Privacy Policy

CoachLink LLC · Michigan Limited Liability Company

Effective Date: April 12, 2026 | Last Updated: April 12, 2026

1. Introduction

CoachLink LLC ("CoachLink," "we," "our," or "us") operates the CoachLink mobile application and web platform (collectively, the "Service"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you access or use the Service.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. CoachLink is not a covered entity or business associate under HIPAA. Health and fitness data described in Section 3 is voluntarily provided and is not protected health information (PHI).

2. Information We Collect

2.1 Information You Provide Directly

  • Account registration data: name, email address, password (hashed), role
  • Profile information: date of birth, gender, weight class, physical measurements, fight record, gym affiliation, biography, photos
  • Health and biometric data (see Section 3)
  • Fight and event data: bout applications, agreements, event participation, results
  • Communications: messages sent through the platform's chat system
  • Support requests

2.2 Information Collected Automatically

  • Device and login data: IP address, approximate location, browser/app user agent, device type, OS, app version
  • Authentication events: login timestamps, session tokens (stored securely)
  • Usage data: features accessed, pages viewed, timestamps
  • Push notification tokens (FCM/APNs)

2.3 Information from Third Parties

  • Tapology fight record imports (if initiated by you)
  • Stripe: payment processing status and customer identifiers (we never store full card numbers)

3. Health and Biometric Data

CoachLink collects health-related information that you voluntarily provide, which may include:

  • Body metrics: weight, height, reach, body fat percentage, lean mass, goal weight, waist and hip measurements
  • Cardiovascular data: resting heart rate, VO2 max, blood pressure
  • Injury records: injury name, body part, type, severity, recovery timeline, treatment notes
  • Wellness self-check data: sleep quality, hours slept, stress level, nutrition score
  • Training session logs: duration, intensity, training types
  • Weight history and cut logs

This data is used to compute readiness scores, support coaching decisions, track training progress, and enable bout booking features. We treat health data with heightened protections and do not sell, license, or share it with advertising networks. CoachLink does not perform medical diagnosis or any activity regulated under HIPAA.

4. Camera and Media Access

The mobile app may request camera and photo library access at runtime. These permissions are entirely optional. Media files are transmitted over encrypted HTTPS and stored in Microsoft Azure Blob Storage. You may delete uploaded media at any time. We do not perform facial recognition, biometric scanning, or automated image analysis.

5. How We Use Your Information

  • Providing and operating the Service
  • Processing payments through Stripe
  • Sending transactional emails via SendGrid
  • Delivering push notifications via Expo (FCM/APNs)
  • Computing readiness scores and performance analytics
  • Enforcing Terms of Service and platform policies
  • Detecting and preventing fraud, abuse, and security incidents
  • Complying with applicable laws and regulations
  • Improving the Service based on aggregated usage patterns

We do not use your personal information for behavioral advertising, third-party ad targeting, or sale to data brokers.

6. Legal Bases for Processing (GDPR)

If you are in the EEA or UK, we process data based on: contract performance, legitimate interests (security, fraud prevention), consent (health data, media access, push notifications), and legal obligation.

7. Data Sharing Within the Platform

When you join a coach, team, or organization, your training profile, readiness score, wellness check-ins, weight logs, training logs, injury status, and performance metrics become accessible to your assigned coach(es) and organization administrators. Coaches may include your profile data in matchmaker submissions only in connection with a bout booking workflow you have initiated. Sensitive fields (injury records, wellness data) are never visible in the public directory.

8. Third-Party Service Providers

  • Microsoft Azure: application hosting, database storage, file storage
  • Stripe: subscription payment processing (only a customer identifier is stored; no raw card data)
  • SendGrid (Twilio): transactional and security notification email delivery
  • Expo / FCM / APNs: push notification delivery

We do not sell your personal information. We do not share data with advertising networks, data brokers, or analytics platforms.

9. California Privacy Rights (CCPA / CPRA)

California residents have the right to know, delete, correct, opt-out of sale/sharing, limit use of sensitive personal information, and non-discrimination. CoachLink does not sell or share personal information for cross-context behavioral advertising. To exercise your rights, email info@coach-link.ai. We will respond within 45 days.

10. Data Retention

  • Account and profile data: retained for the life of your account plus 30 days after deletion
  • Health and biometric data: retained until you delete it or request account deletion
  • Security logs: 12 months
  • Payment records: 7 years (tax law)
  • Bout agreements and e-signatures: 5 years

Upon account deletion request, data is removed or de-identified within 30 days, except where required by law. Backups may retain data up to 90 additional days.

11. Data Security

We implement TLS/SSL encryption in transit, Azure SQL encryption at rest, role-based access controls, JWT-based authentication with refresh token rotation, secure token storage (iOS Keychain / Android Keystore), and audit logging. In the event of a data breach, affected users will be notified within 72 hours.

12. Your Rights and Choices

You have the right to access, correct, delete, and request portability of your personal information, withdraw consent, and object to certain types of processing. Submit requests through the Help & Support section or email info@coach-link.ai. We will respond within 30 days.

13. Children's Privacy

The Service is not directed to children under 13. Users between 13 and 17 may only use the Service under the supervision of a parent or legal guardian. Organizations and coaches who train minors are responsible for obtaining parental consent.

14. Privacy Dispute Resolution

Contact info@coach-link.ai with complaints. Unresolved disputes shall be resolved by binding arbitration under AAA rules, seated in Michigan, consistent with CoachLink's Terms of Service.

15. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via in-app notification and email. Where required by law, we will obtain your consent before applying material changes.

16. Contact Us

CoachLink LLC — Privacy Inquiries
Email: info@coach-link.ai
CoachLink LLC, Michigan, United States
For time-sensitive requests, include "URGENT PRIVACY REQUEST" in the subject line.

© 2026 CoachLink LLC. All rights reserved.