Privacy Policy
Last updated July 20, 2026 · Gym Plus Plus, Rochester, MN
The short version
This policy covers the Gym Plus Plus iPhone app, our website (gymplusplus.app), and the launch waitlist. We collect what we need to run a multi-gym membership: who you are, your plan and billing status, and your check-ins. We use your precise location once, in the foreground, at the moment you check in — we compare it to the gym's location and then discard it. We never collect location in the background and we never store your coordinates.
Two things you should know up front. First, we use analytics and similar tracking technologies on our website and in our app, and we may work with advertising, attribution, and measurement partners; earlier versions of this policy said we used no trackers, and that is no longer accurate. Section 3 explains exactly what we use and the controls you have, and Section 11 explains the California opt-out. Second, before using partner facilities you will be asked to electronically sign a liability waiver; where you sign one, we retain that record (Sections 2.6 and 8). Partner gyms see only limited information about you — never your phone number, email, date of birth, or payment details. You can delete your account any time from Profile in the app.
1. Introduction & Scope
Gym Plus Plus ("Gym Plus Plus," "we," "us," or "our") is based in Rochester, Minnesota, USA. We operate a multi-gym membership service: one monthly subscription that lets members check in at participating partner gyms using a short-lived, location-verified access code shown at the front desk.
This Privacy Policy describes how we collect, use, share, and protect personal information across:
- the Gym Plus Plus mobile app (currently for iPhone);
- our website at gymplusplus.app, including its subdomains;
- the launch waitlist on the website; and
- our related communications with you by email, text message, and in-app notices (together, the "Service").
Gym Plus Plus is the business responsible for the personal information described in this policy (in some laws, the "controller"). You can reach us at hello@gymplusplus.app.
This policy does not cover what partner gyms do on their own premises and systems. Partner gyms are independent businesses: their own privacy practices, house rules, waivers, security cameras, and front-desk records are governed by their own policies, not ours. It also does not cover third-party websites or services we link to.
The Service is intended for people in the United States who are 18 years of age or older. The Service operates in the United States and is available wherever partner gyms participate, expanding to new areas over time.
2. Information We Collect
2.1 Account information
When you create an account we collect:
- Email address — your sign-in identifier; we email a one-time 6-digit verification code each time you sign in, and also use it for receipts, account notices, and support.
- Name — shown to front-desk staff when you check in.
- Phone number — optional; if you provide one, we may use it to text you account or service notices (Section 6).
- Date of birth — to confirm you are 18 or older.
- Postal code, home city, and region — collected during onboarding in the app; used to match you to gyms in your market and to send you a "we've launched near you" alert (see Push Notifications, Section 2.11).
If we offer sign-in through a third-party identity service (such as Sign in with Apple or Google), we receive the basic details you authorize that service to share, such as your name and email address.
2.2 Membership & billing information
We keep your plan (for example, Everyday or All-Access), your billing state (active, past due, canceled), your payment history, and records of any per-visit charges you approved (for example, an extra gym on the same day at the price shown before you confirmed). Payments are processed through Stripe, our payment processor. Depending on how your payment is set up, payment card details may pass through or be processed by our systems to enable autopay and one-time charges (such as extra club visits). We handle payment information under the payment-card security standard (PCI DSS) and keep only what we need to bill you — for example, a secure payment token and limited card metadata such as the card brand, the last four digits, and whether a charge succeeded or failed.
2.3 Check-in records
Each check-in creates a record of which partner gym you visited and on what date. Front-desk staff at that gym see your name and profile photo at the moment they validate your entry. Check-in records are how we count visit-days, apply your plan's included visits, charge approved extra visits, and pay partner gyms.
2.4 Location at check-in only
When you request an access code, your device shares its precise location once, in the foreground, at that moment, so we can confirm you are physically at the gym. We compare the reading to the gym's geofence and then discard it. We do not store your coordinates, we do not collect location in the background, and we do not build any location or route history. Section 7 covers this in detail.
