PlanScore Privacy Policy

Effective Date: September 4, 2026

1. Introduction

Success Mindsets LLC d/b/a PlanScore (“PlanScore,” “we,” “us,” or “our”), a Tennessee limited liability company, provides a financial planning platform used by financial advisory firms and their staff to manage client financial planning data. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with your use of the PlanScore application, including app.planscore.com and planscore.com (collectively, the “Service”).

2. Scope of This Policy

This Policy applies to PlanScore Users — the advisors, planners, and administrative staff at advisory firms who access the Service directly (“Users,” “you”). It does not by itself create a direct relationship between PlanScore and the individual clients of those advisory firms, even though information about those clients may be entered into and processed by the Service on the firm's behalf. See Section 4, “Client Data We Process on Behalf of Advisory Firms,” below.

3. Information We Collect

  • Account & Profile Information: name, email address, firm name/affiliation, role (e.g., advisor, firm admin, super admin), and login credentials.

  • Billing Information: subscription and payment details are processed by our payment processor, Stripe. PlanScore does not store full payment card numbers.

  • Usage & Log Data: pages visited, actions taken within the Service, IP address, browser/device type, and timestamps.

  • Cookies: PlanScore uses only functional/session cookies necessary to keep you logged in and to maintain application state. We do not use cookies to deliver advertising or to track you across other websites. If we begin using analytics or similar technologies, we will update this Policy before doing so.

4. Client Data We Process on Behalf of Advisory Firms

In the course of providing the Service, advisory firms and their staff enter financial planning information about their own clients (“Client Data”) into PlanScore. Client Data may include client names and contact details; account balances, assets, liabilities, and income; observations regarding cash flow, investment strategy, tax planning, insurance coverage, estate planning, and business planning; retirement and other financial goals; and household or dependent information.

PlanScore processes Client Data solely as a service provider acting on behalf of, and under the instructions of, the advisory firm that entered it.

  • The advisory firm remains responsible for its relationship with its own clients, including providing any privacy notices required by applicable law (such as those required under Regulation S-P or the Gramm-Leach-Bliley Act) directly to its clients.

  • Individuals who are clients of a PlanScore-using advisory firm and have questions about their own data should contact their advisor or firm directly, rather than PlanScore.

5. How We Use Information

  • Provide, operate, and maintain the Service

  • Authenticate Users and secure accounts

  • Process subscription billing through Stripe

  • Send transactional and service-related emails (e.g., account notifications, password resets, billing receipts) through Postmark

  • Monitor, troubleshoot, and improve the Service

  • Comply with applicable legal obligations

6. How We Share Information

We do not sell User or Client Data. We share information only with the following categories of service providers, and only as needed to operate the Service:

  • Bubble — our application hosting and infrastructure provider (operating on Amazon Web Services), which hosts the Service and all associated data.

  • Stripe — processes subscription payments on our behalf.

  • Postmark — delivers transactional emails on our behalf.

  • Others, only as required by law or to protect the rights, property, or safety of PlanScore, our Users, or others.

7. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information. The measures described below reflect our security program as of the Effective Date; we may change specific measures as the Service evolves, provided we do not materially reduce the overall level of protection. Our safeguards currently include:

  • Encryption of data in transit and encryption of sensitive data at rest

  • Role-based access controls, restricting Client Data visibility to the record's owning User and their firm administrator

  • Multi-factor authentication, which we require for administrative and infrastructure access and are extending to all User accounts

  • Password requirements designed to reduce the risk of unauthorized access, which we periodically review and strengthen

  • Restricted, key-authenticated access for automated system integrations (such as billing webhooks)

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. Data Retention

We retain Account and Client Data for as long as an advisory firm’s subscription is active and for the periods described below, after which we delete it or render it not reasonably re-identifiable.

  • Account Information — retained while the subscription is active and for twelve (12) months after it ends, then deleted.

  • Client Data — retained while the subscription is active. On termination, the firm has thirty (30) days to export it; we then delete it within ninety (90) days, unless the firm asks us in writing to delete it sooner or applicable law requires us to keep it longer.

  • Usage and Log Data — retained for twenty-four (24) months.

  • Billing Records — retained for seven (7) years, as required for tax and accounting purposes.

A firm may request earlier deletion of its Client Data at any time by contacting us at the address in Section 15. Backups are overwritten on a rolling basis and residual copies are purged within one hundred eighty (180) days.

9. Your Rights and Choices

To access, correct, or request deletion of information, contact us at the address in Section 15. We will acknowledge your request within ten (10) business days and respond substantively within forty-five (45) days, which we may extend once by a further forty-five (45) days where reasonably necessary, with notice to you. If we decline a request, we will tell you why and how to appeal that decision.

10. Location of Processing; International Users

The Service is intended for use only within the United States, and all information is stored and processed in the United States. We do not offer the Service to, and Users may not access the Service from, jurisdictions outside the United States. We do not knowingly collect or process personal data subject to the EU or UK General Data Protection Regulation. If we begin offering the Service outside the United States, we will update this Policy and put appropriate transfer safeguards in place before doing so.

11. Children's Privacy

The Service is intended for business use by adult professionals and is not directed to individuals under the age of 18. We do not knowingly collect information directly from children.

12. Security Incident Notification

If we determine that unauthorized access to or acquisition of Client Data has occurred, we will notify the affected advisory firm without undue delay and in any event within seventy-two (72) hours of that determination. Our notice will describe what we know about the nature and scope of the incident, the categories of information involved, the steps we are taking, and a point of contact for follow-up questions. We will provide the firm with the information it reasonably needs to meet its own notification obligations, including those under Regulation S-P and the Gramm-Leach-Bliley Act, and will cooperate with its investigation.

13. State Privacy Rights

Some information we process is subject to the Gramm-Leach-Bliley Act and is therefore exempt from certain state privacy laws. Information that is not GLBA-covered — principally the account, profile, and usage data of our Users — may be subject to those laws. Depending on your state of residence, you may have the right to know what personal information we hold about you, to obtain a copy of it, to correct it, to request its deletion, and to appeal a denial of any of these requests. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. To make a request, contact us at the address in Section 15.

14. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated to Users through the Service or by email. The Effective Date above reflects the most recent revision.

15. Contact Us

Success Mindsets LLC d/b/a PlanScore

Attn: Privacy

6700 Tower Circle, Suite 310, Franklin, TN 37067

Support@eadvisornetwork.com