← Gym Plus Plus

Privacy Policy

Last updated July 20, 2026 · Gym Plus Plus, Rochester, MN

The short version

This policy covers the Gym Plus Plus iPhone app, our website (gymplusplus.app), and the launch waitlist. We collect what we need to run a multi-gym membership: who you are, your plan and billing status, and your check-ins. We use your precise location once, in the foreground, at the moment you check in — we compare it to the gym's location and then discard it. We never collect location in the background and we never store your coordinates.

Two things you should know up front. First, we use analytics and similar tracking technologies on our website and in our app, and we may work with advertising, attribution, and measurement partners; earlier versions of this policy said we used no trackers, and that is no longer accurate. Section 3 explains exactly what we use and the controls you have, and Section 11 explains the California opt-out. Second, before using partner facilities you will be asked to electronically sign a liability waiver; where you sign one, we retain that record (Sections 2.6 and 8). Partner gyms see only limited information about you — never your phone number, email, date of birth, or payment details. You can delete your account any time from Profile in the app.

1. Introduction & Scope

Gym Plus Plus ("Gym Plus Plus," "we," "us," or "our") is based in Rochester, Minnesota, USA. We operate a multi-gym membership service: one monthly subscription that lets members check in at participating partner gyms using a short-lived, location-verified access code shown at the front desk.

This Privacy Policy describes how we collect, use, share, and protect personal information across:

Gym Plus Plus is the business responsible for the personal information described in this policy (in some laws, the "controller"). You can reach us at hello@gymplusplus.app.

This policy does not cover what partner gyms do on their own premises and systems. Partner gyms are independent businesses: their own privacy practices, house rules, waivers, security cameras, and front-desk records are governed by their own policies, not ours. It also does not cover third-party websites or services we link to.

The Service is intended for people in the United States who are 18 years of age or older. The Service operates in the United States and is available wherever partner gyms participate, expanding to new areas over time.

2. Information We Collect

2.1 Account information

When you create an account we collect:

If we offer sign-in through a third-party identity service (such as Sign in with Apple or Google), we receive the basic details you authorize that service to share, such as your name and email address.

2.2 Membership & billing information

We keep your plan (for example, Everyday or All-Access), your billing state (active, past due, canceled), your payment history, and records of any per-visit charges you approved (for example, an extra gym on the same day at the price shown before you confirmed). Payments are processed through Stripe, our payment processor. Depending on how your payment is set up, payment card details may pass through or be processed by our systems to enable autopay and one-time charges (such as extra club visits). We handle payment information under the payment-card security standard (PCI DSS) and keep only what we need to bill you — for example, a secure payment token and limited card metadata such as the card brand, the last four digits, and whether a charge succeeded or failed.

2.3 Check-in records

Each check-in creates a record of which partner gym you visited and on what date. Front-desk staff at that gym see your name and profile photo at the moment they validate your entry. Check-in records are how we count visit-days, apply your plan's included visits, charge approved extra visits, and pay partner gyms.

2.4 Location at check-in only

When you request an access code, your device shares its precise location once, in the foreground, at that moment, so we can confirm you are physically at the gym. We compare the reading to the gym's geofence and then discard it. We do not store your coordinates, we do not collect location in the background, and we do not build any location or route history. Section 7 covers this in detail.

2.5 Profile photo (required)

A profile photo is required to use Gym Plus Plus. It is shown to front-desk staff so they can visually confirm the person checking in is the account holder — this is an anti-fraud and anti-account-sharing measure that protects members and partner gyms. We do not use profile photos for automated facial recognition or other biometric identification.

2.6 Signed waiver records

Before using partner facilities, members (and, where applicable, guests) will be asked to electronically sign a liability waiver and assumption-of-risk agreement. Where and when you sign a Waiver, we collect and retain that signed record, which includes: your name; the waiver version and text you agreed to; your electronic signature or affirmative act of acceptance; the date and time of signing; and technical metadata that helps verify authenticity (such as the IP address and device used to sign). The waiver includes a self-attestation that you are medically able to exercise — where a signed record exists, we store your acknowledgment of that statement; we do not collect medical records, diagnoses, or health measurements. Partner gyms may require their own separate waivers, which they collect and retain under their own policies.

