Privacy Policy
1. Introduction
This Privacy Policy describes how True Light Collective ("we", "our", "us") collects, uses, and protects your personal data when you visit our website, contact us, or use our coaching services. We follow the principles of the General Data Protection Regulation (GDPR) and applicable local privacy laws.
Data Controller:
True Light Collective
Add your business address in your settings to display it here.
support@example.com
2. Information We Collect
Information you give us directly
- Name, email address, and contact details when you sign up, book a session, or contact us through a form on this website.
- Information you share during coaching sessions, in messages, in onboarding questionnaires, and through any documents you submit.
- Payment details, processed by our payment providers — we receive only the last four digits of your card and a transaction reference.
Information collected automatically
- Device and browser information, IP address, and rough geographic location.
- Usage patterns within the platform — pages visited, features used, content viewed.
- Cookies and similar technologies. Where required, we ask for your consent before placing non-essential cookies.
3. How We Use Your Information
We process your data on the following legal bases under Article 6 of the GDPR:
- Contract — to provide the coaching services you have requested, including session scheduling, programs, and ongoing communication.
- Consent — to send marketing emails, run optional analytics, and other activities you have specifically opted into. You can withdraw consent at any time.
- Legitimate interests — to keep the service secure, prevent fraud, improve features, and respond to support requests.
- Legal obligation — to comply with tax, accounting, and other applicable laws.
4. Sub-processors
True Light Collective relies on the following sub-processors to operate the coaching service. Each is bound by a Data Processing Agreement and applies appropriate safeguards (such as Standard Contractual Clauses) where data is transferred outside the EU/EEA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Coachful (Influencee Agency OÜ) | Platform infrastructure, hosting, support tooling | Estonia / EU |
| Google Firebase (Google LLC) | Authentication, database, file storage | USA |
| Vercel Inc. | Application hosting and edge delivery | USA |
| Stream.io Inc. | Chat and video messaging with clients | USA |
| Resend, Inc. | Email delivery (transactional + broadcasts) | USA |
| Anthropic PBC | AI features (Claude API) used by the Coachful assistant and content tools | USA |
5. International Data Transfers
Several of our sub-processors are based outside the European Economic Area, primarily in the United States. Where this is the case, we rely on the European Commission's Standard Contractual Clauses (SCCs), the EU–U.S. Data Privacy Framework where applicable, and supplementary measures such as encryption in transit (TLS 1.2+) and at rest.
6. Your Rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your data ("right to be forgotten")
- Request a portable copy of your data
- Restrict or object to certain processing
- Withdraw consent at any time, where consent is the basis for processing
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email us at support@example.com. We respond to verified requests within 30 days.
7. Cookies and Tracking
This website uses cookies and similar technologies for essential functions (such as remembering your sign-in) and, where you consent, for analytics and marketing performance. You can change your cookie preferences at any time through your browser settings.
8. Data Retention
We keep your personal data for as long as your coaching engagement is active and for a reasonable period afterwards to support follow-up, recurring sessions, and tax record-keeping obligations. Marketing data is deleted when you unsubscribe. You can ask us to delete your data sooner — see Section 6.
9. Children's Privacy
This service is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to This Policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page, and we will notify clients of significant changes by email.
11. Contact
For questions about this Privacy Policy or how your data is handled, contact us at support@example.com.
