Privacy Policy

Last updated: 3 July 2026

Effective: 3 July 2026

1. Who we are

eplanr ("we", "us", "our") is an AI-assisted event-planning platform operated from India. Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we act as a Data Fiduciary for all personal data processed through the Service.

2. Data we collect

CategoryExamplesSource
Account dataMobile number, first and last nameYou, at sign-up (OTP login)
Event dataEvent descriptions, checklists, budgets, vendor details, timelinesYou, when creating/editing events
Guest dataGuest names and mobile numbersYou (the planner) or imported from your contacts
Usage dataPages viewed, feature interactions, device type, IP addressAutomatic collection
Billing dataSubscription plan, payment historyRazorpay (we never see or store card numbers)

We do not knowingly collect data from anyone under the age of 18. If you believe a minor's data has been submitted, contact us and we will delete it promptly.

3. Purpose and legal basis

We process personal data only for the purposes listed below, on the basis of your consent (provided when you create an account or add guests) and our legitimate need to operate the Service:

  • Operate the Service — generate event plans via AI, manage checklists, budgets, and vendor tracking.
  • Send transactional messages — OTP codes, event invitations, RSVP links, task reminders, and vendor notifications via SMS and WhatsApp.
  • Process payments — manage subscriptions and enforce plan limits through Razorpay.
  • Improve the product — analyse aggregated, de-identified usage data to improve features and fix issues.

We do not use your data for advertising, profiling, or sale to third parties.

4. Guest and co-planner data

If you are a guest receiving an invite from an eplanr planner: the planner provided your name and mobile number so we could deliver the invitation. We store this data only for that event. You can decline further contact at any time by replying STOP or contacting us at the address below. You may also request erasure of your data — see Section 8.

When a planner adds a guest or co-planner, we store the name and mobile number they provide to send invitations, RSVP links, and event updates. Guest data is retained only for the duration of the associated event plus the retention period described in Section 6. Guests are notified of this policy on the invite page.

5. Service providers and cross-border transfers

We share personal data only with the third-party processors listed below, solely to operate the Service. We never sell data to advertisers or data brokers.

ProviderPurposeLocation
AnthropicAI plan generation (event descriptions and checklist content are sent to Claude for processing)United States
NVIDIA NIMAI model inference for event planning featuresUnited States
TwilioSMS and WhatsApp delivery (OTP, invitations, reminders)United States
RazorpayPayment processingIndia
Google Maps PlatformVenue and vendor location servicesUnited States
AWS (cloud infrastructure)Data storage and application hostingMumbai (ap-south-1), with failover to other AWS regions

Under the DPDP Act, transfers to countries not on the restricted list are permitted provided they are disclosed. All providers listed above operate under data-processing agreements with appropriate security safeguards. We take steps to minimise PII in data sent to AI processors (see Section 6).

6. Data retention

  • Account and event data — retained for as long as your account is active. You can delete individual events or request full account deletion at any time.
  • AI processing logs — prompts and responses sent to/from AI providers are logged internally for debugging and abuse prevention. These logs are automatically purged after 90 days. We are progressively redacting PII from these logs to minimise the personal data they contain.
  • Guest data — retained for the life of the associated event. When an event is deleted, guest records tied to it are removed in the subsequent cleanup cycle.
  • Billing records — retained as required by applicable tax and accounting laws (typically 8 years under the Income Tax Act).

7. Security

Sessions are authenticated with HttpOnly cookies; data is encrypted in transit (TLS) and at rest. Administrative access to customer data is logged via an internal audit trail. No method of transmission or storage is 100% secure, but we follow industry-standard practices to protect your information.

8. Your rights under the DPDP Act

As a Data Principal under the DPDP Act, 2023, you have the right to:

  • Access — request confirmation of what personal data we hold about you.
  • Correction — request correction of inaccurate or incomplete data.
  • Erasure — request deletion of your personal data. We will delete your account and associated data, subject to legal retention obligations.
  • Nominate — nominate another person to exercise your rights in case of death or incapacity, as provided under the DPDP Act.
  • Withdraw consent — withdraw consent at any time. Withdrawal does not affect processing already carried out; going forward, we will stop processing data for the withdrawn purpose. This may limit your ability to use the Service.

To exercise any right, contact our Grievance Officer (see Section 11). We will respond within 30 days.

Guests: if you are a guest whose name and phone number were added by a planner, you may exercise these rights independently — you do not need the planner's involvement.

9. Cookies and local storage

We use essential cookies and browser local storage to keep you logged in and remember your preferences. We do not use advertising or third-party tracking cookies.

10. Data breach notification

In the event of a personal data breach that is likely to cause harm, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, within 72 hours of becoming aware of the breach.

11. Grievance Officer

For any questions, complaints, or requests related to your personal data:

Grievance Officer
Email: privacy@eplanr.com
Response time: within 30 days of receipt

If you are unsatisfied with our response, you may file a complaint with the Data Protection Board of India as established under the DPDP Act.

12. Changes to this policy

We will update this policy as the Service evolves and note the "Last updated" date above. Material changes will be announced in-app or by message to your registered mobile number. Continued use of eplanr after a change constitutes acceptance of the updated policy.