Thrive Gym Privacy Policy

Last updated: 23 July 2026


This Privacy Policy explains how Thrive Gym collects, uses, shares, stores and protects personal information when you use our website, join or visit one of our clubs, use our membership services, or use the Thrive Gym member app and portal.


It applies to members, prospective members, day-pass users, visitors, junior members and their parents or guardians, app users, website users, and anyone who contacts or interacts with Thrive Gym.


Who we are

THRIVEGYM247 LTD (company number 14035600), trading as Thrive Gym (referred to as Thrive Gym, we, us or our), is the controller of the personal information described in this policy. This means we decide why and how that information is used.

Registered office: Alden View, Alden Road, Helmshore, Rossendale, England, BB4 4AQ.

Rawtenstall club: Orient One, New Hall Hey Road, Rawtenstall, Lancashire, BB4 6AJ.


Bolton club: Unit 1 Meadow Business Park, Meadow Lane, Breightmet, Bolton, BL2 6PT.


Privacy contact: memberships@thrivegymuk.co.uk.


Website: www.thrivegymuk.co.uk.


Our member technology may be described as Membr, Xplor Gym or Resamania and is supplied by companies within the Xplor group. In this policy, App means the Thrive Gym member app, member portal and related Xplor or Membr services made available to you.


What this policy covers

This policy applies when you:

join, visit or buy a membership, class, product, service or pass from us;

- use our clubs, facilities, Wi-Fi, website, online joining journey, App or member portal;

- book or attend a class, event, induction, programme, personal-training session or other service;

- complete a health, fitness or readiness questionnaire or provide accessibility information;

- connect a wearable, fitness platform, calendar or other third-party service to the App;

- contact us, complete a form, take part in a survey, competition or promotion, leave a review or make a complaint; or

- interact with our advertising, emails, SMS messages, App notifications or social-media pages.


Third-party services

Some services are supplied by third parties that may act as a separate controller for information they collect directly from you. Examples include an independent personal trainer, connected wearable provider, app store, social-media platform or payment provider. Their privacy policy will also apply to their own processing.


How we collect personal information

Information you give us

- when you join, buy a pass, create an account, complete a form, set fitness goals or provide an emergency contact;

- when you book or attend a class, session, event, induction, programme or personal-training service;

- when you contact us, enter a competition, respond to a survey, leave a review or make a complaint;

- when you choose marketing preferences, upload content, connect a device or third-party service, or grant an App permission; and

- when a parent or guardian registers or manages a junior member.


Information collected automatically

When you use our website, App, member portal, club access systems or Wi-Fi, we may automatically collect device and technical information, cookie and similar-technology data, login and security logs, App activity, bookings, access scans, attendance information and interactions with communications.

Information from other sources

We may receive information from Xplor or Resamania; Xplor Pay; and other membership or payment providers; banks and card providers; booking and access systems; connected fitness or wearable services you authorise; personal trainers and instructors; a parent or guardian; an employer or benefit provider; referral or promotional partners; social-media and advertising platforms; fraud-prevention and identity-verification services; and publicly available sources where lawful.

If someone gives us information about another person, such as an emergency contact or junior member, they must have authority to do so and should make this policy available to that person where appropriate.


The personal information we collect

Identity and contact information. Your name, title, date of birth, age, gender where provided, photograph, postal and billing address, email address, telephone number, member number and emergency-contact details.

Membership and profile information. Your membership type and status, club location, start and end dates, account credentials, QR or access identifier, preferences, goals, interests, membership notes and evidence of eligibility for a discount.

- Financial and transaction information. Payment status, Direct Debit details, limited card information, transaction history, invoices, refunds, arrears and payment correspondence. Full card details are normally handled by our payment providers rather than stored by Thrive Gym or in the App.

Booking, attendance and access information. Classes, sessions and events booked or attended, cancellations, waiting lists, club-entry and exit records, guest passes and related access-control or security events.

Fitness and workout information. Fitness goals, activity levels, workouts, exercises, sets, repetitions, weights, progress, programme information, coaching interactions, nutritional information and information from connected devices or services where you choose to connect them.

Health and accessibility information. Information about an injury, illness, disability, pregnancy, medication, long-term condition, accessibility requirement or other health and safety matter that you choose or need to provide, including information supplied for readiness questionnaires, membership freezes, incidents or emergencies.

