Plantative Privacy Policy

Version 2.0 · Effective from 31 August 2026

This Privacy Policy (the ’Policy’) explains how Plantative collects, uses, discloses and otherwise processes personal data when you use the Plantative mobile application, the website at plantative.com and the related back-end services (together, the ’Services’). It is issued in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the ’GDPR’) and the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data.

This Policy forms part of, and is incorporated by reference into, our Terms of Service (together, the ’User Agreement’). Capitalised terms not defined here have the meaning given to them in the Terms of Service. In the event of a conflict between this Policy and the Terms of Service in respect of the processing of personal data, this Policy prevails.

1. Identity of the controller

The controller within the meaning of Article 4(7) GDPR is Sebastiaan Verplancke, a natural person carrying on business as a sole trader established in Belgium and trading under the name Plantative, with place of business at Patijntjestraat 87, 9000 Ghent, Belgium, registered with the Belgian Crossroads Bank for Enterprises under enterprise number 1034.776.796 and identified for VAT purposes under number BE 1034.776.796 (’Plantative’, ’we’, ’us’, ’our’).

All privacy enquiries and all requests to exercise the rights described in section 13 should be addressed to [email protected]. We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR.

Where you sign in using a third-party identity provider, or where you purchase a subscription through an app store, that provider acts as an independent controller for its own processing. This Policy does not govern, and we accept no responsibility for, processing carried out by those parties under their own privacy policies.

2. Scope

This Policy applies to personal data processed through the Services. It does not apply to (a) websites, applications or services operated by third parties that you access from or through the Services, (b) information you disclose directly to another user outside the Services, or (c) processing carried out by other users of content you have made available to them.

3. Categories of personal data we process

3.1 Data you provide to us

  • Account and identity data: email address and authentication credentials, first and last name, profile picture, profile description, interface language, and the fact, date and time of your acceptance of the User Agreement. Passwords are stored solely as salted cryptographic hashes by our authentication provider and are not accessible to us in plaintext.
  • Federated sign-in data: where you sign in with Google, Apple or Facebook, we receive a persistent user identifier and, depending on your settings with that provider and the permissions you grant, your email address, name and avatar. Where Apple Private Relay is used, we receive a relayed address rather than your actual email address.
  • Address and location data: the addresses you add (label, street, number, apartment, postal code, city, country) together with their geographic coordinates, and the visibility setting you select for each (hidden, city only, or full address).
  • User content: plant listings, photographs, descriptions and care notes, growth journal entries and measurements, wanted posts, favourites, trade and offer history, ratings and reviews, direct and community chat messages, and reports you submit about other users or content.
  • Care profile data: the plant-care experience and commitment levels you select, used to tailor care guidance.
  • Support and correspondence data: the content of your messages to us, any documentation you supply, your contact details and any related metadata.
  • Subscription data: where paid features are offered, the purchase is processed by Apple or Google under their own terms. We receive a subscription status and transaction identifier. We do not receive, process or store your payment card or bank details.

3.2 Data collected automatically

  • Device and connection data: IP address, device model and manufacturer, operating system and version, application version and build, device language and region, time zone, and connection status.
  • Diagnostic and stability data: crash reports, exception traces, non-fatal error logs, performance data and the device state at the time of an error, collected through our diagnostics and crash-reporting provider.
  • Integrity and anti-abuse data: device attestation tokens issued by the integrity services of the mobile operating-system platforms and validated through our attestation provider, and rate-limiting and quota counters keyed to your account.
  • Behavioural analytics and session reconstruction: we use a third-party behavioural-analytics provider, which records a reconstruction of your use of the app, including the screens you view, your navigation path, taps, scrolls and gestures, session duration and device characteristics, and which produces heatmaps and aggregated behavioural metrics. That provider operates with default masking enabled, under which text content, including text you enter, is masked before transmission. We do not use this data to identify you personally, but it constitutes personal data because it is capable of being linked to your session and device.
  • Interaction events: listing views, searches, favourites, offers and comparable interactions are transmitted to our own back-end, subject to per-user quotas, and are used to rank and personalise the discovery feed and to maintain aggregate counters. These events are retained in server-side log files.
  • Precise geolocation: where you grant the operating-system permission, we access your device’s coordinates in order to pre-fill an address and to surface listings by proximity. You may withdraw this permission at any time in your device settings, without affecting the lawfulness of processing carried out before withdrawal.
  • Approximate location derived from IP address: where no coordinates are available, we derive a two-letter country code from your IP address in order to produce a relevant feed. The IP address is resolved in memory and discarded; only the country code is used, and it is not written to our interaction records.
  • Push notification identifiers: the messaging token issued to your device installation, used to deliver chat, trade and plant-care notifications.
  • Ambient light readings: where you use the light-measurement feature, readings from the device light sensor are processed locally on your device to produce a light assessment for a plant.
  • Local storage on your device: the application maintains an on-device cache (SQLite, key-value stores and encrypted secure storage) containing your profile, plants, chats and session tokens, so that the application functions offline.

