CoachOS

Privacy Policy

1. Data Protection at a Glance

General Information

The following information provides a simple overview of what happens to your personal data when you visit our website or use our apps (Coach OS, Player OS). Personal data is any data that can personally identify you.

Data Collection on this Website and in the Apps

Who is responsible for data collection?

Data processing is carried out by the website and app operator. Contact details can be found in the 'Responsible Party' section of this privacy policy.

How do we collect your data?

Your data is collected in part by you providing it to us (e.g. during registration, when creating player data or using training functions). Other data is collected automatically or with your consent when visiting the website and using the apps by our IT systems. This is primarily technical data (e.g. internet browser, operating system or time of page access).

What do we use your data for?

Some data is collected to ensure error-free provision of the website and apps. Other data may be used to analyze your user behavior to improve our services. The main use is to provide training planning, player management and statistics functions.

What rights do you have regarding your data?

You have the right at any time to receive information free of charge about the origin, recipients and purpose of your stored personal data. You also have the right to request correction or deletion of this data. If you have given consent to data processing, you can revoke this consent at any time for the future. You also have the right to request restriction of processing of your personal data under certain circumstances.

2. Responsible Party

The responsible party for data processing on this website and in the apps is:

TRAX SPORTS GmbH

Schulterblatt 58

D-20357 Hamburg

Germany

Email: partnerships@coach-os.com

The responsible party is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data (e.g. names, email addresses, etc.).

3. Data Collection on the Website

Cookies

Our website uses cookies. These are small text files that your web browser stores on your device. Cookies help us make our offer more user-friendly and secure.

Some cookies are 'session cookies' that are automatically deleted after your visit ends. Other cookies remain stored on your device until you delete them. These cookies allow us to recognize your browser on your next visit.

The use of cookies is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free and optimized provision of its services.

Server Log Files

The website provider (Vercel Inc.) automatically collects and stores information in server log files that your browser automatically transmits. These are:

  • Browser type and version
  • Operating system used
  • Referrer URL
  • Hostname of the accessing computer
  • Time of the server request
  • IP address

This data is not merged with other data sources. The collection of this data is based on Art. 6 para. 1 lit. f GDPR. The website operator has a legitimate interest in the technically error-free display and optimization of its website.

Historical - Waitlist Registration (No Longer Active)

Previously, when users signed up for our waitlist, we collected the following data:

  • Email address (required)
  • Name (optional)
  • Club/Organization (optional)
  • Registration timestamp

This data was used exclusively to inform users about the product launch and to grant early access to Coach OS. The legal basis was consent according to Art. 6 para. 1 lit. a GDPR.

The waitlist is no longer active as our app is now live. Historical waitlist data has been processed in accordance with our data retention policies.

4. Data Collection in the Apps (Coach OS & Player OS)

Registration and User Account

Registration is required to use Coach OS and Player OS. We collect the following data:

Coach OS (Coaches):

  • Name
  • Email address
  • Password (encrypted storage)
  • Club/Team information
  • Profile information (optional)

Player OS (Players):

  • Name
  • Email address (for players over 16 years)
  • Date of birth (for age verification)
  • Assignment to a team/coach

Processing is based on Art. 6 para. 1 lit. b GDPR for contract fulfillment or implementation of pre-contractual measures.

Player Data and Training Information

As part of using Coach OS, we store and process the following player-related data entered by coaches:

  • Personal information: Name, date of birth, position, jersey number
  • Performance data: Ratings, scorecards, development statistics
  • Attendance data: Presence and absence at training and matches
  • Training data: Participation in exercises, training progress
  • Coach notes and comments

This data is used exclusively to provide training planning and player development functions. The legal basis is Art. 6 para. 1 lit. b GDPR (contract fulfillment).

Special Protection of Minors:

For players under 16 years of age, explicit consent from legal guardians is required. Coaches and clubs assure that they have the required consents before inviting minors to the app.

Legal guardians can request information about their children's stored data and request deletion at any time.

Data Ownership:

All player data entered by coaches and clubs remains the property of the coach or club. TRAX SPORTS GmbH uses this data exclusively to provide the services and not for its own purposes or disclosure to third parties.

Training Plans and Exercise Data

Created training plans, selected exercises and periodization data are stored in your account. This data serves to provide and improve our training functions.

