Privacy Policy
Last updated: 16 July 2026
Planacta ("Planacta", "we", "us") provides media planning, actualization and billing software for advertising agencies. This policy explains what we collect, why, how we protect it, and what you can ask us to do with it. We have tried to write it plainly rather than defensively.
Planacta is operated from Toronto, Ontario, Canada. If you have any question about this policy, email hello@planacta.com.
1. Two different roles
It matters which of these applies to you:
- When you visit our website. We are the controller of the small amount of data described in section 3.
- When your agency uses Planacta. Your agency decides what data goes into the platform and why. Your agency is the controller; we are a processor acting on its instructions. Our commitments in that role are set out in our Data Processing Agreement.
2. What agencies put into Planacta
To provide the service we store the data your agency enters or connects, which includes:
- Account data: user names, email addresses, job titles, roles, and a password stored as a salted scrypt hash. We never store your password itself.
- Your business data: your agency profile, your clients' names and billing details, media plans, budgets, imported advertising spend, fees, taxes, approvals and invoices.
- Advertising platform connections: if you connect Google Ads, Meta or Amazon, we store OAuth tokens (never platform passwords) encrypted at rest, and read reporting data such as campaign names and cost.
- Records: session records, an append-only audit log of changes, and a log of emails the platform sent on your behalf.
We do not sell data, we do not share it with advertisers, and we do not use your business data to train machine learning models.
3. What the website collects
- Contact form: the name, email, company and message you send us, so we can reply. It reaches us by email.
- Google Ads tracking: our public marketing pages load Google's tag (gtag.js) so we can measure which ads lead to demo requests. This uses cookies and shares data with Google. It runs on our public pages only, never inside the logged-in application.
- Essential cookies: the application sets one cookie to keep you signed in. It is not used for tracking.
You can block or delete cookies in your browser. Blocking the Google tag has no effect on the application.
4. Keeping agencies separate
Every agency on Planacta has its own isolated workspace. One agency's users cannot see another agency's clients, plans, spend, invoices, settings or platform connections. That separation is enforced centrally in the code and covered by automated tests that run before we ship.
We do not operate a cross-customer administrator view. Signing in as Planacta staff shows our own workspace only, not yours.
Being straight with you: we host the platform, so our personnel are technically capable of reaching the underlying database. We access customer content only where it is necessary to run, secure or support the service, or where you ask us to. We treat everything in your workspace as confidential.
5. How we protect it
- Encrypted in transit (HTTPS/TLS) across the whole service.
- Passwords hashed with scrypt; advertising platform tokens encrypted with AES-256-GCM at rest.
- Role-based access control inside each workspace, so staff only see what their role allows.
- An append-only audit log recording who changed what, and when.
- Access to production systems limited to personnel who need it.
No service can promise perfect security, and we will not pretend otherwise. If a breach affects your data we will tell you promptly and tell you what we know.
6. Who else processes data
We keep this list short on purpose. Our sub-processors are:
- Railway: application hosting and database storage.
- Resend: sending transactional email such as client approval requests and invoices.
- ImprovMX: forwarding email sent to our @planacta.com addresses.
- Google: advertising measurement on our public marketing pages only.
Where you connect Google Ads, Meta or Amazon, those are your own accounts and their own terms apply to them.
7. Where data is stored
Planacta runs on Railway's cloud infrastructure and data may be stored and processed outside your country, including in the United States. Where required, we rely on appropriate safeguards for those transfers. If your agency has a specific data residency requirement, contact us before you start.
8. How long we keep it
- Workspace data is kept while your account is active. On termination we delete or return it in line with our DPA.
- Audit logs are retained per your workspace's retention setting, because billing records need to be defensible.
- Contact enquiries are kept while we are in touch and for a reasonable period after.
9. Your rights
Depending on where you are, you may have the right to access, correct, delete, export or restrict the use of your personal data, and to object to processing or complain to a regulator. Email hello@planacta.com and we will respond within the time the law allows.
If your data is in a workspace run by an agency, that agency controls it. We will point you to them and support them in answering you.
10. Children
Planacta is a business tool and is not intended for anyone under 16.
11. Changes
If we change this policy materially we will update the date above and, for meaningful changes affecting agencies, tell you by email.
Contact
Planacta, Toronto, Ontario, Canada. hello@planacta.com
Agencies: our processor commitments, security measures and sub-processor list are set out in the Data Processing Agreement.