TRVLFIT Privacy Policy
Last Updated: November 19, 2025
Effective Date: November 19, 2025
Introduction
TRVLFIT ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, website (www.trvlfit.com), and related services (collectively, the "Service").
Please read this Privacy Policy carefully. By accessing or using the Service, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
1. Information We Collect
We collect information about you in various ways when you use our Service.
1.1 Personal Information You Provide
When you register for an account or use the Service, you may provide us with:
Account Information:
- Full name
- Email address
- Phone number (optional)
- Password (encrypted)
- Profile photo (optional)
- Date of birth (for age verification)
Billing Information:
- Billing address (street, city, state, ZIP code, country)
- Payment card information is collected and processed by Stripe (we do not store complete card details)
Communication Information:
- Messages you send us (support emails, feedback)
- Reviews and ratings you submit
- Responses to surveys or questionnaires
Other Information:
- Gym check-in notifications to facilities
- Refund request details and reasons
- Preferences and settings
1.2 Information Collected Automatically
When you use the Service, we automatically collect certain information:
Usage Data:
- Pages or screens viewed
- Time spent on pages
- Links clicked
- Search queries
- Features used
- Check-in history
- Purchase history
- Pass usage patterns
Device Information:
- Device type and model
- Operating system and version
- Unique device identifiers
- Mobile network information
- IP address
- Browser type and version
- Screen resolution
Location Information:
- Precise location (GPS coordinates) when you use location-based features
- Approximate location derived from IP address
- Location data is used to show nearby fitness facilities
You can control location permissions through your device settings. Disabling location access may limit certain features of the Service.
Cookies and Similar Technologies:
- We use cookies, web beacons, and similar tracking technologies to collect information about your activity on our Service
- Cookies help us remember your preferences, analyze usage patterns, and improve the Service
- You can control cookie preferences through your browser settings
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 Service Delivery and Operations
To Provide the Service:
- Create and manage your account
- Process your pass purchases
- Generate QR codes for facility check-ins
- Track your check-ins and pass usage
- Show you relevant fitness facilities based on your location
- Communicate with you about your account and purchases
To Process Payments:
- Facilitate transactions through our payment processor (Stripe)
- Calculate applicable taxes based on your billing address
- Process refunds when approved
- Maintain transaction records for accounting and legal purposes
To Improve the Service:
- Analyze usage patterns and trends
- Identify and fix technical issues
- Develop new features and functionality
- Enhance user experience
- Conduct research and analytics
2.2 Communications
Transactional Communications:
- Purchase confirmations
- Check-in confirmations
- Pass expiration reminders
- Refund status updates
- Password reset instructions
- Important service announcements
Marketing Communications (with your consent):
- New facility announcements
- Special offers and promotions
- Newsletter and blog updates
- Feature announcements
You can opt out of marketing communications at any time by:
- Clicking "unsubscribe" in any marketing email
- Adjusting notification settings in the app
- Contacting us at support@trvlfit.com
Note: You cannot opt out of transactional communications related to your account and purchases.
2.3 Safety and Security
- Verify your identity
- Prevent fraud and abuse
- Enforce our Terms of Service
- Protect our rights and property
- Respond to legal requests and prevent harm
2.4 Personalization
- Remember your preferences and settings
- Show you relevant facilities and passes
- Customize your experience
- Provide personalized recommendations
3. How We Share Your Information
We do not sell your personal information to third parties. We share your information only in the following circumstances:
3.1 With Fitness Facilities
When you purchase a pass or check in at a facility, we share limited information with that facility:
- Your name
- Check-in date and time
- Pass type and details
- Check-in confirmation
This information is necessary for the facility to verify your access and provide services.
3.2 With Service Providers
We share information with third-party service providers who perform services on our behalf:
Payment Processing:
- Stripe, Inc. processes all payments
- Stripe collects and processes your payment card information
- See Stripe's Privacy Policy: https://stripe.com/privacy
Email Services:
- SendGrid and Mailgun send transactional and marketing emails
- These providers have access to email addresses and message content
Cloud Hosting:
- Heroku hosts our backend infrastructure
- Heroku may have access to data stored on our servers
Cloud Storage:
- Cloudinary stores and delivers images (facility photos, user profile photos)
- Cloudinary processes and caches images for optimal delivery
Analytics and Monitoring:
- Firebase provides analytics, crash reporting, and push notifications
- Firebase collects usage data, device information, and performance metrics
Authentication:
- Apple (for Apple Sign In) provides authentication services
- Apple shares minimal information (name, email) when you use Apple Sign In
All service providers are contractually obligated to protect your information and use it only for the purposes we specify.
3.3 For Legal Reasons
We may disclose your information if required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service and other agreements
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users or the public
- Investigate and prevent fraud, security issues, or illegal activity
3.4 Business Transfers
If TRVLFIT is involved in a merger, acquisition, asset sale, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.
3.5 With Your Consent
We may share your information with third parties when you give us explicit consent to do so.