2.7 Waitlist (website)

If you join the launch waitlist at gymplusplus.app, we collect your name, phone number, and ZIP code. We use the ZIP code to gauge demand by city and area, and we use the phone number to send a single "we've launched in your area" text (Section 6).

2.8 Device, usage & analytics data

When you use the app or the website, we and our analytics providers collect information automatically, including:

Section 3 describes the cookies, SDKs, and similar technologies behind this collection and the controls you have.

2.9 Communications

When you contact us — by email, text, or through the app — we keep the correspondence and the details you choose to share so we can respond, fix problems, and keep records of support decisions (for example, a case-by-case refund).

2.10 Information from other sources

2.11 Push notifications

If you allow notifications, the app registers a device push token with Apple (APNs) so we can send you push notifications — including account and service notices and a "we've launched near you" alert once we're live in your area (Section 2.1). We do not send that launch alert to app users by text message; it is delivered by push instead. You can turn push notifications off at any time in iOS Settings → Notifications → Gym Plus Plus.

3. Tracking Technologies & Cookies

This section replaces earlier statements that Gym Plus Plus used no analytics or advertising trackers. We now use tracking and analytics technologies on the website and in the app, and we may work with third-party advertising, attribution, and measurement partners. Here is what that means, honestly and specifically.

3.1 What we use

3.2 What we use them for

3.3 Apple App Tracking Transparency (app)

On iOS, where Apple's App Tracking Transparency framework applies — that is, where we or our partners would track your activity across apps and websites owned by other companies — the app will first ask for your permission through the standard iOS prompt. If you decline, we do not access your device's advertising identifier (IDFA), we honor that choice, and we will not link your app activity with other companies' data for advertising or share it with data brokers without your permission. You can change this at any time in iOS Settings under Privacy & Security → Tracking.

3.4 Your controls

Opting out of analytics or advertising cookies does not remove ads from the internet and does not affect your membership; it means the tracking described above is limited or stopped for that browser or device.

4. How We Use Information

5. How We Share Information

5.1 Partner gyms — limited by design

When you check in at a partner gym, that gym sees:

Partner gyms never receive your phone number, email address, date of birth, payment details, or your visits to other gyms. Remember that partner gyms are independent businesses: anything they collect themselves on their premises (their own waivers, sign-in sheets, cameras) is governed by their own policies.

5.2 Payment processor

Stripe, our payment processor, receives the details needed to charge you and manage your subscription. Depending on how a payment is set up, payment card details may pass through or be processed by our systems to enable autopay and one-time charges; Stripe handles card data under the payment-industry security standard (PCI DSS) and its own privacy policy, and we handle any payment information we process under that same standard.

5.3 Analytics, advertising & attribution partners

Analytics providers, crash-reporting services, and advertising/attribution/measurement partners receive the device, identifier, and usage data described in Sections 2.8 and 3. Some of these partners may use that data for their own purposes, such as improving their services or matching ad campaigns to installs. This is the category of sharing that California law may treat as a "sale" or "sharing" — see Section 5.8 and Section 11.

5.4 Service providers

We use companies that process data on our instructions to run the Service: cloud infrastructure (Cloudflare, in the United States), SMS delivery providers, email delivery providers, customer-support tooling, and — if used — electronic-signature and document-storage providers for waivers. They are bound by contracts to use personal information only to provide services to us.

5.5 Legal, safety & enforcement

We may disclose information if we believe in good faith it is required by law, subpoena, or legal process; to protect the safety of members, gym staff, or the public; to detect and prevent fraud or abuse; or to enforce our Terms of Service and waiver agreements.

5.6 Business transfers

If Gym Plus Plus is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor commitments materially consistent with this policy or to notify you of changes.

5.7 Aggregated and de-identified data

We share statistics that do not identify you — for example, demand heat maps by ZIP code or visit volumes by gym. We commit to maintaining such data in de-identified form and not attempting to re-identify it, and we require recipients to commit to the same.