Technical and usage information. IP address, device and browser type, operating system, time zone, language, approximate location, device identifiers, login data, crash and diagnostic data, App version, pages and features used, referral source and interaction times.

Communications and marketing information. Enquiries, emails, messages, call notes, complaints, feedback, survey and review responses, communication preferences, campaign interactions and advertising-audience information.

- Images and security information. CCTV images, incident footage, profile images, photographs or video taken with permission and call recordings where a call-recording system is used and you are informed.

- Junior-member information. The child's name, date of birth, attendance, membership details and necessary health, safety or accessibility information, together with parent or guardian identity, contact and consent records.

We may also use aggregated or anonymised information for reporting, capacity planning, service improvement and statistical purposes. Information that can no longer identify an individual is not personal information.


Health, fitness and other sensitive information

Information about health, disability, injury, pregnancy or similar matters can be special category personal data and receives extra protection under data-protection law. Fitness and workout information may also reveal information about health, so we handle it carefully.

For routine health and fitness processing, we will normally ask for your explicit consent. You may withdraw that consent at any time. We may also use health information where necessary to protect someone's vital interests in an emergency, to establish, exercise or defend legal claims, or where another condition permitted by law applies.

Please provide only information that is relevant. We are not a medical provider and the App, programmes and fitness information are not a substitute for professional medical advice.

If you do not provide information

Some identity, contact, payment and membership information is required to enter into or administer a membership. Health information is generally optional, but if information is reasonably required to deliver an activity safely, arrange an accessibility adjustment or deal with an emergency, we may be unable to provide that part of the service without it.


How and why we use personal information

We only use personal information when we have a lawful basis. More than one basis may apply. Where we rely on legitimate interests, we consider our business need, whether the use is necessary and the impact on your rights. You can ask us for more information about this assessment.

Responding to enquiries, arranging tours and free passes, and taking steps before membership. We rely on steps taken at your request before a contract and our legitimate interests in customer service and developing our business.

Creating and managing memberships, accounts and App access. We rely on performance of our contract and our legitimate interests in efficient administration and security.

Taking payments, issuing refunds, managing Direct Debits, preventing fraud and recovering arrears. We rely on performance of our contract, legal obligations and legitimate interests in payment administration, fraud prevention and debt recovery.

- Providing club access, class bookings, attendance, coaching, programmes, support and member benefits. We rely on performance of our contract and our legitimate interests in operating and improving services.

Personalising workouts, coaching and the App and connecting authorised devices or services. We rely on performance of our contract, legitimate interests and consent where required. We rely on explicit consent where health data is involved.

Supporting health, accessibility, safeguarding and emergency response. We rely on contract and legitimate interests, together with explicit consent, vital interests, legal claims or another permitted condition for special category information.

Protecting members, staff, visitors, premises, equipment and systems. We rely on legitimate interests in safety, security, loss prevention, enforcing gym rules and dealing with legal claims, together with legal obligations where applicable.

Sending service and operational communications. We rely on performance of our contract and legitimate interests in keeping members and users informed.

Sending offers, news and promotions and measuring marketing. We rely on consent or legitimate interests where permitted. We send electronic marketing only in accordance with the Privacy and Electronic Communications Regulations.

Operating, analysing, securing, testing and improving our website, App, Wi-Fi and services. We rely on legitimate interests and, where required, consent or another permitted exemption for cookies and similar technologies.

Requesting feedback, conducting surveys, managing complaints and maintaining service quality. We rely on legitimate interests in customer service and improvement, and legal obligations for data-protection complaints.

Complying with law, regulators, taxation, insurance and legal claims. We rely on legal obligations, recognised or ordinary legitimate interests and the legal-claims condition where special category information is involved.

Managing a business sale, restructure or acquisition. We rely on legitimate interests in managing our business and corporate transactions.

We will not use personal information for a new purpose that is incompatible with the purpose for which it was collected unless we obtain consent or the use is otherwise permitted by law. We will update this policy or give you a separate notice where required.


The member platform, App and connected services

The App and member portal allow you to manage your account, access the club, browse and book classes, receive service information, communicate with staff or trainers, view programmes and record workouts or progress. The exact functions available may change.

