Legal
Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how LaunchSite OS, LLC ("LaunchSite OS," "we," "us," "our"), a Kentucky limited liability company, collects, uses, discloses, and safeguards information when you use our health-coaching platform. We treat the privacy and security of health-related information as foundational to the product, not an afterthought.
At a glance
- We are a software tool, not a clinic. LaunchSite OS is an educational wellness and coaching platform - not a medical service, and not a HIPAA covered entity or business associate.
- Your coach controls your records. For information a client enters or a coach records in a workspace, the Coach is the decision-maker (controller) and we act as their service provider (processor).
- We never sell your data, we never share it for targeted advertising, and we never use client health-related information to train AI models.
- Every vendor is published. The full list of companies that process data on our behalf, and what each one can see, is at /privacy/subprocessors - currently 26 providers.
- Access is locked down by design - encryption in transit and at rest, database row-level security, and server-side role checks on every request.
- You have rights to access, correct, export, and delete your information, and to withdraw consent for consumer health data. See Your privacy rights.
1. Who we are and our role
LaunchSite OS provides software that lets wellness, fitness, and functional-health coaches ("Coaches") manage their clients and their practice. It is an educational wellness and coaching tool - not a medical service, and not a HIPAA "covered entity" or "business associate." The platform is not intended for use by HIPAA covered entities, or to create, receive, or process Protected Health Information (PHI) on a covered entity's behalf. The client information handled here is treated as sensitive consumer health-related information and protected accordingly, but it is governed by general consumer-privacy and consumer-health-data laws, not HIPAA. For how we handle "consumer health data" and your related rights under laws like the Washington My Health My Data Act, see our Consumer Health Data Privacy Policy.
Our role depends on the information involved:
- Coach account, billing, and platform-usage information - we are the controller (we decide how it is used to operate the service).
- Client information, leads, and messages inside a Coach's workspace - the Coach is the controller of that information and we act as a service provider / processor on the Coach's behalf, handling it only to deliver the service and on the Coach's documented instructions. Clients and leads should direct requests about their own information to their Coach; we help Coaches fulfil them.
The table in Section 2 marks which role applies to each category.
2. Information we collect
The categories below are the complete set the platform handles. Categories marked optional exist only if you or your coach turn the relevant feature on.
Account and profile information
- Name, email address, and password (stored only as a salted hash)
- Coach practice name, brand, logo, and business profile including the postal address used in marketing footers
- Team membership and role (coach, team member, client)
Controller: LaunchSite OS · Sources: Directly from you at signup; From the coach or team owner who invited you; From a system the coach connected to their own workspace with a Partner API key
Client wellness and health-related records · sensitive
- Check-ins, symptoms, complaints, and wellness system-status grades
- Weight, body composition, blood glucose, temperature, and similar self-reported measures
- Supplement, peptide, nutrition, and training programming
- Menstrual or reproductive information, where a client chooses to provide it as intake
- Coach notes and goals
Controller: the Coach (we process on their behalf) · Sources: Directly from the client; Entered or uploaded by the coach on the client’s behalf; Sent by a system the coach connected with a Partner API key, or read back out by it
Pre-participation health screening · sensitive · optional
- Answers to the standard PAR-Q+ readiness questions (heart condition, chest pain, dizziness, chronic conditions, prescribed medication, joint or bone problems, and medically supervised activity)
- Whether any answer was "yes", and the date the questions were answered
- The coach’s decision about a flagged screening, the reason they recorded for it, and who made it
Controller: the Coach (we process on their behalf) · Sources: Directly from the client, through the client portal
Lab files and extracted markers · sensitive
- Uploaded lab PDFs and images (for example serum, gut, hormone, or mycotoxin panels)
- Marker names, values, and reference ranges extracted from those files
Controller: the Coach (we process on their behalf) · Sources: Uploaded by the client or the coach
Progress photos and movement video · sensitive
- Progress and body-composition photos
- Lift and movement video submitted for form review
- Pose landmarks derived from that video to draw form feedback
Controller: the Coach (we process on their behalf) · Sources: Uploaded by the client or the coach
