This Privacy Policy explains how ClassIQ, LLC, a California limited liability company ("ClassIQ", "we", "us", or "our") collects, uses, and shares personal information in connection with the ClassIQ platform at classiq.app and its subdomains, including the ClassIQ mobile applications (together, the "Service"). By using the Service, you agree to this Policy.
The short version
- ClassIQ is software that fitness studios and similar businesses ("Studios") use to manage schedules, bookings, memberships, and payments.
- We never see or store your full card or bank numbers. All payments are processed by Stripe through its hosted checkout; ClassIQ only receives limited payment metadata (such as card brand, the last four digits, amounts, and Stripe identifiers).
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising.
- The mobile app's location and notification features are optional and under your control: location is used only to confirm you've arrived for class, and notifications are operational — never marketing. See "The mobile app" below.
- For the personal information a Studio collects about its own members, the Studio—not ClassIQ—decides how that data is used. See "Our two roles" below.
- A minor can use the Service as a guardian-managed "Dependent" account with no login of its own, or — once 13 or older — with their own account. See "Children and minors" below.
Our two roles (controller vs. processor)
The Service is multi-tenant, so the same data can sit in two different relationships:
- ClassIQ as controller. For information about Studio owners and staff who hold ClassIQ accounts, and for operating, securing, and improving the Service, ClassIQ is the controller.
- ClassIQ as processor. For the personal information a Studio uploads or collects about its members and clients ("Studio Data"), the Studio is the controller and ClassIQ acts as a processor on the Studio's behalf, under our Data Processing Addendum. If you are a member of a Studio, please direct privacy requests about your data to that Studio.
Information we collect
You or your Studio provide:
- Identity and contact details — name, email address, phone number, and (where a Studio collects it) mailing address.
- Account credentials and profile information.
- Booking, attendance, membership, and package history.
- Communications you send us (e.g., support email).
Collected automatically:
- Usage and device data through our self-hosted Rybbit analytics, configured to collect anonymous usage metrics and not to track you across other sites.
- Server logs, including IP address, for security and troubleshooting.
Through the mobile app (each optional, controlled by you):
- Precise location — only if you turn on automatic check-in, and only to confirm you've arrived at your Studio. We do not collect or store a history of your movements. See "The mobile app" below.
- Push notification tokens and device identifiers — if you allow notifications or sign in on a device, so we can deliver booking notifications to that device and keep your session secure.
Payment information:
- Payments run through Stripe (including Stripe Checkout and Stripe Connect). Card and bank details are entered directly with Stripe and are not transmitted to or stored by ClassIQ. We keep only payment metadata (card brand, last four digits, transaction amounts, and Stripe identifiers) needed to display receipts and reconcile accounts. This keeps ClassIQ within PCI DSS SAQ-A scope.
How we use information
We use personal information to provide and operate the Service; create and secure accounts; process and reconcile payments through Stripe; send transactional messages (booking confirmations, reminders, receipts, and account notices); provide support; detect and prevent fraud and abuse; comply with legal obligations; and maintain and improve the Service.
How we share information
We do not sell personal information or share it for cross-context behavioral advertising. We share information only as follows:
- With your Studio (and, if you are a Studio, with the staff you authorize).
- With service providers (sub-processors) that process data on our behalf, each bound to protect it and use it only to provide their service to us:
- Stripe (United States) — payment processing.
- DigitalOcean (United States) — application hosting.
- Cloudflare (United States) — encrypted off-site database backups.
- Amazon Web Services (United States) — file and object storage.
- Resend (United States) — transactional email delivery.
- GitHub (Microsoft) (United States) — source-code hosting (does not process member personal data in the ordinary course).
- Rybbit Analytics (self-hosted, United States) — anonymous usage analytics.
- Anthropic (United States) — AI-assisted development and support tooling. Any access to production data is restricted, logged, used only to operate and troubleshoot the Service, and is not used to train models.
- With Apple, to the limited extent needed to deliver push notifications to Apple devices and to support Sign in with Apple.
- For legal and safety reasons — to comply with law, enforce our terms, or protect the rights, property, or safety of ClassIQ, our users, or the public.
- In a business transfer — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
Cookies and analytics
We use cookies that are strictly necessary to run the Service (for example, to keep you signed in). Our Rybbit analytics is configured for anonymous, first-party measurement and does not follow you across other websites.
The mobile app
Studios can offer the ClassIQ mobile app for booking, schedules, and check-in. Everything in this Policy applies to the app; this section covers what the app adds. The app collects four categories of data — your name, your email address, your precise location (only if you enable automatic check-in), and device identifiers — all used solely to provide the app's features, all linked to your member account, and none used for advertising or to track you across other companies' apps or websites. We do not use third-party advertising or tracking SDKs in the app.
