The Visit Planner

Privacy policy

The Visit Planner is about the people you care for. What you put in it — names, photos, a short note about how the visit went — is private, and we treat it that way. Below is exactly what we store, why, and what you can ask us to do with it.

Last updated: 2 September 2026

Who processes your data

The Visit Planner and Wie Gaat Er Op Bezoek are the same service, published by Luuk de Bruin, registered at Hochstraße 24, 52538 Selfkant, Germany. We are the data controller under the GDPR.

Questions about your data? Email hello@thevisitplanner.com. You will usually hear back within two working days.

What we store

Only what the planner needs to work:

  • The family name and the family password. The password is stored hashed (bcrypt); we cannot read it back.
  • The first name of every family member who signs in, and how many visits they have planned.
  • The name of your grandparent, and if you fill them in: the name and address of the care home, its visiting hours, and your own notes.
  • The planned visits: date, time and who is going.
  • Whatever you add to a visit or to the diary: a note, a photo, a comment or an emoji.
  • The email address of the family admin, for creating the account and for payments.
  • For families on Family Plus: the Stripe customer and subscription id, the subscription status and the date the period ends. We never see your card details.

Why we store it

For the planner itself — names, visits, notes and photos — the legal basis is performance of the contract: without that data there is nothing to plan and nothing to share with the rest of the family.

For the Family Plus data the basis is the contract and, for invoices, a statutory retention obligation.

For the anonymous counting the basis is our legitimate interest: we want to know whether the site works, and nothing about you is stored or traced back. For recognising your browser on a later visit the basis is your consent. You give it in the cookie notice, and you can withdraw it just as easily.

Special category data

The notes you write on a visit or in the diary may concern your grandparent’s health. That is special category data. We never ask for it, we do not read it, and we use it for nothing other than showing it to your family. Whether you fill it in is entirely up to you.

Cookies and analytics

We use PostHog to measure how many people use the site and the app and where they drop off, so we know what to improve. We set no cookie for it — not before your choice, and not after.

While you have chosen nothing, or if you click "Rather not", we count anonymously. Nothing is stored on your device: the random id a page view arrives under exists only while you are on that page, your IP address is left out, and no profile is created. What remains is a count, not a trail.

If you click "That's fine", PostHog keeps that random device and session id in your browser’s local storage, so we can recognise a repeat visit as a repeat visit. In the app we then also link it to your member id and your family — otherwise there is no way to see whether a family actually gets as far as planning a visit. On the website we attach no name or email address to it.

Your choice itself is remembered in your browser’s local storage under the key cookie_consent. That is not a cookie and never reaches us; without it we would have to interrupt you on every page.

To change your choice, clear this site’s data in your browser and the notice will appear again.

We set no advertising cookies and sell nothing on to advertisers.

Who processes data for us

We are a small service and use a handful of suppliers. There is a data processing agreement with each of them.

  • Supabase — database, sign-in and photo storage. Servers in the EU (Frankfurt).
  • Vercel — hosting for the site and the app.
  • Stripe — payments and invoices for Family Plus. Stripe is its own controller for payment data and sees your card details; we do not.
  • Resend — sending email, such as the confirmation mail and the sign-in link.
  • PostHog — analytics, EU cloud. Anonymous counting always; recognition only after your consent.

Where your data lives

The database, the photo storage and the analytics are inside the European Union. Stripe and Resend also process data outside the EU; that happens under the European Commission’s standard contractual clauses.

How long we keep it

For as long as your family uses the planner. If you delete the family in settings, the visits, members, grandparents, diary and photos are deleted straight away, and any running subscription is cancelled.

Invoices are kept longer, because the law requires it.

Analytics events are deleted after twelve months.

Your rights

You have the right to access your data (Art. 15 GDPR), to have it corrected (Art. 16) and to have it erased (Art. 17). You can also object to a processing, ask for it to be restricted, and receive your data in a readable file.

Most of it you can do yourself: visits and notes are editable in the app, and an admin can delete the whole family in one go. If that does not work, or you want an overview of everything we hold, email hello@thevisitplanner.com. We respond within one month at the latest.

If you disagree with how we handle your data, you can complain to the supervisory authority in the country where you live.

Security

Every connection runs over https. The family password is stored hashed. Access to a family’s data runs through that password, so only share it with people who should see the planner, and pick something that is not easy to guess.

Changes

If something important changes about how we handle data, we update this page and put the new date at the top. For a significant change we email the family admin.