Privacy Policy
This privacy policy explains how we handle your data when you use our websites. The responsible party for data processing is Sandro Maier (contact details in the Imprint).
Scope of this Policy
This policy applies to the domain planfold.io and all its subdomains, including but not limited to:
- www.planfold.io (Main website)
- shortener.planfold.io (URL shortener)
Hosting and Content Delivery Network (CDN)
Our websites are hosted via Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare acts as a reverse proxy and CDN. When you access our website, your request is routed through Cloudflare's servers. This is done to increase the security and performance of our website.
Cloudflare collects log data about requests, which may include your IP address, browser type, operating system, and the date and time of access. This data is used for security analysis and to protect our services. For more details, see Cloudflare's Privacy Policy.
Cloudflare Web Analytics
We use Cloudflare Web Analytics to gather non-invasive, privacy-first analytics about our website traffic. This service does not use any client-side state (like cookies or localStorage) and does not 'fingerprint' individuals. It provides us with aggregate data about traffic patterns without tracking individual users.
Cloudflare Turnstile
On some subdomains, we may use Cloudflare Turnstile to protect our services from automated abuse (bots). Turnstile is a CAPTcha alternative that verifies that traffic is from humans without running a visual puzzle. It may collect minimal session data to perform its checks, as detailed in Cloudflare's privacy documentation.
Consultation and Contact Form Data Processing
When you submit the consultation form on www.planfold.io, we collect your name, email address, optional phone number, UTM attribution metadata (source, medium, campaign, term, content), referrer URL, and landing page URL. When you submit the contact form, we collect your name, email address, optional phone number, selected service, message content, and the same UTM attribution metadata. Both forms send this data to our webhook endpoint to respond to your inquiry and attribute its origin.
Your contact data is used only to respond to your inquiry. We do not share this data with third parties except as necessary for webhook routing and email delivery services.
LinkedIn Integration
Our website includes links to our LinkedIn profile and may display LinkedIn sharing buttons. When you click on these links, you will be redirected to LinkedIn's platform. Please note that LinkedIn operates its own privacy policy and data processing practices. We do not receive any data from LinkedIn about your interaction with these links.
Roadmap Generator Data Processing
The roadmap generator on www.planfold.io helps you explore and plan your automation journey. Using it involves the following data processing:
Wizard Progress: When you use the roadmap wizard, your answers to each step, generated roadmap data, and any clarification responses are transmitted to our n8n workflow engine (n8n.h42.at) to produce personalized recommendations.
Lead Capture: If you submit your name and email to save or discuss your roadmap, this data is transmitted to our n8n workflow engine along with your roadmap content and session token.
Session Verification: If you verify your email during the roadmap process, a planfold_verified_session cookie (httpOnly, 30-day expiry) stores your name, email, and session token so you remain logged in across visits.
History and Persistence: You may load, review, or delete previously generated roadmaps. Loading a roadmap sends your roadmap ID and session token to our n8n engine. You can request deletion of your roadmap history at any time via our contact form.
- planfold_roadmap_state — stores your current wizard answers in browser LocalStorage to protect against accidental page closures. Cleared when you complete or abandon a session.
- planfold_roadmap_id — stores the ID of your most recent roadmap in browser LocalStorage so you can resume or load it on return visits.
- planfold_roadmap_user — stores your name and email in browser SessionStorage after you provide them in the lead capture modal, so you do not need to re-enter them during the same browser tab session.
- planfold_verified_session (cookie, httpOnly) — stores your verified name, email, session token, and verification timestamp after you confirm your email. Used to restore your verified session across visits.
- planfold_chat_gate (cookie, httpOnly) — set when you first interact with chat support; contains a unique identifier for conversation routing.
- planfold_utm_data — stores UTM attribution parameters (source, medium, campaign, term, content) in browser LocalStorage for 30 days to attribute enquiries back to their origin.
- planfold_chat_user — stores your chat name, email, and chat session identifier in browser SessionStorage when you provide them, so you do not need to re-enter them during the same browser tab session.
Chat Support Data Processing
Our website features a chat support widget to assist with inquiries about our services. When you interact with chat, we process the following data:
Messages and Context: Your message text, name, and email address are transmitted to our /api/chat/message endpoint and forwarded to our n8n workflow engine (n8n.h42.at) for processing and routing. If you are logged into a verified roadmap session, your name, email, session token, and any active roadmap or milestone context are included automatically. A hashID, verification state, and request heuristics including IP-derived data may also be included for security and routing purposes.
Session Cookie: A cookie named planfold_chat_gate (httpOnly, 30-day expiry) is set when you first interact with chat. It contains a unique identifier that helps us route your conversation across visits.
Data Recipients: Chat messages are processed by our n8n workflow engine (n8n.h42.at). The n8n instance runs on infrastructure we operate.
Data Retention: Chat conversations are processed through our self-hosted n8n workflow engine. Chat logs, contact details, and related routing data may be stored in n8n or connected Planfold-controlled systems according to the workflow configuration and the retention periods described in this policy.
SessionStorage: If you provide your name and email in the chat widget, these are stored in your browser's SessionStorage under the key planfold_chat_user for the current browser tab session. This data is stored only on your device and is not transmitted until you actively submit a message.