3.3 Special categories of personal data

We do not seek to collect special categories of personal data within the meaning of Article 9 GDPR, nor data relating to criminal convictions and offences within the meaning of Article 10 GDPR. You should not include such data in your profile, listings, photographs, chat messages or any other free-text field. Where you nonetheless choose to make such data public through the Services, you do so on your own initiative and, to the extent applicable, you manifestly make that data public within the meaning of Article 9(2)(e) GDPR.

4. Purposes and legal bases

We process personal data only where a legal basis under Article 6(1) GDPR applies, as set out below.

PurposeCategoriesLegal basis
Creating and administering your account; authenticationAccount, identity, federated sign-in dataPerformance of a contract — Art. 6(1)(b)
Publishing listings and wanted posts; operating trades, offers, favourites, follows, reviews and chatUser content, account data, address visibility settingsPerformance of a contract — Art. 6(1)(b)
Providing plant identification, care guidance and the in-app assistantPhotographs, plant metadata, chat history, care profilePerformance of a contract — Art. 6(1)(b)
Pre-filling addresses and surfacing listings by proximityPrecise geolocationConsent — Art. 6(1)(a), given via the operating-system permission and withdrawable at any time
Sending push notificationsPush token, account identifierConsent — Art. 6(1)(a), withdrawable in device or app settings
Behavioural analytics, session reconstruction and heatmapsAnalytics and session data, device dataConsent — Art. 6(1)(a), read together with Article 5(3) of Directive 2002/58/EC, where such consent is required in your jurisdiction; otherwise our legitimate interest in understanding and improving the Services — Art. 6(1)(f)
Ranking and personalising the discovery feedInteraction events, approximate locationLegitimate interests — Art. 6(1)(f): presenting a usable and relevant service
Diagnosing crashes and maintaining stability and performanceDiagnostic data, device dataLegitimate interests — Art. 6(1)(f): keeping the Services operational and secure
Preventing fraud, abuse, spam and unauthorised access; enforcing the User Agreement; moderating content and handling reportsAccount data, device attestation, interaction and content dataLegitimate interests — Art. 6(1)(f): protecting the Services, our users and third parties
Sending service and transactional communications, including email verificationEmail address, account dataPerformance of a contract — Art. 6(1)(b)
Complying with statutory obligations and responding to lawful requests from competent authoritiesAny relevant categoryCompliance with a legal obligation — Art. 6(1)(c)
Establishing, exercising or defending legal claims, including retaining evidence of disputed tradesAny relevant categoryLegitimate interests — Art. 6(1)(f), and Art. 9(2)(f) where applicable
Effecting a merger, acquisition, reorganisation or transfer of assetsAny relevant categoryLegitimate interests — Art. 6(1)(f): conducting and reorganising our business

Where we rely on legitimate interests, we have carried out a balancing exercise between those interests and your interests, rights and freedoms. You may request further information about that assessment, and you have the right to object as described in section 13.

5. Automated processing, artificial intelligence and the accuracy of guidance

Certain features rely on automated processing and third-party artificial-intelligence services. When you use plant identification, the in-app assistant or care enrichment, the relevant photographs, plant metadata and conversation history are transmitted to our third-party providers of generative-artificial-intelligence and image-recognition services, including a specialist plant-identification service, in each case for the purpose of generating a response to you.

The discovery feed is ranked automatically on the basis of your interaction events and approximate location. We do not carry out decision-making based solely on automated processing that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR.

Output generated by these features is informational and probabilistic. It is not professional horticultural, agricultural, botanical, veterinary, medical, nutritional, legal or regulatory advice, and it may be incomplete, outdated or incorrect, including as to species identification, toxicity and edibility. You must independently verify any identification or guidance before acting on it, in particular before ingesting any plant or exposing any person or animal to it, and before importing, exporting, trading or disposing of any plant that may be protected, invasive or otherwise regulated. To the fullest extent permitted by applicable law, we exclude all liability for any loss or damage arising from reliance on such output.