3.6 Aggregated or De-Identified Data
We may share aggregated or de-identified information that cannot reasonably be used to identify you. For example:
- "50 users checked in at this facility this week"
- "Average pass price is $20"
- Industry reports and analytics
4. Data Security
We implement reasonable administrative, technical, and physical security measures to protect your information from unauthorized access, use, disclosure, alteration, or destruction.
Security Measures Include:
- Encryption of data in transit using SSL/TLS
- Encryption of sensitive data at rest
- Secure password hashing (passwords are never stored in plain text)
- Regular security assessments and updates
- Access controls and authentication
- Employee training on data protection
However, please note:
- No method of transmission over the internet is 100% secure
- No method of electronic storage is 100% secure
- We cannot guarantee absolute security of your information
- You are responsible for keeping your account credentials confidential
If a data breach occurs that affects your information, we will notify you in accordance with applicable law.
5. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy.
Retention Periods:
- Account Information: Retained while your account is active and for a reasonable period after deletion (to comply with legal obligations)
- Transaction Records: Retained for at least 7 years for tax, accounting, and legal purposes
- Check-in History: Retained while your account is active and for 1 year after deletion
- Communication History: Retained for 2 years for customer support purposes
- Reviews: Retained indefinitely unless you request deletion or we remove them for violations
- Analytics Data: Aggregated data may be retained indefinitely
When you delete your account:
- Personal information is removed from active systems within 30 days
- Transaction records are retained for legal and accounting purposes
- Anonymized data may be retained for analytics
6. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information.
6.1 Access and Portability
You have the right to:
- Access the personal information we hold about you
- Request a copy of your data in a structured, commonly used format (data portability)
How to exercise: Email us at support@trvlfit.com with your request.
6.2 Correction
You have the right to:
- Correct inaccurate or incomplete personal information
- Update your account information at any time through the app settings
How to exercise: Update information in app settings or email support@trvlfit.com.
6.3 Deletion
You have the right to:
- Request deletion of your personal information
- Delete your account through the app settings
How to exercise: Use the "Delete Account" feature in the app or email support@trvlfit.com.
Note: Some information may be retained as required by law or for legitimate business purposes (transaction records, legal compliance, fraud prevention).
6.4 Opt-Out of Marketing
You have the right to:
- Opt out of marketing emails by clicking "unsubscribe"
- Disable marketing push notifications in app settings
- Request to be removed from marketing lists by emailing support@trvlfit.com
6.5 Location Data Control
You have the right to:
- Enable or disable location services in your device settings
- Control when the app can access your location (always, while using the app, never)
Note: Disabling location access will limit your ability to discover nearby facilities.
6.6 Do Not Track
Some browsers have "Do Not Track" features. Currently, we do not respond to Do Not Track signals because there is no industry standard for how to interpret them.
7. Children's Privacy (COPPA Compliance)
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13.
If you are under 13:
- Do not use the Service
- Do not create an account
- Do not provide any personal information
If we discover that we have collected information from a child under 13:
- We will delete that information immediately
- We will terminate the account
If you believe a child under 13 has provided information to us:
- Please contact us immediately at support@trvlfit.com
For users aged 13-17:
- You may only use the Service with parental consent
- Your parent or guardian must agree to these Terms and Privacy Policy
8. International Data Transfers
TRVLFIT operates in the United States. If you are accessing the Service from outside the United States, please be aware that:
- Your information will be transferred to and processed in the United States
- The United States may have different data protection laws than your country
- By using the Service, you consent to the transfer of your information to the United States
For European Union (EU) and United Kingdom (UK) Users:
- We comply with applicable data protection laws including the General Data Protection Regulation (GDPR)
- Data transfers are protected by appropriate safeguards
- You have additional rights under GDPR (see Section 9)
9. Rights Under GDPR (For EU/UK Users)
If you are located in the European Union or United Kingdom, you have additional rights under the General Data Protection Regulation (GDPR):
9.1 Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract: Processing necessary to provide the Service and fulfill our contract with you
- Consent: You have given consent for specific purposes (e.g., marketing communications)
- Legitimate Interests: Processing necessary for our legitimate business interests (e.g., fraud prevention, analytics)
- Legal Obligation: Processing required to comply with legal obligations
9.2 Your GDPR Rights
In addition to the rights in Section 6, you have the right to:
Right to Object:
- Object to processing based on legitimate interests
- Object to direct marketing at any time
Right to Restriction:
- Request restriction of processing in certain circumstances
Right to Withdraw Consent:
- Withdraw consent at any time (does not affect lawfulness of prior processing)
Right to Lodge a Complaint:
- File a complaint with your local data protection authority
Automated Decision-Making:
- We do not use automated decision-making or profiling that produces legal or similarly significant effects
9.3 EU Representative
For GDPR-related inquiries, contact us at support@trvlfit.com with "GDPR Request" in the subject line.
10. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
10.1 Right to Know
You have the right to request:
- Categories of personal information we collected
- Categories of sources from which information was collected
- Business purpose for collecting information
- Categories of third parties with whom we share information
- Specific pieces of personal information we collected
10.2 Right to Delete
You have the right to request deletion of personal information we collected from you, subject to certain exceptions.
