Privacy Policy | Ringside Fitness

Legal

Privacy Policy

How Ringside Fitness collects, uses and looks after your personal data when you train with us, get in touch, or visit our website.

Last updated 30 August 2026
Data controller Ringside Fitness
01

Who we are

Ringside Fitness is a boxing and fitness gym operating as a sole trader business from Unit 227 Northlight Industries, Pendle Road, Brierfield, Nelson, BB9 5FL. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Ringside Fitness is the "data controller" responsible for your personal data — the business that decides why and how it is used.

This policy explains what information we collect about you, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers everyone who interacts with us: members, class participants (and parents/guardians booking on behalf of a junior member), personal training clients, website visitors, and anyone who gets in touch by phone, email, WhatsApp or our contact form.

If anything in this policy is unclear, or you'd like to talk to us about your data, see Section 15 for our contact details.

02

Information we collect

The information we hold about you depends on how you interact with us. It may include:

  • Identity information — name, date of birth or age range, and (for junior members) the name of the parent or guardian who booked on their behalf.
  • Contact information — email address, telephone number, and postal address where relevant (for example for membership correspondence).
  • Booking and membership information — the classes or sessions you book, attendance history, membership type and status, and any notes relevant to your training (for example a coach's note about technique or progress).
  • Payment information — limited billing details needed to process a payment (such as the last four digits of a card and transaction reference). We do not store full card numbers ourselves — card payments are handled directly by Stripe, our payment processor (see Section 9).
  • Health and emergency information — where relevant to training safely, this can include a health/medical declaration, injuries or conditions we should be aware of, and an emergency contact name and number. See Section 6.
  • Enquiry and communications information — anything you tell us via our contact form, email, phone call, WhatsApp message, or social media, including the content of that message.
  • CCTV footage — image and video footage if you visit our premises. See Section 7.
  • Technical information — limited technical data generated automatically when you use our website, such as your browser type and general usage of the site's pages. See Section 8 for more on cookies.

We do not collect any more personal data than we reasonably need for the purposes set out in this policy, and we do not use your data for any automated decision-making or profiling that produces legal or similarly significant effects on you.

03

How we collect it

Most of the information we hold about you, you give to us directly — for example when you:

  • Book a class, membership or personal training session through our online booking system.
  • Fill in our website contact form, or message us by email, phone or WhatsApp.
  • Complete a health or emergency contact declaration before training.
  • Speak to a coach or member of staff in person at the gym.
  • Interact with us on Instagram or Facebook, or leave us a Google review.

A small amount of information is collected automatically — through CCTV when you're on our premises, and through limited technical data generated by your browser when you visit our website (see Section 8).

04

How and why we use it

UK data protection law requires us to have a valid "legal basis" for every way we use your data. The table below sets out our main purposes and the legal basis we rely on for each.

PurposeWhat we useLegal basis
Managing bookings and membershipsProcessing your booking, running your membership, and letting you know about changes to a class you're booked into. Identity, contact, booking and payment information Performance of a contract with you
Taking paymentProcessing membership fees, class fees and personal training payments. Payment information (via Stripe) Performance of a contract; legal obligation (accounting records)
Training safelyUnderstanding any medical conditions, injuries or emergency contact needs relevant to your session. Health and emergency information Explicit consent; vital interests in an emergency
Responding to enquiriesAnswering questions sent via our contact form, email, phone or WhatsApp. Contact and communications information Legitimate interests (running our business responsively)
Site and member securityCCTV monitoring of our premises to protect members, staff and equipment. CCTV footage Legitimate interests (health, safety and security)
Running our websiteKeeping the site working reliably and securely. Technical/cookie information Legitimate interests; consent (for any non-essential cookies)
Accounting and legal complianceKeeping financial records as required by HMRC and other legal obligations. Booking and payment information Legal obligation

Where we rely on your consent — for example for health information, or for any future marketing communications — you can withdraw that consent at any time by contacting us (see Section 15). This won't affect anything we've already done on the basis of your consent before you withdrew it.