5.8 Do we "sell" or "share" personal information?

We do not sell personal information in exchange for money in the way people usually mean by "selling data," and we do not disclose your date of birth, payment history, check-in history, profile photo, or signed waiver records to third parties for their own independent purposes. We also do not disclose your name, phone number, or email address to advertising partners for their own purposes today; if that ever changes — for example, if we ever use a hashed-email or hashed-phone "custom audience" feature to reach people like our members — we will update this policy first and provide any opt-out or opt-in the law requires. California law, however, defines "sale" and "sharing" broadly enough to cover common advertising and analytics arrangements. Under those definitions, our disclosure of online identifiers and usage data (Sections 2.8 and 5.3) to advertising and analytics partners may qualify as a "sale" or "sharing." We treat it as such, which means California residents (and residents of states with similar laws) can opt out — see Sections 11 and 12. We honor Global Privacy Control as an opt-out signal. We do not knowingly sell or share the personal information of anyone under 18 — minors cannot hold accounts at all.

6. Text Messages (SMS)

When you provide your phone number — for example, while joining the waitlist, or if you add one to your account — you consent to receive the texts that go with that purpose:

Signing in to the app does not use text messages: we email you a one-time 6-digit verification code each time you sign in (Section 2.1). App users who want a "we've launched near you" alert get it by push notification (Section 2.11), not by text.

7. Location Data: The Specifics

Location is the most sensitive thing a gym-access app can touch, so here is precisely how it works:

8. Data Retention & Deletion

8.1 How long we keep things

8.2 Deleting your account

You can delete your account from Profile in the app, or by emailing hello@gymplusplus.app. Deletion removes your profile, photo, and personal details from active systems. Records we are legally required or permitted to keep — financial ledgers, tax records, any signed waiver, and consent logs — are retained for the periods above, without your personal identifiers where possible. Copies may persist briefly in encrypted backups until those backups cycle out.

9. Security

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law.

10. Your Rights & Choices

These choices are available to everyone, regardless of where you live:

To exercise any right, email hello@gymplusplus.app with the subject line "Privacy Request," or use the in-app options. We will verify your request by matching the details you provide against your account (for example, confirming control of the account's phone number or email) and respond within the time required by applicable law (generally 45 days, extendable where the law allows). We do not charge for reasonable requests. An authorized agent may submit a request on your behalf with proof of your written permission; we may still verify your identity directly. If we decline a request, we will explain why, and you may appeal (Sections 11 and 12).

11. California Privacy Rights (CCPA/CPRA)

This section is for California residents and applies to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies to Gym Plus Plus. The CCPA applies to businesses meeting certain size thresholds; as a matter of policy, we generally aim to honor the requests below for all US members, subject to identity verification and applicable legal exceptions, even where a statute does not strictly require it. For California residents, this policy also serves as our notice at collection.

11.1 Categories of personal information

In the last 12 months (and today), we collect the following categories of personal information, as the CCPA defines them:

Categories of personal information we collect, who we disclose them to, and whether they are "sold" or "shared" under California law.
CCPA category What we collect Disclosed to (categories of recipients) "Sold" or "shared"?
Identifiers Name, phone, email, account ID, IP address, device and advertising identifiers, device push token Service providers; Stripe (our payment processor); partner gyms (name only, at validation); analytics/advertising partners (online identifiers only); Apple (APNs, for push delivery) Online and device identifiers — yes, may be shared with advertising/analytics partners; opt out below. Name, phone, email, DOB — not disclosed to advertising/analytics partners for their own purposes (Section 5.8).
Customer records (Cal. Civ. Code 1798.80(e)) Name, phone, payment history (no card numbers) Service providers; Stripe (our payment processor) No
Protected characteristics Age / date of birth (to enforce the 18+ requirement) Service providers No
Commercial information Plan, billing state, purchases, extra-visit charges Service providers; Stripe (our payment processor); partner gyms (tier and that gym's visits only) No
Internet or other network activity App and website usage, interaction events, crash and performance data (Section 2.8) Analytics/advertising/attribution partners; service providers Yes — may be shared with advertising/analytics partners; opt out below.
Geolocation data Precise location once at check-in — compared, then discarded, never stored (Section 7); approximate IP-level location; postal code, home city, and region collected at app onboarding (Section 2.1) Precise: no one — it is discarded. Approximate IP-level location may accompany usage data above. Postal code / home city / region: service providers only. Precise: no. Approximate IP-level: only as part of network-activity data above. Postal code / home city / region: no.
Audio/visual information Profile photo (required) Partner gym staff, at check-in validation only No
Inferences Limited — aggregate demand by ZIP, usage patterns Service providers No
Sensitive personal information Precise geolocation, only at the moment of check-in; where you sign a Waiver, its medical-fitness acknowledgment (an eligibility attestation — not medical records, never analyzed to infer health conditions) Geolocation: no one — used to verify presence, then discarded. Waiver acknowledgment: where one exists, only service providers that store that record No

