Privacy Policy

1. INTRODUCTION AND SCOPE 

This Privacy Policy (“Policy”) describes how Eclipse Indoor Cycling, LLC (“we,” “us,”  or “our”), a boutique fitness business located at 12 East Central Avenue, Pearl River, New York 10965 collects, uses, shares, and protects personal information obtained from individuals (“you”  or “users”) who interact with our services, including through our website at  eclipseindoorcycling.com mobile applications, in-person at our studio, or through any other  means of communication. 

This Policy applies to all personal information collected by us in connection with our  workout class services and related activities. By using our services, accessing our website,  providing your information to us, or otherwise engaging with us, you acknowledge that you have  read and understood this Privacy Policy and consent to the collection, use, and disclosure of your  information as described herein. 

We are committed to protecting your privacy and handling your personal information in  an open and transparent manner in compliance with applicable privacy laws and regulations,  including Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, which prohibits unfair  or deceptive practices. 

2. INFORMATION WE COLLECT 

2.1 Contact Information 

We collect basic contact information from you, including: 

  • Full name 
  • Email address 
  • Phone number 
  • Mailing address (if provided) 
  • Emergency contact information 
  • Account credentials (username and password) 
  • Payment information (credit card details, billing address) 

2.2 Health and Fitness Information 

To provide you with appropriate workout class services and ensure your safety during  workouts, we collect certain health and fitness-related information, including: 

  • Fitness goals and objectives 
  • Health conditions and limitations that may affect your ability to participate in spinning  classes 
  • Workout performance data (including metrics such as heart rate, calories burned,  distance, resistance levels, and other performance indicators)

We recognize that health information is sensitive and requires special protection. We collect  and process such information in accordance with applicable laws, including the New York  Health Information Privacy Act (NYHIPA) and the FTC Health Breach Notification Rule, 16  CFR Part 318. 

2.3 Cookies and Tracking Technologies 

We use cookies and similar tracking technologies on our website and mobile applications to  collect information about your browsing activities and interactions with our digital platforms.  These technologies may collect information such as: 

  • IP address 
  • Device information (type, operating system, browser type) 
  • Usage data (pages visited, time spent on pages, links clicked) 
  • Location data (if permitted by your device settings) 
  • Referral sources 

3. HOW WE USE YOUR INFORMATION 

3.1 Business Operations 

We use your personal information for the following business operation purposes: 

  • Creating and managing your account 
  • Processing payments and billing 
  • Scheduling and confirming class reservations 
  • Communicating with you about your account, classes, or services 
  • Providing customer support and responding to inquiries 
  • Personalizing your workout class experience 
  • Analyzing usage patterns to improve our services 
  • Maintaining records of your attendance and performance 
  • Ensuring the safety and security of our facilities and users 
  • Complying with legal obligations 

3.2 Marketing and Advertising 

With your consent, we use your personal information for marketing and advertising purposes,  including: 

  • Sending promotional emails about new classes, special offers, events, or other  information we think may interest you 
  • Conducting targeted advertising campaigns through our website, social media  platforms, or other digital channels 
  • Creating personalized content and recommendations based on your preferences and  past activities 
  • Analyzing the effectiveness of our marketing efforts 
  • Inviting you to participate in surveys or provide feedback 

You may opt out of receiving marketing communications at any time by following the  unsubscribe instructions included in our marketing emails or by contacting us using the  information provided in Section 11 of this Policy.

3.3 Legal Requirements 

We may use your personal information to comply with applicable laws, regulations, legal  processes, or enforceable governmental requests, including: 

  • Responding to subpoenas, court orders, or legal process 
  • Enforcing our terms of service or other agreements 
  • Protecting our rights, property, or safety, or that of our users or others
  • Detecting, preventing, or addressing fraud, security, or technical issues 

4. INFORMATION SHARING AND DISCLOSURE 

4.1 Service Providers 

We share your personal information with certain third-party service providers who perform  functions on our behalf to help us operate our business and deliver services to you. These service  providers include: 

  • Payment processors to process transactions and billing 
  • Scheduling software providers to manage class bookings 
  • Customer relationship management (CRM) systems to maintain customer records • Email service providers to send communications 
  • Analytics providers to help us understand website and app usage 
  • Cloud storage providers to securely store data 

All service providers are contractually obligated to use your personal information only for  the purposes of providing services to us and to maintain appropriate security measures to protect  your information. 

4.2 Legal Requirements 

We may disclose your personal information if required to do so by law or in response to  valid requests by public authorities (e.g., a court or government agency). We may also disclose  your information to: 

  • Enforce our policies and agreements 
  • Protect and defend our rights or property 
  • Prevent or investigate possible wrongdoing in connection with our services • Protect the personal safety of users of our services or the public 
  • Protect against legal liability 

In the event of a data breach that compromises your personal information, we will notify  you and relevant authorities as required by the New York Data Breach Notification Law, General  Business Law § 899-aa. 

4.3 No Other Third-Party Sharing 

Except as described in this Privacy Policy, we do not sell, rent, trade, or otherwise share  your personal information with third parties. We do not share your personal information with  third parties for their direct marketing purposes without your consent.