Marketing. At present, Ringside Fitness does not run an email newsletter or marketing mailing list. If we introduce one in the future, we will only add you with your clear consent (or, where the law allows it for existing customers about similar services, a right to opt out on every message), and this policy will be updated to reflect it.

05

Information about children

We run Kids & Youth Boxing sessions for children aged 6–13, and some of our other sessions accept members from age 14 upwards. We take the privacy of young members seriously.

  • For Kids & Youth Boxing, a parent or guardian creates the booking and provides the child's name, age and any relevant health or emergency contact information on the child's behalf. We do not knowingly collect personal data directly from a child without a parent or guardian's involvement.
  • For any member under 18 across our other sessions, a parent or guardian is responsible for the booking and for giving any consent we need (for example, consent to hold health information).
  • We only use a child's information for the purposes set out in this policy — running the session safely, managing the booking, and keeping in touch with the parent or guardian about it. We do not use children's data for marketing.
  • A parent or guardian can ask to see, correct or delete the information we hold about their child at any time — see Section 12.
06

Health & medical information

Boxing and contact-based fitness training carries a physical demand, so before you train with us we may ask about any relevant health conditions, injuries or medication, and for an emergency contact. This is "special category data" under UK GDPR, which means it gets extra protection.

  • We only ask for what's needed to run your session safely — for example, whether a coach should be aware of an injury, or who to contact if you need medical attention.
  • We collect this information with your explicit consent (or, for a junior member, your parent or guardian's consent), and it's shared only with the coaches and staff who need it to keep you safe during training.
  • We will use it without consent only where necessary to protect someone's vital interests — for example, sharing relevant details with paramedics in a genuine emergency.
  • You can update or withdraw this information at any time by speaking to us — see Section 15.
07

CCTV at our premises

We operate CCTV at our Nelson gym to protect the safety and security of our members, staff and equipment. Signage is displayed on-site to let you know CCTV is in operation.

  • Footage is used solely for security, incident investigation and safeguarding purposes.
  • Access to footage is restricted to authorised staff, and it is only reviewed when there's a genuine reason to (for example, following a reported incident).
  • Footage is retained for no longer than necessary — typically no more than around 30 days — before it is automatically overwritten, unless a specific clip needs to be kept for longer as part of an investigation, insurance claim or legal process.
  • We do not share CCTV footage with third parties except where required by law, or where necessary to report a crime to the police.
08

Cookies and similar technologies

Our website uses a small number of cookies — tiny text files stored on your device — to make the site work properly. We keep this to a minimum:

  • Strictly necessary cookies. These are required for the site and our online booking system to function — for example, remembering your booking session as you move through the checkout, and security cookies set by Cloudflare (our website's security and performance network) to help protect the site from malicious traffic. These cannot be switched off, as the site won't work properly without them.
  • Embedded third-party content. Some pages embed content from other services — for example a Google Map showing our location. When that content loads, the third party (in this case Google) may set its own cookies in line with its own privacy policy, which we don't control.

We do not currently use analytics cookies (such as Google Analytics) or advertising/tracking cookies (such as a Meta/Facebook pixel) on our website. If that changes in the future, we will update this policy and, where the law requires it, ask for your consent through a cookie banner before any non-essential cookie is set.

Most web browsers let you control cookies through their settings, including blocking or deleting them. Doing so may affect how well parts of our website — including online booking — work.

09

Who we share your information with

We don't sell your personal data, and we only share it where it's genuinely needed to run our business or where the law requires it. This includes:

  • Stripe — our payment processor, who securely handles card payments on our behalf. Stripe is PCI-DSS certified and processes payment data under its own privacy policy; we don't see or store full card details ourselves.
  • Our website and booking platform — our website, contact form and class booking system run on our own hosted WordPress website (protected by Cloudflare's security network), where booking and enquiry data is stored on our behalf as part of running the site.
  • WhatsApp — if you message us via the WhatsApp link on our site, that conversation is carried over WhatsApp's own platform (owned by Meta) and is subject to WhatsApp's own privacy policy.
  • Google — our website embeds a Google Map to show our location, and links to our Google Reviews page; both are provided by Google under its own privacy policy.
  • Instagram and Facebook — our social channels are hosted by Meta; if you message or interact with us there, that's covered by Meta's own privacy policy.
  • Professional advisers and authorities — such as our accountant for bookkeeping purposes, or the police/emergency services where necessary for safety, security or to comply with the law.

