Privacy Policy — Coach'em
1. Introduction
This Privacy Policy describes how Coach'em (“App”, “Platform”, “Service”, “we”) collects, uses, stores, shares, and protects personal data of coaches, athletes, and other users (“you”, “data subject”), in compliance with Brazil’s LGPD and applicable law.
2. Definitions
- Personal data: information relating to an identified or identifiable natural person.
- Sensitive data: health-related data, including sports/wellness metrics from wearables when authorized.
- Controller / Operator / DPO: as defined under LGPD.
- Coach / Athlete: user roles in the training management workflow.
- Sports health data: aggregated workout-window metrics (e.g. heart rate), not clinical records.
3. Controller and DPO
- Legal name: V6 CORE LTDA · CNPJ 65.416.259/0001-63
- Product: Coach'em (Vision10)
- Address: Alameda Princesa Izabel, 891
- Email: suporte.vision10@gmail.com
- WhatsApp: +55 41 99252-2854
- DPO: Rodrigo Antonio Lombardo Tosi
4. Data we collect
4.1. Account data
Email, password (Firebase Auth), profile type, optional photo, subscription status.
4.2. Training data
Workouts, assignments, completion, feedback, load history, coach–athlete linkage.
4.3. Health & wearables (optional — athletes)
Only with explicit in-app consent, between Start workout and Mark completed: heart rate aggregates, calories, distance, steps, exercise sessions from Apple Health / Health Connect.
We do not access diagnoses, ECGs, or hospital records. Aggregates may be stored in Firebase and shown to the linked coach. See Health & wearables consent.
4.4–4.6. Usage, technical, and push data
App interactions, security logs, device/OS info, optional push tokens.
5. Purposes
Service delivery, optional sports health display, security, product improvement (anonymized where possible), communications, legal compliance.
6. Legal bases (LGPD)
Consent (Art. 7 I / Art. 11 I for sensitive data), contract performance, legal obligation, legitimate interest (balanced). Wearables rely on specific, highlighted consent, revocable anytime.
7. Sharing
Linked coach (training scope); operators (Firebase/Google Cloud, Apple/Google health APIs on device, RevenueCat, Expo push); authorities when required. No sale of personal data. International transfers use LGPD Art. 33 safeguards.
8. Security
TLS, Firestore rules, authentication, aggregated health only on server, monitoring and backups. See section 13 for incidents.
9. Retention
- Active account: while needed for the Service.
- Account data: up to 5 years after closure where legally required.
- Sports health: while consent is active; stop new collection on revoke; deletion on request where applicable.
- Access logs: at least 6 months.
10. Your rights (LGPD Art. 18)
Access, correction, deletion, portability, sharing information, consent withdrawal, objection. Contact: suporte.vision10@gmail.com — response within 15 days where applicable.
11–12. Cookies and notifications
Essential cookies on legal web pages; push/email for service-related messages, opt-out for marketing where offered.
13. Security incidents
Containment, ANPD notification when required, user notice without undue delay, internal records.
14–17. Changes, minors, third-party links, law
Minors require guardian consent. Brazilian law applies; EEA users may have additional GDPR rights (Arts. 15–22, 9, 44–49).
18. Related documents
19–20. Contact and effective date
suporte.vision10@gmail.com · DPO: Rodrigo Antonio Lombardo Tosi