Privacy
Last updated September 21, 2026
The short version
We keep an email address so you can sign in, the files you upload so we can hand them to whoever scans your code, a record that you agreed to our Terms and Conditions, and statistics about how often each collection is opened and downloaded, which describe the collection and not the person. We do not sell anything about you, we do not advertise, we do not profile you, and there is no advertising or analytics third party anywhere on PlanStake. One third-party request exists: a human-verification check on the sign-in, invitation and abuse-report screens, described under Cookies and third-party requests.
What we collect
Your account
An email address and a name. Sign-in is a link we email you, so there is no password on your account to store.
Signing in also creates a session record, which holds the IP address the sign-in came from and the browser's user-agent string alongside the session's own token and expiry date. That is standard sign-in bookkeeping: it keeps you signed in, and it is what we would go on if you ever told us to cut off a device. The record is kept with the session and removed after the session ends or expires, within 30 days. The activity log described below keeps a network address for longer. All of this is about your account only; nothing like it is kept for the people who scan your codes.
When you agree to our Terms and Conditions we record which version you agreed to, when, the account you were working in, the network address (IP) the request came from and the browser you used. This is the record we would need if a payment or the agreement is ever questioned, so it is not deleted when your account is. We may also keep a copy of that record, and of the exact text you agreed to, in separate storage that is not reachable from the website.
We also keep a log of actions taken in your account, such as signing in, creating a collection, uploading or deleting a file, sending an invitation and opening checkout or the billing page. Each entry records when it happened, the network address (IP) and the browser used. It never records file names, collection names, notes or anyone's email address. It is the record we would need if a payment is ever questioned, so it is kept for 24 months, including after an account is closed. Nothing is logged for someone who signs in but does not agree to the Terms and Conditions.
What you upload
The files you add to a collection, and the details you give the collection: its name, description, client label, status, and when it was created and last changed. File names, sizes and types are stored with them so the download page can list them.
If we disable a collection page, for example after a report, we keep a note of why, who on our side did it and when. That note stays even if the collection is later deleted.
If you ask us to stop invitation emails
Every invitation email has a link that stops further invitations to that address. If you use it, we keep a one-way fingerprint of the address and the date, so we can honor the request. We do not store the address itself for this, and the record does not say who invited you. You do not need an account to use the link.
If you report a collection
Anyone can report a collection or file, with or without an account. We keep what the form says: the reason you chose, the address you reported, anything you wrote in the details, your email address if you chose to give one, and the time. We also keep a keyed hash of the network address the report came from, so a flood of reports can be told apart from real ones. The network address itself is not stored, and the hash is cleared when the report is marked handled or after 90 days, whichever comes first. The report is emailed to our abuse mailbox and shown to the people on our side who handle reports. We use your email address only to ask you about the report.
Cookies and third-party requests
We set three cookies, and every one of them is strictly necessary:
- a session cookie, which keeps you signed in;
- a collection unlock cookie (
pk_<id>, or__Host-pk_<id>), which the person who types a collection's password gets so that device does not have to type it again for 24 hours; - an active account cookie (
ps_account, or__Host-ps_account), which remembers which of your accounts you were last working in. It holds an account identifier and nothing else, and lasts a year.
There are no advertising cookies, no third-party cookies and no analytics scripts.
Our pages make one third-party request, and only on the screens that ask us to email you a sign-in link and on the form for reporting a collection: a human-verification check called Turnstile, which loads from Cloudflare and exists to stop scripts making us send mail to strangers or flooding us with reports. It is run by Cloudflare, who host PlanStake anyway, so no new company is involved. On the sign-in screen and the report form it loads with the form. On an invitation it loads only if you press the button to be emailed a link, so simply reading an invitation makes no third-party request at all. Neither does opening a collection page, downloading a file or using the app — no hosted fonts, no embedded widgets, nothing.
Scans and downloads
Each collection carries a running count of how many times its page has been opened. When someone opens a collection page or downloads a file we also record the collection, the file for a download, the kind of event (a scanned code, a plain link or a download), the country as reported by our network provider, a coarse device type (phone, tablet, computer, automated or unknown), the host name of the website that referred them, and the size of the download. Collection owners see totals per day for their collections: how many scans, visits and downloads, how much was downloaded, and how much of it was automated. They do not see individual visits.
These statistics describe a collection, not a person. We do not record the visitor's IP address, their full browser details or the full address of the page that referred them in these statistics. The request itself also appears in short-lived server logs, which are not attached to a person. We do not store the IP addresses of people who scan your codes in our application database, and we do not fingerprint them.
Collection passwords
A password you put on a collection is stored only as a salted hash. We cannot read it or recover it, and it is never sent anywhere.
Who else handles it
Cloudflare is our infrastructure provider. The application, the database and the file storage all run on Cloudflare (Workers, D1 and R2), and the transactional email we send — sign-in links and invitations — goes out through Cloudflare as well. The human-verification check on the sign-in, invitation and abuse-report screens is Cloudflare's too, so the one request our pages make to another domain still goes to the company already hosting them. Your files sit in private storage and are served through the application, never from a public bucket.
Stripe will handle payments when billing opens. Card numbers go to Stripe directly; we never see them and never store them.
What we do not do
We do not sell or rent personal information. We do not run advertising. We do not build profiles of you or of the people who scan your codes. Apart from the human-verification check described above, we load nothing from a third party into our pages at runtime.
How long we keep things
Collections and files stay until you delete them or close your account. After that they are removed within 30 days. If we disabled a collection after a report, we keep it, together with the note of what we did and why, even if you delete it. Account records we have to keep for tax or accounting reasons are kept for as long as the law requires and nothing longer.
The record that you agreed to our Terms and Conditions is kept while you have an account and for six years after the account is closed. The log of actions in your account is kept for 24 months. A request to stop invitation emails is kept until you ask us to remove it. Abuse reports, including a reporter's email address when one was given, are kept as a record of what was reported and what we did about it; the hash of the reporter's network address is cleared as described above. The detailed scan and download statistics are kept for about three months. The daily totals made from them hold no information about a visitor. They are kept while the collection exists and are deleted when the collection is permanently deleted.
Files and information shared through PlanStake
PlanStake is a hosting tool. The people who upload files and hand out links are solely responsible for what they upload and who they share it with.
We do not review, verify or endorse anything uploaded to a collection. Plans, drawings, specifications, prices and every other document come from the account holder, not from us, and we make no representation that any of it is accurate, current, complete or fit for any purpose.
Anyone who downloads a file or relies on it does so at their own risk. To the fullest extent the law allows, we accept no liability for any information or files shared through the service, including any loss or damage arising from relying on them, downloading them or opening them.
We may remove content or disable a collection that breaks the acceptable-use rules, and we will tell the account holder when we do.
Getting a copy, or getting it deleted
Email privacy@planstake.com from the address on the account and ask for a copy of what we hold or for it to be deleted. We answer within 30 days. Deleting an account deletes its collections and files, which means printed codes pointing at them stop resolving. The record that you agreed to our Terms and Conditions is not deleted with the account; it is kept for the time given above. To undo a request to stop invitation emails, write to the same address from the mailbox in question.
Children
PlanStake is a tool for trades and businesses. It is not directed at anyone under 16 and we do not knowingly collect information from them. If you believe a child has an account, write to privacy@planstake.com and we will remove it.
Changes to this policy
If we change it, we change the date at the top, and we email account holders before any change that affects what we collect or who handles it.
Contact
Privacy questions: privacy@planstake.com. Abuse reports: abuse@planstake.com. Anything else: support@planstake.com.