- Location (optional — automatic check-in). If you turn on automatic check-in, the app uses a geofence around your Studio to notice when you arrive for a class you've booked and to check you in as proof of arrival. Because arrival has to be detected while the app is closed, this uses the operating system's "Always" location permission. Location is used only to confirm arrival: we record the resulting check-in, not your movements — no location history or trail is collected, stored, or shared, and location is never used for advertising. Automatic check-in is off until you enable it, and you can turn it off at any time in the app or in your device's settings; booking and checking in manually work fine without it.
- Push notifications (optional). If you allow notifications, the app registers a device push token so we can send you operational messages about your bookings — for example a class cancellation, a schedule change, or a spot opening up from a waitlist. We do not send marketing push notifications. You can turn notifications off at any time in your device's settings.
- Sign in with Apple. You can sign in to the app with your Apple ID, including with Apple's "Hide My Email" private-relay addresses. We honor relay addresses: one is treated as your email address like any other, and mail we send to it is delivered through Apple's relay. Note that a relay address identifies its own account — if you previously joined your Studio under your real email address, hiding your email at sign-in creates a separate account.
- Device identifiers. The app stores device-level identifiers (such as the push token and a record of the device your session is signed in on) to route notifications to the right device and to secure your account. These are removed when your devices are removed from your account, including on account deletion.
Data retention
We keep personal information for as long as needed to provide the Service and for legitimate business or legal purposes (such as tax, accounting, and dispute resolution). Studio Data is retained according to the Studio's instructions and our Data Processing Addendum; on termination it is returned or deleted except where the law requires us to keep it.
Deleting your member account
If you are a member of a Studio, you can delete your ClassIQ account yourself, directly in the mobile app: go to Home → your avatar → Delete account. You can also request deletion by emailing privacy@classiq.app from the address on your account.
Deletion is immediate and irreversible. It removes your name, email address, phone number, and other profile details; your sign-in credentials, connected devices, and push tokens; and your membership links to every Studio you belong to. Active recurring memberships billed through the Service are canceled, and Sign in with Apple access for the account is revoked.
Some records are retained by your Studio in de-identified form. Studios need their own operational and legal records to run their business — so signed waivers, accepted terms, class attendance history, billing and payment history, no-show records, and the Studio's own notes and messages remain, kept for purposes like insurance, accounting, tax, and dispute resolution. After deletion these records are no longer connected to your name, email address, or any other identifier — they belong to a de-identified record that cannot be used to contact or identify you, and they cannot be re-linked if you later create a new account.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to appeal a decision about a request. ClassIQ honors the rights provided by applicable U.S. state privacy laws, including the California Consumer Privacy Act (as amended by the CPRA) and the Texas Data Privacy and Security Act (TDPSA).
- California residents: we do not sell or share (as those terms are defined under the CCPA/CPRA) your personal information, and we have not in the preceding 12 months. You may exercise your rights without discrimination.
- Members can delete their own account at any time — see "Deleting your member account" above.
- To make a request about data ClassIQ controls, email privacy@classiq.app. If your request concerns data held by a Studio (where ClassIQ is a processor), we will refer you to, or assist, that Studio as the controller.
We will verify your request as required by law and respond within the applicable timeframe.
Children and minors
The Service is not directed to children under 13, and ClassIQ does not knowingly collect personal information directly from a child under 13 who is registering their own account. Minors participate in the Service in two ways:
- As a Dependent. A parent or legal guardian can add a minor of any age to the Service as a "Dependent" through a Studio's family accounts feature — a managed account with no email, password, or independent ability to sign in. The guardian consents to this Policy on the Dependent's behalf, and can exercise the access, correction, and deletion rights described in "Your privacy rights" below for any Dependent they manage, by contacting us or the Studio. Deleting the guardian's own account deletes their linked Dependents' accounts too.
- With their own account. Consistent with our Terms of Service, a member must be at least 13 to create and hold their own account.
For any minor, the Studio is the controller of the personal information it collects (see "Our two roles" above) and is responsible for obtaining any parental or guardian consent its own programs require beyond the above. If you believe a minor's information has been collected without the consent required by law, contact privacy@classiq.app and we will work with the relevant Studio to address it.
Data location and international users
The Service is operated and hosted in the United States. If you access it from outside the United States, you understand that your information will be processed in the United States. Where Studio Data is transferred from the EEA, the United Kingdom, or Switzerland, those transfers are governed by our Data Processing Addendum and its incorporated Standard Contractual Clauses.
Security
We use commercially reasonable administrative, technical, and organizational measures to protect personal information, including encryption in transit and at rest, access controls, and encrypted backups. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond promptly to incidents.
Changes to this Policy
We may update this Policy from time to time. Each version is tracked, dated, and identified by a version number. Material changes affecting Studios' acceptance are re-presented for acceptance.
Contact us
ClassIQ, LLC, a California limited liability company 6403 Grant Wood Street, Bakersfield, CA 93312, USA Privacy: privacy@classiq.app · Legal: legal@classiq.app · Support: support@classiq.app