Subcoach — Privacy Policy
| Document version | 1.0 |
| Last updated (drafted) | 2026-08-29 |
| Effective date | 1 September 2026 |
| Data controller | Itai Lahat — sole proprietor / Einzelunternehmer, Germany |
| Postal address | Itai Lahat, Hauptstr. 50, 13158 Berlin, Deutschland |
| Contact / data requests | support@subcoach.app |
This Privacy Policy explains what personal data Subcoach ("we") collects, why, and your rights. It applies to the Subcoach mobile application and related services (the "Service"). The data controller under the GDPR is Itai Lahat (sole proprietor / Einzelunternehmer), Germany. We have not appointed a Data Protection Officer: based on our current assessment (no large-scale systematic monitoring, no large-scale special-category processing, and headcount below the § 38 BDSG threshold), we do not believe a DPO is currently required — we will reassess as the Service grows, and this assessment is on the counsel review list.
1. Data we collect
- Account & profile data: name, email, role (studio or teacher), and profile details you provide (e.g. studio name, location, logo; teacher experience, self-reported certifications, work areas, photos, date of birth for teachers — collected to verify the 18+ age requirement). Providing the basic account data is required to use the Service (a contractual requirement, Art. 13(2)(e) GDPR): without it we cannot create or operate your account. Optional profile details are marked as such in the app.
- Usage data: shifts posted/applied to, messages, bookmarks, notifications, and in-app activity needed to operate the marketplace.
- Billing data (studios): subscription status and Stripe customer/subscription identifiers. Card details are handled by Stripe and are never stored on Subcoach servers.
- Location/geocoding data: addresses you enter are geocoded to coordinates via Google's Geocoding API to power location matching. Matching/ranking is algorithmic (profiles are scored by distance, availability, and fit), but no decision producing legal or similarly significant effects is made solely automatically (GDPR Art. 22): studios and teachers always decide themselves whether to engage.
- Consent records: the consents you give or withdraw (terms, privacy, content policy, marketing, "do not sell", analytics), with version, timestamp, source, and best-effort region tag.
- Trust & safety data: reports you file, moderation/sanction records about your account, and an immutable audit log of key actions. A report about you is personal data we receive from the reporting user (not from you) — GDPR Art. 14 source information; we do not notify you of a report's existence where that would prejudice the investigation (Art. 14(5) balancing).
- Device & technical data: push tokens and basic diagnostics.
Self-reported credentials. Certifications and qualifications shown on profiles are provided by users and are not verified by Subcoach. See the Terms of Service, "No verification of teacher credentials."
2. How we use data & legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Operate the marketplace, match studios and teachers, provide the account | Contract (Art. 6(1)(b)) |
| Process subscriptions and payments | Contract (Art. 6(1)(b)) |
| Send transactional / service notifications | Contract / legitimate interest (Art. 6(1)(b)/(f)) |
| Security, fraud prevention, abuse moderation, audit logging | Legitimate interest (Art. 6(1)(f) — our interests: keeping the marketplace safe, preventing fraud and abuse, establishing/defending legal claims); legal obligation (Art. 6(1)(c)) |
| Marketing communications — email today; push notifications and in-app messages only if we ever introduce them, each with its own separate opt-in | Consent (Art. 6(1)(a)) — opt-in, default off. For advertising email, § 7(2) Nr. 2 UWG separately requires prior express consent and a legitimate interest cannot replace it. See §10. |
| Comply with legal, accounting and tax obligations | Legal obligation (Art. 6(1)(c)) |
3. Sharing & processors
We share personal data with:
-
Other users as inherent to the marketplace (e.g. a teacher's profile is visible to studios they apply to, and vice versa). Users who receive your information through the marketplace are themselves responsible for how they further handle it (e.g. a studio processing applicant details for its hiring decision); Subcoach does not control that downstream use. (The precise controller-role allocation is on the counsel review list.)
-
Service providers (processors) who help us run the Service, each engaged under its standard published data-processing agreement (DPA). Each of those DPAs commits the provider to handle the personal data we entrust to it on our instructions. For EU→US transfers our safeguard is the EU Standard Contractual Clauses in those DPAs. Some providers are additionally self-certified under the EU–US Data Privacy Framework; we treat that as an extra, not as the safeguard we rely on (see §7). Per-provider confirmation is a tracked open item. Stripe is a special case and is described separately below.
