Coachew

Privacy policy

Last updated 8 August 2026

Coachew is a coaching platform operated by HACHI SOFTWARE SYSTEMS in Malaysia. This page explains what we hold about you, why we hold it, who else can see it, and how to get it back or get rid of it. It is written to be read, not to be survived.

There are two kinds of people here, and it matters which one you are

Coaches buy a Coachewworkspace from us. For a coach's own account and billing details, we decide what happens to that information — we are the data controller, and this policy is our promise to you.

Clientsare the people a coach trains. Everything in a client's record was entered by, or on behalf of, their coach. The coach decides what is collected and what it is used for — they are the controller of it, and we process it on their instructions. If you are a client and you want your records changed or deleted, ask your coach first; they can do it in the app. You can also write to us at support@coachew.com and we will help, but we will usually need to involve your coach, because it is their record.

What we collect from coaches

  • Your account: name, email address, time zone, your role, and which workspace you belong to. Your password is stored only as a hash by our authentication provider and is never shown back to anyone, including us. Being exact, because it matters: when you create a coach workspace the password you type is posted to our server and passed straight to that provider — it is in transit through our code for the length of that one request, and we neither log it nor keep it.
  • Your workspace: its name, its web address, the brand colours you choose, and everything you create inside it (clients, sessions, exercises, packages, availability).
  • Billing: your Stripe customer and subscription references, your plan and billing term, trial and renewal dates, when you first paid, and any refund we issue.
  • A card fingerprint — a scrambled code Stripe derives from your card that cannot be turned back into a card number. We store it so that the 14-day free trial and the 30-day money-back guarantee can each be used once per card. Full detail, including how long we keep it: how we use card data.
  • What you send us: emails to support@coachew.com.

We never receive your card number.Card details are entered on Stripe's own checkout page and are never sent to, processed by, or stored on our servers.

What coaches store about their clients — including health information

This is the most sensitive data on the platform, so it is worth being specific rather than saying “fitness data”. Depending on which features a coach uses, a client record can contain:

  • Contact and admin: name, email address, phone number, time zone, tags, and free-text notes written by the coach.
  • Body and training data: bodyweight, a history of weight entries, mood recorded against a session, session notes, and every exercise logged with its sets, reps and loads.
  • Nutrition data: daily calories, protein, carbohydrate, fat, fibre and water, the individual foods logged against each day, and any nutrition targets the coach sets.
  • Homework assigned by the coach and whether it was completed.
  • Signatures.If a session is signed off, we store the signature drawn on screen — both the coach's and the client's — as an image against that session.
  • Purchases and credits: session-credit balance and its full history, what was paid, and the Stripe reference for the payment.
  • Feedback a client submits in the app, including its text and an email address if one is given. Please read this before ticking “anonymous”: that setting hides your name from the coach and admin screens, but the record still stores which account submitted it. It is anonymous to the reader, not to the database. We would rather tell you here than let you assume otherwise.

Bodyweight, nutrition and training records are health information about an identifiable person. A coach using Coachewis responsible for having a lawful basis and their client's consent to record it, for collecting no more than they need, and for keeping their own login secure. Coachew is a record-keeping tool: it is not a medical device and must not be used for diagnosis or treatment.

Workspaces are designed to be isolated from one another: the rules that decide who may read a row live in the database itself rather than in the application, so a coach is served their own clients and a client their own records.

Google data

Signing in with Google.If you use “Continue with Google”, we receive your name, email address and profile picture from your Google account so we can create and identify your login. That is all we ask for at sign-in.

Google Calendar. Connecting a new calendar is currently switched off in the app; connections made before it was switched off keep working. Where a calendar is connected, the app requests the .../auth/calendar.events permission and we store: the Google account email, the calendar identifier, the set of permissions the app asked for, an access token, a refresh token (so sync can continue while you are not using the app), and the identifiers of the calendar events we create.

We use that access for one thing: keeping your sessions and availability in step between Coachew and your calendar. That means creating, updating and deleting the events we manage, and reading your calendar so the app knows when you are busy. We do not use it to build a profile, we do not use it for advertising, and we do not sell it.

