Privacy Policy
Effective date: 30 October 2025
Last updated: 30 October 2025
Who we are
Glassbox Fitness Inc. (“Glassbox Fitness®”, “we”, “our”, “us”)
Registered office: 430 Hazeldean Road, Unit 6, Kanata, Ontario, Canada, K2L 1W3
Privacy contact: privacy@glassbox.fitness
We provide neurodiversity training/fitness education and related licensing and programs. We respect your privacy and protect personal information in line with Canadian privacy law (PIPEDA) and, where applicable, other regional laws.
Scope & relationship to this policy
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you visit our website, communicate with us, or participate in our programs, certifications, and licenses. It replaces and consolidates the terms in our prior “Customer Data Usage Consent Form” for website use. Program‑specific consent forms may still apply where local law requires explicit consent (e.g., sensitive health/fitness information or minors).
Training/fitness scope; non‑medical: Our services provide training and fitness education. We do not provide medical, clinical, or therapeutic services.
Personal information we collect
We only collect what we need for clearly defined purposes.
1) Identity & contact
Name, email, phone, address, organization/employer, role, preferred language.
2) Participant & fitness context (sensitive)
Self‑reported or caregiver‑reported information to plan training/fitness (non‑medical)—e.g., goals, preferences, access needs, high‑level health context (e.g., conditions relevant to safe training), scheduling constraints, and program attendance.
We treat this as sensitive. Where required, we will request explicit consent.
3) Fitness assessment & progress artifacts
ESL‑friendly “snapshots” and structured notes (non‑clinical) to track participation, adherence, and skill development in training/fitness contexts.
4) Commercial & transaction data
Licensing details, certification seats, invoices/receipts, and payment confirmations (payment card details are processed by our payment processor; we don’t store full card numbers).
5) Communications & support
Emails, forms, consultation notes, Chat/GPT assistant messages (public‑safe content only), feedback.
6) Website/technical
Cookie and usage data (e.g., pages viewed, device/browser type). See Cookies & analytics below.
Minors
For participants under 18, we collect information from and with consent of a parent/guardian. We don’t knowingly collect data from children online without appropriate consent.
Why we use your information (purposes)
- Provide and personalize training/fitness education, certifications, and licenses.
- Plan, schedule, and administer programs (including attendance logs and non‑clinical progress snapshots).
- Issue credentials, designations, and brand packs (where applicable).
- Billing and accounting, payment confirmations, receipts.
- Customer support and operational communications.
- Safety and quality assurance, including safeguarding and program QA.
- Improve services (e.g., anonymised/aggregated analytics).
- Legal and compliance (tax, audits, lawful requests).
Lawful basis (how we justify processing)
- Consent: for sensitive information and certain communications.
- Contract: to deliver services you requested (e.g., certifications, licenses).
- Legitimate interests: to operate, secure, and improve our services in ways that don’t override your rights.
- Legal obligations: to meet tax, audit, and record‑keeping duties.
You can withdraw consent at any time (see Your rights & choices).
Cookies & analytics
We use necessary cookies for site operation and may use analytics cookies to understand aggregated usage. You can adjust your browser settings to limit cookies. If we use advanced analytics/advertising cookies, we will show a cookie banner and let you choose.
AI‑assisted tools (public‑safe only)
We may use AI‑assisted tools to help prepare non‑clinical admin outputs (e.g., ESL‑friendly summaries, progress snapshots, or templated communications). A human reviews these outputs before they are shared. We do not disclose internal, proprietary methods in public systems. Do not submit confidential health documents via chat unless we explicitly request them through a secure channel.
Payment processing
Payments are processed by a third‑party payment processor (e.g., Stripe). We receive confirmation of payment and limited details needed for records; we do not store full card numbers. Your payment is subject to the processor’s privacy policy.
Sharing & disclosure
We do not sell personal information. We share it only with:
- Service providers under contract (e.g., secure hosting, emailing, payment processing, LMS/portal) who must protect it and use it only for our instructions.
- Authorized personnel (need‑to‑know basis, confidentiality bound).
- Legal authorities when required by law or to protect rights, safety, or security.
- Successors in a reorganization, merger, or acquisition (your information stays protected and you’ll be notified where required).
International transfers
Your information may be processed in Canada and other jurisdictions where our service providers operate. We use contractual safeguards and reasonable measures to protect information across borders (e.g., standard contractual clauses where applicable). You can contact us to learn more.
Security
We use industry‑standard administrative, technical, and physical measures to protect personal information (e.g., encryption in transit, role‑based access, logging). No system is 100% secure; we maintain incident response processes and will notify you and regulators where required.
Retention
We keep personal information only as long as necessary for the purposes above, to meet legal/accounting requirements, and to resolve disputes. Then we anonymize or securely delete it.
Your rights & choices
Your rights depend on where you live, but typically include:
Everyone (including Canada/PIPEDA):
- Access and obtain a copy of your information.
- Request correction/updates.
- Withdraw consent (does not affect prior processing).
- Ask about our use, disclosures, and safeguards.
EEA/UK (GDPR/UK‑GDPR):
Above, plus the right to object/limit certain processing, portability (where applicable), and lodge a complaint with your data protection authority.
California (CPRA):
Right to know, delete, correct, and opt‑out of certain sharing. We do not sell personal information.
How to exercise rights
Email privacy@glassbox.fitness. We may verify your identity and respond within legal timeframes. For minors, a parent/guardian should contact us.
Withdrawing consent
Where we rely on consent (e.g., sensitive training/fitness context), you may withdraw it at any time by emailing privacy@glassbox.fitness. This may affect our ability to provide personalized training/fitness education.
Third‑party links
Our website may link to third‑party sites or platforms. Their privacy practices are their own. Review their policies before sharing information.
Changes to this policy
We may update this policy from time to time. We will change the “Last updated” date above and, where required, notify you.
Contact us
Glassbox Fitness Inc.
430 Hazeldean Road, Unit 6, Kanata, Ontario, Canada, K2L 1W3
Email: privacy@glassbox.fitness
How to complain (Canada): Office of the Privacy Commissioner of Canada — https://www.priv.gc.ca/
(EEA/UK users may contact their local Data Protection Authority.)
Summary (ESL‑friendly)
- We collect only what we need to deliver training/fitness education (non‑medical).
- Sensitive information is handled with care and often requires explicit consent.
- We use service providers under contract; we don’t sell personal data.
- You can access, correct, or withdraw consent anytime.
- Write to privacy@glassbox.fitness with questions or requests.
Parent/guardian consent (minors)
For participants under 18, a parent or legal guardian must approve participation and data use.
Trademark note: Glassbox Fitness® is a registered trademark. All other names may be trademarks of their respective owners.
Optional website footer micro‑notice (one line)
Privacy: We use your information to deliver training/fitness education (non‑medical). See our full Privacy Policy.