6. Recipients and processors

We disclose personal data only as described below. Our processors act on our documented instructions under agreements concluded pursuant to Article 28(3) GDPR.

Recipient categoryFunctionRole
Providers of cloud infrastructure, storage and databasesHosting of the Services, storage of data and images, operation of our API and search index, and server logsProcessor
Providers of authentication, security and integrity servicesAccount sign-in, device attestation, abuse prevention and rate limitingProcessor
Providers of diagnostics and crash reportingCrash, error and stability diagnosticsProcessor
Providers of behavioural and product analyticsUsage analysis, session reconstruction and improvement of the ServicesProcessor
Providers of email, messaging and push-notification deliveryDelivery of transactional, verification and notification messagesProcessor
Providers of image-recognition and artificial-intelligence servicesPlant identification and assistant features based on the content you submitProcessor
App-store operators and third-party sign-in providersFederated sign-in, and app-store distribution and billingIndependent controllers for their own processing
Other users of the ServicesReceipt of the profile information, listings and messages you choose to share with themIndependent controllers
Professional advisers, insurers and auditorsLegal, accounting and insurance purposesControllers or processors, as applicable
Competent authorities, courts and law-enforcement bodiesCompliance with legal obligations and lawful requests, and defence of legal claimsIndependent controllers
An acquirer or successor entityMerger, acquisition, reorganisation, insolvency or transfer of all or part of our business or assetsController

A current list of the sub-processors we engage, including their identity and place of establishment, is available on request by contacting us at the address in section 1.

We do not sell personal data, and we do not share personal data for cross-context behavioural advertising or for the targeted-advertising purposes of any third party.

7. International transfers

Certain of the recipients listed above process personal data outside the European Economic Area, including in the United States. Where such a transfer takes place, it is carried out on the basis of an adequacy decision of the European Commission, including the EU–U.S. Data Privacy Framework where the recipient is certified under it, or on the basis of the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, supplemented where appropriate by additional technical and organisational measures. You may request a copy of the relevant safeguards by contacting us at the address in section 1.

8. Information that is visible to others

The Services are a social marketplace. Your display name, profile picture, profile description, ratings, follower relationships, listings, wanted posts and the images and descriptions you attach to them are visible to other users and, where the relevant pages are publicly accessible, may be accessible without an account and indexed by search engines. Your address is disclosed only to the extent permitted by the visibility setting you select for it.

Once information has been made available to another user, that user may retain, copy, screenshot, republish or otherwise process it outside our control, and deletion of your account will not retrieve it. To the fullest extent permitted by applicable law, we are not responsible or liable for the acts or omissions of other users, including any unlawful use of information you have chosen to disclose to them. You should not publish information through the Services that you would not wish to become public.

9. Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter for the period during which claims may be brought or as required by law.

CategoryRetention period
Account, profile and address dataFor the duration of the account. Deleted or irreversibly anonymised within 30 days of a valid deletion request.
Listings, wanted posts, photographs and care recordsFor the duration of the account, or until you delete them.
Chat messagesFor as long as the conversation exists, and thereafter for 12 months after the last participant deletes or leaves the conversation.
Trade, offer and review recordsFor the duration of the account and thereafter for as long as necessary for the establishment, exercise or defence of legal claims.
Diagnostic and crash dataIn accordance with the retention period applied by our diagnostics provider, in principle not exceeding 90 days.
Behavioural analytics and session reconstruction dataIn accordance with the retention period applied by our analytics provider, after which it is deleted by that provider.
Interaction event logsUp to 12 months, after which they are deleted or aggregated into non-personal statistics.
Server, security and anti-abuse logsUp to 12 months, or longer where required to investigate a specific incident.
Records subject to statutory retention obligations, including accounting recordsFor the statutory period, which under Belgian law is in principle seven years for accounting records.
Data on your own deviceUntil you log out, clear the application data or uninstall the application.
BackupsResidual copies may persist in encrypted backups for a limited period after deletion, and are overwritten in the ordinary backup cycle.

10. Deleting your account

You may delete your account at any time:

  1. Open your profile from the right-hand side of the navigation bar.
  2. Tap the edit button at the top of the screen.
  3. Scroll to the bottom of the page and select ’Delete Account’.
  4. Confirm the deletion.

