Legal
Privacy Policy
Last updated: June 2025
1. Introduction
Coacheckin ("we", "us", "our") is a trading name operated by Mehdi Elyoussefi, a self-employed individual (auto-entrepreneur) registered in Morocco. We are committed to protecting the personal data of coaches, clients, and visitors who use our platform. This Privacy Policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, and password (hashed)
- Profile data: coaching identity, speciality, philosophy, certifications
- Client health data: weight, height, BMI, blood pressure, heart rate, blood sugar, body fat, injuries, medications — entered by coaches or clients
- Usage data: IP address, browser type, device type, pages visited, session data
- Communications: messages exchanged between coaches and clients within the platform
- Progress media: progress photos uploaded by clients
3. Payment Processing via Dodo Payments
Subscription payments are processed by Dodo Payments, who acts as the authorised reseller (Merchant of Record) for Coacheckin subscriptions. When you subscribe, your payment information (cardholder name, card identifiers, billing address, payment amount) is collected and processed directly by Dodo Payments.
Dodo Payments may collect and retain transaction data, your email address, and device information as part of fraud prevention and regulatory compliance. Their data practices are governed by the Dodo Payments Privacy Policy.
We receive confirmation of payment status from Dodo Payments but do not store full card details on our servers.
4. How We Use Your Data
We use personal data to:
- Provide and improve the Coacheckin platform
- Process subscriptions and manage billing
- Enable coaches to manage client programs and track progress
- Power AI features (daily digests, coaching identity) — processed via Anthropic's Claude API
- Send transactional emails (account confirmation, billing notifications)
- Comply with legal and regulatory obligations
5. Data Sharing
We do not sell your personal data. We share data only with:
- Supabase — database and authentication provider (data stored with row-level security)
- Dodo Payments — payment processing and subscription management
- Anthropic — AI processing for coaching features (Claude API)
- Google Analytics — anonymised site usage analytics
- Legal and regulatory authorities when required by law
All third-party processors are contractually bound to use data only for the purposes we specify.
6. Data Security
All data is stored with Supabase row-level security — coaches can only access data from clients linked to their account, and clients can only see their own data. Progress photos are served via signed URLs that expire after one hour. We use HTTPS for all data in transit.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law (e.g. billing records, which are retained for the legally required period).
8. International Transfers
Your data may be processed in countries outside your own, including the United States, where our service providers (Supabase, Anthropic) operate. Where required, transfers are subject to appropriate safeguards such as Standard Contractual Clauses.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access a copy of your personal data
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Object to or restrict certain processing
- Data portability
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at support@coacheckin.com.
10. CCPA (California Residents)
If you are a California resident, you have the right to know what personal information we collect, request deletion, and opt out of any sale of personal information. Coacheckin does not sell personal information. To submit a request, contact us at support@coacheckin.com.
11. Cookies
We use essential cookies for authentication and session management. We also use Google Analytics cookies for anonymised usage analytics. You can control non-essential cookies through your browser settings.
12. Children
Coacheckin is not intended for users under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via a notice within the platform. Continued use after changes take effect constitutes acceptance.
14. Contact
For privacy questions or data requests, contact us at support@coacheckin.com or via our Contact page.