2.5 Profile photo (required)
A profile photo is required to use Gym Plus Plus. It is shown to front-desk staff so they can visually confirm the person checking in is the account holder — this is an anti-fraud and anti-account-sharing measure that protects members and partner gyms. We do not use profile photos for automated facial recognition or other biometric identification.
2.6 Signed waiver records
Before using partner facilities, members (and, where applicable, guests) will be asked to electronically sign a liability waiver and assumption-of-risk agreement. Where and when you sign a Waiver, we collect and retain that signed record, which includes: your name; the waiver version and text you agreed to; your electronic signature or affirmative act of acceptance; the date and time of signing; and technical metadata that helps verify authenticity (such as the IP address and device used to sign). The waiver includes a self-attestation that you are medically able to exercise — where a signed record exists, we store your acknowledgment of that statement; we do not collect medical records, diagnoses, or health measurements. Partner gyms may require their own separate waivers, which they collect and retain under their own policies.
2.7 Waitlist (website)
If you join the launch waitlist at gymplusplus.app, we collect your name, phone number, and ZIP code. We use the ZIP code to gauge demand by city and area, and we use the phone number to send a single "we've launched in your area" text (Section 6).
2.8 Device, usage & analytics data
When you use the app or the website, we and our analytics providers collect information automatically, including:
- Device data: device model, operating system and version, app version, language, and time zone.
- Identifiers: device identifiers, an app instance or installation identifier, cookie identifiers, and — where you permit it under your device settings — mobile advertising identifiers (such as Apple's IDFA).
- Usage data: pages and screens viewed, features used, taps and interaction events, session length, referring pages or campaigns, and crash and performance diagnostics.
- Network data: IP address and browser type. Like nearly all internet services, our servers and analytics tools can infer an approximate, city-level location from your IP address; this is different from the precise device location described in Section 7, which is used only at check-in and discarded.
- Log data: standard server logs (request time, URL, response code) used for security and reliability. Access codes and exact coordinates are never written to logs.
Section 3 describes the cookies, SDKs, and similar technologies behind this collection and the controls you have.
2.9 Communications
When you contact us — by email, text, or through the app — we keep the correspondence and the details you choose to share so we can respond, fix problems, and keep records of support decisions (for example, a case-by-case refund).
2.10 Information from other sources
- Stripe (our payment processor): payment outcomes and limited card metadata, as described in Section 2.2.
- Partner gyms: a gym may report an incident involving your membership (for example, suspected code sharing or misuse at the front desk).
- Attribution and measurement partners: if you install the app or visit the site after an ad or campaign link, we may receive campaign-level information about how you found us (Section 3).
2.11 Push notifications
If you allow notifications, the app registers a device push token with Apple (APNs) so we can send you push notifications — including account and service notices and a "we've launched near you" alert once we're live in your area (Section 2.1). We do not send that launch alert to app users by text message; it is delivered by push instead. You can turn push notifications off at any time in iOS Settings → Notifications → Gym Plus Plus.
3. Tracking Technologies & Cookies
This section replaces earlier statements that Gym Plus Plus used no analytics or advertising trackers. We now use tracking and analytics technologies on the website and in the app, and we may work with third-party advertising, attribution, and measurement partners. Here is what that means, honestly and specifically.
3.1 What we use
- Cookies — small files stored by your browser. We use first-party cookies (set by gymplusplus.app, for things like sessions, security, and preferences) and may use third-party cookies (set by analytics or advertising partners).
- Local storage and similar browser technologies — used like cookies to remember state and preferences.
- Web beacons and pixels — tiny images or code snippets on web pages and in emails that tell us whether a page was viewed, an email was opened, or a campaign led to a signup.
- Mobile SDKs — code libraries inside the app from analytics, crash-reporting, and attribution providers that collect the device and usage data described in Section 2.8.
- Device and advertising identifiers — including resettable mobile advertising identifiers, where your device settings permit their use.
- Server-side analytics — measurement of traffic and feature usage from our own infrastructure.
