Legal
Privacy Policy
Last updated: May 25, 2026
At Planbetr, we respect your privacy and are committed to protecting the personal data you entrust to us. This Privacy Policy explains what information we collect, how we use it, and your rights in relation to it when you use the Planbetr platform and its associated services (the "Service").
1. Scope and Controller
This Privacy Policy applies to all users of the Planbetr platform, including institution administrators, invited teachers, staff, and any other registered users.
Planbetr acts as the data controller for personal data collected through the Service. If you have any questions about how your data is handled, please contact us at privacy@planbetr.com.
2. Information We Collect
We collect only the information necessary to provide and improve the Service. This includes:
2.1 Account Information
When you register for a Planbetr account, we collect your name, email address, and password (stored securely as a hash). If you sign in via Google OAuth, we receive the basic profile information (name, email, and profile picture) that Google provides.
2.2 Profile and Onboarding Data
During onboarding, you may optionally provide additional information such as your role, institution name, and preferences. You may also upload a profile photo, which is stored via Cloudinary.
2.3 Institution and Workspace Data
Institution administrators configure data within their workspaces, including department structures, classroom information, teacher profiles, lecture schedules, and timetable configurations. This data is associated with the institution's workspace and is accessible only to authorized workspace members.
2.4 Scheduling and Booking Data
When you create or manage schedules, events, and appointments through the Service, we collect and store the relevant scheduling data, including event times, participants, and booking status, to operate the Service as intended.
2.5 Notification Preferences
We store your notification settings and preferences to deliver relevant alerts, reminders, and updates about your scheduling activity.
2.6 Third-Party Integration Data
If you connect a third-party integration, including Google Calendar, Google Meet-related features, or Zoom, we may store connection tokens, calendar identifiers, availability or free/busy information, event metadata needed to create or sync events you request through Planbetr, meeting link metadata, and other relevant configuration data required to maintain the integration. We do not store your Google password, Zoom password, or other full third-party account credentials.
Google user data is used only to provide and improve user-facing functionality that you explicitly enable, such as authentication, checking availability, syncing calendar events, and generating meeting links. We do not sell Google user data, use it for targeted advertising, or transfer it to third parties for purposes unrelated to providing or improving the functionality of the Service.
2.7 Usage and Technical Data
We may collect technical data such as your browser type, device information, and general usage patterns to help us diagnose issues, improve performance, and understand how the Service is used. IP addresses may be temporarily retained to prevent abuse and unauthorized access.
2.8 Communications with Us
If you contact our support team, we collect the content of your messages and any contact information you provide in order to respond to your inquiry and improve the Service.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Planbetr platform and its features.
- Authenticate your identity and manage your account securely.
- Enable institution administrators to manage their workspaces, members, and scheduling data.
- Provide Google Calendar synchronization, availability checks, event creation, and Google Meet link generation when you choose to connect your Google account.
- Send transactional communications, including account verification emails, password reset links, and scheduling notifications.
- Respond to your support requests, questions, and feedback.
- Detect and prevent fraudulent, abusive, or unauthorized activity.
- Improve and develop the Service based on aggregated, anonymized usage patterns.
- Comply with applicable legal obligations.
We do not use your personal data for targeted advertising, and we do not sell or rent your data to third parties.
In particular, Google user data is processed only for the limited purposes described in this Policy, such as authenticating your account, checking calendar availability, creating or syncing events, and generating meeting links you request through the Service.
4. Legal Bases for Processing
Where applicable (such as under GDPR), we rely on the following legal bases to process your personal data:
- Contract performance — to deliver the Service you have signed up for.
- Legitimate interests — to maintain security, prevent abuse, and improve the Service, where these interests are not overridden by your rights.
- Consent — for optional features or communications where we ask for your agreement (e.g., marketing emails, optional integrations). You may withdraw consent at any time.
- Legal obligation — to comply with applicable laws and respond to lawful requests from authorities.