Deletion is irreversible. For transparency, deletion does not remove: (a) messages already delivered to other users, which remain in their conversations; (b) content that other users have copied or saved outside the Services; (c) aggregated or irreversibly anonymised statistics, which no longer constitute personal data; or (d) records we are required or entitled to retain under section 9, in particular for the establishment, exercise or defence of legal claims and for compliance with statutory obligations. Such retained records are restricted to what is necessary for those purposes.

11. Security

We implement technical and organisational measures appropriate to the risk, in accordance with Article 32 GDPR. These include encryption of data in transit using TLS, encryption at rest by our infrastructure providers, server-side access rules enforcing least-privilege access to stored records, device attestation, encrypted secure storage for credentials on your device, code obfuscation in release builds, and access controls and logging on administrative interfaces.

No method of transmission over the internet and no method of electronic storage is entirely secure. While we take appropriate measures, we cannot and do not warrant or guarantee the absolute security of personal data, and, to the fullest extent permitted by applicable law, we exclude liability for unauthorised access, disclosure, alteration or destruction that occurs despite the implementation of such measures. You are responsible for maintaining the confidentiality of your credentials and for all activity carried out under your account, and you must notify us without undue delay of any suspected compromise. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with Article 34 GDPR.

12. Children

The Services are intended exclusively for persons aged 18 years or older, and we do not knowingly process personal data of minors. If we become aware that a person under 18 has created an account, we will delete that account and the associated personal data without undue delay. A parent or guardian who believes that a minor has provided personal data to us should contact us at [email protected].

13. Your rights

Subject to the conditions and exceptions in the GDPR, you have the right to:

  • obtain confirmation as to whether we process personal data concerning you and obtain access to it (Article 15);
  • obtain rectification of inaccurate personal data and completion of incomplete personal data (Article 16);
  • obtain erasure of personal data (Article 17);
  • obtain restriction of processing (Article 18);
  • receive the personal data you have provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller (Article 20);
  • object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests (Article 21); and
  • withdraw any consent you have given, at any time, without affecting the lawfulness of processing carried out before the withdrawal (Article 7(3)).

Requests may be submitted at any time to [email protected]. We will respond without undue delay and in any event within one month of receipt, which period may be extended by two further months where necessary taking into account the complexity and number of requests, in which case we will inform you of the extension and the reasons for it. Where we have reasonable doubts as to your identity, we may request additional information necessary to confirm it. Requests are free of charge, save that we may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive, in particular because of its repetitive character.

You may also control certain processing directly in the application: you may edit your profile, manage or delete your listings, adjust the visibility of your address, manage notification preferences, block other users, and withdraw location and notification permissions in your device settings.

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The Belgian supervisory authority is the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels, Belgium, [email protected].

14. Third-party services

The Services may contain links to, or interoperate with, websites, applications and services operated by third parties, including the identity providers and app stores referred to above. Those parties process personal data under their own privacy policies, over which we have no control. We make no representation as to, and to the fullest extent permitted by applicable law accept no liability for, the content, practices or availability of any such third party.

15. Changes to this Policy

We may amend this Policy from time to time to reflect changes in the Services, in our processing activities or in applicable law. Where a change is material, we will give notice through the application or by email at least 30 days before it takes effect, and the version number and effective date at the head of this Policy will be updated. Where a change requires your consent under applicable law, we will obtain that consent before the relevant processing begins. Your continued use of the Services after the effective date of a change constitutes acceptance of the amended Policy to the extent permitted by applicable law.

16. Severability and mandatory law

If any provision of this Policy is held to be invalid, unlawful or unenforceable, that provision shall be severed and the remaining provisions shall continue in full force and effect. Nothing in this Policy operates to exclude or limit any right you have under mandatory provisions of applicable law that cannot lawfully be excluded or limited, including your rights under the GDPR and under mandatory Belgian consumer protection law, and no exclusion or limitation of liability in this Policy applies to liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or to any other liability that cannot lawfully be excluded.

17. Governing law

This Policy is governed by Belgian law, without prejudice to any mandatory protection afforded to you by the law of your country of habitual residence and without prejudice to your right to lodge a complaint with your local supervisory authority.

18. Contact

Sebastiaan Verplancke, trading as Plantative
Patijntjestraat 87, 9000 Ghent, Belgium
Enterprise number 1034.776.796 · VAT BE 1034.776.796
[email protected]

Last Updated: 31 August 2026

Plantative logo