Xplor and Resamania

Companies within the Xplor group provide our membership-management technology, App and related services. They generally process member information on our instructions as our processor, although they may be a separate controller for limited purposes described in their own privacy notice.

Xplor privacy information: www.xplortechnologies.com/privacy-notice/.

App and device permissions

Depending on the features you use, the App may ask for permission to send notifications, use your camera for QR or profile functions, add a booking to your calendar, use approximate location or connect to a fitness or wearable service. Optional permissions can be managed in the App or device settings. Disabling a permission may prevent the related feature from working.

Connected fitness and wearable services

If you choose to connect a wearable, health platform, calendar, Technogym service or another third-party service, we will receive and share only the information needed for the connection and the features you select. You can disconnect the service through available settings. The third party's privacy policy will also apply.

App security

You are responsible for keeping your account credentials and devices secure. Tell us promptly if you believe an account or QR access credential has been compromised. Do not share your member access credential with another person.


Payments and membership administration

We use specialist providers to process card payments, Direct Debits, recurring payments, refunds and payment communications. Depending on your membership and the date it was set up, these may include Xplor Pay, banks, card schemes and other regulated payment partners.

Payment providers may receive identity, contact, membership, bank, card and transaction information and may process some information as separate controllers to meet regulatory, fraud-prevention and payment-network obligations. Thrive Gym and the App do not normally retain full payment-card details.

If an account falls into arrears, relevant information may be shared with the membership administrator, payment provider, debt-recovery or tracing service, professional adviser or court where necessary and lawful.


Marketing, advertising and communications

Service messages

We may send messages that are necessary to administer your membership or provide a service, such as payment, access, booking, timetable, safety, maintenance, opening-hours and important policy updates. These are not marketing and may continue even if you opt out of promotional messages.

Promotional marketing

We may send news, offers, events and promotions by email, SMS, App notification, telephone or post where we have consent or another lawful basis and the communication is permitted by direct-marketing law. You can opt out at any time by using an unsubscribe link, replying STOP where offered, changing App preferences or contacting us.

Opting out does not erase all information. We may keep a minimal suppression record so that we can respect your choice.


Advertising audiences and measurement

Where permitted, we may measure campaign performance and use limited information to create or exclude advertising audiences on services such as Google, Meta and TikTok. Information may be hashed before upload, but it may still be personal information. We use these functions only where our lawful basis and the relevant cookie or marketing rules allow. Platform privacy settings provide additional controls.


Photographs, video and member stories

We will seek permission or rely on another clear lawful basis before using an identifiable member image, video, testimonial or transformation story for promotional purposes. General CCTV footage is not used for marketing.


Cookies and similar technologies

Our website, App, member portal, emails and advertising may use cookies, pixels, software development kits, local storage and similar storage or access technologies. These can keep services working, remember preferences, secure accounts, understand use, diagnose problems and measure or personalise marketing.

Strictly necessary and security technologies. These support core site, App, login, payment, preference and security functions. They are normally used without consent where the law permits because the service cannot work properly without them.

Functionality technologies. These remember settings and improve a requested feature. We use consent or a legal exemption where available and provide a simple means of objecting where required.

Analytics and performance technologies. These help us understand visits, usage, faults and performance. They are used with consent unless a specific legal exemption applies.

Advertising and social-media technologies. These measure campaigns, limit repetition and support relevant advertising or social features. They are used only with consent where required.

Use the cookie-preference control on our website or the relevant App and device settings to manage available choices. Browser settings can also block or delete cookies, although this may affect functionality. Our cookie banner or cookie list should be read with this policy and identifies the technologies currently in use.


CCTV, access control, incidents and club safety

We may use CCTV in and around our clubs, together with QR codes, member access credentials, entry systems and attendance records, to protect members, staff, visitors, premises and equipment; manage access and capacity; investigate accidents, complaints, misconduct, theft and damage; and establish or defend legal claims.

CCTV is used only in areas where it is appropriate and is not used in changing rooms, toilets, showers or other areas where a high degree of privacy is expected. Signs are displayed where CCTV is used. We do not use CCTV for facial recognition or marketing. We do not routinely record audio unless a specific system and clear notice state otherwise.