Processor Purpose Region Safeguard Supabase Database, auth, file storage US (us-west-1) DPA + SCCs Expo (650 Industries) Push notifications US DPA + SCCs Twilio SendGrid Transactional email US DPA + SCCs Google (Maps Platform / Geocoding) Address geocoding US DPA + SCCs Sentry (planned, not currently active) Error diagnostics US DPA + SCCs (on activation) The maintained list is kept current at
docs/compliance/sub-processors.md. -
Stripe — our payment provider, and a controller in its own right. Stripe is not only a processor for us. Stripe's own data-processing agreement (section 2) reserves to Stripe "the sole and exclusive authority to determine the purposes and means of Processing Personal Data" it receives through us, for Stripe's own purposes: monitoring, preventing and detecting fraud, limiting financial loss and security risk, running the internal processes behind its products, complying with law (including anti-money-laundering and know-your-customer checks), and analysing, improving and developing its products. Stripe is our processor only where it services the Stripe platform and provides the Stripe products and services for us and on our instructions.
What this means for you. Only studios subscribe: teachers use Subcoach free of charge and are never asked for payment details. For the subscription payment we ask Stripe to take, come to us. For everything Stripe does for its own purposes, Stripe is the controller and Stripe's privacy policy applies — a request for access, correction, erasure or objection about that processing has to go to Stripe, and we cannot decide it for them. Stripe publishes its policy and its request routes at https://stripe.com/privacy (privacy@stripe.com; data protection officer dpo@stripe.com). You may write to us first and we will point you to the right place where we can — but only Stripe can act on a request about its own processing.
Which Stripe company. Our data-processing agreement is with Stripe's Irish company Stripe Payments Europe, Limited. Stripe names a second Irish company, Stripe Technology Company, Limited, as its main establishment in Europe under the GDPR. Stripe also processes data in the United States. Stripe publishes its current list of legal entities at https://stripe.com/privacy-center/legal.
Safeguard for the US leg: the EU Standard Contractual Clauses in the Stripe agreement. Stripe is also self-certified under the EU–US Data Privacy Framework, but we do not rely on that certification (see §7). Stripe's PCI-DSS certification is a card-security standard, not a transfer mechanism.
-
For legal reasons where required by law or to protect rights and safety.
We do not sell your personal data, and we do not "sell" or "share" it for cross-context behavioural advertising as those terms are defined under California law (see §11 CCPA/CPRA).
4. Retention & deletion
We retain personal data for as long as your account is active and as needed to provide the Service. On a deletion request we begin a 30-day soft-deletion grace period; after it elapses your personal data is deleted or irreversibly anonymised. During the grace period the request can be reversed.
We retain certain records beyond deletion where required or permitted — and in anonymised form where they no longer identify you:
| Data | Retention |
|---|---|
| Active profile data | While account active; 30-day grace + purge on deletion |
| Shift / marketplace activity | 3 years |
| Messages | 1 year after the related shift |
Audit log (audit_log) |
7 years (a security/audit-accountability target aligned with SOC 2; the GDPR sets no fixed minimum — the retention basis and duration are on the counsel review list); user link SET NULL on purge |
Moderation / sanction records (moderation_actions) |
7 years; subject link SET NULL, moderator link scrubbed; reason text retained as enforcement evidence (Art. 17(3)) |
Consent records (user_consents) |
Retained as proof of consent; user link SET NULL on account purge (de-identified proof — the direct account link is removed) |
| Billing / payment data | 8 years — the German statutory minimum for accounting records (§ 257 (4) HGB / § 147 (3) AO), counted from the end of the calendar year in which the record arose (§ 257 (5) HGB). We hold payment-event records ourselves; Stripe additionally holds card data under its own retention |
Data-export files (gdpr-exports) |
Delivered via a 7-day signed link |
These windows reconcile with docs/ops/audit-retention-policy.md and the data
inventory at docs/compliance/data-inventory.md. Where multiple windows apply,
the longer window governs (e.g. audit logs are retained 7 years).
5. Your rights (GDPR)
Subject to applicable law, you may request access, rectification, erasure, restriction, portability (export in JSON); you may also object to processing based on legitimate interests and withdraw consent at any time (without affecting prior lawful processing). You can:
- Download your data in the app (Privacy & Data settings) — we email a secure, time-limited link to a JSON export of your data.
