Who controls your information
For a coach account, CoachIntake is the data controller. For an applicant or coaching client, the coach normally decides why and how application and client information is used, making that coach the controller; CoachIntake acts mainly as their processor. We remain a controller for security, platform billing and legal records we determine ourselves.
Information we process
We process account and contact details, application answers, selected plans, booking details, notification preferences, payment and subscription status, support messages, security logs and service usage. Coaches can mark questions that may collect health or other special-category information. Applicants must provide separate explicit consent before submitting those answers.
Purposes and legal bases
We use information to provide accounts and contracted services, process requested applications and bookings, secure and improve the platform, meet legal duties and communicate about the service. Depending on the context, our UK GDPR bases are contract, legitimate interests, legal obligation or consent. Explicit consent is used for special-category application answers and can be withdrawn, although this does not undo earlier lawful processing.
AI summaries and messaging
CoachIntake can send a filtered version of application answers to OpenAI to create a short coach summary. Names, contact details and questions marked or detected as sensitive are excluded. Summaries can be wrong and coaches must review the original application. Email may be sent through Resend and WhatsApp through Twilio. Sensitive answers are not placed in those notification messages.
Payments and service providers
Stripe handles coach and client subscription payments; CoachIntake does not store full card numbers. We use Supabase for authentication and database services, our deployment host for application delivery, OpenAI for optional summaries, Resend for email, Twilio for WhatsApp and Stripe for payments. Each receives only the information needed for its function.
International transfers and security
Some providers may process information outside the UK. Where required, we rely on UK adequacy regulations or approved contractual safeguards such as the UK International Data Transfer Addendum. We use access controls, row-level database policies, encryption in transit, short-lived links, audit events and restricted service credentials. No online service can promise absolute security.
Retention
Application and client data is retained while the coaching relationship or application workflow remains active. Once an application is declined, cancelled or archived, the coach's chosen retention period begins; the platform default is 180 days. A longer period may apply where necessary for legal claims, fraud prevention or accounting. Temporary access links expire within hours or days. Billing and legal records may be kept for up to seven years where required.
Your rights
UK data protection law may give you rights to access, correct, erase, restrict or object to processing, obtain portable data and withdraw consent. Client account holders can download their data and submit a tracked deletion request in the client portal. CoachIntake reviews requests, verifies scope and records the outcome; erasure removes linked client records and the client login unless data must be retained by law. Applicants should normally contact their coach first; CoachIntake will assist the coach. You may complain to the UK Information Commissioner's Office at ico.org.uk.
Cookies and age restriction
CoachIntake uses essential authentication, security and form-state cookies. We do not currently use non-essential advertising cookies. The service and public application forms are for UK adults aged 18 or over.
Contact
Controller: CoachIntake. Address: Registered address not configured. Privacy email: privacy@coachintake.com. ICO registration: ICO registration not configured.