Your Rights: You can clear the planfold_chat_user SessionStorage entry and the planfold_chat_gate cookie from your browser at any time. Doing so will remove your locally stored chat identity and require you to re-enter your details on your next visit.
Optional Telemetry and Logging
When the environment variables NEXT_PUBLIC_OO_ENABLED, NEXT_PUBLIC_OO_CLIENT_TOKEN, and NEXT_PUBLIC_OO_ORG are configured, our website activates OpenObserve browser Real User Monitoring (RUM) and server-side log collection to help us understand performance, detect errors, and improve service quality.
When enabled, page views, session events, browser performance metrics, and console errors are sent to our OpenObserve instance via proxy routes (/rum/v1/* and /logs/v1/*). Logged data may include your IP address, browser type, operating system, page URL, and timing information. This data is used for operational observability and security analysis only.
You can opt out of OpenObserve RUM by disabling browser JavaScript execution or by blocking requests to our /rum/v1/* and /logs/v1/* routes at the network level. OpenObserve telemetry is only active when NEXT_PUBLIC_OO_ENABLED is set to true and the required token and organization variables are present.
Google Ads Conversion Tracking
We use Google Ads conversion tracking to measure the effectiveness of our advertising campaigns. When you click on one of our ads and subsequently visit our website, Google may place a conversion tracking cookie on your device.
This cookie allows Google to recognize that you have clicked on an ad and tracks whether you complete certain actions on our website (such as submitting a contact form). The data collected is used to analyze ad performance and optimize our marketing efforts. We do not receive any personally identifiable information from Google through this tracking.
You can opt out of personalized advertising by visiting Google Ads Settings.
Google Analytics (GA4)
We use Google Analytics (GA4) to analyze website usage. This service is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies to collect information about your use of the website (including your IP address), which is typically transmitted to and stored on a Google server in the USA.
We have activated IP anonymization (IP masking) on our website. This means that your IP address is shortened by Google within member states of the European Union or in other signatory states to the Agreement on the European Economic Area before being transmitted to the USA.
The data collected through Google Analytics helps us understand how visitors interact with our site, allowing us to improve our services and marketing. You can prevent the storage of cookies by adjusting your browser settings or by installing the browser add-on to deactivate Google Analytics: https://tools.google.com/dlpage/gaoptout.
Data Stored on Your Device (Cookies, LocalStorage, SessionStorage)
Some data is stored locally on your device using your browser's storage capabilities. This browser storage is separate from data that may be processed or stored on Planfold-controlled systems when you submit forms, use chat, verify a roadmap session, or contact us:
- LocalStorage (planfold_utm_data): Stores UTM attribution parameters (source, medium, campaign, term, content) and a timestamp in your browser for 30 days to attribute enquiries back to their marketing origin.
- SessionStorage (planfold_chat_user): Stores your chat name, email address, and chat session identifier when you provide them in the chat widget. This allows you to use chat without re-entering your information during the same browser tab session.
- LocalStorage (planfold_roadmap_state): Stores your current roadmap wizard answers to protect against accidental page closures. Cleared when you complete or abandon a session.
- LocalStorage (planfold_roadmap_id): Stores the ID of your most recent roadmap so you can load it again on return visits.
- SessionStorage (planfold_roadmap_user): Stores your roadmap name and email after you provide them in the lead capture modal for the current browser tab session.
- SessionStorage: May be used for temporary session-related information that is deleted when you close your browser tab.
- Cookies (planfold_verified_session, planfold_chat_gate): These httpOnly cookies are set when you verify your roadmap session or first interact with chat. They store a unique session token and have a 30-day expiry.
- Cookies (Cloudflare): Cloudflare may place strictly necessary cookies (e.g.,
__cflb,__cf_bm) for security and network functionality. We do not place our own tracking or marketing cookies.
Optional Google Drive Integration
The hub.planfold.io service offers an optional feature to back up and sync your settings with your own Google Drive account. This feature is opt-in and requires you to explicitly grant access. We only request permission to access files created by our application. We do not have access to any other files in your Google Drive. All data handling within your Google Drive is subject to Google's Privacy Policy.
Data Sharing
We do not sell your personal data. We only share or transmit personal data where necessary to provide the website and related services, such as hosting, security, advertising measurement, webhook routing, and email delivery. Our n8n automation platform is self-hosted on infrastructure we operate, so n8n processing is handled under our control rather than sent to a third-party n8n provider. Optional OpenObserve telemetry data is processed under our control and not shared externally.
PII Storage and Retention (n8n & EU Hosting)
Personal Identifiable Information (PII) provided through our forms, chat, roadmap generator, webhook flows, or email workflows may be processed and stored on systems we operate or control, including our self-hosted n8n automation engine. Our n8n instance is hosted on infrastructure located within the European Union (EU), supporting processing under EU data protection requirements (GDPR).
Data retention is limited to what is necessary for the purposes of processing. Contact information and message history are typically retained for up to 24 months to support ongoing business relationships and follow-up inquiries, unless you request earlier deletion.
Your Rights (GDPR & CCPA)
Depending on the data and service you use, you may have rights regarding personal data processed by us, by our service providers, and data stored locally on your device. These rights can include:
- Access and Delete: Access, modify, or delete any data stored in your browser's LocalStorage or SessionStorage for our sites.
- Information: Be informed about the data collected, which is the purpose of this policy.
- Lodge a Complaint: Lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.