Privacy Policy

We take your personal info seriously. Here's the straight talk on how we handle your data at the Citadel.

Last Updated: October 28, 2025

Introduction

Look, we get it - nobody actually enjoys reading privacy policies. But here at Xenrath Citadel Fitness, we're all about transparency, whether that's your training progress or how we handle your personal information.

This policy lays out exactly what data we collect when you train with us, why we need it, and what we do with it. We're not gonna hide behind legal jargon or corporate speak - just real talk about your privacy.

By signing up for our programs, using our facility, or even just browsing our website, you're agreeing to the terms laid out here. If something doesn't sit right with you, hit us up at info@xenrathcitadel.info and let's chat about it.

Information We Collect

Personal Details

When you join the Citadel, we're gonna need some basics: your name, email, phone number, home address, date of birth, and emergency contact info. This isn't us being nosy - it's standard stuff we need for membership management and to reach you (or someone who cares about you) if you push too hard during a session.

Health & Fitness Information

Here's where it gets more specific to what we do. We collect medical history, injury records, fitness goals, current physical condition, dietary restrictions, and workout performance data. Combat training and heavy lifting ain't something to mess around with - we need to know your baseline so we can push you hard without breaking you.

Payment & Billing Data

Credit card details, billing addresses, membership tier info, and transaction history. We use secure payment processors - we don't actually store your full credit card numbers on our servers.

Usage & Facility Access

Check-in times, class attendance, equipment usage patterns, and facility access logs through our security system. This helps us manage capacity, schedule classes better, and yeah, keep track of who's actually using their membership.

Technical & Website Data

IP addresses, browser types, device info, and how you navigate our website. Standard internet stuff that helps us keep the site running smooth and figure out what content actually matters to people.

How We Use Your Data

Service Delivery

Managing your membership, scheduling your training sessions, customizing workout programs based on your goals and limitations, and providing nutrition coaching that actually fits your lifestyle.

Communication

Sending class reminders, membership updates, promotional offers for new programs, and responding to your questions. We won't spam you - just the stuff that matters.

Safety & Compliance

Maintaining facility security, emergency response protocols, and meeting legal requirements for operating a high-intensity training facility in British Columbia.

Improvement & Analytics

Analyzing trends to improve our programs, understanding what equipment gets used most, optimizing class schedules, and developing new training protocols that actually work.

Financial Processing

Processing membership payments, managing billing cycles, handling refunds when applicable, and keeping records for accounting purposes.

Community Building

Organizing member events, creating training groups with similar goals, and fostering the Citadel community vibe that keeps people coming back.

Data Sharing & Disclosure

We're not in the business of selling your info. Period. But there are a few situations where we might need to share your data:

Service Providers

Payment processors, email service providers, our booking system vendor, and cloud storage services. These folks are bound by strict confidentiality agreements and can only use your data for the specific services they provide to us.

Medical Emergencies

If you get hurt during training, we'll share relevant health info with paramedics and emergency responders. Your safety trumps privacy in these situations.

Legal Requirements

If the law requires it, if we get a valid court order, or if there's a legitimate legal proceeding, we might have to disclose your information. We'll fight it if it seems unreasonable, but we're not gonna break the law.

Business Transitions

If we ever sell the gym or merge with another facility (not planning on it, but you never know), your membership info would transfer to the new owners. You'd be notified well in advance.

Data Security

We take protecting your data as seriously as we take proper deadlift form. Here's what we've got in place:

  • Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols. Your stored data is also encrypted at rest.
  • Access Controls: Only authorized staff members who actually need access to your info can see it. We use role-based permissions and multi-factor authentication for our systems.
  • Regular Backups: We back up data regularly to secure, off-site locations. If something goes wrong, we can restore your information.
  • Security Monitoring: Our systems are monitored for suspicious activity 24/7. We've got alerts set up for anything that looks off.
  • Staff Training: Everyone on our team goes through privacy and security training. They know what's at stake and how to handle your info properly.
  • Physical Security: Our servers and physical records are kept in secure, access-controlled areas. We don't leave membership files lying around where anyone can grab 'em.
Real talk: No system is 100% hack-proof. We do everything we reasonably can to protect your data, but if there's ever a breach, we'll let you know immediately and tell you exactly what happened and what we're doing about it.

Your Rights

Under Canadian privacy laws (specifically PIPEDA), you've got some solid rights when it comes to your personal information. Here's what you can do:

Access

You can request a copy of all the personal data we have on you. We'll provide it in a readable format within 30 days.

Correction

If something in your file is wrong or outdated, tell us and we'll fix it. Keeping accurate records matters to us.

Deletion

Want us to delete your data? We'll do it, unless we're legally required to keep it for tax or liability reasons.

Portability

You can get your data in a format that you can take to another gym. No hard feelings - we want you to have control.

Opt-Out

Don't want marketing emails? Click unsubscribe or let us know. You'll still get essential membership communications though.

Withdraw Consent

If you've given consent for something specific, you can take it back. Just know it might affect the services we can provide.

How to Exercise Your Rights

Shoot us an email at info@xenrathcitadel.info or call us at (604) 555-8742. We'll need to verify your identity first (can't just hand out member data to anyone who asks), then we'll handle your request within 30 days.

Cookies & Tracking Technologies

Yeah, we use cookies. Not the protein kind - the digital tracking kind. Here's the breakdown:

Essential Cookies

These keep the website functioning. They remember your login session, your language preference, and basic stuff needed for the site to work. You can't really turn these off without breaking the site.

Analytics Cookies

We use Google Analytics to see how people use our site - which pages get visited most, where people drop off, that kind of thing. It's anonymized data that helps us make the site better. You can opt out of these through your browser settings.

Marketing Cookies

These track your browsing to show