One consequence of “knowing when you are busy” is worth stating plainly: for a connected coach we keep a rolling copy of the times you are booked — including events that have nothing to do with Coachew, because that is what makes those slots unbookable by your clients. We store the times only: date, start and end. We do not store the title, description, location or attendees of an event we did not create, and your clients never see anything but “unavailable”. The copy is replaced on each sync and disappears when the connection does.

Limited Use. Coachew's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to others except as needed to provide or improve the calendar feature, to comply with the law, or as part of a merger or acquisition; and no human reads it except with your explicit consent, for security purposes, or where it has been aggregated and made anonymous.

Turning it off. You can revoke Coachew's access at any time from your Google account permissions, which immediately invalidates the tokens we hold. That works for anyone. Coaches can also stop live push updates from the Calendar page in the app; clients have no equivalent control. To have the stored connection and its tokens deleted from our records outright, email support@coachew.com — there is no self-serve button for that, for either role.

Payments

There are two separate money flows, and we handle them differently.

  • You paying us for your Coachew subscription. Stripe processes the card; we store the references and the fingerprint described above.
  • Your clients paying youfor training packages. That money goes directly to the coach's own Stripe account. We take no cut, we never hold the funds, and we store only what is needed to credit the right number of sessions to the right client.

In both cases Stripe handles card data under its own privacy policy and its own regulatory obligations.

Who else processes your data

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • Stripe — payments, both flows above.
  • Google — sign-in, and calendar sync where connected.

These providers operate internationally, so your data may be stored or processed outside Malaysia. We do not sell your data, and we do not share it with advertisers.

Cookies and browser storage

We run no advertising or analytics trackers. Your browser stores your login session (set by our authentication provider) and a small number of local values the app needs to work — for example, an invite you have not finished accepting. Clearing your browser storage signs you out; it does not delete anything from your account.

How long we keep things, and how to get rid of them

We keep your workspace and its records for as long as the account exists, because that is the point of it — a coach's training history is the product. The card fingerprint has its own retention rule, explained on the card data page.

There is no self-serve delete button yet. Email support@coachew.com and we will delete or export your data. We would rather say that plainly than point you at a control that does not exist.

Coaches: deleting your workspace deletes your clients' records with it. Those records may be the only copy of someone's training and nutrition history. Tell them before you ask us to delete, and export anything they should keep.

Your rights

Under Malaysia's Personal Data Protection Act you may ask for a copy of the personal data we hold about you, ask us to correct it, ask us to stop using it, and withdraw consent you have given. If you are in the UK or the European Economic Area, the UK GDPR / GDPR additionally give you rights of erasure, restriction, portability and objection. Write to support@coachew.com and we will answer as quickly as we can, and within 30 days at the outside. If you are a client, see the first section — we will usually need to work through your coach.

A practical note about that address. It reaches us reliably, but we do not yet send from it — a reply will come from a personal address rather than support@coachew.com. We are fixing that; in the meantime, do not treat a reply from an unfamiliar address as a phishing attempt without checking with us first.

Children

A Coachewaccount must be held by someone aged 18 or over. Coaches often train people who are younger, and that is fine — it means the login belongs to an adult, usually the parent or guardian. A coach may only record a minor's training, bodyweight or nutrition data with that parent or guardian's consent, and is responsible for obtaining it. If you believe we hold a child's data without that consent, email support@coachew.com and we will remove it.

Security

The measures we take: access rules are enforced in the database rather than left to the application to remember; traffic is served over HTTPS; passwords are hashed by our authentication provider and are never visible to us; card numbers never reach our servers.

What we will not tell you is that this makes us secure. Coachew is an early-stage product and no system is free of defects; we find and fix them on an ongoing basis. If we discover a breach affecting your data we will tell you and the relevant authority. If you think you have found a security problem, email support@coachew.com — we would much rather hear it from you.

Changes to this policy

If we change what we collect or what we do with it, we will update this page and the date at the top. We have no way to notify you automatically — the product sends no email of its own — so for a material change we will contact coaches by hand. The date at the top is the reliable signal; check it if this matters to you.

Contact

HACHI SOFTWARE SYSTEMS, Malaysiasupport@coachew.com.