3.2 What we use them for
- Strictly necessary: signing you in, keeping sessions secure, rate-limiting, and preventing fraud and abuse. These cannot be switched off without breaking the Service.
- Preferences: remembering settings and choices.
- Analytics: understanding which features are used, where people drop off, what crashes, and how the Service performs, so we can improve it.
- Advertising, attribution & measurement: measuring whether our ads and campaigns work (for example, which campaign led to an install or a waitlist signup) and, if we advertise, reaching likely members and limiting how often people see our ads.
3.3 Apple App Tracking Transparency (app)
On iOS, where Apple's App Tracking Transparency framework applies — that is, where we or our partners would track your activity across apps and websites owned by other companies — the app will first ask for your permission through the standard iOS prompt. If you decline, we do not access your device's advertising identifier (IDFA), we honor that choice, and we will not link your app activity with other companies' data for advertising or share it with data brokers without your permission. You can change this at any time in iOS Settings under Privacy & Security → Tracking.
3.4 Your controls
- Cookie choices: where we show a cookie banner or consent manager on the website, you can accept, decline, or customize non-essential cookies there and revisit your choice later.
- Browser controls: every major browser lets you block or delete cookies and site data, and block third-party cookies entirely. Blocking strictly necessary cookies may break sign-in.
- Global Privacy Control (GPC): we honor GPC signals from your browser as a valid opt-out of "sale" and "sharing" (Section 11) for that browser. Older "Do Not Track" signals have no settled meaning, so we treat GPC as the operative signal.
- Email pixels: most email apps let you block remote images, which disables open-tracking pixels.
- iOS controls: the App Tracking Transparency prompt (Section 3.3), plus Settings-level controls over the advertising identifier.
- Industry opt-outs: you can opt out of interest-based advertising from participating companies at optout.aboutads.info (Digital Advertising Alliance), optout.networkadvertising.org (Network Advertising Initiative), and for mobile apps via youradchoices.com/appchoices.
- California and other state opt-outs: see Sections 11 and 12 for the "sale"/"share"/targeted-advertising opt-out and how to submit it.
- Questions: you can always email hello@gymplusplus.app to ask what tracking is active on the Service.
Opting out of analytics or advertising cookies does not remove ads from the internet and does not affect your membership; it means the tracking described above is limited or stopped for that browser or device.
4. How We Use Information
- Provide the Service: create and maintain your account, authenticate you with sign-in codes, generate single-use access codes, validate check-ins at partner gyms, and show staff your name and photo at the desk.
- Verify presence: compare your device's location, once at check-in, against the gym's geofence — then discard the coordinates (Section 7).
- Billing: charge your subscription, apply your plan's included visit-days, charge approved extra visits at the price shown before you confirmed, handle failed payments, and keep payment history.
- Pay partner gyms: count unique visit-days per gym so gyms are paid correctly. Gyms are paid per visit-day, which is why accurate check-in records matter.
- Security & fraud prevention: detect and prevent location spoofing, code sharing, and account misuse; enforce attempt limits and rate limits; investigate anomalies in check-in patterns and device signals. This analysis works on gym-level check-in records and device signals — not stored coordinates, which we do not have.
- Analytics & product improvement: understand usage, fix crashes, measure performance, and decide what to build next (Sections 2.8 and 3).
- Marketing & growth: send the one-time launch text to waitlist members, measure campaigns and attribution, and — if you opt in to marketing — send you news and offers. Waitlist ZIP codes are used in aggregate to see which cities have the most demand.
- Communications: send transactional messages (sign-in codes, receipts, billing and account notices, changes to terms or this policy) and respond to support requests.
- Legal & compliance: keep records we are required to keep (tax, accounting, consent logs, signed waivers), respond to lawful requests, enforce our Terms of Service, and establish or defend legal claims.
- Aggregated and de-identified data: we compile statistics that no longer identify anyone (for example, demand by city or visits per gym per month) and may use and share them freely, including with partner gyms and in investor or partner materials.
