Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how Athlete Rising LLC ("Athlete Rising," "we," "us") collects, uses, shares, and protects personal information. It applies to athleterising.com, the Athlete Rising gym management platform, and our mobile applications for gym staff and gym members (together, the "Services").
1. Two different roles
Athlete Rising handles personal information in two distinct capacities, and your rights differ depending on which applies.
- As a controller. When a gym owner or staff member creates an account, when someone contacts us, or when a visitor browses our website, we determine how that information is used. This Policy governs it directly.
- As a service provider to gyms. When a gym uses our platform to manage its members, the gym decides what member information is collected and why. We process that information on the gym's instructions, under our agreement with them. If you are a gym member, your gym's own privacy policy governs that data, and requests about it should go to your gym first. We will support the gym in responding.
2. Information we collect
Account and gym information
Name, email address, and password credentials for gym owners and staff; gym name, sport type, location, business settings, and subscription plan.
Gym member information
Provided by the gym or by members themselves: name, email address, phone number, membership status and history, class and attendance records, check-in timestamps, notes the gym records, and lead or inquiry details submitted through a gym's sign-up form.
Payment information
Payments are processed by Stripe, Inc. Card numbers and bank details are submitted directly to Stripe and are never stored on Athlete Rising systems. We retain only non-sensitive records such as transaction identifiers, amounts, dates, subscription status, and the last four digits and brand of a payment method where Stripe provides them. Stripe's handling of your data is governed by Stripe's Privacy Policy.
Device and usage information
IP address, browser or device type, operating system version, app version, pages or screens viewed, and timestamps. We use this for security, diagnostics, and reliability.
Communications
Messages you send us, and records of emails or text messages sent through the platform on a gym's behalf, including delivery status.
Biometrics โ what we do not collect
Our mobile apps can use Face ID, Touch ID, or an equivalent device biometric to unlock a saved session. This check happens entirely on your device through the operating system. Athlete Rising never receives, transmits, or stores biometric data of any kind. We are told only whether the device unlock succeeded.
3. How we use information
- To provide, operate, and maintain the Services
- To authenticate users and keep accounts secure
- To process subscription payments and, for gyms, to facilitate member payments through Stripe
- To send transactional messages โ receipts, payment notices, security alerts, and service updates
- To send member engagement messages on behalf of a gym, at that gym's direction
- To generate attendance, retention, and revenue analytics for the gym's own business
- To provide support and respond to inquiries
- To detect, investigate, and prevent fraud, abuse, and security incidents
- To comply with legal obligations
4. How information is shared
- With your gym. Member information is accessible to the gym that manages the membership.
- Service providers. Amazon Web Services (hosting and infrastructure), Stripe (payment processing), and email and SMS delivery providers. Each is bound to handle information only as needed to provide their service.
- Integrations you enable. If a gym connects a CRM or another third-party tool, information flows according to that configuration and the third party's own policy.
- Legal and safety. Where required by law, subpoena, or legal process, or to protect the rights, safety, and property of Athlete Rising, our customers, or the public.
- Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy's continued application.
5. Data retention
We retain information for as long as an account is active and as needed to provide the Services. Specific periods:
- After suspension for non-payment, account data is retained for ninety (90) days from the suspension date, giving the account holder a chance to reactivate or export before permanent deletion. This is described in our Terms of Service.
- After voluntary account closure, data is deleted or anonymized within a commercially reasonable period, except where retention is required by law.
- Financial and transaction records are retained as long as required by tax, accounting, and audit obligations.
- Security and diagnostic logs are retained on a rolling short-term basis.
6. Security
We use industry-standard safeguards, including encryption in transit and at rest, isolated per-gym data boundaries, least-privilege access controls, and secrets management for credentials. On mobile devices, session tokens are stored in the operating system's secure keychain and are never written to plain-text storage. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your choices and rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. You may also have the right to appeal a denied request and to be free from discrimination for exercising these rights.
- Gym owners and staff can exercise these rights through account settings or by contacting us.
- Gym members should contact their gym, which controls that data. We assist the gym in fulfilling requests.
- Marketing messages can be stopped by using the unsubscribe link in any email or replying STOP to a text. Transactional messages about your account will still be sent.
To make a request, email privacy@athleterising.com.
8. Children's privacy
The Services are not directed to children, and we do not knowingly collect personal information directly from children. Many gyms and academies operate youth programs. Where a gym enters information about a minor member into the platform, the gym is responsible for obtaining any parental or guardian consent required by law, and a parent or guardian should direct requests about that information to the gym. If we learn we have collected information directly from a child without appropriate consent, we will delete it.
9. Where data is processed
The Services are operated in the United States, and information is processed and stored there. If you access the Services from outside the United States, you understand that your information will be transferred to and processed in the United States.
10. Cookies and similar technologies
Our website uses only what is necessary to serve pages and remember essential preferences. The platform uses cookies and equivalent local storage strictly to maintain your signed-in session and protect against abuse. We do not use advertising or cross-site tracking cookies.
11. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above will change, and material changes will be communicated by email or through the Services before taking effect.
12. Contact us
Athlete Rising LLC
Brooklyn, New York
privacy@athleterising.com