Privacy notice
Effective October 8, 2026. This notice describes the current PlanMyERP website. Questions or requests can be sent to contact@planmyerp.ca.
Project inquiries
The project inquiry form asks for your name, email, company, service interest, province or territory, company team size and the message you choose to provide. You may optionally tell us how you found the site. The form can also record the preceding public page on this website. If you allow traffic analytics, it can include the first and latest source, medium, approved campaign code, landing page and recognized referring service stored in your browser. These are browser-reported context, not verified statements about where you came from. Full referring URLs, search queries and advertising click IDs are not saved with your inquiry. It also records your consent to use those details to respond to the inquiry. Do not include passwords, payment details, employee records or other sensitive information.
The current form prepares a message in your email application. It does not save a submission to the website. Your email provider processes the message when you choose to send it.
We use these details to review your request and communicate with you about it. The inquiry form does not enroll you in marketing emails. We do not sell inquiry information or use it for advertising audiences.
Planning tools and checklists
Project-planner and training-planner selections, budget inputs and acceptance-checklist selections are held in your current browser tab. No account or email address is required. A brief is generated on your device when you use copy or download. If you choose to carry a brief or budget to the inquiry form, that generated text is temporarily placed in this tab’s session storage, then removed when the form reads it. Unopened drafts are rejected after 15 minutes on the next read; closing the tab clears session storage. You can review and edit the text before submitting. If you choose to email your brief, it is shared through your email application after you send it.
Security and operational data
Our hosting infrastructure may process connection data, including IP addresses and request metadata, to deliver the site and protect it. When server-side inquiries are enabled, the application uses a keyed hash of the source IP for short-lived abuse limits. Raw IP addresses are not stored in the inquiry tables. Hosting infrastructure may have separate operational logs.
Inquiry endpoints validate fields, limit request sizes, require same-origin requests, use expiring submission tokens and restrict submission frequency. The website provides no public endpoint for viewing stored inquiries. No system can be guaranteed completely secure.
Privacy choices and optional analytics
Third-party analytics are not active in this build. The following controls are prepared for launch; the website will load configured analytics services only after your permission.
You can allow traffic analytics and visual session replay separately, reject both, or change your choices using Privacy settings in the footer. Optional vendor scripts do not load before permission. The website also honours Global Privacy Control and Do Not Track signals by keeping optional measurement off. Your privacy choice is stored in your browser for up to 90 days. Essential hosting and security functions continue when you decline.
Traffic and conversions
With traffic analytics permission, Google Analytics can measure page visits, campaign sources, approximate geography and device information, navigation, phone and email link clicks, scrolling, tool actions, inquiry progress and confirmed saved inquiries. We send known page paths and approved event categories, not your name, email, company, inquiry text, search text, budget figures or generated briefs. Advertising signals and ad personalization are disabled in this integration. Phone and email clicks are interest signals, not proof that a call connected or an email was sent.
When configured, Cloudflare Web Analytics also measures browser visits and performance after traffic analytics permission. Cloudflare’s separate hosting and security reports may include requests from bots and infrastructure activity, so report totals can differ.
First and latest source context uses browser local storage for up to 90 days after you allow traffic analytics. Campaign values are restricted to approved codes. Returning directly or following internal links does not overwrite a known latest source. Withdrawing traffic analytics clears this stored context and local conversion deduplication markers; it does not retroactively erase an inquiry you already submitted.
Heatmaps and session replay
With separate replay permission, Microsoft Clarity can collect pseudonymous interaction data for heatmaps and masked replays on eligible public information pages. The document is marked for content masking. The contact page, project and training planners, cost calculator, and searchable directory pages are excluded. Vendor tracking is also suppressed on unrecognized URL parameters or potentially identifying referrers. We do not send inquiry identifiers or contact details to Clarity.
Google and Microsoft may use first-party analytics cookies and process information outside Canada. Their services receive network information as part of those connections. Turning off a running service clears accessible first-party analytics cookies and refreshes the page so its scripts no longer run. Provider-side records already collected are not automatically erased by a browser preference change.
The planning tools do not require analytics cookies. Deliberately transferring a brief uses temporary session storage as described above. Hosting or access-control infrastructure may use cookies needed for security. We do not use these analytics choices as consent to marketing email or advertising audiences.
Service providers and data location
The site uses Cloudflare hosting and a Cloudflare D1 database managed in our hosting account. If server-side email notifications are enabled, SMTP2GO processes the notification content. When you allow the corresponding optional service and it is configured, Google Analytics, Microsoft Clarity and Cloudflare Web Analytics process the measurement data described above. Email providers also process messages you send directly. We do not promise Canadian-only storage or processing; provider infrastructure may operate outside Canada.
Provider information: Google privacy policy, Microsoft Clarity privacy information, and Cloudflare privacy policy.
Retention and your requests
Our Google Analytics property is configured for 14-month user and event data retention, with extensions based on new activity turned off. These provider settings differ from the 90-day browser privacy-choice and source-context window. Google’s aggregated standard reports can have different retention rules.
For server-side inquiry records, the application removes records older than 90 days during successful new-submission processing. This is not a scheduled daily deletion: older records may remain if there are no subsequent submissions. Email copies and records required for an ongoing business relationship are managed separately.
You can request access, correction, withdrawal of consent for future follow-up, or deletion by emailing contact@planmyerp.ca. We may need to verify your identity and consider any required record retention before acting. Do not send identity documents with your initial request.