Privacy Policy — Marketing – The Coach Company (internal app)
This policy covers only the internal “Marketing – The Coach Company” Google Ads dashboard — not The Coach Company’s public coach hire booking websites, which have their own separate privacy policy.
Who this application is for
This application is used exclusively by The Coach Company’s own marketing staff. It has no public users and no public sign-up.
What data it processes
- Google Ads account data — spend, campaign, ad group, and keyword performance for the Google Ads accounts the company advertises with, read via the Google Ads API.
- Lead and booking data — quote/booking records exported from the company’s own CRM/booking system for the company’s own websites, imported by an admin. This includes the customer’s email address and the value of their booking.
- Consent for using this data with Google Ads — the customers whose data is included here submitted it directly through the company’s own quote forms, under the company’s public-facing privacy policy, which covers using that information for the company’s own advertising and remarketing purposes, including Google Ads Customer Match and offline conversion measurement.
How the data is used
- To report on which Google Ads campaigns produced real bookings, internally, for the marketing team.
- To upload the company’s own conversion values back to the company’s own Google Ads accounts, so Google’s bidding tools can optimize toward real bookings rather than just quote submissions.
- To upload hashed (SHA-256) customer email addresses to the company’s own Google Ads Customer Match audiences, for the company’s own remarketing and audience-building. Emails are hashed before leaving this application and are never sent to Google in plain text.
What this application does not do
- It does not sell, rent, or share this data with any third party outside Google Ads (used only to serve the company’s own advertising).
- It does not use this data for any purpose beyond the company’s own marketing measurement and advertising, described above.
- It has no public-facing data collection of its own — all customer data originates from the company’s existing quote/booking forms, not from this application.
Data protection and security measures
The customer email addresses and booking values processed here are treated as sensitive data. Specific technical and organizational measures in place:
- Encryption in transit — the application is served exclusively over HTTPS/TLS. There is no plain-HTTP access to any page or data in this application.
- Hashing before transmission to Google — email addresses are one-way hashed with SHA-256, on our server, before ever being sent to Google’s Customer Match API. Google never receives a plain-text email address from this application.
- Authenticated access only — every page and API endpoint requires sign-in with an allowlisted Google account. There is no anonymous or public access to any customer data.
- Session security — sessions use HttpOnly, SameSite=Lax, Secure cookies, so session tokens are inaccessible to page scripts and are never sent over an insecure connection.
- Role-based access — only accounts marked as admin inside the application can import lead data, configure Google Ads integrations, or trigger uploads to Google. Standard staff accounts have read-only access to reporting.
- Database access control — the underlying database is not internet-facing and is only reachable by this application’s own server process.
- Data minimization — only the fields needed for advertising measurement (email, booking value, booking status, campaign identifiers) are processed; no payment details, passwords, or government ID data are ever collected or stored by this application.
- Retention and deletion — imported lead data is retained only as long as needed for the marketing reporting purposes described above. An administrator can delete an entire month’s imported data at any time from within the application, which removes it from this application’s database.

