1 Introduction
Welcome to IronForge Fitness ("we," "our," or "us"). We are committed to protecting your privacy and handling your personal data in an open and transparent manner. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our mobile application, or become a member of our fitness facilities.
By accessing or using any of our services — including our website, mobile app, member portal, fitness tracking tools, or any of our physical gym locations — you agree to the collection and use of information in accordance with this policy.
Important: This Privacy Policy works in conjunction with our Terms of Service. Please review both documents to understand our practices regarding your personal information.
If you have any questions about this Privacy Policy, our data practices, or your privacy rights, please contact us using the information provided in Section 14.
2 Information We Collect
We collect several types of information from and about users of our services, including information that may identify you ("Personal Information") and information that does not directly identify you ("Non-Personal Information").
2.1 Personal Information You Provide Directly
When you use our services, we may collect the following personal information that you provide directly:
- Identity Information: Full name, date of birth, gender, and profile photograph
- Contact Information: Email address, phone number, physical mailing address, and emergency contact details
- Account Information: Username, password, membership tier, payment details (processed securely through our payment processor), and billing address
- Health & Fitness Data: Body composition metrics (weight, body fat percentage, muscle mass), heart rate data, workout history, exercise preferences, fitness goals, dietary information, and medical conditions or restrictions relevant to training
- Communication Data: Correspondence, feedback, survey responses, class booking preferences, and support ticket history
- Payment Information: Credit/debit card details, bank account information for direct debit, and transaction history (processed and stored by our PCI-compliant payment provider)
2.2 Information Collected Automatically
When you use our website or mobile application, certain information is collected automatically:
- Device Information: Hardware model, operating system and version, unique device identifiers, and mobile network information
- Usage Data: Pages viewed, time spent on pages, click patterns, class attendance records, check-in/check-out times at our facilities, and equipment usage patterns
- Location Data: GPS coordinates (with your consent) for fitness tracking, nearest facility suggestions, and in-facility check-ins
- Connection Data: IP address, browser type and version, time zone setting, and referring/exit URLs
- Biometric Data: If you use our heart rate monitoring features, wearable device integrations (Apple Watch, Fitbit, Garmin, etc.), or facial recognition for entry, we process biometric identifiers
2.3 Information from Third Parties
We may also receive information about you from third-party sources:
- Fitness Wearable Platforms: Synced data from Apple Health, Google Fit, Fitbit, Garmin Connect, or other connected health devices
- Social Media: If you connect your social media accounts, we may access profile information from Instagram, Facebook, or Strava
- Payment Processors: Transaction confirmations and verification status from our payment partners
- Corporate Partners: If your membership is sponsored by an employer, limited employment and group plan details
| Data Category | Examples | Collection Method |
|---|---|---|
| Identity & Contact | Name, email, phone | Direct input |
| Health & Fitness | Workout data, body metrics | Direct & automated |
| Financial | Card details, billing | Payment processor |
| Device & Usage | IP, browser, app usage | Automated |
| Location | GPS, facility check-ins | Consent-based |
| Biometric | Heart rate, facial ID | Consent-based |
3 How We Use Your Information
We use the information we collect for various purposes related to providing, improving, and personalizing our fitness services:
3.1 Service Delivery & Management
- Processing your membership registration, renewals, and account management
- Granting access to our gym facilities, including keycard or app-based entry systems
- Managing class bookings, personal training sessions, and program enrollments
- Processing payments and managing billing in accordance with your membership plan
- Providing customer support and responding to inquiries, complaints, or feedback
- Monitoring facility usage to maintain appropriate class sizes and equipment availability
3.2 Personalization & Fitness Programming
- Creating personalized workout plans based on your fitness goals, preferences, and progress
- Tracking and displaying your fitness progress through our app and member dashboard
- Recommending classes, trainers, and programs tailored to your interests and ability level
- Sending reminders for scheduled classes, training sessions, and membership renewals
- Integrating data from your connected fitness devices for a unified health dashboard
3.3 Communication
- Sending transactional messages (receipts, booking confirmations, policy updates)
- Delivering promotional offers, new program announcements, and member-exclusive deals (with your consent)
- Notifying you of important facility updates, maintenance schedules, or emergency closures
- Conducting surveys and requesting feedback to improve our services
3.4 Safety & Security
- Verifying identity and membership status for facility access
- Monitoring for fraudulent activity, unauthorized access, or system abuse
- Contacting emergency contacts in case of medical emergencies at our facilities
- Complying with health and safety regulations for physical fitness environments
3.5 Analytics & Improvement
- Analyzing usage patterns to optimize our services and user experience
- Conducting aggregate research on fitness trends and member behavior
- Testing new features, programs, and service improvements
Note: We will always require your explicit opt-in consent before sending you marketing communications. You may withdraw consent at any time by following the unsubscribe instructions in our emails or updating your preferences in your account settings.
