← Peachy Plans

Peachy Plans Privacy Policy

Effective date: July 20, 2026 · Last updated: October 1, 2026 (v1.1)

Peachy Plans is operated by BrandSpill Insights Inc. (“Peachy Plans,” “we,” “us,” or “our”).

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use the Peachy Plans website, mobile web application, and related services collectively referred to as the “Service.”

1. Scope

This Policy applies to personal information processed through:

  • The Peachy Plans public website;
  • Account creation and authentication;
  • Authenticated trip experiences;
  • Payments;
  • Email and in-app communications;
  • Customer support;
  • Peachy Journal;
  • Pulse and Peachy Insights;
  • AI-assisted Group Notes; and
  • Administrative and security systems.

It does not govern third-party websites, airlines, accommodations, map providers, booking platforms, or social networks linked through the Service.

2. Information we collect

A. Account information

We may collect:

  • Name and display name;
  • Email address;
  • Profile image;
  • Authentication provider;
  • Hashed password credentials;
  • Preferred language;
  • Timezone;
  • Account role;
  • Account creation and login information;
  • Terms acceptance records; and
  • Privacy acknowledgment records.

We do not store readable account passwords.

B. Trip information

We may collect information submitted by authorized trip members, including:

  • Trip names, destinations, and dates;
  • Itinerary items;
  • Flight and airport details;
  • Transportation and accommodation information;
  • Addresses and meeting points;
  • Reservation and confirmation information;
  • Maps and reference links;
  • Tasks and assignees;
  • Day Notes;
  • Trip Updates;
  • Approved Group Notes;
  • Trip roles and permissions;
  • Invitations; and
  • Access codes.

Trip information is visible to authorized members according to the Service’s permissions.

C. Contact and communication information

We may collect:

  • Email address;
  • Notification preferences;
  • Quiet hours;
  • Email marketing consent;
  • Consent wording version;
  • Consent timestamp and source;
  • Unsubscribe and opt-out records;
  • Delivery status;
  • Bounce information; and
  • Spam or complaint status.

D. Payment information

Payments are processed by Stripe.

We may receive:

  • Transaction identifier;
  • Payment status;
  • Purchased Trip Pass;
  • Price and currency;
  • Billing country or region;
  • Refund information;
  • Dispute information; and
  • Limited billing details.

We do not directly store complete card numbers or card security codes.

E. Tasks and Day Notes

Tasks and Day Notes are shared trip information.

We may collect:

  • Task or note content;
  • Creator or author;
  • Assignee;
  • Trip date and time;
  • Completion status;
  • Completion actor;
  • Creation and modification timestamps; and
  • Associated trip.

This information may be visible to authorized trip members.

F. Mood check-ins

Pulse may collect:

  • Selected mood;
  • Optional structured reasons;
  • Trip and check-in period;
  • Submission time; and
  • Modification time.

Individual responses are private and are not intended to be shown to trip members or Trip Leads.

Peachy Plans may use privacy-protected patterns to generate general Peachy Insights. Recipient-facing insights should not disclose:

  • A user’s identity;
  • The precise mood selected;
  • The reason selected;
  • Exact negative-response counts; or
  • Information that reasonably identifies a respondent.

G. Peachy Journal

Journal entries may contain personal feelings, frustrations, worries, thoughts, and suggestions.

Journal entries:

  • Are private to the author;
  • Are not automatically shared;
  • Are not automatically converted into Group Notes;
  • Are not shown to regular trip members;
  • Are not included in recipient-facing notifications; and
  • May be deleted by the author subject to technical and legal retention.

AI may privately suggest that a user create a Group Note. The user must approve the exact Group Note and publication time.

Only the approved note is shared. The original Journal entry remains private.

We may retain restricted ownership and security metadata to prevent abuse and allow author-controlled changes.

H. AI interactions

When you intentionally use an AI feature, we may process:

  • Text intentionally submitted to that feature;
  • Limited context needed to perform the request;
  • AI-generated content;
  • User edits;
  • Approval decisions;
  • Moderation results; and
  • Scheduling instructions.

We seek to limit AI providers’ access to the minimum information necessary.

We will not use private Journal content or raw mood information to train general-purpose AI models unless we clearly disclose the practice and obtain any required consent.

I. Technical and usage information

We may automatically collect:

  • IP address;
  • Browser and device type;
  • Operating system;
  • App version;
  • Preferred language;
  • Approximate region;
  • Login and session activity;
  • Pages and features used;
  • Error and crash information;
  • Performance information;
  • Security events;
  • Cookie identifiers; and
  • Referral information.

J. Support information

When you contact support, we may collect:

  • Support messages;
  • Screenshots;
  • Attachments;
  • Account and trip identifiers;
  • Troubleshooting information; and
  • Resolution history.

Support tools should not ordinarily expose private Journal text, raw mood responses, passwords, authentication tokens, or Group Note author identities.

