Privacy Policy
Last Updated: March 24, 2026
Contents
Introduction
Dickson Creations Lab LLC (“Company”, “we”, “our”, or “us”) operates the Crest Coach platform (“Platform”). We respect your privacy and are committed to protecting it through our compliance with this policy.
This policy describes how we collect, process, retain, and disclose personal data about you when you use our Platform and the services, features, and tools accessible through it (our “Services”), and our practices for using, maintaining, protecting, and disclosing that information.
This policy applies to information we collect:
- Through the Platform and Services.
- In communications between you and us, including email, support tickets, and feedback submissions.
- When you register for and use your Crest Coach account.
It does not apply to information collected by any third party that does not link to this policy, including through any application or content that may link to or be accessible from the Services.
Please read this policy carefully to understand our practices. By using the Platform or providing us with your information, you agree to the collection, use, and sharing of your information as described here. This policy may change from time to time (see Changes to Our Privacy Policy below). Your continued use of the Platform after any changes constitutes acceptance of those changes.
Children's Privacy
The Platform is intended for professional and aspiring coaches aged 18 and older. We do not knowingly collect personal data from individuals under the age of 18. If we learn that we have collected or received personal data from a person under 18 without verification of parental consent, we will delete that information promptly. If you believe we may have information from or about a minor, please contact us at support@crest-coach.com.
The Personal Data That We Collect
“Personal data” is information that identifies, relates to, or describes you as an individual — such as your name, email address, or payment information. The categories of personal data we collect include:
Account and Contact Information
When you register, we collect your name, email address, and profile information you choose to provide, such as your coaching niche, certification status, and professional goals.
Coaching Practice Data (Client Data)
You may enter information about your coaching clients and sessions into the Platform, including client names, contact details, session notes, goals, and ICF competency tracking data (collectively, “Client Data”).
Important: You are solely responsible for obtaining your clients’ consent before entering their information into the Platform. Crest Coach is NOT a HIPAA-compliant service. You must not enter Protected Health Information (PHI), medical diagnoses, clinical records, Social Security numbers, government-issued identification numbers, financial account numbers, or payment card numbers into the Platform. See Data We Do Not Accept below.
Payment Information
Payment processing is handled by Stripe, Inc. We do not store your full credit card number, CVV, or banking credentials on our systems. We receive limited transaction metadata from Stripe — such as the last four digits of your card, card type, and billing address — for billing management purposes.
Voice Session Data
When you use the Mastery Coach Lab voice feature, your voice is captured by your device’s microphone and transmitted in real time to OpenAI’s Realtime API to generate AI responses. See Voice Data and Recording Consent and How We Share Your Information for full details on how this data is handled.
Usage and Technical Data
We automatically collect information about how you interact with the Platform, including pages visited, features used, session duration, browser type, device type, operating system, and IP address. We also collect technical information such as clickstream data, page response times, and error logs.
Communications
If you contact our support team or submit feedback, we retain those communications along with any information you include in them.
Statistics and Aggregated Data
We may derive non-personal statistical or aggregated data from personal data — for example, to calculate the percentage of users accessing a specific feature. Aggregated data does not directly identify you. If we combine aggregated data with personal data in a way that directly or indirectly identifies you, we treat the combined data as personal data.
Data We Do Not Accept
The Platform is not designed or authorized to process the following categories of sensitive data. You must not enter this information into the Platform:
- Protected Health Information (PHI) as defined under HIPAA or equivalent laws.
- Medical diagnoses, prescriptions, clinical records, or treatment history.
- Financial account numbers or payment card numbers (beyond Stripe’s secure checkout).
- Social Security numbers or government-issued identification numbers.
Crest Coach is not a HIPAA-compliant service
and must not be used to store, transmit, or process health information governed by HIPAA or similar laws. We are not liable for any harm resulting from the entry of prohibited data types into the Platform.
Coaches whose practices involve health, wellness, or any health-adjacent specialty must ensure that no clinical, medical, or health-covered information — including information about a client’s physical or mental health conditions — is entered into the Platform under any circumstances. If you are uncertain whether information constitutes PHI or falls within the prohibited categories above, do not enter it.
How We Collect Your Information
Information You Provide Directly
We collect information you provide when you create or update your account, purchase a subscription, use Platform features, enter Client Data, contact support, or submit feedback.
