1. How we protect data
- All traffic is encrypted in transit with TLS; data is encrypted at rest by our hosting providers.
- Row-level security in the database means coaches and clients can only read their own data and the data of people they are actually connected to.
- Photos, videos and voice notes live in private buckets and are served through short-lived signed URLs.
- Administrative actions are logged with actor, target and timestamp.
- Payment card details never touch our servers — Stripe handles them directly.
- Chat media, voice notes and progress photos are automatically purged on a schedule.
2. Reporting a vulnerability
Email Contact@Coachpro.website with the subject "Security". Please include steps to reproduce, the impact you believe it has, and any proof-of-concept you used. We aim to acknowledge within 3 business days and to keep you updated until it is resolved.
3. Safe harbour
We will not pursue legal action against researchers who act in good faith, follow this policy, and give us a reasonable window to fix an issue before disclosing it.
- Do not access, modify, download or delete data that isn't yours.
- Do not run automated scanning that degrades service for others, and no denial-of-service testing.
- Do not use social engineering, phishing or physical attacks against us, our users or our providers.
- Use test accounts you own.
We do not currently run a paid bug bounty, but we credit reporters who want to be named.
4. Breach notification
If a personal-data breach occurs, we notify the Danish Data Protection Agency (Datatilsynet) within 72 hours of becoming aware of it where the breach is likely to result in a risk to individuals, and we notify affected users without undue delay where the risk is high.
5. Machine-readable policy
This policy is also published at /.well-known/security.txt.