3. How we collect information

We collect information:

  • Directly from you;
  • From other authorized trip members;
  • From authentication providers;
  • From payment providers;
  • Automatically through technical systems;
  • From email providers;
  • From support interactions; and
  • From service providers acting on our behalf.

4. How we use information

We may use information to:

  • Create and authenticate accounts;
  • Operate trips;
  • Display content to authorized members;
  • Process Trip Pass purchases;
  • Manage invitations;
  • Provide tasks and Day Notes;
  • Deliver email and in-app communications;
  • Save private mood check-ins;
  • Generate Peachy Insights;
  • Operate Peachy Journal;
  • Provide AI-assisted Group Notes;
  • Moderate content;
  • Respond to support requests;
  • Detect fraud and misuse;
  • Protect the Service;
  • Maintain audit records;
  • Improve performance;
  • Enforce our Terms;
  • Comply with legal obligations; and
  • Establish or defend legal claims.

We will not use personal information for a materially different purpose without providing notice and obtaining consent where required.

5. Consent and grounds for processing

Depending on your jurisdiction, we process information based on:

  • Your consent;
  • Performance of our agreement with you;
  • Our legitimate interest in operating and securing the Service;
  • Compliance with legal obligations; and
  • Protection of users and the public.

For Canadian users, we seek meaningful consent appropriate to the sensitivity of the information and the reasonable expectations of the individual.

We do not bundle optional marketing consent with required account creation.

You may withdraw consent where permitted. Withdrawal may prevent certain optional features from functioning.

6. How we disclose information

A. Other trip members

Authorized members may receive access to:

  • Shared itinerary information;
  • Member display information;
  • Tasks;
  • Day Notes;
  • Approved Group Notes; and
  • Other content intentionally shared with the trip.

They do not receive access to:

  • Private Journal entries;
  • Raw mood responses;
  • Private AI conversations;
  • Passwords;
  • Authentication tokens; or
  • Group Note author identity.

B. Service providers

We may disclose information to providers that perform services for us, including:

  • Hosting and databases: Lovable Cloud;
  • Authentication: Lovable Cloud authentication;
  • Payments: Stripe;
  • AI processing: Lovable AI Gateway;
  • Email delivery: our email provider;
  • Maps and location services: Google Maps;
  • Analytics: our analytics provider;
  • Error monitoring: our error monitoring provider; and
  • Support: our support tools.

Providers may process information only for authorized purposes and subject to contractual, privacy, and security obligations.

C. Legal and safety reasons

We may disclose information when reasonably necessary to:

  • Comply with law, court orders, or valid legal process;
  • Protect the safety of users or others;
  • Investigate fraud or abuse;
  • Respond to security incidents;
  • Enforce our Terms; or
  • Establish or defend legal claims.

D. Business transactions

Information may be transferred as part of a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable legal requirements and confidentiality protections.

E. At your direction

We may disclose information when you direct or authorize us to do so.

7. Email communications

Essential emails

We may send emails necessary to operate or secure the Service, including:

  • Verification emails;
  • Password resets;
  • Security notices;
  • Receipts;
  • Refund confirmations;
  • Support responses;
  • Account deletion notices; and
  • Material legal notices.

Essential emails are not marketing messages and may continue while the applicable account or transaction remains active.

Optional trip emails

You may choose to receive:

  • Invitations;
  • Itinerary summaries;
  • Plan changes;
  • Task reminders;
  • Group Note notifications;
  • Planning reminders; and
  • Other trip activity.

You can manage these preferences globally or by trip.

Marketing emails

We send marketing emails only where permitted and based on applicable consent or another valid legal basis.

Marketing consent is optional.

Marketing emails will include:

  • Sender identification;
  • A valid mailing address;
  • An unsubscribe link; and
  • A link to this Policy.

Unsubscribing from marketing does not stop essential account, security, payment, or legal emails.

We retain limited suppression information to ensure that unsubscribed addresses remain unsubscribed.

9. Sale, sharing, and targeted advertising

Peachy Plans does not sell personal information for money.

We do not sell personal information or share personal information for cross-context behavioural advertising.

If our practices change, we will update this Policy and provide applicable notices and opt-out controls.

10. Cookies and similar technologies

We may use necessary technologies for:

  • Authentication;
  • Session security;
  • Preferences;
  • Payments;
  • Fraud prevention;
  • Reliability; and
  • Load balancing.

We may also use optional analytics technologies where permitted.

Where legally required, optional technologies will not operate until consent is provided.

Users may be offered controls to accept optional technologies, reject optional technologies, or manage preferences.

11. Cross-border processing

Peachy Plans and its service providers may process information in Canada, the United States, or other jurisdictions.

Information processed outside your province, state, or country may be subject to the laws of that jurisdiction and lawful access by courts, law enforcement, or public authorities.

