Security and your data
What this page is
A plan carries your customers' names, their addresses and the arrangement they pay you under. This page says where that sits, what can reach it, and what you can ask us to do with it.
It describes how the software is built. Nothing here is a setting you have to find and switch on.
Where it lives
Your customer records, your plan details and the history of what has been paid sit in one place, in London, and stay there.
Card numbers are the exception, and they are an exception by design. They go straight to the payment service that takes the payment, so they never reach our servers, our logs, our database or our error reports. That is a property of how the payment side is built rather than a setting.
- Where the data sits
- London
- Backups
- London
- Card numbers
- Never reach us
What one business can reach
Every business on Planramp sees its own customers and nobody else's. That separation is enforced by the database itself, underneath the application, so it holds even where a piece of software above it asks the wrong question. It is checked on every change rather than reviewed once.
- Your own records
- Yours
- Another business's records
- Out of reach
- Where that is enforced
- In the database
The bar we build to
Planramp is built to an external standard rather than to a list we wrote for ourselves, so a reviewer has a checklist that was not written by the people being reviewed.
- The standard
- OWASP ASVS 5.0, Level 2
- Stricter still on three things
- Payments, signing in, keeping businesses apart
- Independent audit
- Not carried out
Your rights, and how to use them
The data is yours and your customers'. Every row below is something you can ask for, and the address to ask at is in the privacy policy.
- What we hold about you
- Ask, and we tell you
- Anything that is wrong
- Ask, and we correct it
- Anything you want gone
- Ask, and we erase it
- If we get it wrong
- The ICO can be told
Where the legal version of this lives
This page describes how the software is built. The privacy policy is the document with legal weight: what is collected, why, how long it is kept, and the address to write to.