10.3 Right to Opt-Out of Sale
We do not sell your personal information. California residents have the right to opt out of the sale of personal information, but since we do not sell information, this right does not apply.
10.4 Right to Non-Discrimination
You have the right to not receive discriminatory treatment for exercising your CCPA rights.
10.5 How to Exercise Your Rights
To exercise your CCPA rights:
- Email: support@trvlfit.com with "CCPA Request" in the subject line
- Include your name, email, and description of your request
- We will verify your identity before processing the request
Response Time: We will respond within 45 days of receipt.
10.6 Authorized Agent
You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.
10.7 California "Shine the Light" Law
California residents can request information about how we disclose personal information to third parties for direct marketing purposes. Contact us at support@trvlfit.com with "California Shine the Light" in the subject line.
11. Other State Privacy Rights
Residents of other states may have additional privacy rights under state law. We will comply with all applicable state privacy laws.
If you are a resident of:
- Virginia (Virginia Consumer Data Protection Act)
- Colorado (Colorado Privacy Act)
- Connecticut (Connecticut Data Privacy Act)
- Utah (Utah Consumer Privacy Act)
You may have rights similar to those described in Section 10. Contact us at support@trvlfit.com to exercise your rights.
12. Cookies and Tracking Technologies
12.1 What Are Cookies?
Cookies are small text files stored on your device that help us provide and improve the Service.
12.2 Types of Cookies We Use
Essential Cookies:
- Required for the Service to function
- Enable core features like account authentication
- Cannot be disabled
Performance Cookies:
- Help us understand how users interact with the Service
- Collect anonymous usage data
- Help us improve performance and user experience
Functional Cookies:
- Remember your preferences and settings
- Provide enhanced features and personalization
Marketing Cookies (with consent):
- Track your activity for marketing purposes
- Help us deliver relevant advertising
12.3 Third-Party Cookies
Third-party service providers (like analytics providers) may set their own cookies. We do not control these cookies.
12.4 Managing Cookies
You can control cookies through:
- Browser Settings: Most browsers allow you to refuse or delete cookies
- Mobile Device Settings: Control app tracking and advertising preferences
- Opt-Out Tools: Use opt-out tools provided by advertising networks
Note: Disabling cookies may limit functionality of the Service.
13. Third-Party Links
The Service may contain links to third-party websites, services, or applications that are not operated by us.
We are not responsible for:
- Privacy practices of third-party sites
- Content of third-party sites
- Your interactions with third-party sites
We recommend that you review the privacy policy of any third-party site you visit.
Examples of third-party links:
- Gym websites
- Social media platforms
- Payment processor (Stripe)
- Map services (Google Maps, Apple Maps)
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons.
When we make changes:
- We will update the "Last Updated" date at the top of this policy
- We will notify you of material changes by email or push notification
- We will post the updated policy on the Service
Your continued use of the Service after changes become effective constitutes your acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Data Protection Officer
While we are not required to appoint a Data Protection Officer (DPO), you can contact us with privacy-related questions at:
Email: support@trvlfit.com
Subject Line: "Privacy Inquiry" or "Data Protection"
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
TRVLFIT
138 Ewald Ave
Marlborough, MA 01752
United States
Email: support@trvlfit.com
Website: www.trvlfit.com
For Privacy-Related Requests:
- Include "Privacy Request" in the email subject line
- Provide your name, email address, and account information
- Describe your request or concern in detail
- We will respond within 30 days (or as required by applicable law)
17. Consent
By using the Service, you consent to the collection, use, and sharing of your information as described in this Privacy Policy.
You can withdraw consent for certain uses of your information (such as marketing communications) at any time by:
- Adjusting your notification settings in the app
- Clicking "unsubscribe" in emails
- Contacting us at support@trvlfit.com
Note: Withdrawing consent does not affect the lawfulness of processing based on consent before its withdrawal.
18. Additional Information for Specific Jurisdictions
18.1 Australia
If you are in Australia, you may have rights under the Australian Privacy Act. Contact us at support@trvlfit.com with "Australian Privacy Inquiry" in the subject line.
18.2 Canada
If you are in Canada, you may have rights under the Personal Information Protection and Electronic Documents Act (PIPEDA). Contact us at support@trvlfit.com with "Canadian Privacy Inquiry" in the subject line.
18.3 Other Countries
If you are in a country with specific privacy laws not addressed above, we will comply with applicable local privacy laws. Contact us to learn more about your rights.
19. Definitions
Personal Information: Information that identifies, relates to, or could reasonably be linked with you.
Service: The TRVLFIT mobile application, website, and all related services.
Device: Any device that can access the Service, such as a smartphone, tablet, or computer.
Cookies: Small files stored on your device that help us provide and improve the Service.
Usage Data: Information about how you use the Service, including pages viewed, features used, and interactions.
Acknowledgment
BY USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.
IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, DO NOT USE THE SERVICE.
ยฉ 2025 TRVLFIT. All rights reserved.