Where a third party processes personal data on our behalf (like Stripe or our hosting provider), we only work with providers who give appropriate guarantees to protect your data, and we only share what's necessary for them to provide their service to us.

10

International transfers

We aim to keep your personal data within the UK wherever possible. Some of the third-party services we use — such as Stripe, Google and Meta (WhatsApp, Instagram and Facebook) — operate internationally and may process data outside the UK, including in the United States.

Where this happens, those providers are required to put appropriate safeguards in place, such as the UK's International Data Transfer Addendum or the EU Standard Contractual Clauses, or to rely on a UK "adequacy" arrangement, so that your data continues to receive a level of protection equivalent to UK law.

11

How long we keep your information

We only keep personal data for as long as we genuinely need it. As a general guide:

  • Membership and booking records are kept for as long as you're an active member or client, and for a period afterwards to handle any follow-up queries and to meet our legal obligation to keep financial records — currently at least 6 years from the end of the relevant tax year, in line with HMRC requirements.
  • Enquiries that don't lead to a booking (for example a one-off contact form message) are kept for up to 12 months, then deleted.
  • Health and emergency contact information is kept for as long as you remain a member or client, and is securely deleted within a reasonable period after your membership ends, unless we need to keep it longer for a specific legal or insurance reason (for example, following an incident).
  • CCTV footage is retained for no longer than around 30 days on a rolling basis, unless a specific recording needs to be kept longer as part of an investigation. See Section 7.

When we no longer need your personal data, we securely delete or anonymise it.

12

Your rights

Under UK GDPR, you have a number of rights over your personal data. You can ask us to:

  • Access the personal data we hold about you, and get a copy of it.
  • Correct any information that's inaccurate or incomplete.
  • Delete your personal data, where there's no good reason for us to keep using it.
  • Restrict how we use your data, in certain circumstances.
  • Object to us using your data where we're relying on legitimate interests.
  • Receive a copy of certain data in a portable, machine-readable format.
  • Withdraw consent at any time, where we're relying on your consent (for example, health information).

To exercise any of these rights, contact us using the details in Section 15. We'll respond within one month, and we won't charge you for a reasonable request. We may need to ask you to verify your identity before we can act on a request, to make sure we're not disclosing your data to the wrong person.

13

Keeping your information secure

We take reasonable technical and organisational steps to protect your personal data against loss, misuse or unauthorised access — including restricting who at Ringside Fitness can see sensitive information (like health data), using a reputable, security-protected hosting and payment infrastructure, and only sharing data with third parties who meet appropriate security standards.

No method of storing or transmitting data online is completely secure, but we work to protect your information to a good industry standard and to keep our practices under review.

14

Changes to this policy

We may update this policy from time to time — for example if we start using a new booking system, payment provider or marketing tool. Where a change is significant, we'll take reasonable steps to let existing members know. The "last updated" date at the top of this page shows when it was last revised, and we'd encourage you to check back periodically.

15

Contact & complaints

If you have a question about this policy, or want to exercise any of your rights, we'd rather you speak to us directly first — we're a small, local business and we'll always try to sort things out properly.

Get in touch

Ringside Fitness, Unit 227 Northlight Industries, Pendle Road, Brierfield, Nelson, BB9 5FL.

Not happy with our response?

If you're unhappy with how we've handled your personal data, you have the right to complain to the UK's independent data protection regulator, the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We'd appreciate the chance to address your concerns before you contact the ICO, but you're free to contact them directly at any time.