5. How We Share Information
5.1 Partner gyms — limited by design
When you check in at a partner gym, that gym sees:
- your name;
- your profile photo;
- your membership tier; and
- your visits to that gym — dates and counts, which determine what the gym is paid.
Partner gyms never receive your phone number, email address, date of birth, payment details, or your visits to other gyms. Remember that partner gyms are independent businesses: anything they collect themselves on their premises (their own waivers, sign-in sheets, cameras) is governed by their own policies.
5.2 Payment processor
Stripe, our payment processor, receives the details needed to charge you and manage your subscription. Depending on how a payment is set up, payment card details may pass through or be processed by our systems to enable autopay and one-time charges; Stripe handles card data under the payment-industry security standard (PCI DSS) and its own privacy policy, and we handle any payment information we process under that same standard.
5.3 Analytics, advertising & attribution partners
Analytics providers, crash-reporting services, and advertising/attribution/measurement partners receive the device, identifier, and usage data described in Sections 2.8 and 3. Some of these partners may use that data for their own purposes, such as improving their services or matching ad campaigns to installs. This is the category of sharing that California law may treat as a "sale" or "sharing" — see Section 5.8 and Section 11.
5.4 Service providers
We use companies that process data on our instructions to run the Service: cloud infrastructure (Cloudflare, in the United States), SMS delivery providers, email delivery providers, customer-support tooling, and — if used — electronic-signature and document-storage providers for waivers. They are bound by contracts to use personal information only to provide services to us.
5.5 Legal, safety & enforcement
We may disclose information if we believe in good faith it is required by law, subpoena, or legal process; to protect the safety of members, gym staff, or the public; to detect and prevent fraud or abuse; or to enforce our Terms of Service and waiver agreements.
5.6 Business transfers
If Gym Plus Plus is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will require the recipient to honor commitments materially consistent with this policy or to notify you of changes.
5.7 Aggregated and de-identified data
We share statistics that do not identify you — for example, demand heat maps by ZIP code or visit volumes by gym. We commit to maintaining such data in de-identified form and not attempting to re-identify it, and we require recipients to commit to the same.
5.8 Do we "sell" or "share" personal information?
We do not sell personal information in exchange for money in the way people usually mean by "selling data," and we do not disclose your date of birth, payment history, check-in history, profile photo, or signed waiver records to third parties for their own independent purposes. We also do not disclose your name, phone number, or email address to advertising partners for their own purposes today; if that ever changes — for example, if we ever use a hashed-email or hashed-phone "custom audience" feature to reach people like our members — we will update this policy first and provide any opt-out or opt-in the law requires. California law, however, defines "sale" and "sharing" broadly enough to cover common advertising and analytics arrangements. Under those definitions, our disclosure of online identifiers and usage data (Sections 2.8 and 5.3) to advertising and analytics partners may qualify as a "sale" or "sharing." We treat it as such, which means California residents (and residents of states with similar laws) can opt out — see Sections 11 and 12. We honor Global Privacy Control as an opt-out signal. We do not knowingly sell or share the personal information of anyone under 18 — minors cannot hold accounts at all.
6. Text Messages (SMS)
When you provide your phone number — for example, while joining the waitlist, or if you add one to your account — you consent to receive the texts that go with that purpose:
- Waitlist launch text: if you joined the waitlist, a single message — which you agreed to receive when you signed up — when we launch in your area.
- Account and service texts: if you have a phone number on file, we may text you about your membership when needed (for example, a billing failure or a required notice).
- We will not send you recurring marketing texts unless you separately opt in to them.
- Consent to marketing texts is never a condition of buying a membership.
- Message and data rates may apply. Message frequency depends on your use of the Service.
- Reply STOP to opt out of texts at any time, or email us; after a STOP we send one final message confirming your opt-out, then stop. Reply HELP for help.
- We keep records of SMS consent and opt-outs so we can honor and document them.