4 How We Share Your Information
We do not sell your personal information. We may share your data only in the following circumstances:
4.1 Service Providers & Business Partners
We share data with trusted third-party service providers who assist us in operating our business:
- Payment Processors: Stripe and PayPal for secure payment processing (PCI DSS compliant)
- Cloud Hosting: Amazon Web Services (AWS) for secure data storage and website hosting
- Communication Tools: Twilio for SMS notifications, SendGrid for email delivery
- Analytics Providers: Google Analytics for aggregated, anonymized usage statistics
- Fitness Platform APIs: Apple HealthKit, Google Fit, and wearable manufacturer APIs for data synchronization
- CRM Systems: Salesforce for managing member relationships and service delivery
4.2 Legal Obligations
We may disclose your personal information where required by law or to protect rights:
- In response to a valid subpoena, court order, or government request
- To protect the safety, rights, or property of IronForge Fitness, our members, or the public
- To enforce our Terms of Service, including fraud investigation
- In connection with a merger, acquisition, or sale of all or part of our business assets
4.3 Trainers & Staff
Your relevant fitness data and health information may be shared with your assigned personal trainers, coaches, and authorized gym staff to the extent necessary for delivering your training program and ensuring your safety during workouts. All staff are bound by strict confidentiality agreements.
4.4 Emergency Situations
In a medical emergency at our facilities, we may share necessary health information with emergency medical services (EMS) or healthcare providers to facilitate treatment.
Data Transfers: Our service providers may be located in countries outside of your jurisdiction. We ensure that all international data transfers comply with applicable data protection laws and use appropriate safeguards such as Standard Contractual Clauses (SCCs) or Privacy Shield certifications.
5 Data Security
We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:
- Encryption: All data transmitted between your device and our servers is encrypted using TLS 1.3 (Transport Layer Security). Stored data is encrypted at rest using AES-256 encryption
- Access Controls: Role-based access control (RBAC) ensures that only authorized personnel can access personal data, and only to the extent necessary for their role
- Network Security: Enterprise-grade firewalls, intrusion detection systems (IDS), and regular vulnerability assessments
- Physical Security: Our server facilities and gym locations employ 24/7 surveillance, access logs, and controlled entry systems
- Regular Audits: Annual third-party security audits, penetration testing, and compliance reviews
- Employee Training: Mandatory data protection training for all employees and contractors, with annual refresher courses
- Data Breach Response: A formal incident response plan to detect, investigate, and remediate security incidents, with notification to affected individuals and regulators where required
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We encourage you to use strong, unique passwords and to never share your login credentials with others.
6 Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including meeting legal, accounting, and reporting requirements:
- Active Members: Data is retained for the duration of your membership plus any active billing cycles
- Former Members: General account data is retained for 3 years after membership cancellation for warranty, dispute, and legal purposes. Payment records are retained for 7 years in accordance with tax and financial regulations
- Fitness & Health Data: Retained while you are an active member and for 2 years after membership termination, unless you request earlier deletion
- Communications: Support tickets and correspondence are retained for 3 years
- Marketing Consent: Retained until you withdraw consent or for 2 years of inactivity, whichever comes first
- CCTV Footage: Retained for 30 days unless required for security investigations
When data is no longer needed, it is securely deleted or anonymized using industry-standard data destruction methods.
7 Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data. These rights may be subject to certain limitations under applicable law:
7.1 Access & Portability
You have the right to request a copy of all personal data we hold about you, in a structured, machine-readable format (CSV, JSON, or PDF). We will respond within 30 days.
7.2 Correction
You may request correction of any inaccurate or incomplete personal data at any time through your account settings or by contacting our support team.