Sources: you; your devices; partner gyms (validation and incident reports); Stripe, our payment processor; attribution partners. Purposes: Section 4. Retention: Section 8, per category.

11.2 Sensitive personal information

The main category of sensitive personal information we handle is precise geolocation, and only at the moment of check-in: we use it solely to verify you are at the gym, then discard it. Where you sign our liability waiver, it also records your acknowledgment that you are medically able to exercise (Section 2.6); we treat this as a simple eligibility attestation — we do not collect medical records, and we do not analyze it to infer any health condition. We do not use or disclose sensitive personal information to infer characteristics about you or for any purpose that would give rise to the right to limit under the CCPA and its regulations, so we do not offer a separate "Limit the Use of My Sensitive Personal Information" control. If our use of sensitive personal information ever expands beyond these permitted purposes, we will offer that control.

11.3 Your CCPA rights

11.4 How to exercise and appeal

Submit requests to hello@gymplusplus.app (subject "Privacy Request") or through the app. We will acknowledge your request within 10 business days and explain how we will process it. We verify requests as described in Section 10 and respond within 45 days, extendable by another 45 where permitted with notice. Authorized agents may act for you with written permission. If we deny a request, you may appeal by replying to our decision; a person senior to the original reviewer will re-examine it and respond in writing. You may also direct concerns to the California Privacy Protection Agency or the California Attorney General.

11.5 California "Shine the Light"

Separately from the CCPA, California Civil Code Section 1798.83 lets California residents request, once per year, details about personal information we disclosed to third parties for those third parties' own direct marketing. We do not currently disclose personal information to third parties for their own direct marketing purposes; if that changes, we will provide this information on request.

12. Other US State Privacy Laws

A growing number of states — including Minnesota (our home state, under the Minnesota Consumer Data Privacy Act), Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and Utah — grant residents rights similar to California's: to confirm and access the personal data we process, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, "sale," and certain profiling. These laws apply to businesses meeting size thresholds, and the specific rights available depend on your state — for example, not every state grants a right to correct or an appeal process. Whether or not a given law strictly applies to us, we generally aim to make these choices available to any US resident as a matter of policy, subject to identity verification and applicable legal exceptions.

13. Children & Age Requirement

Gym Plus Plus is for adults. You must be 18 or older to create an account, and we collect date of birth to enforce this. The Service is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact hello@gymplusplus.app and we will delete it.

14. Where Your Data Is Processed

Gym Plus Plus runs on Cloudflare's platform in the United States, and our service providers process data in the United States. Data is encrypted in transit; access codes and session tokens are stored hashed. The Service is designed for US residents. If you access it from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your location.

15. Changes to This Policy

We will update this policy as the Service evolves. When we make material changes, we will post the updated policy on this page with a new "Last updated" date and give notice in the app and on the website; where a change materially expands how we use previously collected information, we will provide more prominent notice or obtain consent where the law requires it.

Note on this update: the July 20, 2026 revision adds disclosures about tracking and analytics technologies (Section 3) — which earlier versions of this policy stated we did not use — and about signed waiver records (Sections 2.6 and 8), and expands the waitlist description to name, phone number, and ZIP code.

16. Contact Us

For questions about this policy, or to exercise any privacy right described here: