Privacy Policy

Last updated: 20 July 2026

Data controller

Adrenaline Muay Thai (Grimsby, United Kingdom) is the data controller for personal information you provide through adrenalinemt.uk. Contact: [email protected].

What we collect

  • Identity & contact — name, email, phone number, date of birth, gender, emergency contact details.
  • Health-screening — answers to the PAR-Q questionnaire and any medical notes you choose to disclose.
  • Membership — plan, join date, class bookings, check-ins, purchases, attendance history.
  • Payment — a GoCardless mandate ID and payment history. We do not see or store your bank account details; those live only with GoCardless.
  • Photo — a profile photo, if you upload one.
  • Technical — session cookies, IP address, browser type, timestamps of login and important actions.

Why we use it

  • Managing your membership, bookings and access to the gym.
  • Sending you sign-in codes (PIN emails) so you can log in.
  • Collecting membership payments through direct debit.
  • Contacting you about booking confirmations, cancellations, incidents and important service updates.
  • Meeting our health-and-safety obligations (waiver, PAR-Q, incident log).
  • Preventing fraud and unauthorised access to your account.

Legal basis

We rely on contract (to deliver the membership you have paid for), legitimate interest (to run the gym safely and prevent fraud), legal obligation (record-keeping for payments and incidents), and where required, consent (for optional communications).

Who we share it with

We use a small number of trusted processors to run the Service:

  • Neon (AWS eu-west-2, London) — database hosting.
  • DigitalOcean (London) — application server.
  • Cloudflare — CDN, TLS and security in front of the app; also file storage (R2) and image delivery.
  • GoCardless — direct-debit collection.
  • Resend — transactional email (sign-in PINs, receipts, notifications).

We do not sell personal data. We do not share your data with third parties for their own marketing.

How long we keep it

While you are a member we keep your data for as long as your membership is active. After you cancel, we retain enough to meet legal and accounting obligations (typically six years for financial records) and then delete or anonymise the rest.

Your rights

Under UK GDPR you can:

  • Request a copy of the personal data we hold about you.
  • Ask us to correct anything that is wrong.
  • Ask us to delete your data (subject to legal record-keeping duties).
  • Object to processing based on legitimate interest, or withdraw consent for optional communications.
  • Ask us to export your data in a portable format.

To exercise any of these, email [email protected]. You can also complain to the UK Information Commissioner's Office at ico.org.uk.

Security

We use HTTPS everywhere, encrypted passwords/PIN hashes, and role-based access to the admin tools. No system is perfectly secure — if you spot a vulnerability, please email [email protected].

Changes to this policy

We may update this policy from time to time. The "Last updated" date at the top shows when the most recent change took effect. Material changes will be notified by email.

Related: Terms of Service · Cookie Policy