OnePlanner Privacy Policy
This Privacy Policy explains how ONEPLANNER TECHNOLOGIES (Registration No. 202503272767 (NS0314486-M)) ("OnePlanner", "we", "us") collects, uses, discloses, and protects personal data in connection with the OnePlanner platform, in accordance with Malaysia's Personal Data Protection Act 2010 ("PDPA") and its amendments.
OnePlanner is a business-to-business CRM used by licensed financial planning firms ("Firms") and their planners ("Planners") to manage the financial profiles of the Firm's clients ("Clients"). This policy reflects two different roles we play, because they carry different obligations under the PDPA:
- Where we hold Planner and Firm account data (names, work email, phone, role, login activity), we act as the data controller ("data user") — we decide why and how that data is processed.
- Where a Planner enters or uploads a Client's financial data (income, debt, goals, insurance, investments, retirement plans, tax information, notes, uploaded documents), we act as a data processor on behalf of the Planner's Firm, which is itself the data user in relation to its Clients. Clients do not create accounts with us or interact with us directly under the current B2B product — their data reaches our systems solely because their Planner, acting for the Firm, entered it. Any obligations the Firm or Planner owes their Clients (advisory duties, their own PDPA notices, professional confidentiality rules under applicable financial-services regulation) are the Firm's and Planner's responsibility, not ours, though we support them with the security and access controls described below.
If you are a Client and believe your Planner or Firm has provided data about you to OnePlanner, please direct data subject requests to your Planner or Firm in the first instance — they control that data. We will support the Firm in fulfilling valid requests.
Last Updated: July 23, 2026
1. What We Collect
1.1 From the public website (lead capture)
The "Join Waitlist" form on the OnePlanner marketing site collects: name, email, phone. Submissions are stored in a Google Sheet accessed via a Google service account, timestamped, and tagged with the source of submission. Submitting this form also triggers an internal analytics event recording that a demo was requested.
1.2 From Firms and Planners using the platform
- Account data: name, work email, phone, role (Owner/Planner), authentication credentials (via Supabase Auth, including Google OAuth if used).
- Usage data: pages viewed, actions taken, session activity, device/browser information, IP address, collected via PostHog and Google Analytics.
1.3 Client financial data entered by Planners (processed on the Firm's behalf)
This can include: contact details, income and expenses, debts, financial goals, insurance policies and uploaded policy documents, investment holdings, retirement plans and scenarios, tax submissions, risk profile answers, notes, appointments, and tasks. This is the core purpose of the platform and is the most sensitive category of data we process.
2. How We Use Personal Data
| Purpose | Data used | Basis |
|---|---|---|
| Provide the CRM platform to Firms and Planners | Account data, Client financial data | Performance of contract with the Firm |
| Generate AI-assisted insights and draft reports | Client financial data submitted to AI features | Performance of contract with the Firm; Firm/Planner instruction |
| Respond to waitlist/demo requests | Name, email, phone | Consent (form submission) |
| Product analytics and improvement | Usage data | Legitimate interest in operating and improving the platform |
| Security, fraud prevention, and account protection | Account data, usage data, IP address | Legitimate interest / legal obligation |
| Billing | Firm billing contact, payment details | Performance of contract |
We do not sell personal data, and we do not use Client financial data to train third-party AI models beyond what is necessary to generate the specific output the Planner requested, subject to the terms of our AI subprocessors below.
3. AI Features
Certain features (fact-find analysis, retirement/goal scenario generation, report drafting) send relevant Client financial data to OpenAI and/or Google (Gemini) to generate output. These providers act as our subprocessors under their own data processing terms; we do not permit them to use submitted data to train their general-purpose models except where their standard enterprise/API terms already exclude such training — this should be reconfirmed against each vendor's current terms before this policy is treated as final, since AI vendor training defaults can change. Exa may be used for supporting search functionality within AI features.
4. Disclosure of Personal Data
We disclose personal data only to:
- Subprocessors listed on our Subprocessors page, under contractual confidentiality and security obligations.
- Other Planners or Owners within the same Firm, according to the Firm's internal role-based access configuration — this is expected and necessary for the Firm to operate the platform, and is the Firm's responsibility to configure appropriately.
- Law enforcement or regulators, where required by Malaysian law or a valid legal process.
- A successor entity, in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections.
We do not disclose Client financial data to any party outside the Firm's own organization except as listed above.
5. International Data Transfers
Some subprocessors (OpenAI, Google, GA4) process data on servers outside Malaysia, including in the United States. Where this occurs, we rely on the transfer mechanisms available under PDPA Section 129; the specific basis relied upon for each subprocessor should be confirmed with qualified counsel before this policy is treated as final.
6. Data Retention
- Client financial data is retained for as long as the Firm's subscription is active, plus 90 days after termination to allow for data export, unless the Firm requests earlier deletion or a longer period is required by applicable financial-services record-keeping regulation.
- Waitlist/demo request data is retained for 12 months from submission, or until the lead is converted to a Firm account or disqualified, whichever happens first.
- Account and usage data is retained for the duration of the account plus 12 months for security and audit purposes.
7. Security
See our Security Policy for details on how we protect personal data, including access controls and our breach-notification process.
8. Your Rights under the PDPA
Data subjects (Planners and Owners with direct accounts) have the right, subject to the PDPA, to:
- Access personal data we hold about them.
- Request correction of inaccurate data.
- Withdraw consent for processing based on consent (e.g. marketing communications), where applicable.
- Request information about how their data is used and to whom it may be disclosed.
To exercise these rights, contact support@oneplannerapp.com. We may need to verify your identity before acting on a request. Clients whose data is entered by a Planner should direct such requests to their Firm/Planner, who will coordinate with us as needed.
9. Cookies
In the OnePlanner app itself, we use:
| Cookie / tool | Purpose | Type |
|---|---|---|
| Supabase Auth session cookie | Keeps you signed in | Strictly necessary |
| sidebar:state | Remembers whether your sidebar is expanded or collapsed | Strictly necessary / functional (no tracking) |
| PostHog | Product analytics — autocaptures page views and in-app actions, and links activity to your account (name/email) once you're signed in | Analytics (non-essential) |
The app does not currently present a cookie consent banner. Because PostHog here only activates for signed-in Firm/Planner users acting under our Terms of Service, we treat this as covered by the Firm's agreement to those Terms rather than a separate consent flow — this is a judgment call, not a settled point, and should be confirmed with counsel before this policy is treated as final.
On the OnePlanner marketing/landing site (a separate codebase from the app), Google Analytics (GA4) is also used for web analytics. That site does not currently present a cookie consent banner either — this is a known gap for that public-facing site that we intend to resolve.
10. Children
OnePlanner is not directed at individuals under 18. We do not knowingly process personal data of minors except where a Client's dependents (e.g. children) are recorded by a Planner as part of that Client's financial profile — in which case that data is processed strictly on the Firm's instruction and is subject to the same protections as other Client data.
11. Changes to This Policy
We will update the "Last updated" date above and, for material changes, notify Firms by email at least 30 days before the change takes effect.
12. Contact
ONEPLANNER TECHNOLOGIES (Registration No. 202503272767 (NS0314486-M))
P.O. Box 10251, GPO Kuala Lumpur, 50708 WPKL
Questions about this policy: support@oneplannerapp.com