Automatically Through the Platform
As you use the Platform, we use automatic data collection technologies to collect usage, technical, and device information. These technologies may include:
- Cookies. Small files placed on your device that enable authentication, session management, and platform functionality. You may disable cookies through your browser settings, though doing so may affect Platform functionality.
- Analytics Tools. We may use analytics services to understand how users interact with the Platform, including usage patterns and feature adoption.
- Web Beacons and Pixel Tags. Small electronic files that allow us to count users who visit certain parts of the Platform and gather related statistics.
You can set your browser to refuse all or some cookies or to alert you when cookies are being sent. Some browsers support a “Do Not Track” (DNT) signal. Because there is no common standard for interpreting DNT signals, our Platform may not respond to all browser DNT signals. You can use the cookie controls described in this section to manage data collection instead.
From Third-Party Service Providers
We may receive information about you from third-party service providers we use to operate the Platform, including authentication providers, analytics providers, and payment processors.
How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Platform and Services.
- Process payments, manage your subscription, and send transactional communications such as receipts, password resets, and account notices.
- Power AI features using your practice data and session context.
- Respond to support requests and communicate with you about your account.
- Monitor for security incidents, fraud, and abuse.
- Analyze usage patterns to improve Platform performance and user experience.
- Estimate audience sizes and understand usage patterns.
- Store your preferences to customize the Platform to your individual interests.
- Carry out our obligations and enforce our rights arising from any contracts between you and us, including for billing and collection.
- Comply with applicable legal obligations.
- For any other purpose disclosed at the time you provide the information, or with your consent.
We do not sell your personal data to third parties. We do not use your personal data or Client Data to train AI models without your explicit consent.
Voice Data and Recording Consent
The Mastery Coach Lab voice feature uses your device’s microphone to capture audio input. By enabling voice sessions, you:
- Consent to your voice being captured by your device and transmitted to OpenAI’s servers for real-time processing.
- Acknowledge that AI-generated feedback and competency scores from your practice sessions are saved to the Platform to support progress tracking. Voice session transcripts and chat transcripts are not retained by the Platform after the session ends.
- Represent that you are the only person whose voice is being captured during practice sessions. Voice sessions are designed for solo practice with AI persona, not for multi-party conversations.
All-Party Consent Jurisdictions
If you are located in a jurisdiction that requires consent from all parties to a recorded or transmitted conversation (including California, Florida, Illinois, and certain international jurisdictions), you represent and confirm that you are complying with any applicable recording or interception consent laws before initiating a voice session. The AI personas in Mastery Coach Lab are not human, but you are responsible for understanding and complying with your own local legal obligations regarding voice transmission and recording.
Your Rights and Choices
This section describes the choices you can make about your information and the rights you may have depending on where you live.
Cookies and Tracking Technologies
You can set your browser to refuse all or some browser cookies or to alert you when cookies are being sent. If you disable cookies, some Platform features may be inaccessible or not function properly. See How We Collect Your Information above for more detail.
Account Information
You may review, update, or correct your account information by logging into your account settings at any time.
Data Deletion
You may request deletion of your personal data by contacting us at support@crest-coach.com. Upon account cancellation or a verified deletion request, we will delete your personal data within 30 days, subject to exceptions for legal and regulatory compliance.
Your State Privacy Rights
Depending on your state of residency, you may have certain rights related to your personal data, including:
- Access and Data Portability. You may confirm whether we process your personal data and request a copy of the personal data we process. Where feasible and required by applicable law, we will provide data in a portable format.
- Correction. You may request that we correct inaccuracies in your personal data, taking into account the information’s nature and processing purpose.
- Deletion. You may request that we delete personal data about you that we maintain, subject to certain exceptions under applicable law.
- Opt Out of Targeted Advertising, Profiling, and Data Sales. You may request that we do not use your personal data for targeted advertising or profiling. We do not sell personal data.
Important: The exact scope of these rights varies by state. There are several exceptions where we may not be obligated to fulfill your request.
To exercise any of these rights, contact us at support@crest-coach.com.
Some browsers and browser extensions support the Global Privacy Control (“GPC”) signal. When we detect a GPC signal, we will make reasonable efforts to respect your choices as required by applicable law.
California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know. You have the right to know what categories and specific pieces of personal information we collect, use, disclose, or sell.