Signing in to the app does not use text messages: we email you a one-time 6-digit verification code each time you sign in (Section 2.1). App users who want a "we've launched near you" alert get it by push notification (Section 2.11), not by text.
7. Location Data: The Specifics
Location is the most sensitive thing a gym-access app can touch, so here is precisely how it works:
- Foreground only, at check-in only. Your device shares its precise location a single time, when you tap to request an access code with the app open. That is the only time we use precise location.
- Compared, then discarded. The reading is compared against the gym's geofence (default radius roughly 150 meters, with accuracy and code-lifetime rules enforced per gym). Once the comparison is made, the coordinates are discarded.
- Never stored, never logged. Exact coordinates are not written to our databases and not written to logs. What remains after a successful check-in is the gym and the date — not where you stood.
- No background location. The app does not request or use background location, ever.
- No route history. We do not build movement profiles or location timelines.
- Approximate IP location is separate. As with nearly all internet services, our servers and analytics tools can infer a rough, city-level location from your IP address (Section 2.8). That is network-level information, not your device's precise GPS location.
- Your control. Location permission is controlled in iOS Settings. If you decline, the app cannot verify your presence, so location-verified check-in will not be available.
8. Data Retention & Deletion
8.1 How long we keep things
- Account information: for as long as your account is active, then deleted or de-identified within a reasonable period after account deletion, subject to the exceptions below.
- Billing, payment & visit-day ledgers: as long as required by tax, accounting, and audit obligations. These ledgers are append-only; after account deletion we retain them without your personal identifiers where possible.
- Check-in records: retained as part of the financial ledgers above, because each visit-day drives a gym payout.
- Signed waivers (where one exists): retained at least as long as legal claims related to your gym use could be brought (the applicable statute of limitations following your last visit or the end of your membership), and longer where law requires — including after you delete your account, because these records protect both you and us if a dispute arises.
- Waitlist entries: until we launch in your area and send the single launch text, until you ask us to delete yours, or until we periodically purge stale entries — whichever comes first.
- SMS consent and opt-out records: as long as needed to honor and document your choices.
- Support correspondence: as long as needed to resolve the issue and keep a record of decisions such as refunds.
- Analytics data: retained for the finite period configured in our analytics tools — we do not configure indefinite retention — after which it is deleted or aggregated.
- Precise location at check-in: not retained at all — compared and discarded (Section 7).
8.2 Deleting your account
You can delete your account from Profile in the app, or by emailing hello@gymplusplus.app. Deletion removes your profile, photo, and personal details from active systems. Records we are legally required or permitted to keep — financial ledgers, tax records, any signed waiver, and consent logs — are retained for the periods above, without your personal identifiers where possible. Copies may persist briefly in encrypted backups until those backups cycle out.
9. Security
- Encryption in transit: connections to the Service use modern TLS encryption.
- Access codes: server-generated, random, single-use, scoped to one member and one gym, short-lived, attempt-limited, stored hashed, and never written to logs.
- Session tokens: stored hashed.
- Card data: handled under the PCI DSS standard; we keep a secure payment token and limited card metadata (such as the last four digits), not full card numbers in the clear.
- Coordinates: never stored or logged (Section 7).
- Abuse controls: rate limiting, sign-in attempt limits, and anomaly detection for suspicious check-in patterns.
- Access controls: staff and system access to personal information is limited to what a role requires.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a breach affecting your personal information, we will notify you and regulators as required by law.
10. Your Rights & Choices
These choices are available to everyone, regardless of where you live:
- Access & correction: see and update your account details in the app, or ask us for a copy of the personal information we hold about you.
- Deletion: delete your account from Profile in the app or by contacting us (Section 8.2).
- Marketing opt-outs: reply STOP to texts (Section 6); use the unsubscribe link in any marketing email. Transactional messages — including your emailed sign-in codes, receipts, and billing notices — continue while you have an account, because the Service cannot run without them.