Connected device and wearable metrics · sensitive · optional
- Daily aggregates for steps, sleep duration, resting heart rate, and heart-rate variability
- Recovery, strain, readiness, and similar scores produced by the device maker
Controller: the Coach (we process on their behalf) · Sources: Apple Health, at the client’s direction, after Apple’s own permission prompt; Whoop, Oura, Fitbit, or Ultrahuman, after the client authorises the connection
Messages and conversation content
- In-app messages between a coach and a client
- SMS, WhatsApp, Instagram, and LinkedIn conversations connected to the coach’s inbox
- Website chat-widget conversations
- Consent state and opt-out history for each phone number and email address
Controller: the Coach (we process on their behalf) · Sources: Sent by you; Received from the person you are talking to; Delivery receipts from the carrier or platform
Voice input, call recordings, transcripts, and synthetic voice · sensitive · optional
- Recordings and transcripts of consults and coaching calls the coach chooses to capture
- Derived call metrics about the coach’s own delivery (talk ratio, questions asked, whether a next step was set)
- Audio generated from a configured synthetic voice
- Microphone audio captured while a coach uses a voice feature — the Cowork consoles, voice check-in, and dictation — and sent for transcription
- A short segment recorded while the assistant is speaking, if the coach has turned on “Talk to interrupt”, so that a sentence spoken over the assistant is not lost
Controller: the Coach (we process on their behalf) · Sources: Uploaded or captured by the coach; Meeting platform transcripts the coach imports; The coach’s microphone during a voice session they started
Prospect, lead, and CRM contact information
- Name, email, phone, company, and stage for people in a coach’s pipeline
- Form submissions, booking requests, business-card scans, and QR-code captures
- UTM campaign, medium, content, and term recorded when a lead arrives from a link
- Notes, tasks, deals, estimates, and activity history the coach records
Controller: the Coach (we process on their behalf) · Sources: The person, when they complete a public form, book a call, or scan a card; The coach, when they add or import a contact
Subscription and payment information
- Plan, subscription status, invoices, and billing email
- Limited card metadata (brand, last four digits, expiry) returned by the payment processor
- For coaches who sell through the platform: payout account status and marketplace transaction records
- For a call booked on a coach’s public booking page: the amount, currency, whether it was paid, and the processor’s session identifiers, linked to the appointment it paid for
Controller: LaunchSite OS · Sources: You, at checkout; Our payment processor; A visitor to a coach’s public booking page, when that page charges for the call
Campaign and engagement records
- Which campaign emails and messages were sent to whom, and when
- Delivery, bounce, complaint, and unsubscribe events reported by the sending provider
- Which members a coach put on a retention list, the stated reason, and whether a staff member contacted or skipped them
- A staff member’s own note about a contact attempt, and the date it was made
- Whether a member agreed to marketing on a given channel, when, what wording they were shown, and whether they later withdrew it
- A member’s unsubscribe token, so a one-click unsubscribe works without them signing in
Controller: the Coach (we process on their behalf) · Sources: Generated when the coach sends a campaign; Reported back by the email or SMS provider; Recorded by a staff member working a LaunchPoint retention list; Captured from the member themselves — at the desk, on a form, or by their own unsubscribe
AI prompts, outputs, and workspace memory · sensitive
- The workspace content sent to an AI provider to produce a requested output
- Drafts, summaries, and suggestions the AI returns
- Saved AI memories and embeddings derived from workspace content
- A per-coach record of AI usage and cost against the monthly credit limit
Controller: the Coach (we process on their behalf) · Sources: Generated when a coach or client uses an AI-assisted feature
Usage, device, and diagnostic data
- Log data, IP address, browser and device type, and actions taken in the app
- Error reports, scrubbed of request bodies, cookies, and personal data
- Push notification tokens for the web and mobile apps
- Audit records of privileged actions inside a workspace
Controller: LaunchSite OS · Sources: Automatically, as you use the platform
Workforce and employment records (LaunchPoint ERP) · optional
- Employee name, preferred name, work email, phone, employment type, and hire and end dates
- Assigned work sites, shifts, clock-in and clock-out records, and approved hours
- Pay rates and labor cost, visible only to those the account owner has granted access
- Job title, department, reporting line, team membership, and a written description of the role
- A sign-in account for an employee, where the account owner chooses to issue one
Controller: the Coach (we process on their behalf) · Sources: Entered by the account owner or an authorised administrator; Recorded by the employee at a time-clock device
Building access records (LaunchPoint ERP) · optional
- A door credential — a fob or card serial, a phone token, or a door PIN, each stored only as a one-way hash
- Which door was used, at which site, and the exact time it was used
- Whether entry was allowed or refused, and the reason it was refused
- Attempts by a credential that is not recognised, recorded without a name because there is none
- Whether anybody was rostered on at the time
Controller: the Coach (we process on their behalf) · Sources: Issued by the account owner or an authorised administrator; Recorded by a door reader when a credential is presented
Children and collection records (LaunchPoint ERP) · sensitive · optional
- A child’s name and date of birth, held so the room’s supervision ratio can be computed
- Which member is the child’s guardian
- The adults that guardian has authorised to collect the child, with a relationship and phone number
- Each check-in and check-out: the time, who handed the child over, and who collected them
- A written reason where a child was released to somebody not on the authorised list
Controller: the Coach (we process on their behalf) · Sources: Entered by the account owner or their staff from what the guardian tells them at the desk
Bank statement records (LaunchPoint ERP) · optional
- A name for a bank account, the bank it is held at, and the last four digits of its number — never the full number
- Imported statement lines: the date, the amount, and the description the bank wrote, which often names the counterparty
- Which line was matched to which bill, expense or ledger entry, by whom, and when
- Which months the account owner has closed, and when a closed month was reopened
Controller: the Coach (we process on their behalf) · Sources: A statement file the account owner exports from their own bank and imports themselves
We do not buy personal information from data brokers. Where information reaches us from a device or an outside service - Apple Health, a wearable, a connected calendar or inbox, a payment processor - it does so because you authorised that connection, and you can disconnect it.
California statutory categories
For California residents, the categories above map to the statutory categories in the CCPA/CPRA as follows. We collect each of these for the business purposes in Section 4, disclose them only as described in Section 8, and sell or share none of them.
- Identifiers (name, email, phone, IP address, account identifiers) - collected as: Account and profile information; Messages and conversation content; Prospect, lead, and CRM contact information; Subscription and payment information; Campaign and engagement records; Usage, device, and diagnostic data; Workforce and employment records (LaunchPoint ERP); Building access records (LaunchPoint ERP); Children and collection records (LaunchPoint ERP); Bank statement records (LaunchPoint ERP).
- Personal information in customer records (Cal. Civ. Code § 1798.80(e)) - collected as: Account and profile information; Client wellness and health-related records; Pre-participation health screening; Lab files and extracted markers; Connected device and wearable metrics; Messages and conversation content; AI prompts, outputs, and workspace memory; Workforce and employment records (LaunchPoint ERP); Children and collection records (LaunchPoint ERP).
- Characteristics of protected classifications - collected as: Children and collection records (LaunchPoint ERP).
- Commercial information (products or services purchased or considered) - collected as: Prospect, lead, and CRM contact information; Subscription and payment information; Bank statement records (LaunchPoint ERP).
- Biometric information - collected as: Voice input, call recordings, transcripts, and synthetic voice.
- Internet or other electronic network activity - collected as: Messages and conversation content; Prospect, lead, and CRM contact information; Campaign and engagement records; Usage, device, and diagnostic data.
- Geolocation data - collected as: Building access records (LaunchPoint ERP).
- Audio, electronic, visual, or similar information - collected as: Progress photos and movement video; Voice input, call recordings, transcripts, and synthetic voice.
- Professional or employment-related information - collected as: Account and profile information; Workforce and employment records (LaunchPoint ERP).
- Inferences drawn from the above - collected as: Client wellness and health-related records; Prospect, lead, and CRM contact information; AI prompts, outputs, and workspace memory.
- Sensitive personal information (including health information) - collected as: Client wellness and health-related records; Pre-participation health screening; Lab files and extracted markers; Progress photos and movement video; Connected device and wearable metrics; Voice input, call recordings, transcripts, and synthetic voice; AI prompts, outputs, and workspace memory; Children and collection records (LaunchPoint ERP).
Statutory categories not listed - notably precise geolocation - are not collected.
3. Information we deliberately do not collect
- We do not store full payment card numbers; the payment processor handles them.