We assess providers and use appropriate contractual and security protections where required.

12. Retention

We retain information only as long as reasonably necessary to:

  • Provide the Service;
  • Maintain security;
  • Resolve disputes;
  • Meet financial and legal obligations;
  • Prevent fraud; and
  • Enforce agreements.

Retention periods vary based on the type and sensitivity of information.

We maintain or intend to maintain retention rules for:

  • Accounts;
  • Trips;
  • Invitations;
  • Itinerary items;
  • Tasks;
  • Day Notes;
  • Payment records;
  • Consent records;
  • Mood check-ins;
  • Journal entries;
  • Group Notes;
  • Support records;
  • Security logs; and
  • Backups.

Users may delete individual Journal entries.

When an account is deleted:

  • Active sessions are revoked;
  • Trip access is removed;
  • Private content is deleted or de-identified where legally permitted;
  • Shared content may remain where necessary for the other trip members’ experience;
  • Financial, fraud, security, and legal records may be retained; and
  • Backup copies are deleted according to the applicable backup cycle.

13. Security

We use safeguards appropriate to the sensitivity of the information, which may include:

  • Encryption in transit;
  • Encryption at rest;
  • Hashed passwords;
  • Role-based access;
  • Trip-scoped authorization;
  • Restricted administrator access;
  • Audit logging;
  • Rate limiting;
  • Secure secret storage;
  • Backups;
  • Vendor review; and
  • Incident-response procedures.

No system is completely secure, and we cannot guarantee absolute security.

14. Privacy and security incidents

We maintain procedures to identify, investigate, contain, document, and remediate privacy and security incidents.

Where required, we will notify affected individuals and relevant regulators.

15. Your privacy rights

Depending on your jurisdiction and subject to legal exceptions, you may have the right to:

  • Know whether we hold information about you;
  • Access information;
  • Correct inaccurate information;
  • Delete information;
  • Withdraw consent;
  • Request information about uses and disclosures;
  • Receive a portable copy where applicable;
  • Object to or restrict certain processing;
  • Opt out of sale, sharing, or targeted advertising where applicable;
  • Limit certain uses of sensitive information where applicable;
  • Appeal a denied request where applicable; and
  • Exercise rights without discriminatory treatment.

Canadian residents

Canadian residents may have rights under applicable federal or provincial privacy law, including rights to access, correct, and challenge our handling of personal information.

Quebec residents

Quebec residents may have additional rights under applicable Quebec privacy law, including rights relating to:

  • Access;
  • Correction;
  • Withdrawal of consent;
  • De-indexation in applicable circumstances;
  • Information concerning certain automated decisions; and
  • Complaints to the Commission d’accès à l’information du Québec.

United States residents

Residents of certain US states may have additional rights under state privacy laws, including rights to access, correct, delete, obtain a copy, or opt out of certain processing.

To exercise a right, contact: team@peachyplans.co

We may verify your identity using only information reasonably necessary to process the request.

Authorized agents may submit requests where permitted, subject to verification of their authority.

16. California notice

Where California privacy law applies, the categories of information we may collect include:

  • Identifiers;
  • Customer-record information;
  • Commercial information;
  • Internet or network activity;
  • Geolocation at an approximate level;
  • User-generated content;
  • Inferences used to provide Peachy Insights; and
  • Potentially sensitive personal information contained in private Journal or mood features.

We collect and use these categories for the purposes described in this Policy.

We do not use sensitive personal information to infer characteristics for unrelated advertising purposes.

17. AI and automated processing

Peachy Plans uses AI to assist with writing, suggestions, moderation, and Peachy Insights.

AI does not make decisions that produce legal or similarly significant effects concerning employment, credit, housing, insurance, education, or healthcare.

AI-assisted Group Notes are not automatically published. The author must approve the exact message.

18. Children

Peachy Plans is intended only for people who are at least 18 years old.

We do not knowingly permit users under 18 to maintain accounts.

Peachy Plans is not directed to children under 13 and does not knowingly collect personal information from them.

If we learn that an ineligible minor created an account, we may suspend the account and delete the associated information, subject to legal obligations.

19. Third-party links and services

Trips may contain links to third-party maps, airlines, hotels, transportation providers, social platforms, restaurants, and booking services.

We do not control their privacy or security practices. Review their policies before providing information.

20. Changes to this Policy

We may update this Policy to reflect changes in our Service, vendors, legal obligations, or privacy practices.

For material changes, we will provide appropriate notice and obtain renewed consent where required.

21. Contact and complaints

Questions, privacy requests, or complaints may be sent to: team@peachyplans.co

Canadian residents may also contact the Office of the Privacy Commissioner of Canada or the applicable provincial regulator.

Quebec residents may contact the Commission d’accès à l’information du Québec.

US residents may contact their applicable state regulator or attorney general.