5. CHILDREN’S PRIVACY (UNDER 18) 

5.1 Parental Consent Requirements 

We welcome minors to participate in our workout classes with appropriate parental consent.  For individuals under the age of Eighteen (18) years of age, we require verifiable parental  consent before collecting, using, or disclosing any personal information. Parents or legal  guardians must: 

  • Complete and sign a consent form in person at our studio 
  • Provide proof of identity and relationship to the minor 
  • Review this Privacy Policy with the minor
  • Acknowledge and consent to the collection and use of the minor’s personal  information as described in this Policy 

If any minor participates without first providing parental consent, we have the right to  delete said information without further notice.  

6. YOUR PRIVACY RIGHTS 

6.1 Access Rights 

You have the right to access the personal information we hold about you. Upon request,  we will provide you with a copy of your personal information in a structured, commonly used,  and machine-readable format. To exercise this right, please contact us using the information  provided in Section 11 of this Policy. 

6.2 Correction Rights 

You have the right to request that we correct any inaccurate or incomplete personal  information we hold about you. If you believe any information we hold about you is incorrect or  incomplete, you may request that we update or correct it by contacting us using the information  provided in Section 11 of this Policy. 

6.3 Deletion Rights 

You have the right to request the deletion of your personal information in certain  circumstances, such as when the information is no longer necessary for the purposes for which it  was collected, or when you withdraw consent and there is no other legal basis for processing. To  exercise this right, please contact us using the information provided in Section 11 of this Policy. 

6.4 Data Portability Rights 

You have the right to receive your personal information in a structured, commonly used,  and machine-readable format and to transmit that information to another data controller without  hindrance, where technically feasible. To exercise this right, please contact us using the  information provided in Section 11 of this Policy. 

We will respond to all legitimate requests within 30 days. Occasionally, it may take us  longer if your request is particularly complex or you have made several requests. In this case, we  will notify you and keep you updated on the progress of your request.

7. DATA RETENTION AND DELETION 

We retain your personal information for as long as necessary to fulfill the purposes  outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.  The specific retention periods depend on the nature of the information and the purposes for  which it is used. 

For active members and account holders, we retain your personal information for the  duration of your membership or account relationship with us. When you terminate your  membership or account, we will retain your information for a reasonable period as required for: 

  • Legal and regulatory compliance 
  • Financial record-keeping 
  • Resolving disputes 
  • Enforcing our agreements 
  • Protecting against fraudulent or illegal activity 

For health and fitness information, we will dispose of such information within 60 days after  it is no longer needed for the purposes for which it was collected, in accordance with NYHIPA  requirements. 

You may request deletion of your personal information at any time by contacting us using  the information provided in Section 11 of this Policy. Upon receiving a verified deletion request,  we will delete your personal information from our records unless retention is necessary for the  reasons outlined above. 

8. DATA SECURITY MEASURES 

We implement appropriate technical, administrative, and physical safeguards to protect your  personal information from unauthorized access, disclosure, alteration, or destruction. Our  security measures include: 

  • Encryption of sensitive personal information both in transit and at rest • Access controls and authentication procedures to limit access to personal information • Regular security assessments and vulnerability testing 
  • Employee training on privacy and data security practices 
  • Physical security measures at our facilities 
  • Incident response procedures to address potential data breaches 
  • Regular backups to prevent data loss 

While we strive to use commercially acceptable means to protect your personal information,  no method of transmission over the Internet or electronic storage is 100% secure. Therefore, we  cannot guarantee absolute security. If you have reason to believe that your interaction with us is  no longer secure, please immediately notify us using the contact information provided in Section  11 of this Policy.

9. CHANGES TO THIS PRIVACY POLICY 

We may update this Privacy Policy from time to time to reflect changes in our practices,  services, or applicable laws and regulations. When we make changes, we will update the “Last  Updated” date at the top of this Policy and take the following steps to notify you: 

  • Send an email notification to the email address associated with your account
  • Post a notice on our website homepage 
  • Display a prominent notice when you next log in to your account 

We will provide at least ten (10) days’ advance notice before implementing any material  changes that affect your rights or how we use your personal information. Your continued use of  our services after the effective date of the revised Privacy Policy constitutes your acceptance of  the changes. 

We encourage you to review this Privacy Policy periodically to stay informed about our  information practices. If you do not agree with any changes made to this Policy, you must  discontinue using our services. 

10. CONTACT INFORMATION FOR PRIVACY MATTERS 

If you have any questions, concerns, or requests regarding this Privacy Policy or our  privacy practices, please contact us using the following information: 

Privacy Officer 

Victoria Bertussi  
12 East Central Avenue 
Pearl River, New York 10965 

Email: info@eclipseindoorcycling.com Phone: (845) 825-9726 

We are committed to working with you to obtain a fair resolution of any privacy concern  or complaint. If you believe that we have not adequately addressed your concerns, you may have  the right to file a complaint with a data protection authority or other regulatory agency. 

11. EFFECTIVE DATE 

This Privacy Policy is effective as of November 24, 2025 and may be modified or  amended from time to time.