Footage and access records are limited to authorised staff and relevant providers. They may be disclosed to police, insurers, legal advisers or others where necessary and lawful. If footage is needed for an incident, complaint or claim, the relevant clip may be kept longer than the routine period.


Junior members and children

Adult membership is available from age 16. We may also offer Kids Boxing or another supervised service for children under 16. Our App is not intended to be used independently by children under 16 unless we expressly provide an age-appropriate service.

Where a child takes part in a junior service, a parent or guardian should complete and manage the registration unless we state otherwise. We may collect the child's name, date of birth, attendance and the minimum health, safety or accessibility information needed to provide the activity, together with parent or guardian contact and consent records.

We take children's needs into account when designing online services likely to be used by them. We do not knowingly use children's information for behavioural advertising or send direct marketing to a child. We use additional safeguards and will remove information collected without appropriate authority when identified.

A parent or guardian can contact us about a child's information. Depending on age, understanding and the law, the child may be able to exercise their own data-protection rights.


Who we share personal information with

We do not sell personal information. We share it only where necessary for the purposes described in this policy, where the law permits, and with appropriate protections.

Membership, App and payment providers. This includes Xplor or Resamania, Xplor Pay, banks, card schemes and Direct Debit services.

IT and operational providers. This includes website hosting and management, cloud storage, cybersecurity, access control, Wi-Fi, communications, email, SMS, survey, analytics, customer-support and booking services.

Club service providers. This includes instructors, coaches, personal trainers, cleaners, maintenance providers, first-aid or emergency support and member-benefit partners where needed to provide a requested benefit.

Advertising and social platforms. This can include Google, Meta and TikTok where the relevant consent or other legal permission applies.

Professional and risk advisers. This includes insurers, auditors, accountants, solicitors, debt-recovery providers and fraud-prevention services.

Authorities and recipients required by law. This can include police, emergency services, courts, regulators, tax authorities and the Information Commissioner's Office.

Corporate transaction parties. This can include a prospective buyer, investor, funder, adviser or successor if our business or assets are sold, reorganised or transferred.

Service providers acting as our processors may use personal information only on our documented instructions, must keep it secure and must not use it for their own unrelated purposes. Where a recipient acts as a separate controller, its own privacy policy and legal duties apply.

Independent personal trainers and partners

An independent personal trainer, therapist, chiropractor, studio or other partner may be a separate controller for information you give them directly. We will not routinely share health or fitness information with an independent provider unless this is needed for a service you request and there is an appropriate lawful basis.


International data transfers

Some providers, support teams, data centres or group companies may be outside the United Kingdom. This can include locations in the European Economic Area, the United States, Canada and other countries.

Where personal information is transferred internationally, we use a lawful transfer mechanism unless an exemption applies. This may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses or another approved safeguard. We also assess protection in the destination and apply supplementary measures where appropriate.

Contact us if you would like more information about a relevant transfer safeguard. We may provide a summary or a redacted copy where needed to protect confidential information.


How we protect personal information

We use appropriate technical and organisational measures designed to protect personal information from accidental or unlawful loss, alteration, disclosure, destruction or unauthorised access. Measures may include access controls, role-based permissions, authentication, encryption in transit or at rest where appropriate, backups, system monitoring, staff training, supplier due diligence, contractual controls and incident-response procedures.

Access is limited to people who need information for their role and those people are subject to confidentiality duties. No system is completely secure, but we review risks and improve controls where necessary.


If a personal-data breach occurs, we will investigate, contain and document it and notify affected people and the Information Commissioner's Office where the law requires.


How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purpose for which it was collected, including to meet legal, tax, accounting, insurance and reporting requirements and to establish or defend claims. We consider the amount, nature and sensitivity of the information, the risk of harm, the purpose, available alternatives and applicable limitation periods.

Membership, contract and payment records. We normally keep these for the membership and for up to six years afterwards, or longer where legal, tax, fraud, dispute or claim requirements apply.

Prospect, enquiry, tour and free-pass records. We normally keep these for up to 24 months after the last meaningful interaction unless you become a member, ask us to delete them sooner, or continued marketing is lawfully permitted.

Health, readiness, accessibility and fitness information. We keep this for as long as needed to deliver the service safely. Information linked to an incident, membership freeze, complaint or claim may be kept for up to six years or longer if required. Optional workout information may be deleted or anonymised sooner.