- Tracking controls: cookie choices, browser and iOS controls, Global Privacy Control, and industry opt-outs (Section 3.4).
- Photo: the profile photo is required and is retained while your account is active; you can update it at any time in the app.
To exercise any right, email hello@gymplusplus.app with the subject line "Privacy Request," or use the in-app options. We will verify your request by matching the details you provide against your account (for example, confirming control of the account's phone number or email) and respond within the time required by applicable law (generally 45 days, extendable where the law allows). We do not charge for reasonable requests. An authorized agent may submit a request on your behalf with proof of your written permission; we may still verify your identity directly. If we decline a request, we will explain why, and you may appeal (Sections 11 and 12).
11. California Privacy Rights (CCPA/CPRA)
This section is for California residents and applies to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), applies to Gym Plus Plus. The CCPA applies to businesses meeting certain size thresholds; as a matter of policy, we generally aim to honor the requests below for all US members, subject to identity verification and applicable legal exceptions, even where a statute does not strictly require it. For California residents, this policy also serves as our notice at collection.
11.1 Categories of personal information
In the last 12 months (and today), we collect the following categories of personal information, as the CCPA defines them:
| CCPA category | What we collect | Disclosed to (categories of recipients) | "Sold" or "shared"? |
|---|---|---|---|
| Identifiers | Name, phone, email, account ID, IP address, device and advertising identifiers, device push token | Service providers; Stripe (our payment processor); partner gyms (name only, at validation); analytics/advertising partners (online identifiers only); Apple (APNs, for push delivery) | Online and device identifiers — yes, may be shared with advertising/analytics partners; opt out below. Name, phone, email, DOB — not disclosed to advertising/analytics partners for their own purposes (Section 5.8). |
| Customer records (Cal. Civ. Code 1798.80(e)) | Name, phone, payment history (no card numbers) | Service providers; Stripe (our payment processor) | No |
| Protected characteristics | Age / date of birth (to enforce the 18+ requirement) | Service providers | No |
| Commercial information | Plan, billing state, purchases, extra-visit charges | Service providers; Stripe (our payment processor); partner gyms (tier and that gym's visits only) | No |
| Internet or other network activity | App and website usage, interaction events, crash and performance data (Section 2.8) | Analytics/advertising/attribution partners; service providers | Yes — may be shared with advertising/analytics partners; opt out below. |
| Geolocation data | Precise location once at check-in — compared, then discarded, never stored (Section 7); approximate IP-level location; postal code, home city, and region collected at app onboarding (Section 2.1) | Precise: no one — it is discarded. Approximate IP-level location may accompany usage data above. Postal code / home city / region: service providers only. | Precise: no. Approximate IP-level: only as part of network-activity data above. Postal code / home city / region: no. |
| Audio/visual information | Profile photo (required) | Partner gym staff, at check-in validation only | No |
| Inferences | Limited — aggregate demand by ZIP, usage patterns | Service providers | No |
| Sensitive personal information | Precise geolocation, only at the moment of check-in; where you sign a Waiver, its medical-fitness acknowledgment (an eligibility attestation — not medical records, never analyzed to infer health conditions) | Geolocation: no one — used to verify presence, then discarded. Waiver acknowledgment: where one exists, only service providers that store that record | No |
Sources: you; your devices; partner gyms (validation and incident reports); Stripe, our payment processor; attribution partners. Purposes: Section 4. Retention: Section 8, per category.
11.2 Sensitive personal information
The main category of sensitive personal information we handle is precise geolocation, and only at the moment of check-in: we use it solely to verify you are at the gym, then discard it. Where you sign our liability waiver, it also records your acknowledgment that you are medically able to exercise (Section 2.6); we treat this as a simple eligibility attestation — we do not collect medical records, and we do not analyze it to infer any health condition. We do not use or disclose sensitive personal information to infer characteristics about you or for any purpose that would give rise to the right to limit under the CCPA and its regulations, so we do not offer a separate "Limit the Use of My Sensitive Personal Information" control. If our use of sensitive personal information ever expands beyond these permitted purposes, we will offer that control.
