Plekk
Privacy statement
What data Plekk processes, why, for how long, and what you can do about it.
Last updated: 10 September 2026
Who processes your data
Marleo, Deinze, Belgium, is the controller for the data of businesses using Plekk. Contact: hallo@plekk.be.
For the data of a business's customers, that business is the controller; Plekk acts as processor.
What data and why
From the business: name, address, phone, email, VAT number and owner login. Needed to run your account and invoice you.
From customers: name, phone, email, the booking itself and any notes. Needed to carry out and confirm the booking.
Technical data: IP address and timestamp at sign-in, to prevent abuse.
No advertising cookies, and no tracking across other websites.
Legal basis
For the business: performance of the subscription (art. 6.1.b GDPR) and our statutory accounting duty (art. 6.1.c).
For customers: performance of their booking, on the business's instructions.
How long we keep it
Booking data: as long as the business needs it, then 60 days after the subscription ends.
Invoices and accounts: seven years, as the law requires.
Sign-in logs: twelve months.
Who we share with
Supabase (European servers) for the database.
Resend and Amazon SES for sending emails.
Stripe for payments. Stripe handles card details directly; Plekk never sees or stores a card number.
Nothing else is shared, and we never sell data.
Your rights
You can access, correct, delete or take your data elsewhere. Write to hallo@plekk.be; we answer within 30 days.
You may lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels.
Cookies
Plekk uses one cookie to keep you signed in and one to remember your language. Both are necessary, so no consent is required.
The public booking pages carry no tracking cookies.
Security
All traffic runs over HTTPS. Passwords are stored only as hashes. The database sits within the EU.
Found a security issue? Report it to hallo@plekk.be; we respond within two working days.