- We do not use third-party advertising cookies, tracking pixels, or cross-site tracking, and no advertising network receives your data.
- We do not collect precise geolocation.
- We do not collect raw continuous sensor streams from wearables - only the daily aggregates and scores needed for coaching trends.
4. How we use information, and our legal basis
We use each category only for the purposes listed for it. Where the GDPR or UK GDPR applies to you, the legal basis is stated alongside.
Account and profile information
- Create and secure your account
- Authenticate you and enforce role-based access
- Send service, security, and account notices
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(f) legitimate interests in securing the service
Client wellness and health-related records
- Operate the coaching workspace and the client portal
- Produce coaching outputs: grades, programs, summaries, reminders, progress tracking
- Enable coach-to-client communication
Legal basis: Art. 6(1)(b) performance of the coaching contract, with Art. 9(2)(a) explicit consent for health data obtained by the Coach as controller
Pre-participation health screening
- Establish whether a client should speak to a doctor before starting physical activity
- Require a coach to review a flagged answer before that client books a class themselves
- Give the business a record of who has been screened and who has not
Legal basis: Art. 6(1)(b) performance of the coaching contract, with Art. 9(2)(a) explicit consent for health data obtained by the Coach as controller
Lab files and extracted markers
- Produce lab summaries and overlays for coaching
- Track markers over time
Legal basis: Art. 6(1)(b) with Art. 9(2)(a) explicit consent obtained by the Coach
Progress photos and movement video
- Visual progress tracking
- Coach form review and feedback
Legal basis: Art. 6(1)(b) with Art. 9(2)(a) explicit consent obtained by the Coach
Connected device and wearable metrics
- Show source-labeled trends to the client and their coach
- Inform coaching decisions
Legal basis: Art. 6(1)(a) consent, with Art. 9(2)(a) explicit consent for health data
Messages and conversation content
- Deliver the message and show the conversation
- Prove consent and honour STOP, unsubscribe, and quiet-hours rules
- Detect and prevent abuse of the messaging channels
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation for consent and opt-out records
Voice input, call recordings, transcripts, and synthetic voice
- Help the coach review and improve their own calls
- Produce audio playback of written content
- Turn what the coach said into the text of their request
Legal basis: Art. 6(1)(a) consent of every party to the call, obtained by the Coach; Art. 6(1)(f) legitimate interests in the coach’s own performance review
Prospect, lead, and CRM contact information
- Run the coach’s pipeline
- Attribute which campaign produced a lead
- Follow up with the person
Legal basis: Art. 6(1)(f) legitimate interests of the Coach in managing their own business enquiries; Art. 6(1)(a) consent where required for electronic marketing
Subscription and payment information
- Take payment and manage subscriptions
- Pay out marketplace sellers
- Let a coach charge for a consultation booked on their own booking page, and show them which bookings are paid
- Meet tax and accounting obligations
Legal basis: Art. 6(1)(b) performance of a contract; Art. 6(1)(c) legal obligation for tax and accounting records
Campaign and engagement records
- Show the coach whether a campaign delivered
- Suppress future sends to people who unsubscribed or complained
- Let a coach see who has already been contacted, so the same member is not approached twice
- Report how many contacted members returned to a class
Legal basis: Art. 6(1)(f) legitimate interests in measuring delivery; Art. 6(1)(c) legal obligation for suppression records
AI prompts, outputs, and workspace memory
- Produce the output that was requested
- Keep AI features grounded in the coach’s own workspace
- Reconcile stored memories when newer information contradicts them
- Meter usage
Legal basis: Art. 6(1)(b) performance of a contract, inheriting the Art. 9 condition of the underlying record
Usage, device, and diagnostic data
- Keep the service secure and reliable
- Diagnose faults
- Deliver notifications you asked for
- Investigate abuse
Legal basis: Art. 6(1)(f) legitimate interests in the security, integrity, and reliability of the service
Workforce and employment records (LaunchPoint ERP)
- Operate the employer’s rota, timesheet, and labor-cost reporting
- Show the organization’s structure — who works where and who reports to whom
- Authenticate an employee and decide which parts of the organization they may read
- Keep an audit record of changes to employment, access, and approved hours
Legal basis: Art. 6(1)(b) performance of the employment relationship and Art. 6(1)(f) legitimate interests of the employer in operating and staffing the business, in each case with the employer as controller
Building access records (LaunchPoint ERP)
- Decide whether a member or employee may enter the building at that moment
- Answer who was in the building after an incident, an injury, or a theft
- Show the account owner which entries happened while nobody was on shift
Legal basis: Art. 6(1)(b) performance of the membership or employment relationship for entry itself, and Art. 6(1)(f) legitimate interests of the operator in the security of their premises and the safety of the people in them, with the operator as controller
Children and collection records (LaunchPoint ERP)
- Make sure a child is only released to an adult their guardian authorised
- Keep the room within its staff-to-child supervision ratio
- Answer who had a child, and when, after an incident or a dispute
Legal basis: Art. 6(1)(f) legitimate interests of the operator and, decisively, of the child in being released only to an authorised adult — an interest that a child cannot assert for themselves, which is why the guardian supplies the record and the operator is controller. Art. 6(1)(c) legal obligation where local childcare regulation requires an attendance and collection register. No Art. 9 processing: no health data about a child is collected.