The exercise database itself (exercise descriptions, videos, graphics) is protected by copyright and remains the property of TRAX SPORTS GmbH.

5. Payment Processing

For payment processing, we use various payment service providers, depending on the platform through which you subscribe to our services:

Stripe (Website Payments)

For payments via our website, we use Stripe. Provider is Stripe Inc., 510 Townsend Street, San Francisco, CA 94103, USA (for European customers: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland).

Stripe processes your payment data (credit card number, name, address). We do not store complete credit card data, but only receive an encrypted reference from Stripe.

Data processing is based on Art. 6 para. 1 lit. b GDPR (contract fulfillment). Stripe is certified under the EU-US Data Privacy Framework.

Stripe Privacy Policy: https://stripe.com/privacy

RevenueCat (Subscription Management)

For subscription management, we use RevenueCat. Provider is RevenueCat Inc., 633 Tarava St, San Francisco, CA 94116, USA.

RevenueCat processes subscription information, purchase IDs and anonymized user data to manage your subscriptions across different platforms. RevenueCat does not have access to your complete payment data.

Data processing is based on Art. 6 para. 1 lit. b GDPR (contract fulfillment).

RevenueCat Privacy Policy: https://www.revenuecat.com/privacy

Apple App Store (iOS Payments)

If you subscribe to Coach OS or Player OS via the Apple App Store, payment processing is carried out by Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA.

Apple processes your payment information in accordance with Apple's privacy policies. We only receive information from Apple about the subscription status, not about your payment details.

Processing is carried out according to Apple's terms. We have no influence on Apple's data processing.

Apple Privacy Policy: https://www.apple.com/legal/privacy/

Google Play Store (Android Payments)

If you subscribe to Coach OS or Player OS via the Google Play Store, payment processing is carried out by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Google processes your payment information in accordance with Google's privacy policies. We only receive information from Google about the subscription status, not about your payment details.

Processing is carried out according to Google's terms. We have no influence on Google's data processing.

Google Privacy Policy: https://policies.google.com/privacy

6. App Installation and Usage

Installation via Apple App Store (iOS)

When installing the apps via the Apple App Store, Apple's data protection provisions apply. Apple collects installation data, usage statistics and device information in accordance with their privacy policy.

We do not have access to this data. Your interaction with the App Store is exclusively subject to Apple's policies.

Apple App Store Privacy: https://www.apple.com/legal/privacy/data/en/app-store/

Installation via Google Play Store (Android)

When installing the apps via the Google Play Store, Google's data protection provisions apply. Google collects installation data, usage statistics and device information in accordance with their privacy policy.

We do not have access to this data. Your interaction with the Play Store is exclusively subject to Google's policies.

Google Play Privacy: https://policies.google.com/privacy

App Permissions

Our apps require certain permissions on your device:

  • Storage: For saving training plans and offline access
  • Camera (optional): For uploading profile pictures or exercise videos
  • Notifications: For training reminders and updates
  • Internet: For synchronization with the server

You can revoke these permissions at any time in the device settings. Some functions may then be restricted.

7. Customer Care and Support

Zendesk Chat and Support System

For our customer service and support, we use Zendesk. Provider is Zendesk Inc., 989 Market Street, San Francisco, CA 94103, USA (for European customers: Zendesk International Ltd., 55 Charlemont Place, Saint Kevin's, Dublin 2, D02 F985, Ireland).

When you use our chat support or create a support ticket, the following data is processed:

  • Name and email address
  • Your message and inquiry
  • Technical information (browser, operating system)
  • Conversation history
  • Timestamps

We use this data exclusively to process your inquiry and improve our support. The legal basis is Art. 6 para. 1 lit. b GDPR (contract fulfillment) or Art. 6 para. 1 lit. f GDPR (legitimate interest in customer service).

Zendesk is certified under the EU-US Data Privacy Framework and provides an adequate level of data protection.

Zendesk Privacy: https://www.zendesk.com/company/agreements-and-terms/privacy-notice/

8. Data Storage and Security

Storage Location and Infrastructure

Our servers and databases are hosted in certified data centers in the European Union. We use cloud infrastructure with the highest security standards:

  • Website hosting: Vercel (EU region)
  • Database: Encrypted cloud databases in EU data centers
  • Backup: Automatic, encrypted backups in EU regions

All data transfers are encrypted via HTTPS/TLS.

