← Back to home Data Protection
Privacy Policy
This Privacy Policy explains what personal data CoachCards collects, why we collect it, how we use it,
and the rights you have over it — in plain English, in full compliance with UK GDPR and the Data Protection Act 2018.
Effective date: 1 June 2026 · Governing law: England & Wales
🔒
Your data is safe and protected.
CoachCards is committed to the highest standards of data protection. We never sell your personal data,
never share it with third parties for commercial or marketing purposes, and never store
payment information on our servers. All data is encrypted in transit using TLS 1.2+ and at rest
using AES-256. Our infrastructure runs on Supabase, hosted within ISO 27001-certified,
EU-based data centres, fully compliant with UK GDPR adequacy provisions.
🔐
Encrypted
TLS in transit · AES-256 at rest
🇬🇧
UK GDPR Compliant
Data Protection Act 2018 aligned
🚫
Never Sold
Zero commercial data sharing
1. Data Controller
CoachCards is the Data Controller for all personal data processed via the Platform, as defined under
the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
As Data Controller, we determine the purposes and means of processing your personal data and are responsible
for ensuring that processing is lawful, fair, and transparent.
2. Personal Data We Collect
2.1 Trainer Data
- Full name and email address (collected at registration)
- Professional information: city, qualifications, certifications, specialties, biography
- Profile photo (optional, uploaded by the Trainer)
- Account preferences: avatar colour, profile background theme
2.2 Client / Reviewer Data
- Full name (as entered when submitting a Review)
- Star rating and written testimonial
- Date and time of submission
Clients are not required to create an account. No email address is collected from Clients.
2.3 Technical Data
- IP address and browser type (collected automatically by our hosting infrastructure for security and fraud prevention)
- Approximate geolocation derived from browser permission (used solely to display local trainer results — not stored on our servers)
- Authentication session tokens stored in browser cookies for logged-in Trainer accounts
2.4 Data We Do Not Collect
We do not collect: payment card details, national insurance numbers, passport or ID documents, health or medical data,
or any special category data as defined by UK GDPR Article 9.
3. Lawful Basis for Processing
We process personal data under the following lawful bases as defined by UK GDPR Article 6:
- Contract (Art. 6(1)(b)) — processing necessary to provide the Platform services to registered Trainers
- Legitimate Interests (Art. 6(1)(f)) — displaying Reviews and rankings, preventing fraud, maintaining platform security, and improving our services
- Consent (Art. 6(1)(a)) — where a Client voluntarily submits a Review and their name is displayed publicly
- Legal Obligation (Art. 6(1)(c)) — retaining certain records where required by applicable law
4. How We Use Your Data
Data you provide is used exclusively to:
- Display your public trainer profile and ranking on the Platform
- Calculate your BMP Score from verified reviews
- Send account-related emails (sign-up confirmation, profile updates)
- Detect and prevent fraud and abuse of the Platform
- Improve the Platform based on usage patterns
We will never use your data to send unsolicited marketing emails, sell it to third parties,
or share it with advertisers under any circumstances.
5. Your Data Protection Rights
Under UK GDPR, you have the following rights. To exercise any of them, contact us at
personaltrating@protonmail.com.
We will respond within 30 calendar days.
- Right of Access (Art. 15) — request a copy of all personal data we hold about you
- Right to Rectification (Art. 16) — request correction of inaccurate or incomplete data
- Right to Erasure (Art. 17) — request deletion of your data where no longer necessary, subject to legal retention obligations
- Right to Restriction (Art. 18) — request that we restrict processing in certain circumstances
- Right to Data Portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to Object (Art. 21) — object to processing based on legitimate interests at any time
- Right to Withdraw Consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
If you believe your data rights have been violated, you have the right to lodge a complaint with the
Information Commissioner's Office (ICO) at
ico.org.uk or by calling 0303 123 1113.
6. Third-Party Data Processors
We share personal data only with the following processors, each bound by a Data Processing Agreement (DPA)
and compliant with UK GDPR:
- Supabase Inc. — database hosting, authentication, and file storage. Hosted in EU-based, ISO 27001-certified data centres.
- Netlify Inc. — web hosting and content delivery network. GDPR-compliant DPA in place.
We do not share personal data with advertising networks, data brokers, or any third party for commercial
marketing purposes. We will not sell personal data under any circumstances.
In the event of a merger, acquisition, or sale of assets, Users will be notified in advance and equivalent
data protection obligations will be imposed on any acquiring entity.
7. Data Retention
- Trainer account data — retained for the duration of the account and deleted within 30 days of an account deletion request
- Review content — retained while the Trainer account is active; may be kept in anonymised form after deletion for platform integrity purposes
- Authentication logs — retained for up to 90 days for security and fraud prevention
- Geolocation data — not stored; processed transiently in-browser only and never transmitted to our servers
Upon account deletion, all personally identifiable data is permanently removed from our systems within 30 days.
Anonymised, non-identifiable statistical data may be retained indefinitely.
8. Cookies & Local Storage
8.1 Essential Cookies
We use authentication session cookies strictly necessary for Trainer login functionality.
These cannot be disabled without preventing access to authenticated areas of the Platform.
They expire at session end or after a fixed period determined by our authentication provider.
8.2 Local Storage
We use browser local storage to remember your dashboard preferences between sessions (such as last-seen review counts).
This data is stored entirely on your device and is never transmitted to our servers.
8.3 No Tracking or Advertising Cookies
CoachCards does not use tracking cookies, advertising cookies, or any third-party analytics cookies.
We do not participate in cross-site tracking or behavioural advertising networks of any kind.
9. Changes to This Policy
We reserve the right to update this Privacy Policy at any time. When we make material changes, we will update
the effective date above and, where reasonably practicable, notify registered Trainers by email at least
14 days before changes take effect. Continued use of the Platform after that date constitutes acceptance.