- Delete your account in the app (30-day grace, reversible during the grace period).
- Manage marketing consent and the "Do Not Sell/Share" preference in the app.
To exercise any right you can also contact us at support@subcoach.app, or via the contact form at https://subcoach.app/contact. Wherever the GDPR applies to our processing of your data, you have the right to lodge a complaint with a supervisory authority (Art. 77) — regardless of your nationality or residence; in Germany the competent authority is the data-protection authority of the operator's federal state (Berliner Beauftragte für Datenschutz und Informationsfreiheit (BlnBDI), Alt-Moabit 59–61, 10555 Berlin — https://www.datenschutz-berlin.de). You may also complain to the authority of your own habitual residence or place of work.
6. Security
We use industry-standard measures (encryption in transit, access controls, row-level security, append-only audit logging) to protect data. No system is perfectly secure; we cannot guarantee absolute security.
7. International transfers
We run Subcoach from Germany, but a good deal of your data is handled outside the European Union and the wider European Economic Area (EEA). This section sets out where your data goes and what makes each of those transfers lawful.
Your data is stored in the United States. Your account, profile, shift and message data lives in a database that Supabase runs for us (§3), and that database is hosted in the United States — in Supabase's US region (us-west-1). For most of your data, storage outside the EU/EEA is therefore the normal case rather than the exception. The safeguard we rely on for that transfer is the EU Standard Contractual Clauses in Supabase's standard data-processing agreement, which applies when we use the service; confirming and filing that paperwork with each provider is a tracked open item on our counsel review list (§3). If we move the database to a different region, we will update this section before the move.
Our other providers. The other providers listed in §3 also process data in the United States. There is no general adequacy decision for the United States — the European Commission has not found that US law protects personal data to an EU standard across the board. Its decision of 10 July 2023 covers only US organisations that hold a live certification under the EU–US Data Privacy Framework. Some of our providers, including Stripe, are self-certified under that Framework, but we do not rely on it as our safeguard: adequacy decisions for the United States have twice been struck down by the Court of Justice of the European Union, in 2015 and again in 2020. We rely instead on the Standard Contractual Clauses in each provider's data-processing agreement, which keep working whatever happens to the Framework. Stripe's PCI-DSS certification is a card-security standard, not a transfer mechanism.
Stripe acts for itself as well as for us. As §3 explains, Stripe is our processor for the subscription payment we ask it to take, but it is also a controller in its own right for its own fraud, risk, compliance and product purposes. For that part Stripe decides, and Stripe's own privacy policy applies: a request for access, correction, erasure or objection about Stripe's own processing has to go to Stripe (https://stripe.com/privacy, privacy@stripe.com, data protection officer dpo@stripe.com). We cannot decide such a request for you. Write to us first if you prefer, and we will point you to the right place.
Other users, wherever they are. Subcoach is a marketplace. What you publish — your profile, your shifts, the messages you send — becomes visible to the people you deal with, and they may be in another country. The app currently offers cities in Germany, Spain and France (inside the EU/EEA) and in the United Kingdom, Israel and the United States (outside it), and we may add more. If the person you deal with is in one of those places outside the EU/EEA, your information reaches that country. Where that other user is a separate business, that visibility is itself a transfer out of the EU/EEA. We do not put Standard Contractual Clauses in place with individual users, and we do not control what they do with what they see (§3 explains this; the precise legal roles are on our counsel review list). This list names the places the app offers — it is not a promise about where any individual user happens to be.
Adequacy, country by country. The GDPR requires us to tell you whether the European Commission has decided that a country outside the EU/EEA offers an adequate level of protection (Art. 13(1)(f)). For the three countries outside the EU/EEA named above:
- United Kingdom — adequacy decision in place. The European Commission decided on 28 June 2021 that the United Kingdom offers an adequate level of protection, and renewed that decision in December 2025. While it is in force, no additional transfer safeguard is legally required (Art. 45(1) GDPR).
- Israel — adequacy decision in place. The European Commission has decided that Israel offers an adequate level of protection (Commission Decision 2011/61/EU). While it is in force, no additional transfer safeguard is legally required. The decision does not cover every kind of transfer; where it does not reach, another basis is needed. We store no data on servers in Israel — access from Israel happens through the Service.