7.3 Deletion (Right to be Forgotten)
You may request the deletion of your personal data, subject to our legal obligations to retain certain records (e.g., financial transactions, safety records).
7.4 Restriction of Processing
You may request that we temporarily or permanently restrict processing of your data in certain circumstances, such as when you contest the accuracy of your data or object to our processing activities.
7.5 Objection
You may object to the processing of your data for direct marketing purposes at any time. You can also object to other processing activities where we rely on legitimate interests as our lawful basis.
7.6 Withdrawal of Consent
Where we rely on consent to process your data (e.g., marketing communications, location tracking, biometric data), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing conducted prior to withdrawal.
7.7 Automation & Profiling
You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects. Our fitness recommendations use algorithmic profiling, but all final training decisions are made by human trainers.
GDPR Residents: If you are in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation, including the right to lodge a complaint with a supervisory authority. Our Data Protection Officer is available at dpo@ironforge.fit.
To exercise any of these rights, please contact us using the details in Section 14. We may ask for verification of your identity before processing your request.
8 Cookies & Tracking Technologies
Our website and application use cookies and similar tracking technologies to enhance your experience, analyze usage, and deliver personalized content.
8.1 Types of Cookies We Use
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security, session management | Session |
| Functional | Remember preferences, language, class filters | 1 year |
| Analytics | Understand how visitors interact with our site | 2 years |
| Marketing | Deliver relevant ads and measure campaign effectiveness | 13 months |
8.2 Managing Cookies
You can control and manage cookies through your browser settings. Most browsers allow you to refuse or delete cookies, though this may affect the functionality of our services. You can also manage your cookie preferences through our cookie consent banner or your account settings.
8.3 Third-Party Tracking
We use Google Analytics for website analytics and Facebook Pixel for advertising measurement. These services set their own cookies. We recommend reviewing the privacy policies of these third parties for more information on their data practices:
9 Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. Minors aged 13–15 may use our services only with verifiable parental or guardian consent.
If you are a parent or guardian and become aware that your child has provided us with personal data without your consent, please contact us immediately. Upon verification, we will take steps to delete such data from our systems.
For youth fitness programs (ages 13–17), all registration must be completed by a parent or legal guardian, who will serve as the account holder and be responsible for all communications and billing.
10 Third-Party Links & Services
Our website and app may contain links to third-party websites, services, or applications (e.g., Strava, MyFitnessPal, supplement retailers). These links are provided for your convenience and do not signify our endorsement.
We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites or services before providing them with your personal information.
When you connect third-party services (e.g., syncing your Fitbit or Apple Watch), data sharing is governed by both our policy and the third party's terms. You control what data is shared through your device and app settings.
11 International Data Transfers
IronForge Fitness operates in multiple countries, and your personal information may be transferred to, and processed in, countries other than your country of residence. These countries may have data protection laws that differ from your jurisdiction.
When we transfer personal data internationally, we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) for transfers from the EEA
- Adequacy decisions by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Encryption of data in transit and at rest
Our primary data processing centers are located in the United States (AWS US-East-1) and the European Union (AWS EU-West-1). We process data in the region closest to where the member is located whenever possible.
12 California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the specific pieces of personal information we have collected, categories of sources, purposes of collection, and categories of third parties with whom data is shared
- Right to Delete: Request deletion of personal information collected through our services
- Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of your personal information for cross-context behavioral advertising (we do not sell personal information)
- Right to Correct: Request correction of inaccurate personal information
- Right to Limit Use of Sensitive Data: Limit the use and disclosure of sensitive personal information (health data, precise geolocation)
- Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights
To exercise these rights, please submit a verifiable consumer request via our contact information below. We will respond within 45 days and verify your identity before fulfilling your request.
13 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational, regulatory, or legal reasons. We encourage you to review this policy periodically.
When we make material changes, we will notify you by:
- Posting a prominent notice on our website homepage and app home screen at least 30 days before the change takes effect
- Sending an email to the address associated with your account
- Updating the "Last Updated" date at the top of this policy
Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised policy. If you do not agree with the changes, you may close your account and request deletion of your data.
14 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your personal information, please reach out to us:
IronForge Fitness — Privacy Team
New York, NY 10001, United States
If you are in the EEA and are not satisfied with how we handle your data protection complaint, you have the right to lodge a complaint with your local supervisory authority.