Security Measures

We use extensive technical and organizational measures to protect your data:

  • SSL/TLS encryption for all data transfers
  • Encrypted password storage (hashing with bcrypt/Argon2)
  • Access control and permission management
  • Regular security updates and patches
  • Firewall and intrusion detection systems
  • Regular security audits
  • Data backup and disaster recovery plans

Despite all security measures, 100% security cannot be guaranteed for internet transmissions.

Retention Period

We store your personal data only as long as necessary for the fulfillment of purposes:

  • Account data: For the duration of your membership + 30 days after cancellation
  • Player data: As long as the coach account is active (can be deleted at any time)
  • Payment data: According to legal retention periods (6-10 years)
  • Support tickets: 2 years after ticket closure
  • App registration data: For the duration of your membership + 30 days after deletion

After the retention period expires, data is automatically deleted unless there are legal retention obligations.

9. Your Rights

According to the GDPR, you have the following rights regarding your personal data:

Right to Access (Art. 15 GDPR)

You have the right to receive information about your stored personal data. This information includes in particular the processing purposes, the categories of data, the recipients and the planned retention period.

Right to Rectification (Art. 16 GDPR)

You have the right to have incorrect personal data corrected. You can do this directly in your account under 'Settings' or by contacting us.

Right to Erasure (Art. 17 GDPR)

You have the right to request deletion of your personal data, provided there are no legal retention obligations. After account deletion, all your data will be completely deleted within 30 days.

Right to Restriction (Art. 18 GDPR)

You have the right to request restriction of processing of your data if the accuracy of the data is disputed, processing is unlawful or we no longer need the data.

Right to Data Portability (Art. 20 GDPR)

You have the right to receive your data in a structured, common and machine-readable format. You can export your training data and player statistics at any time as CSV/JSON.

Right to Object (Art. 21 GDPR)

You have the right to object at any time to the processing of your data if processing is based on Art. 6 para. 1 lit. f GDPR (legitimate interest).

Right to Withdraw Consent

If data processing is based on your consent, you can revoke this consent at any time with effect for the future. The legality of the processing carried out until the revocation remains unaffected.

Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your data violates the GDPR.

Competent supervisory authority:

The Hamburg Commissioner for Data Protection and Freedom of Information

Ludwig-Erhard-Str. 22, 20459 Hamburg

https://datenschutz-hamburg.de

Exercising Your Rights

To exercise your rights, you can contact us at any time:

Email: partnerships@coach-os.com

Or directly in the app under: Settings > Privacy & Account

We will process your request within 30 days and inform you about the measures taken.

10. Data Disclosure and Third Parties

We only pass on your personal data to third parties if this is legally permissible or you have consented. The following third parties may have access to your data:

Hosting and Infrastructure

  • Vercel Inc. (Website hosting) - USA/EU, EU-US DPF certified
  • Cloud database providers (EU region) - encrypted data storage

Payment Service Providers

  • Stripe Inc. - USA/EU, EU-US DPF certified
  • RevenueCat Inc. - USA, Standard Contractual Clauses
  • Apple Inc. - USA (for App Store purchases)
  • Google Ireland Ltd. - Ireland (for Play Store purchases)

Customer Service

  • Zendesk Inc. - USA/EU, EU-US DPF certified

Data Transfer to Third Countries

Some of our service providers are based in the USA or other third countries outside the EU. Data transfer is based on:

  • EU-US Data Privacy Framework (DPF) certification
  • EU Standard Contractual Clauses according to Art. 46 GDPR
  • EU Commission adequacy decisions

We only work with service providers that ensure an adequate level of data protection.

No Selling of Your Data

We do not sell your personal data to third parties. We only pass on your data to the named service providers who support us in providing our services.

11. Changes to this Privacy Policy

We reserve the right to update this privacy policy to adapt it to changed legal situation or changes to our services.

Significant changes will be communicated to you by email or via an in-app notification. The current version can be found on our website at www.coach-os.app/datenschutz.

We recommend that you regularly review this privacy policy to stay informed about the protection of your data.

Contact for Privacy Questions

If you have questions about data protection, exercising your rights or this privacy policy, you can contact us at any time:

Email: partnerships@coach-os.com

TRAX SPORTS GmbH, Schulterblatt 58, D-20357 Hamburg, Germany

Last Updated: 16. Januar 2026

Privacy Policy - CoachOS | Your Data is Safe