Bank statement records (LaunchPoint ERP)
- Check the business’s own books against its bank statement
- Show what moved on the bank with no record behind it, and what was recorded and never settled
- Produce a general journal and trial balance the account owner can give to their accountant
Legal basis: Art. 6(1)(f) legitimate interests of the business in keeping accurate books, and Art. 6(1)(c) legal obligation where accounting and tax law requires records to be reconciled and retained, with the account owner as controller
Across all categories we also use information to secure the platform, prevent and investigate abuse, meet our legal obligations, and enforce our terms.
We do not sell or rent personal information, we do not share it for cross-context behavioural advertising, and we do not use client health-related information for advertising, targeted advertising, or profiling that produces legal or similarly significant effects. We do not use client data to train AI models, and our AI providers are contractually barred from doing so.
5. AI-assisted features
Some features - draft program suggestions, lab-result summaries, message drafts, transcription, and the coach copilot - are generated with the help of AI providers. The providers we use are listed at /privacy/subprocessors. When you use these features, the relevant workspace data is sent to a provider solely to produce the output you requested. By contract, your data is not used to train or improve any AI model and is not retained by the provider for its own purposes.
AI features operate only on your own workspace data. Output is assistive and informational - a drafting aid for the Coach, not medical advice - and the Coach reviews and remains responsible for any decision. Client-authored content is treated as untrusted input when it enters a prompt, and actions that change data run only from an explicit, authorised instruction.
6. How we protect information
- Encryption of data in transit (HTTPS/TLS) and at rest at the database and storage layers.
- Database row-level security so a Coach can reach only their own clients, and a client only their own records.
- Server-side enforcement of coach and client roles on every request; authorisation roles are never taken from user-editable data.
- Health files, lab uploads, and progress photos are held in private storage and served only through authenticated, short-lived access - never a public or long-lived URL.
- Hardened HTTP security headers (HSTS, anti-clickjacking, MIME protection).
- Least-privilege, scoped access for automated and AI tooling, and audit records of privileged actions.
No method of transmission or storage is perfectly secure, but we work to protect your information using safeguards appropriate to its sensitivity.
7. Service providers (subprocessors)
We use 26 third-party providers to operate the platform. Each one is published, with its purpose, its processing region, and the categories of data it can see, at /privacy/subprocessors. We enter into data-processing terms with each, none may use client data for its own purposes or to train AI models, and providers that only operate once you connect them are marked as such.
We maintain that page as the current register rather than a list "available on request." If you are a Coach and want notice of changes to it, email privacy@launchsite-os.com.
8. Sharing and disclosure
We disclose information only:
- to the Coach who owns the client or lead relationship, and to team members that Coach has authorised;
- to subprocessors under contract, as described above;
- to a third-party service you connected, to the extent needed to provide that feature;
- to comply with law or valid legal process - we assess each request, require valid process, and will notify the affected user unless legally prohibited;
- to protect the rights, safety, and security of users and the platform, or to investigate abuse; or
- in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honour this policy and will notify you of any material change.
We will not otherwise disclose client health-related information without authorisation.
9. Data retention
We keep information only as long as it is needed for the purpose it was collected for:
- Account and profile information - While the account is active, then deleted or de-identified generally within 90 days of closure, subject to tax and legal holds.
- Client wellness and health-related records - While the coach’s workspace holds the record. Coaches may export or delete a client’s records at any time; deleted records are purged from active systems and roll off backups on the backup schedule.
- Pre-participation health screening - Held while the coach’s workspace holds the client record, so the business can show who was screened before training. Deleting the client deletes their answers. Answers are never copied into the activity log — only whether a screening was flagged — and are never sent to an AI model.
- Lab files and extracted markers - Held in private storage while the workspace holds the record; deleted on client or coach request.
- Progress photos and movement video - Held in private storage while the workspace holds the record; deleted on client or coach request.
- Connected device and wearable metrics - Disconnecting a device stops future sync and removes the imported aggregates from the active workspace. Revoking access at the device maker separately stops new reads.
- Messages and conversation content - Conversations are held while the workspace holds them. Opt-out records are kept indefinitely on purpose — an erased opt-out is an opt-out that stops working.
- Voice input, call recordings, transcripts, and synthetic voice - Recordings and transcripts are held while the coach keeps them and are deleted on request. Derived call metrics about the coach are retained without the underlying transcript where the coach deletes it. Microphone audio captured for a voice feature is sent for transcription and is not stored by us afterwards — what is kept is the resulting text, as part of the conversation it belongs to. The segment recorded while the assistant is speaking is discarded in the browser as soon as that reply finishes, and is only ever sent anywhere if the coach actually interrupted; it is never captured at all when “Talk to interrupt” is off.
- Prospect, lead, and CRM contact information - While the coach keeps the record. A person may ask the coach to export or erase their record; erasure keeps only a non-identifying audit entry proving the erasure happened.
- Subscription and payment information - Transaction records are retained for the period tax and accounting law requires, typically seven years.
- Campaign and engagement records - Engagement events roll off with the campaign. Suppression and complaint records are kept indefinitely so they keep working. A member’s consent log (client_marketing_consents) is APPEND-ONLY and kept for the life of the workspace: a withdrawal is a new row rather than a deletion, because “we stopped when they asked” is only provable if the record of them asking survives — and deleting the earlier grant would destroy the evidence that the send before it was lawful.
- AI prompts, outputs, and workspace memory - Prompts and outputs are held with the workspace record they belong to. No AI provider we use is permitted to retain them for its own purposes or to train models on them. A saved memory a coach deletes is recoverable for 30 days and is then permanently removed. A memory that newer information replaces is NOT deleted straight away: it is marked superseded, stops being used in any answer, and is kept alongside what replaced it — with a record of why it was replaced — so the change is visible and can be undone. That history is kept for 12 months and then permanently deleted. Deleting a memory removes it; superseding one defers removal. Where a client moves to a different coach, the previous coach’s saved memories about them are deleted outright.
- Usage, device, and diagnostic data - Operational logs are retained on a rolling short-term schedule. Audit records are retained for the life of the workspace.
- Workforce and employment records (LaunchPoint ERP) - For the life of the employer’s workspace. Employment records are retired rather than deleted — an employee’s status is set to terminated and the record is kept as employment history. An employee sign-in account is deleted when the account owner revokes it, and revoking it also deletes that person’s access grants.
- Building access records (LaunchPoint ERP) - For the life of the operator’s workspace. A revoked credential is deactivated rather than deleted, and door records are kept rather than trimmed, because the question they answer — who was in the building on a given night — is usually asked long afterwards.
- Children and collection records (LaunchPoint ERP) - Collection records are kept for the life of the operator’s workspace rather than trimmed, because the question they answer — who collected this child, on this day — is asked long afterwards and usually only when something has gone wrong. A child who stops attending is deactivated, not deleted, for the same reason; an authorised adult is revoked rather than removed, so who was permitted last March stays answerable.
- Bank statement records (LaunchPoint ERP) - For the life of the account owner’s workspace. Deleting an import removes its lines and their matches; once a month is closed, imports inside it cannot be deleted, because a reconciliation whose evidence can be removed is not one. Accounting records are typically retained for the period tax law requires.
