
Privacy policy
What we collect, who holds it, and what we will never do with it.
Draft — awaiting legal review. The wording below describes how Coach Igniter actually operates, but it has not yet been reviewed by an attorney. Passages marked For counsel are open questions, not statements of policy.
01
Who we are
Coach Igniter is a trading name of The Raven Group, LLC, a Colorado limited liability company at 209 Kalamath St Unit 1, Denver, CO 80223. When this policy says “we”, it means that company. You can reach us on 720.730.2123 or by replying to any email we send you.
This policy covers coachigniter.com and everything you can reach from it: the shop, checkout, your account, the course area, the booking calendar and the affiliate program.
02
What we collect
We collect what we need to sell you something, give you what you paid for, and keep your account yours. Each item below is named by the system that actually holds it, so you can audit us against this policy.
Account data. When you sign in we store your email address and the date the account was created. Sign-in is a six-digit code sent to your email — there is no password, so we never hold one. This lives in Supabase, in a US region.
Order data. When you buy, we store your email address, what you bought, the amount charged, the currency, and identifiers issued by Stripe for the payment. We keep this in Supabase alongside a record of what your purchase unlocked.
Payment data. Card details never reach our servers. Payment is entered inside a form hosted and rendered by Stripe. We receive an identifier for the payment and the amount, never the card number.
Course progress. If you enrol in a track, we store which lessons you have marked complete and how far into a video you had reached, so it resumes where you left off.
Booking data. When you book a call, Cal.com collects your name, email, timezone and answers to any questions on the booking form, and places the event on our calendar.
Affiliate data. If you apply to the affiliate program we store your name, email, PayPal address, whatever you told us about where you would share your link, your referral code, and the commissions it earns.
Referral attribution. If you arrive through an affiliate link we store that affiliate's code in a cookie so the person who introduced you is credited. See “Cookies” below.
Consent records. If you buy something delivered immediately, we store the moment you accepted the terms and waived your cancellation right, because that is the record either of us would need if the charge were ever disputed.
Request logs. Our host, Vercel, records standard server access logs — IP address, user agent, timestamp, URL and response code — under its own retention policy.
For counsel: confirm whether Colorado's Privacy Act obligations are triggered at current volumes, and whether the CPA's universal opt-out mechanism requirement applies here.
03
What we use it for
To sell and deliver. We use your email and order record to take payment, unlock what you bought, send your receipt, and deliver the download link for any file you purchased.
To let you back in. Your email is how we send the sign-in code, and how we reattach a purchase you made before you had an account.
To run the coaching. Your progress record is what unlocks the next lesson. Your booking answers are how we prepare for your call.
To pay affiliates. Commission records exist so we can pay people what they earned and show them why.
To keep the lights on. We use logs and Stripe's own fraud signals to spot abuse and failed payments.
There is no advertising here, no behavioural profiling, no data broking, and nothing is sold. We do not build a picture of you across other websites.
04
Who else holds it
We share data with the vendors we need to operate, and only as far as each one needs.
Stripe — payments, subscriptions and billing. Receives the card and billing details you enter at checkout, directly. PCI-DSS Level 1.
Supabase — accounts, orders, entitlements, course progress, affiliate records. US region.
Resend — sends receipts, download links and sign-in codes. Receives your email address and the message content.
Cloudflare Stream — hosts course video. Playback is by short-lived signed link, so a video URL cannot be shared onward.
Cal.com — scheduling. Receives what you enter on the booking form.
Vercel — hosting and analytics. Receives standard request metadata. Its analytics is cookieless.
We will also disclose data where the law requires it, and would tell you unless legally prevented.
For counsel: confirm whether a public subprocessor list with change notice is warranted, and whether any of the above need a signed DPA given the EU/UK visitors this site attracts.
05
Cookies and local storage
This site has no cookie banner, because it sets nothing that needs consent.
Sign-in session. Set once you sign in, so you stay signed in. Strictly necessary.
Your cart. Held in your browser's local storage, never sent to us until you check out. Clearing your browser data clears it.
Referral code. If you arrive through an affiliate link, a first-party cookie stores that code for 60 days so the introduction is credited. It holds a code, not an identity, and is never used for advertising.
Analytics. We use Vercel Web Analytics, which counts page views without cookies and without any cross-site identifier. We chose it precisely so this site would not need a banner. We do not use Google Analytics.
Stripe and Cal.com set their own cookies inside their own embedded frames, governed by their policies.
For counsel: confirm whether the 60-day referral cookie is “strictly necessary” under ePrivacy for EU/UK visitors, or whether it requires consent. Our position is that it is functional rather than advertising, but it is the one judgement call in this section.
06
How long we keep it
Orders and payment records: retained for as long as US tax and accounting record-keeping requires.
Entitlements: for as long as your access lasts. Programs are sold with lifetime access, so those records persist.
Course progress: until you ask us to delete it or close your account.
Affiliate records: for as long as the account is active, and afterwards as long as needed for tax records of what we paid you.
Server logs: per Vercel's default retention.
For counsel: set explicit retention periods where you want them fixed rather than tied to necessity.
07
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Email us and we will act within 30 days.
Deleting your account removes your profile and progress. It does not remove order and payment records we are required to keep, and it ends access to anything you purchased.
You can unsubscribe from any non-essential email at any time. Receipts, download links and sign-in codes are not marketing and will still be sent.
For counsel: add the specific rights language for Colorado, California, and UK/EU visitors, and confirm the appeals process the CPA requires.
08
Security
Card data never touches our servers. There are no passwords to steal, because sign-in is a one-time emailed code. Purchased files are stored outside the public web and served only through signed links that expire in 72 hours. Course video requires a signed playback token that lasts two hours. Database access is restricted per-account by row-level security.
No system is perfect. If we ever suffer a breach affecting your data, we will tell you and the relevant regulator as the law requires.
09
Children
This is a professional training business and is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
10
Changes and how to reach us
If we change this policy we will update the date below and, for anything material, email account holders.
The Raven Group, LLC · 209 Kalamath St Unit 1, Denver, CO 80223 · 720.730.2123.
For counsel: add the effective date, the controller/processor characterisation, and a named privacy contact.