App, booking, attendance and access records. We keep these for the active account and a proportionate period afterwards. Security or incident-related records may be kept longer. Routine operational logs are deleted or anonymised under our retention schedule.

CCTV. We normally keep CCTV for up to 30 days. Relevant footage may be isolated and kept for the duration of an investigation, complaint, insurance matter or legal claim.

Marketing records. We keep these until you opt out, consent expires or the information is no longer needed. A minimal suppression record may be kept for as long as necessary to respect an opt-out.

Data-protection requests and complaints. We normally keep these for up to six years after closure to demonstrate how the matter was handled and manage legal or regulatory risk.

Cookies and similar technologies. We keep these for the period shown in the cookie-preference tool or current cookie list, or until you withdraw consent or clear the technology where applicable.

At the end of the retention period, we securely delete or anonymise information. Anonymised information may be kept for research, reporting and statistical purposes.


Your data-protection rights

Depending on the circumstances, you may have the right to:

Access. Ask whether we use your personal information and obtain a copy of the information we hold about you.

Correction. Ask us to correct incomplete or inaccurate information.

Erasure. Ask us to delete information where there is no good reason for us to continue using it.

Restriction. Ask us to pause or limit the use of information in certain circumstances.

Object. Object to processing based on legitimate interests and object at any time to direct marketing.

Data portability. Receive certain information in a structured, commonly used, machine-readable format or ask us to transfer it to another controller.

Withdraw consent. Withdraw consent at any time where we rely on it, without affecting processing that was lawful before withdrawal.

Challenge certain automated decisions. Obtain safeguards and challenge certain decisions made solely by automated means that have legal or similarly significant effects.

These rights are not absolute and exemptions may apply. If deleting or restricting information prevents us from performing a membership or providing a feature, we will explain the practical effect.

How to make a request

Email memberships@thrivegymuk.co.uk with the subject line Data Protection Request, use the website contact form, or write to our registered office. Tell us which right you wish to exercise and provide enough detail for us to locate the information.

We may ask for reasonable proof of identity or authority. We normally respond within one calendar month. We may extend by up to two further months where a request is complex or several requests are made, and we will tell you within the first month if this applies. Requests are normally free, but the law allows a reasonable fee or refusal in limited cases.


Data-protection complaints

You have the right to complain to us if you believe we have not handled personal information properly.

Email: memberships@thrivegymuk.co.uk.


Subject line: Data Protection Complaint.


Online contact form: www.thrivegymuk.co.uk/contact.


Post: Privacy Lead, THRIVEGYM247 LTD, Alden View, Alden Road, Helmshore, Rossendale, England, BB4 4AQ.


Please include your name and contact details, what happened, the information or processing involved, the outcome you are seeking and any relevant dates or documents. We will acknowledge a data-protection complaint within 30 days, investigate it appropriately and respond without undue delay. We will explain the outcome and any action taken.


You can also complain to the Information Commissioner's Office (ICO), the UK supervisory authority. We would appreciate the opportunity to resolve the issue first, but you do not have to contact us before approaching the ICO.


ICO website: ico.org.uk/make-a-complaint/.


ICO telephone: 0303 123 1113.


ICO postal address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.


Automated decision-making and profiling

We may use limited profiling to segment communications, understand service use, recommend content or create advertising audiences. We do not currently make decisions about members solely by automated means where the decision has a legal or similarly significant effect.

If this changes, we will provide the information and safeguards required by law, including meaningful information about the logic and likely consequences and a way to obtain human intervention and challenge the decision where applicable.


Third-party websites, apps and social media

Our website, App and communications may link to third-party websites, apps, payment pages, benefit providers, social networks or connected-fitness services. We do not control their independent processing. Review their privacy information before providing personal information or connecting an account.

When you interact with our social-media pages, the platform may process information as a separate controller and may provide us with aggregated page insights. Your use of the platform is governed by its own privacy policy and settings.


Changes to this policy

We may update this policy to reflect changes to our services, technology, suppliers, clubs, legal requirements or data practices. The latest version will be published on our website and, where appropriate, made available through the App.

If a change is material, we will take reasonable steps to draw it to your attention, for example by email, App message, website notice or club notice. Where a new use requires consent, we will ask for it.


Effective date: 23 July 2026.