Privacy Policy

Last updated: March 28, 2026

At CoachNest, your privacy is important to us. This policy explains what data we collect, why we collect it, and how you can control it.

1. Information We Collect

We collect information you provide directly to us and information generated automatically when you use CoachNest.

Account Information

When you create an account we collect your name, email address, and password (stored as a secure hash). If you sign in via a third-party provider, we receive the profile information that provider makes available.

Payment Information

Payments are processed through Stripe. We do not store full card numbers or CVV codes on our servers. We receive and store a payment reference ID and the last four digits of your card solely for billing records.

Learning Activity

We record course enrollments, lesson completion, quiz scores, certificates earned, and time spent on the platform to power your learning dashboard and personalised recommendations.

Usage Data

We automatically collect log data including IP address, browser type, pages visited, and referring URLs. This data is aggregated and used for analytics and platform improvement.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account
  • Process payments and issue receipts
  • Deliver course content and track your progress
  • Send transactional emails (receipts, certificates, password resets)
  • Send product updates and promotional content (you can opt out at any time)
  • Detect and prevent fraud or abuse
  • Improve the platform through analytics and A/B testing
  • Comply with legal obligations

We do not sell your personal data to third parties for their own marketing purposes.

3. Sharing Your Information

We share data only in the following circumstances:

  • Service Providers — trusted vendors who process data on our behalf (e.g., Stripe for payments, Resend for email delivery, Vercel for hosting). These parties are contractually bound to protect your data.
  • Instructors — if you enrol in a course, the instructor can see your display name and aggregate progress to support your learning journey.
  • Legal Requirements — if we believe disclosure is required by law, subpoena, or legal process.
  • Business Transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before such a transfer occurs.

4. Cookies & Tracking

We use cookies and similar technologies to operate the platform and understand how you use it. You can manage your cookie preferences at any time via our Cookie Policy.

Types of cookies we use

  • Strictly Necessary — required for authentication, session management, and core functionality.
  • Analytics — help us understand traffic patterns and feature usage (e.g., aggregate page view data).
  • Preference — remember your settings such as language or theme.

We do not use third-party advertising cookies.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. If you delete your account:

  • Profile data is deleted within 30 days.
  • Payment records are retained for 7 years to comply with tax and accounting obligations.
  • Anonymised, aggregated analytics data may be retained indefinitely.

6. Your Rights

Depending on your location you may have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data ("right to be forgotten").
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.
  • Withdraw Consent — opt out of marketing emails via the unsubscribe link in any email or through your account settings.

To exercise any of these rights, please contact us at our contact page.

7. Security

We implement industry-standard measures to protect your data, including:

  • TLS/HTTPS encryption for all data in transit
  • bcrypt password hashing
  • Regular security audits and dependency updates
  • Least-privilege access controls for internal systems

No method of transmission over the Internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

8. Children's Privacy

CoachNest is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data, please contact us immediately so we can delete the information.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "last updated" date at the top of this page and notify you via email or an in-app notice for material changes. Your continued use of CoachNest after such notification constitutes your acceptance of the updated policy.

10. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy, please reach out: