1. Who We Are
This Privacy Policy explains how Everthere Ltd ("we", "us", or "our") collects, processes, and protects personal data when you visit our website (coachtrip.club), enquire about our services, or use the CoachTrip software application.
Company Name: Everthere Ltd
Registered in England & Wales: Company No. 04546865
Registered Office: 14a Albany Road, Weymouth, Dorset, DT4 9TH, United Kingdom
ICO Data Protection Registration: ZA935330
Privacy Contact: admin@everthere.com
2. Controller vs. Processor: Understanding Our Roles
Under the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Data Protection Act 2018, data protection law distinguishes between a "Data Controller" and a "Data Processor":
- Everthere Ltd as a Data Controller: We are the Data Controller for the personal data of our direct customers, organiser contacts, billing contacts, and prospective clients who submit demo enquiries on our website.
- Everthere Ltd as a Data Processor: When a subscribing club uploads its member directory, assigns coach seats, and records trip bookings within CoachTrip, the Club is the Data Controller of that member data, and Everthere Ltd is the Data Processor acting strictly on the Club's written instructions. Our formal Data Processing Addendum (DPA) governing this relationship is set out in our Terms of Service.
3. What Personal Data We Collect as Data Controller
We collect and process the following categories of information when you interact with us directly:
- Demo Enquiries & Contact Details: Name, club or society name, organiser role, email address, telephone number, approximate club member count, and any notes or questions submitted via our demo request form.
- Customer Account & Administration Data: Names, organiser email addresses, login credentials (hashed passwords), and communication logs for authorised club administrators.
- Billing & Invoicing Records: Club invoicing address, treasurer/contact name, email address, purchase history, and bank transfer payment references. (We do not store credit card numbers).
- Technical Server Logs: Essential server connection logs (IP addresses, request timestamps, user-agent strings) recorded for system security, diagnostics, and prevention of fraudulent access.
4. Lawful Bases for Processing
We process personal data only when an applicable lawful basis under Article 6 of the UK/EU GDPR exists:
5. Where Your Data is Stored & Sub-Processors
We take data sovereignty seriously. All application servers and primary databases are hosted securely within the United Kingdom:
- Primary Hosting: IONOS Datacentre (United Kingdom). All databases, encrypted backups, and application infrastructure are hosted on dedicated, secure servers in the UK.
- System & Notification Emails: Mailtrap. Used to dispatch system notifications (e.g. organiser alerts, member booking confirmations, and 1-click RSVP invitations).
- Enquiry & Communication Management: MailerLite. Used to manage incoming demo walkthrough requests and customer onboarding communications.
All sub-processors are vetted for robust GDPR compliance and operate under binding data processing agreements with appropriate safeguards (including UK International Data Transfer Agreements or EU Standard Contractual Clauses where applicable).
6. Cookies & Tracking Technologies
Zero Marketing Tracking. No Cookie Banner Required.
We respect your digital privacy. We do not use Google Analytics, Meta Pixel, tracking beacons, or cross-site advertising cookies on our website or software.
We only use strictly necessary technical session cookies. These are essential for:
- Maintaining secure administrator login sessions.
- Protecting forms against cross-site request forgery (CSRF).
- Providing secure tokenised magic-link access to the member portal without requiring passwords.
Under the Privacy and Electronic Communications Regulations (PECR) and UK GDPR, strictly necessary cookies do not require consent banners because the site cannot function securely without them.
7. Data Retention & Cancellation
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Customer Subscription Data: Maintained for the duration of the active subscription agreement.
- Upon Cancellation: If a club terminates its subscription, service access continues until a mutually agreed date. On that date, we provide a complete export of all club data (CSV/TSV format). Club data is permanently deleted from our live databases within 30 days of the agreed termination date.
- Financial & Invoice Records: Retained for 6 years in accordance with UK statutory tax and company accounting obligations (HMRC requirements).
- General Enquiries: Retained for up to 12 months from the date of last contact unless converted into an active customer account.
8. Your Legal Rights Under UK & EU GDPR
As an individual, data protection law grants you specific enforceable rights regarding your personal data:
Note for Club Members: If your information was uploaded to CoachTrip by your club organisers, your club is the Data Controller. Please contact your club secretary directly to exercise your rights. We will assist the club in fulfilling any such requests in accordance with our DPA.
9. The Right to Lodge a Complaint
If you have any concerns about our use of your personal data, we welcome the opportunity to resolve it with you first. Please contact us at admin@everthere.com.
You also have the right to lodge a complaint at any time with the UK supervisory authority for data protection:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Helpline: 0303 123 1113 | Website: ico.org.uk
Everthere Ltd Registration Ref: ZA935330
10. Contact Us
If you have any questions about this Privacy Policy, our data protection practices, or wish to exercise any of your statutory rights, please contact our team:
Everthere Ltd (CoachTrip.club)
14a Albany Road, Weymouth, Dorset, DT4 9TH, United Kingdom
Email: admin@everthere.com