This page describes third party services that Plan✕ uses in order to provide a software service. It does not include external data integrations with Plan✕, such as GIS data integrations, Ordnance Survey, planning.data.gov.uk etc) or back office systems (BOPS, Uniform etc).

Supplier What do we use it for? Certifications Location of servers Does it include any personal data? How long do they retain data for? Note
Amazon Web Services Hosting https://aws.amazon.com/compliance/programs/ UK Yes As per agreed data retention period with PlanX customers
Cloudflare Load balancing and some security layers https://www.cloudflare.com/en-gb/trust-hub/compliance-resources/ US IP address, briefly Temporary (usually fractions of a second)
Scanii Scanning user uploaded files https://scanii.com/security UK If included in uploaded files Temporary
(usually fractions of a second)
Airbrake Error monitoring service https://www.airbrake.io/ US Rarely, if part of an error report 7 days Error logging is used for debugging purposes. Personal data would only ever be included in reports of unhandled errors that include that data (most error reports do not include any). Access is controlled via SSO and limited to developers working on fixing issues. Logs are reset and deleted on each production deploy (generally every few days).
GOV.UK Notify Email sending service https://www.notifications.service.gov.uk/features/security UK Yes 7 days PlanX does not itself use these services to run but it does integrate so users may receive notifications via Notify
GOV.UK Pay Payment service https://www.payments.service.gov.uk/security/ UK Yes From GovUK Pay - “We won’t retain that data any longer than we need it, and definitely no longer than 7 years, and only share it if it’s necessary to run GOV.UK Pay or if required by law.” PlanX does not itself use these services to run but it does integrate with these services and PlanX users may be redirected to GOV.UK Pay
Stripe (substituting Gov.UK Pay as the only payment provider integrated with PlanX from January 2027) Payment service https://docs.stripe.com/security US (with UK/EU data transferred under the UK Extension to the EU-US DPF and the UK International Data Transfer Addendum) Yes For as long as Stripe provides the service to the council, then for as long as legally required afterwards (anti-money laundering, fraud prevention, tax, and card scheme record-keeping obligations) PlanX does not itself use Stripe to run, but it integrates with Stripe Connect: OSL is the platform account and each council has its own connected Stripe account. Applicants pay through Stripe, and their name, email, billing address, card details and device/IP data are processed by Stripe. Card details are handled by Stripe and never stored by PlanX.
Resend Email integration service https://resend.com/security EU servers used for sending email.

US servers used to retain data (with UK/EU data transferred under the UK Extension to the EU-US DPF and the UK International Data Transfer Addendum) | Yes | Email and log data is retained for 30 days | Resend is used to trigger internal emails within PlanX, such as onboarding new Editors and triggering submission emails to LPAs via the “send to email” method. These emails include some personal data to identify the application (name, address, reference) but not the entire submission payload. |