In general, when an account closes we delete or de-identify its information within 90 days, subject to legal, tax, and security retention obligations, and backups are purged on a rolling schedule. Coaches control client records within their workspace and may export or delete them at any time.
10. Your privacy rights
Depending on where you live, you may have the right to:
- Know what personal information we hold and obtain a copy of it;
- Correct inaccurate information;
- Delete your information;
- Obtain a portable copy of information you provided;
- Limit the use of sensitive personal information;
- Opt out of sale, sharing, or targeted advertising - we do none of these, so there is nothing to opt out of;
- Withdraw consent for the processing of consumer health-related data;
- Object to processing, or restrict it, where the GDPR applies; and
- Not be discriminated against for exercising any of these rights.
These rights come from laws including the California Consumer Privacy Act (CCPA/CPRA), the Kentucky Consumer Data Protection Act, the Washington My Health My Data Act, other state comprehensive privacy laws, and - where applicable - the EU and UK GDPR.
How to exercise them. If your information sits in a Coach's workspace - as a client or as someone in a Coach's pipeline - contact that Coach first. They control that workspace, they can export or erase your record in the app, and they are who you actually have a relationship with. If you do not know who holds your information, or a Coach does not respond, contact us at privacy@launchsite-os.com and we will help.
Coaches and other account holders may contact us directly at privacy@launchsite-os.com. We verify every request against the information we already hold, and respond within the timeframe applicable law requires (generally 45 days, extendable where the law allows). An authorised agent may submit a request with proof of authority. If we decline a request you may appeal by replying to our decision; we will reconsider and respond as the law requires, and will tell you how to complain to your state Attorney General or supervisory authority.
One deliberate exception: opt-out, unsubscribe, and complaint records are not erased. Deleting the record of an opt-out would cause messaging to that person to resume, which is the opposite of what the request intends. We keep the minimum needed to keep the suppression working.
11. Cookies and tracking
We use only strictly necessary cookies, for authentication, session management, and remembering whether the app is running embedded. We do not use third-party advertising cookies or cross-site tracking, and we do not run analytics that profile you across sites. Because we do not track for advertising, "Do Not Track" and Global Privacy Control signals do not change what we collect - there is nothing for them to switch off.
Where a Coach adds their own tracking to a page they publish through the platform, that is the Coach's decision and their responsibility to disclose.
12. Children
The platform is not directed to children under 13 (or the applicable age in your jurisdiction) without verifiable parental or guardian consent obtained by the Coach. We do not knowingly collect information from children without that consent; if you believe we have, contact us at privacy@launchsite-os.com and we will delete it. We do not knowingly sell or share the personal information of anyone under 16 - we do neither for anyone.
13. International users and transfers
The platform is operated from the United States (Kentucky), and information is processed there. If you access it from outside the United States, your information will be transferred to and processed in the United States, which may not provide the same level of protection as your home country.
If the EU or UK GDPR applies to you: we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) for transfers, together with the technical and organisational measures described in Section 6. Coaches established in the EEA or UK who need a Data Processing Addendum with those clauses can request one at privacy@launchsite-os.com. We have not appointed an Article 27 representative; if you need one in place before using the platform, contact us first.
14. Breach notification
If we discover a breach of security affecting health-related or other personal information, we will notify affected individuals, affected Coaches, and any authorities as required by applicable law - including the U.S. FTC Health Breach Notification Rule, applicable state breach-notification laws (including Kentucky's), and the GDPR's 72-hour rule where it applies - within the timeframes those laws require.
15. Changes to this policy
We may update this policy. Material changes will be posted here with a revised "Last updated" date, and where required by law we will provide additional notice before they take effect. The subprocessor register is updated as vendors change; that page carries its own date.
16. Contact
Privacy requests and questions about this policy: privacy@launchsite-os.com. General support: support@launchsite-os.com. LaunchSite OS, LLC (Kentucky, USA). Our mailing address is available on request.
This document describes our practices and safeguards. It is not legal advice. LaunchSite OS is a wellness and coaching tool and is not a HIPAA covered entity or business associate; Coaches are responsible for handling their clients' information consistent with the consumer-privacy and consumer-health-data laws that apply to them.