- United States — no general adequacy decision. As set out above, adequacy covers only organisations certified under the EU–US Data Privacy Framework. An ordinary user is not a certified organisation, so for what reaches another user in the United States there is neither an adequacy decision nor Standard Contractual Clauses. That exposure is inherent in an international marketplace; the right legal basis for it is on our counsel review list.
The Commission keeps every adequacy decision under review and can amend, suspend or withdraw it. If a decision named here stops covering a transfer we make, we will say here what we rely on instead.
Getting a copy. The Standard Contractual Clauses and the adequacy decisions named above are public documents published by the European Commission on EUR-Lex. Where a safeguard is in place for a specific provider, you can ask us for details at support@subcoach.app.
8. Children
The Service is not directed to anyone under 18 and we do not knowingly collect their data. Users affirm they are 18 or older at signup.
9. Cookies, device storage & tracking
This section covers two things: the website at subcoach.app, and the Subcoach mobile app. The German rule here is § 25 TDDDG, and it is not really a cookie rule — it covers anything stored on your device, and anything read back off it, in a browser and inside an app alike.
The website (subcoach.app). This website sets no cookies. It runs no analytics, no tracking pixels and no third-party scripts, it loads nothing from any third-party host — the fonts are served from subcoach.app itself — and it stores nothing on your device. Because nothing non-essential is written to your device and nothing is read back off it, § 25 TDDDG requires no consent here, and this site needs no cookie banner.
The app. The app uses no browser cookies, no advertising identifier, no third-party tracking and no analytics SDK. Signing in opens your device's own browser, which may set cookies of its own for the sign-in provider; Subcoach neither sets nor reads those. The app does keep a small amount of data on your device. Every item in the table below is there because the app cannot deliver what you asked it for without it — the exemption in § 25(2) Nr. 2 TDDDG:
| What is stored | Where | Why it is necessary |
|---|---|---|
| Your sign-in session and its one-time login code — access token, refresh token, and the one-time code that completes a sign-in | iOS Keychain / Android Keystore, encrypted by the operating system | Keeps you signed in so you do not log in again on every launch. Removed when you sign out. |
| A returning-device marker — a single yes/no note that this device has been signed in before, carrying no name, no account ID and no token | App storage on your device | Lets the app tell "you were signed out" apart from "you have never signed in". |
| Your preferences — app language, opportunity filters, in-app reminders you dismissed | App storage on your device | Remembers the choices you made in the app. |
| Unsaved work — a profile or shift form you started but have not submitted, and changes you made offline that are waiting to sync | App storage on your device, encrypted with a key derived for your account | So half-finished or offline work is not lost when the app closes. |
| Checkout record (studios) — a short-lived note of your subscription status, written just before you are sent to Stripe and good for about an hour | App storage on your device | Lets the app recognise your payment when Stripe sends you back. |
Push notifications. If you allow notifications, the app stores on your device the address the notification service uses to reach this handset, and reads your device's model name so a notification can be matched to the right phone. Neither happens unless you grant the notification permission first. Both are also sent to our servers and to Expo so that a notification can actually be delivered — see sections 1 and 3. They are removed from your device and from our servers when you sign out.
What else the app reads off your device. It reads files you choose to upload — a profile or studio photo from your photo library, or a certificate document — and only after you have picked them, and only for that upload. It reads your device's language setting to choose the app's starting language. Each of those reads happens only for something you started, which is the same § 25(2) Nr. 2 TDDDG exemption. The app reads no advertising ID and no unique device identifier, it does not read your device's location, and it never browses your photo library or your files on its own.
If this changes. If we add analytics, advertising, or any other storage that is not strictly necessary — on the website or in the app — we will ask for your consent first (§ 25(1) TDDDG) and update this section before it goes live.
10. Marketing communications
Email. Marketing emails are opt-in only and off by default. The switch is in the app's Privacy & Data settings and you can turn it on or off there at any time. We do not currently send marketing email. If we start, every marketing email will carry a working unsubscribe link. Two separate rules apply to advertising email, and we follow both:
- § 7(2) Nr. 2 UWG (Germany's Act Against Unfair Competition, implementing Art. 13(1) of Directive 2002/58/EC) requires prior express consent before an advertising email. It is not a data-protection rule, so a "legitimate interest" cannot be used in place of that consent — and it protects business recipients too, a studio's company mailbox exactly like a teacher's private one. A narrow statutory exception exists for advertising your own similar goods or services to existing customers (§ 7(3) UWG); we do not rely on it. We apply this standard to everyone we email, wherever you are.