11.3 Your CCPA rights
- Right to know/access: the categories and specific pieces of personal information we collect, the sources, purposes, and third parties involved.
- Right to delete: subject to legal exceptions (for example, records we must keep for tax, security, or legal-claims purposes, such as a signed waiver, if any).
- Right to correct: inaccurate personal information.
- Right to opt out of "sale"/"sharing": as described in Section 5.8, the identifiers and usage data disclosed to advertising/analytics partners may qualify. Opt out by emailing hello@gymplusplus.app with the subject "Do Not Sell or Share My Personal Information," using any cookie/consent controls or "Your Privacy Choices" link shown on our website, or enabling Global Privacy Control in your browser, which we honor for that browser.
- Right to non-discrimination: we will not deny you the Service, charge you more, or degrade quality because you exercised privacy rights.
11.4 How to exercise and appeal
Submit requests to hello@gymplusplus.app (subject "Privacy Request") or through the app. We will acknowledge your request within 10 business days and explain how we will process it. We verify requests as described in Section 10 and respond within 45 days, extendable by another 45 where permitted with notice. Authorized agents may act for you with written permission. If we deny a request, you may appeal by replying to our decision; a person senior to the original reviewer will re-examine it and respond in writing. You may also direct concerns to the California Privacy Protection Agency or the California Attorney General.
11.5 California "Shine the Light"
Separately from the CCPA, California Civil Code Section 1798.83 lets California residents request, once per year, details about personal information we disclosed to third parties for those third parties' own direct marketing. We do not currently disclose personal information to third parties for their own direct marketing purposes; if that changes, we will provide this information on request.
12. Other US State Privacy Laws
A growing number of states — including Minnesota (our home state, under the Minnesota Consumer Data Privacy Act), Virginia, Colorado, Connecticut, Texas, Oregon, Montana, and Utah — grant residents rights similar to California's: to confirm and access the personal data we process, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, "sale," and certain profiling. These laws apply to businesses meeting size thresholds, and the specific rights available depend on your state — for example, not every state grants a right to correct or an appeal process. Whether or not a given law strictly applies to us, we generally aim to make these choices available to any US resident as a matter of policy, subject to identity verification and applicable legal exceptions.
- Targeted advertising / sale opt-out: handled the same way as California's (Section 11.3) — email us, use cookie controls, or enable Global Privacy Control.
- Profiling: we do not use personal information for profiling that produces legal or similarly significant effects (such as automated denial of essential services or credit).
- Appeals: if we deny your request, you may appeal by replying to our decision. We will respond in writing within the time your state's law requires. If your appeal is denied, you may contact your state attorney general.
13. Children & Age Requirement
Gym Plus Plus is for adults. You must be 18 or older to create an account, and we collect date of birth to enforce this. The Service is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, contact hello@gymplusplus.app and we will delete it.
14. Where Your Data Is Processed
Gym Plus Plus runs on Cloudflare's platform in the United States, and our service providers process data in the United States. Data is encrypted in transit; access codes and session tokens are stored hashed. The Service is designed for US residents. If you access it from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those of your location.
15. Changes to This Policy
We will update this policy as the Service evolves. When we make material changes, we will post the updated policy on this page with a new "Last updated" date and give notice in the app and on the website; where a change materially expands how we use previously collected information, we will provide more prominent notice or obtain consent where the law requires it.
Note on this update: the July 20, 2026 revision adds disclosures about tracking and analytics technologies (Section 3) — which earlier versions of this policy stated we did not use — and about signed waiver records (Sections 2.6 and 8), and expands the waitlist description to name, phone number, and ZIP code.
16. Contact Us
For questions about this policy, or to exercise any privacy right described here:
- Email: hello@gymplusplus.app (use the subject "Privacy Request" for rights requests)
- In the app: Profile → account and deletion options
- Mail: Gym Plus Plus, Rochester, Minnesota, USA