- Right to Delete. You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Correct. You have the right to request correction of inaccurate personal information.
- Right to Opt Out of Sale or Sharing. We do not sell or share personal information as defined under California law.
- Right to Non-Discrimination. We will not discriminate against you for exercising your CCPA/CPRA rights.
The categories of personal information we collect are identified in The Personal Data That We Collect above. The categories of third parties to whom we disclose personal information are identified in Who We Share Your Information With above.
To submit a California privacy request, contact us at support@crest-coach.com. We will respond within 45 days as required by law.
Nevada Residents
Note Regarding Client Data and Data Controllers
Your Coach is Your Data Controller. For coaching clients whose personal data is entered into the Platform by a coach, the coach — not Dickson Creations Lab LLC — is the data controller under applicable privacy laws (including GDPR and CCPA). If you are a coaching client and wish to exercise your privacy rights regarding your data, please contact the coach who entered your information directly.
How We Protect Your Personal Data
We implement industry-standard administrative, physical, and technical measures to protect your personal data from unauthorized access, use, alteration, disclosure, accidental loss, or destruction. These measures include encryption in transit (TLS/SSL), encryption at rest, access controls, and regular security reviews.
However, no website, platform, electronic storage system, or online service is completely secure. We cannot guarantee the security of your personal data transmitted to, through, or in connection with the Services. In particular, email, texts, and other electronic communications sent to or from the Platform may not be fully secure. Any transmission of personal data is at your own risk.
In the event of a data breach that affects your rights, we will notify you as required by applicable law.
How We Retain Your Personal Data
We retain personal data for as long as your account remains active, or for as long as reasonably necessary to fulfill the purposes described in this policy, or as otherwise legally permitted or required — including to maintain the Platform, comply with legal obligations, resolve disputes, and support fraud prevention and security.
We consider our legal and business obligations, potential risks of harm, and the nature of the information when deciding how long to retain personal data. At the end of the applicable retention period, personal data will be deleted, destroyed, or de-identified.
If you cancel your account or submit a verified deletion request, we will delete your personal data within 30 days, except where retention is required for legal or regulatory compliance.
Voice Session Data: Voice data transmitted to OpenAI is subject to OpenAI’s data retention policies (approximately 30-day log retention; approximately 1-hour audio session state for abuse monitoring).
Data Retention Table
The following table summarizes our retention practices for the principal categories of data we process.
| Data Type | Retained by Company | Retention Period | Notes |
|---|---|---|---|
| Account & contact information | Yes | Duration of account + 30 days post-closure | Deleted upon verified deletion request |
| Client Data (session notes, goals) | Yes | Duration of account + 30 days post-closure | Coach is data controller |
| AI feedback & competency scores | Yes | Duration of account | Stored in Supabase |
| Session chat transcripts | No | Not retained | Deleted at session end |
| Voice session audio | No | Not retained by Company | Processed in real time by OpenAI |
| OpenAI abuse monitoring logs | Controlled by OpenAI | ~30 days (OpenAI) | Outside Company's control |
| OpenAI audio session state | Controlled by OpenAI | ~1 hour (OpenAI) | Outside Company's control |
| Payment metadata | Yes | As required by Stripe / law | Limited metadata only |
| Usage & technical data | Yes | [X months] |
International Data Transfers
The Platform is operated from the United States. If you access the Platform from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence. By using the Platform, you consent to the transfer of your information to the United States and its processing there.
For users in the EU, UK, or EEA: Client Data entered by a coach is controlled by the coach, not by Dickson Creations Lab LLC. If applicable, please consult the coach regarding the legal basis for processing and applicable safeguards for international transfers. If you have questions about our role as a data processor, contact us at support@crest-coach.com.
Changes to Our Privacy Policy
We may update this policy from time to time and will provide notice of any material changes as required by law. The date this policy was last updated is identified at the top of this page. We will notify you of material changes by email or by posting a prominent notice on the Platform. Your continued use of the Platform after changes are posted constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.
Contact Information
To exercise your rights, ask questions about this policy, or raise privacy concerns, please contact us at:
Dickson Creations Lab LLC
(operating as Crest Coach)
Email: support@crest-coach.com
Website: crest-coach.com
We will respond to privacy rights requests within 30 days of receipt.