- GDPR Art. 6(1)(a) and Art. 7 require consent to be freely given and recorded, and withdrawal to be as easy as giving it (Art. 7(3)). Art. 21(2) gives you an unconditional right to object to direct marketing at any time.
Push notifications and in-app messages are separate channels. Agreeing to marketing email is not agreement to marketing push, and we do not treat it as one. Today the app has a single marketing switch and it covers email only.
- We do not send promotional push or promotional in-app messages today. The push and in-app notifications we do send are service messages (e.g. a shift that matches the work areas you set, an update on an application, a new message, a payment or moderation notice).
- All push from Subcoach can be switched off at any time in your device's system settings for the app (iOS: Settings → Notifications → Subcoach; Android: Settings → Apps → Subcoach → Notifications).
- Promotional push would get its own switch, and that switch ships first. If we ever introduce promotional push or promotional in-app messages, a separate in-app opt-in and in-app opt-out for that channel goes live before the first such message, off by default. A push notification has no unsubscribe link, so that control has to live inside the app.
What counts as a service message. Transactional/service messages — account, billing, security and safety, and messages about a shift you posted, applied to, or that matches the work areas and radius you set yourself — are sent as necessary to operate the Service. They carry no promotional content. That is the test, not the label: under German case law a message is direct advertising if it promotes something, even when the same message also carries something you asked for — a customer-satisfaction survey sent together with an invoice is direct advertising (BGH, judgment of 10 July 2018 – VI ZR 225/17). So the moment we put promotional content into a service message, such as an "invite a colleague" line or an upgrade pitch, that message becomes marketing and needs your marketing opt-in first.
Our service emails carry a link labelled "Unsubscribe from notification emails." That link covers service notifications, not marketing, and essential emails (e.g. a data-export link) are sent either way. You can also ask us at support@subcoach.app to switch off non-essential notification email and push for your account — a single setting on your account controls both.
11. California privacy rights (CCPA / CPRA)
This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA").
Categories of personal information we collect (CCPA categories): identifiers (name, email); characteristics (date of birth for teachers — age verification); customer/commercial records (subscription status); internet/usage activity (in-app activity, messages you send through the marketplace); geolocation-derived data (geocoded address — whether this constitutes "precise geolocation" sensitive personal information under the CPRA is on the counsel review list); professional/employment information (self-reported teaching experience); audio/visual (profile photos, studio logos); and limited device data (push tokens). We collect these for the business purposes in §2 and retain them per §4.
No sale or sharing. We do not sell your personal information and have no plans to, and we do not "share" it for cross-context behavioural advertising, as those terms are defined by the CCPA/CPRA. We do not use or disclose sensitive personal information beyond the purposes permitted under the CCPA. (Note: Subcoach currently falls below the CCPA's "business" thresholds — this notice is provided voluntarily as best practice.)
Your California rights: the right to know/access, delete, correct, opt out of sale/sharing, and limit the use of sensitive personal information, and the right not to be discriminated against for exercising them. Because we do not sell or share, the opt-out is honoured as a standing preference.
"Do Not Sell or Share My Personal Information." US users can record a
Do Not Sell/Share preference in the app's Privacy & Data settings. We honour
it as a binding opt-out flag even though we do not sell data. Source detail:
docs/compliance/ccpa-notice.md.
To exercise these rights, contact support@subcoach.app. You may use an authorised agent. We will verify requests against your account information.
12. Changes
We may update this policy. Material changes will be notified in-app or by email, and re-acceptance will be requested where required.
13. Provider identification (Impressum, § 5 DDG)
The provider/controller is Itai Lahat (sole proprietor / Einzelunternehmer),
Germany. Full provider details (§ 5 DDG) are in the Terms of Service "Impressum"
section and at docs/legal/impressum.md.
14. Contact
Privacy questions or data requests: support@subcoach.app, or via the contact form at https://subcoach.app/contact.