Effective Date: 2/14/26 · Location Planner LLC · California, US
Privacy Policy
How we collect, use, store, and protect your information when you use Location Planner.
Introduction
Location Planner LLC operates a web-based location planning application ("Service") for U.S.-based companies. This Privacy Policy explains how we collect, use, store, and protect information when you use our website and application.
By accessing or using the Service, you agree to this Privacy Policy.
Information We Collect
A. Account Information
- Name
- Email address
- Company name
- Organization account information
- User role (Admin or Invited User)
B. Project and File Data
- Uploaded PDFs and plans
- Sign placements
- Message schedules
- Legends
- Project metadata
C. Payment Information
Payments are processed securely through Stripe. We do not store full credit card details. Stripe processes payment data in accordance with its own privacy policy.
D. Automatically Collected Data
- IP address
- Browser type
- Device information
- Usage data
- Session duration
- Analytics data (PostHog)
E. Trial Session Data
Users may test the Service without creating an account. Trial session activity may be temporarily processed but is not permanently stored unless an account is created.
F. Marketing & Signup Forms
When you submit our trial signup form, demo request, or an advertising landing page, we collect the details you provide (name, work email, company, phone, role, and team-size answers) together with campaign attribution (UTM parameters, ad click identifiers, and referrer) so we can follow up with you and measure our advertising. This information is used for sales and onboarding contact — it is never sold.
How We Use Information
We use information to:
- Provide and operate the Service
- Store and manage project files
- Process subscription payments
- Enable organization-based account management
- Improve system performance
- Monitor usage and analytics
- Prevent fraud or abuse
- Comply with legal obligations
Organization Accounts
Organization Admin accounts may:
- Invite users under their organization
- View all projects created by invited users
- Delete projects within their organization
- Delete invited user accounts
- Delete their own admin account
Invited Users:
- May create and manage projects
- May export and delete their own projects
- Cannot delete their own user account
- Must request account deletion from their Organization Admin
If an Organization Admin account is deleted, all associated user accounts and project data may also be deleted.
Data Retention
We store user files and project data until:
- The user deletes the project
- The Organization Admin deletes the project
- The account is deleted
- The account is suspended or terminated pursuant to our Terms of Use
Upon deletion, data may be permanently removed from active systems within a reasonable timeframe.
Data Sharing
We do not sell personal data.
We may share information with:
- Stripe (payment processing)
- Cloud hosting providers
- Analytics providers
- Legal authorities when required by law
All service providers are required to maintain appropriate data protection safeguards.
Security
We take the security of your data seriously, particularly given that many clients upload sensitive site plans and documents that may be subject to confidentiality agreements. Our infrastructure is built on Supabase, which provides enterprise-grade security.
Database Security
- Row Level Security (RLS): Enforced at the database level on every table. Users can only access data belonging to their own organization — enforced by database policy, not just application logic.
- Encryption at rest: All database data is encrypted using AES-256.
- Encryption in transit: All connections use TLS 1.2 or higher.
File Storage Security
- Private storage buckets: All uploaded files are stored in private, non-public buckets. Files cannot be accessed without a valid authenticated session token scoped to the owning organization.
- No public URLs: There are no publicly accessible file URLs. Every file request requires authentication.
Infrastructure
- Hosted on AWS in the US West (Oregon) region
- Supabase is SOC 2 Type 2 certified
- SSL/TLS encryption on all API endpoints
No system can guarantee absolute security. In the event of a data breach, we will notify affected users as required by applicable law.
File Confidentiality
Location Planner LLC does not access, view, read, or use the contents of any files you upload, including PDFs, site plans, message schedules, sign placements, or project documentation.
We store your files solely as a service to your organization. Our staff has no access to your project content. We do not analyze, mine, or process file contents for any purpose.
- Files are stored encrypted and accessible only to authenticated users within your organization
- Organization data is isolated at the database level
- Location Planner LLC employees do not have routine access to customer file contents
If you require a formal data processing agreement (DPA) or have specific confidentiality requirements, contact us at hello@locationplanner.org.
User Rights
Users may:
- Export their project data
- Delete their projects
- Request deletion of their account (Admin required for invited users)
Requests may be submitted to hello@locationplanner.org.
Cookies and Analytics
We use PostHog, a product analytics tool, to understand how users interact with our Service. PostHog may collect:
- Pages visited and time spent
- Click and interaction events
- Session replays (a recording of your interactions with the app)
- Browser type and device information
- IP address (used to derive approximate location)
Analytics are only loaded after you have provided consent via the cookie notice displayed on your first visit.
California Residents — CCPA Rights
If you are a California resident, you have the following rights under the CCPA:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you.
- Right to Correct: Request correction of inaccurate personal information we hold about you.
- Right to Delete: Request deletion of personal information we have collected from you.
- Right to Opt-Out of Sale or Sharing: We do not sell or share your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise these rights, contact us at hello@locationplanner.org. We will respond within 45 days.
Other U.S. State Privacy Rights
Residents of Virginia, Colorado, Connecticut, Texas, and other states with applicable privacy laws may have similar rights to access, correct, delete, or opt out of certain processing. Contact us at hello@locationplanner.org to make a request.
International Visitors — GDPR / UK GDPR
The Service is intended for U.S.-based companies and we do not target the European Economic Area or the United Kingdom. If you nevertheless use the Service from the EEA or UK, the following applies:
- Controller: Location Planner LLC (contact: hello@locationplanner.org).
- Legal bases: performance of a contract (providing the Service), legitimate interests (security, fraud prevention, service improvement), consent (analytics cookies and marketing forms), and legal obligations.
- Your rights: access, rectification, erasure, restriction of processing, data portability, and objection. You may also withdraw consent at any time (e.g., analytics) without affecting prior processing, and you may lodge a complaint with your local supervisory authority.
- International transfer: data is stored and processed in the United States (AWS US West via Supabase). Our processors provide appropriate safeguards, including Standard Contractual Clauses where applicable.
- Retention: as described in Section 5 — data is kept while your account is active and deleted on account/project deletion or on request.
To exercise any of these rights, email hello@locationplanner.org. We respond within 30 days.
Changes to This Policy
We may update this Privacy Policy periodically. Continued use of the Service constitutes acceptance of changes.