NowMatters Official

Template — not legal advice. This is placeholder boilerplate to be reviewed and completed with qualified counsel before launch. Replace every [bracketed] value.

Privacy Policy

Last updated: [DATE]. This is a draft to be reviewed by counsel before publishing.

1. Who we are

[COMPANY LEGAL NAME], [REGISTERED ADDRESS] (“we”) is the data controller for personal data processed through this platform. For a coach’s branded academy, the coach may be an independent controller for their student relationships; where that applies it is described at [COACH DPA / ARRANGEMENT]. Contact our data protection contact at [PRIVACY EMAIL] ([DPO / EU REPRESENTATIVE IF APPLICABLE]).

2. Data we collect

  • Account: name, email, role (coach/student), and your sign-in method (Google or email magic-link).
  • Learning activity: enrollments, training/action completions, XP, badges, goals, streaks, and messages you send coaches.
  • Coach content: tracks, trainings, media, articles, videos, and automations you create.
  • Payments: purchase records (amount, track, date, coupon). Card details are handled by Stripe — we never see or store full card numbers.
  • Technical & usage: pages visited, article/video views with referrer/UTM, log data, IP address, device/browser, and cookie data (see the Cookie Policy).

3. How and why we use it (and legal bases)

  • Provide the service — deliver tracks, monitor progress, run messaging (performance of a contract).
  • Process payments and prevent fraud (contract / legal obligation).
  • Send transactional email, and marketing email only where permitted (legitimate interests / consent).
  • Run track automations and give coaches aggregate insight into their students (legitimate interests).
  • Security, abuse prevention, analytics, and legal compliance (legitimate interests / legal obligation; cookie-based analytics per your cookie choice, while server-side product events — tied to internal account ids only, never cookies — run under legitimate interest). For signed-in accounts, and only after you accept analytics cookies, the analytics session is additionally linked to the internal account id and account type — never your email or name — so we can understand how the product is used.

4. Who we share it with

We share data with service providers (processors) who act on our instructions, including: hosting & analytics ([VERCEL]), database ([NEON]), payments ([STRIPE]), transactional email ([SENDGRID] / [RESEND]), rate-limiting ([UPSTASH]), error monitoring ([SENTRY]), sign-in ([GOOGLE] / email magic-link), and the AI providers behind the writing and page-generation features ([OPENAI] / [ANTHROPIC]), which receive the text a coach submits to those tools. Coaches can see the data of students enrolled in their own courses. We do not sell personal data. Confirm the current, complete sub-processor list before publishing.

5. Retention & international transfers

How long we keep things, in practice:

  • Your account and learning activity: for as long as the account is open. When you close it (Account settings → Close my account) sign-in stops immediately and nothing is destroyed for 30 days, so a mistake can still be put right; after that we either delete the account outright or permanently erase your identity from it.
  • Erased rather than deleted, where other people are involved: a coach's record is anonymized instead of removed, because deleting it would take their students' enrollments, progress and receipts with it. Name, email, photo and academy address are destroyed; what stays behind is no longer personal data.
  • Payment records: kept for at least seven years after the transaction, which bookkeeping law requires of us (in Sweden, Bokföringslagen 1999:1078). This is the exception in Article 17(3)(b) GDPR — we keep the receipt, not your identity.
  • Error monitoring: errors are tagged with an account ID and a role — never a name or an email address — and expire on our monitoring provider's retention schedule.
  • Copies held by others: when an account closes we also revoke its Google sign-in grant and remove its contact from our email provider's marketing lists.

Data is processed in the European Union and the United States. Where it leaves the EU/EEA, transfers rely on appropriate safeguards — EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

6. Your rights

Depending on your location (e.g. EU/UK GDPR, CCPA/CPRA), you may have the right to access, correct, export (portability), delete, restrict, or object to processing, and to withdraw consent at any time without affecting prior processing. You can export your data and close your account yourself from Account settings. For anything else, or if closing your account needs a hand because students depend on it, email [PRIVACY EMAIL] ; we will respond within the period required by law. You may also lodge a complaint with your local supervisory authority (in Sweden, the Integritetsskyddsmyndigheten (IMY)).

7. Security & children

We use technical and organizational measures (encryption in transit, access controls, error monitoring) to protect personal data, but no system is perfectly secure. The service is not directed to children under [AGE], and we do not knowingly collect their data.

8. Changes & contact

We may update this policy; we will post material changes here and, where required, notify you. Questions or requests: [PRIVACY EMAIL].