, its status, and when the current period ends. Your invoices and card details are held by Stripe and reached through its billing portal.
If you are a vendor supplying verification documents
- The document type, its reference number — which may be a certificate number or a DBS number — its issue and expiry dates, and a scan of the document. Scans are held in private storage and are not published.
- An administrator’s notes on whether the document was accepted.
[Under review: a DBS number is criminal-offence data. The lawful basis and the condition relied on for it must be confirmed before this section is published.]
Whenever anyone uses the site
- Security. We count requests per IP address to stop one client overwhelming the site. Those counts are held in memory and discarded after fifteen minutes. Our provider, Cloudflare, keeps its own edge logs.
- Sign-in and contact forms are protected by Cloudflare Turnstile, which checks that a request comes from a person rather than a script.
- Errors. If a page fails, the browser sends an error report to Sentry so we can fix it. It carries the page path, with any query string removed, the browser version and the release. We do not attach your name or account to it.
- Visitor numbers. We use Cloudflare Web Analytics, which counts page views without cookies and without following you between sites.
- Address lookups. When you enter a postcode we ask an address provider for the matching places, and we keep the answer so the next person asking the same thing costs no second lookup. What is kept is the postcode and the addresses in it, which is public information and is not linked to you.
3. Lawful basis
[For review by a qualified adviser. The bases below are drafted, not settled.]
- Your account, and sending an enquiry: performance of a contract, or steps taken at your request before one.
- Reviews, visitor counts, error reports, security and rate limiting: our legitimate interests in running a marketplace that works and is not abused.
- Vendor verification documents: to be confirmed — see the note in section 2.
We do not rely on consent for anything above, and we send no marketing email.
4. Cookies and what the site stores in your browser
Every cookie below is set by this site, is strictly necessary for it to work, and none of them tracks you across other sites. We set no advertising or profiling cookies.
client_version — tells the server which version of the site your browser loaded, so a stale page cannot send a request the server no longer understands.access_token and refresh_token — keep you signed in. Set only when you sign in, and cleared when you sign out.access_token_expiry — lets the page know when your session is about to lapse so it can renew it quietly.eventsplans_link_intent — set for a few minutes only while you link a Google or Facebook account to an existing account.
The site also keeps two things in your browser’s own storage, which never reach us: your search filter preferences, so a catalogue opens the way you left it, and a note that a page reloaded itself after a failed download, so it does not loop.
5. Who else processes your data
These are the only third parties involved, and each one acts on our instructions:
- Cloudflare — serves the site, filters abusive traffic, stores uploaded images, provides the bot check, and counts visits without cookies.
- Google and Facebook — only if you choose to sign in with them.
- Our address-lookup providers — receive a postcode or a partial address, and nothing about you.
- Sentry — receives error reports.
- Stripe — takes payment for a listing plan, if you buy one. It receives your name, email address and card details on its own pages; we receive a customer reference and the plan’s status.
- Our email provider — sends the emails we send on your behalf or to you.
Some of these operate outside the United Kingdom. [The transfer safeguards relied on need confirming.]
6. How long we keep it
Some periods are enforced by the system itself:
- A password-reset link and an account-linking token last ten minutes.
- A registration confirmation link lasts one day.
- A listing-claim code lasts until it expires, then the record is removed.
- A sign-in session token is removed when it expires.
- The copy of a quote request kept for the vendor is removed two years after it arrives.
- Request counts used for rate limiting are discarded after fifteen minutes.
Everything else — your account, your reviews, your messages, and the emails we have sent — is kept until you ask us to remove it. [A retention period for a dormant account and for sent email should be set, and this paragraph rewritten once it is.]
7. Your rights
Under United Kingdom data protection law you may ask us to:
- give you a copy of the personal data we hold about you;
- correct anything inaccurate;
- delete your data, where we have no continuing reason to keep it;
- restrict or object to how we use it;
- provide it in a portable form.
Email [email protected], or write to EventsPlans, 485 The Avenue, Cambridge, CB44 5HN. We will answer within one month, and there is no charge.
There is currently no button that deletes your account. Ask us and we will do it by hand. We would rather say so than imply a self-service route that does not exist.
If you are unhappy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or by calling 0303 123 1113. We would like the chance to put it right first.
8. Security
The site is served only over an encrypted connection. Passwords are stored as bcrypt hashes. Session tokens are held in cookies that JavaScript cannot read, and a signed-in session lasts fifteen minutes before it is renewed. Uploaded documents are held in private storage. No measure is perfect, and we will tell you and the regulator if a breach affects you.
9. Children
The service is for adults. Our terms require you to be at least eighteen to create an account, and we do not knowingly collect data about children. If you believe a child has given us data, write to us and we will remove it.
10. Changes
If we change this notice we will change the date at the top. If a change materially affects how we use data you have already given us, we will tell account holders directly.