5. Data Sharing and Disclosure
We do not sell, trade, or otherwise transfer your personal data to outside parties for commercial purposes. We may share your data only in the following limited circumstances:
- Service providers — We share data with trusted third-party processors that assist us in operating the Service (e.g., cloud hosting, image storage, authentication providers). These processors are bound by confidentiality obligations and may not use your data for their own purposes.
- Connected platform services — If you connect Google Calendar or request Google Meet link generation through Planbetr, we send the minimum relevant data to Google that is necessary to perform the action you requested. We do not disclose Google user data to third parties for independent advertising, marketing, or resale.
- Within your workspace— Scheduling data, member profiles, and workspace configurations are visible to other authorized members of your institution's workspace, as determined by the roles and permissions set by your administrator.
- Legal requirements — We may disclose data if required by law, court order, or a competent governmental authority, or where we believe disclosure is necessary to protect our rights or the safety of users.
- Business transfers — In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.
6. Third-Party Services
Planbetr integrates with the following third-party services that may process your data:
| Service | Purpose | Data Processed |
|---|---|---|
| Google OAuth and Google Calendar | Account authentication, calendar sync, availability checks, event creation, and Google Meet link generation | Name, email, profile picture, calendar identifiers, availability or free/busy information, event metadata needed for synced events, meeting link metadata, and connection tokens |
| Zoom | Video meeting integration for scheduling | Zoom account connection tokens, meeting links |
| Cloudinary | Profile image storage and delivery | Profile photos uploaded by users |
Each third-party service operates under its own privacy policy. We encourage you to review those policies before connecting your accounts.
7. Data Security
We implement industry-standard technical and organizational security measures to protect your personal data against unauthorized access, loss, destruction, or alteration. These include:
- Encrypted data transmission over HTTPS/TLS.
- Secure hashing of passwords using industry-standard algorithms.
- Authentication tokens with expiration and refresh controls.
- Restricted access and secure storage practices for connected integration tokens and related account metadata.
- Role-based access controls limiting data access within workspaces.
- Regular security reviews of our infrastructure.
While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security and encourage you to protect your account with a strong, unique password.
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within a reasonable period, except where we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
Workspace data associated with an institution (such as timetables, department structures, and scheduling records) may be retained separately for as long as the institution's workspace remains active.
If you disconnect a Google integration or delete your account, we will delete or de-identify stored Google user data and connection tokens within a reasonable period, except where limited retention is required for security logging, backup restoration cycles, dispute resolution, or compliance with applicable law.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Access — Request a copy of the personal data we hold about you.
- Correction — Request that we correct inaccurate or incomplete data.
- Deletion — Request that we delete your personal data, subject to legal retention requirements.
- Portability — Request a machine-readable copy of your data where technically feasible.
- Objection or restriction — Object to or request restriction of certain processing activities.
- Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at privacy@planbetr.com. We will respond to your request within a reasonable timeframe and in accordance with applicable law. For certain requests, we may need to verify your identity before proceeding.
10. Cookies and Tracking Technologies
Planbetr uses cookies and similar technologies to maintain your session, remember your preferences, and ensure the secure functioning of the Service. We use:
- Essential cookies — Required for the Service to function, such as authentication session tokens. These cannot be disabled.
- Preference cookies — Used to remember your settings (e.g., language, theme) across sessions.
We do not use tracking cookies for advertising or cross-site behavioral profiling. You can manage cookie preferences through your browser settings, though disabling essential cookies may prevent some features from functioning correctly.
11. Children's Privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from individuals under 16. If we become aware that we have collected such data without appropriate consent, we will take steps to delete it promptly. If you believe a minor has provided us with personal data, please contact us at privacy@planbetr.com.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we do, we will revise the "Last updated" date at the top of this page. For material changes, we will notify you via email or a prominent notice within the Service.
Your continued use of the Service after any changes take effect constitutes your acceptance of the revised Privacy Policy.
13. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please reach out to us:
Planbetr — Privacy Team
Email: privacy@planbetr.com
© 2026 Planbetr. All rights reserved.
View Terms of Use →