Last Updated: March 17, 2021
- Through our website at tonal.com (the “Site”),
- Through the fitness equipment made available by us for your use in workouts (the “Equipment”),
- Through the software applications made available by us for use on or through computers and mobile devices (the “Apps”),
Collectively, we refer to the Site, the Equipment, the Apps, and our Social Media Pages as the “Services”).
“Personal Information” is information that identifies you as an individual or relates to you as an identifiable individual. You do not need to provide us Personal Information in order to the use the Equipment or other Services. However, if you create an account for the Services, Personal Information we may collect includes:
- Postal address (including billing and shipping addresses)
- Telephone number
- Email address
- Credit and debit card number
- Unique identifier assigned to your Equipment
- Equipment use history and metrics, including frequency and length of workouts, workout start and end times, exercises performed, the number of sets and repetitions for each exercise, the amount of weight lifted, your height and weight, age (date of birth), and gender or sex will be associated with your profile if you are logged in while using the Equipment
- Fitness goals and preferences
- Profile picture
- Certain Personal Information from your social media account that you share with us if you connect your social media account to your Services account with us, including social media account ID, your name, email address, photo, list of social media contacts, and any other information that may be or you make accessible to us when you connect your social media account to your Services account
- Other users with whom you may share Equipment
- Other users with whom you connect and interact through the Services and information about your interactions
- Information transmitted by third-party devices that you choose to connect to, and to share data with, the Equipment, Apps or other Services. For example, these devices may include heart rate monitors, wearable technology, and fitness accessories containing sensors.
USE OF PERSONAL INFORMATION
We and our service providers may use Personal Information:
- To respond to your inquiries, fulfill your requests, complete your purchases, and provide you with related customer service.
- To send administrative information to you, such as changes to our terms, conditions, and policies, as well as marketing communications that we believe may be of interest.
- To personalize your experience on the Site by presenting products and offers tailored to you, and to facilitate social sharing functionality.
- To personalize your use of the Equipment by customizing workouts or other content.
- To facilitate social sharing functionality that you choose to use.
- To allow you to participate in sweepstakes, contests, and similar promotions and to administer these activities. Some of these activities may have additional rules containing information about how we use and disclose your Personal Information.
- For our business purposes, such as data analysis, audits, fraud monitoring, and prevention, developing new products, improving or modifying our Services, identifying usage trends, determining the effectiveness of promotional campaigns, and operating and expanding business activities.
DISCLOSURE OF PERSONAL INFORMATION
Your Personal Information may be disclosed:
- To our third party service providers who provide services such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, auditing, and other services.
- To allow third parties to offer or provide you goods and services through the Equipment.
- To third-party sponsors of sweepstakes, contests and similar promotions.
- By you, on message boards, chat, profile pages and blogs and other services to which you are able to post information and materials. Please note that any information you post or disclose through these services will become public information.
- To the owner of Equipment that you use, when you login to your account on Equipment that you do not own; in this case, the information shared with the Equipment’s owner may include your name, email, Equipment use history and metrics.
OTHER USES AND DISCLOSURES
We may also use and disclose your Personal Information as we believe to be necessary or appropriate: (a) to comply with applicable law, to respond to requests from public and government authorities, to cooperate with law enforcement, or for other legal reasons; (b) to enforce our terms and conditions; and (c) to protect our rights, privacy, safety or property, and/or that of our affiliates, you, or others. We may use, disclose or transfer your information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
“Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual. Other Information we may collect includes:
- Browser type and version
- Mobile application phone type, version, and OS
- IP address
- Application usage data
- Machine usage data
- Information collected through cookies, pixel tags and other technologies
- Demographic and other information provided by you that does not reveal your specific identity, or information that has been de-identified or aggregated in a manner that it no longer reveals your specific identity
- Application version
- Device identification number
- Connected peripheral information
- Motor data
We may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.
COLLECTION OF OTHER INFORMATION
We and our service providers may collect Other Information in a variety of ways, including:
- Through your browser or device: Certain information is collected by most browsers or automatically through your computer, mobile phone, or other device, such as your Media Access Control (MAC) address, computer type (Windows or Macintosh), screen resolution, operating system name and version, device manufacturer and model, language, and Internet browser type and version. We use this information to ensure that the Site functions properly.
- App usage data: When you download and use the App, we and our service providers may track and collect data such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.
- Using pixel tags and other similar technologies: Pixel tags (also known as web beacons and clear GIFs) may be used to, among other things, track the actions of Site users and email recipients, measure the success of our marketing campaigns and compile statistics about Site usage and response rates.
- IP Address: Your IP Address is a number that is automatically assigned to your computer, mobile device or Equipment by your Internet Service Provider. An IP Address may be identified and logged automatically in our server log files whenever a user accesses the Services, along with the time of the visit and, if applicable, the pages visited. We use IP Addresses for purposes such as calculating usage levels, diagnosing server problems, and administering the Services. We may also derive your approximate location from your IP Address.
CALIFORNIA CONSUMER PRIVACY ACT PRIVACY NOTICE ADDENDUM
This California Consumer Privacy Act Addendum provides additional details regarding our collection, use, and disclosure of Personal Information relating to California residents, pursuant to the California Consumer Privacy Act of 2018 (“CCPA”). This Addendum does not apply to our job applicants, employees, contractors, owners, directors, or officers where the Personal Information we collect about those individuals relates to their current, former, or potential role at our company. For purposes of this Addendum, “Personal Information” means information that identifies, relates to, or could reasonably be linked with a particular California resident or household.
Collection of Personal Information
We plan to collect, and have collected within the preceding 12 months, the following categories of Personal Information, as listed in the CCPA:
- “Identifiers.” Identifiers such as name, postal address (including billing and shipping addresses), telephone number, email address, username, unique identifier assigned to your Equipment, and certain Personal Information from your social media account that you share with us if you connect your social media account to your Services account with us, and IP address.
- “Customer Records Information.” Personal information as defined in the California customer records law, such as name, contact information, and credit and debit card number.
- “Protected Class Information.” Characteristics of protected classifications under California or federal law, such as age (date of birth), gender, gender identity, or sex, and disabilities such as physical limitations.
- “Transaction Information.” Commercial information, such as transaction information and purchase history.
- “Online Use Information.” Internet or network activity information, such as history of online Equipment use, including frequency and length of workouts, workout start and end times, exercises performed, the number of sets and repetitions for each exercise and the amount of weight lifted, and your interactions with our Services and other users with whom you share the Equipment or with whom you connect and interact through the Services.
- “Geolocation Data.” Geolocation data such as approximate location derived from IP address.
- “Audio/Video Data.” Audio, electronic, and visual information, such as your profile picture, other images or videos you have uploaded to the Services, and telephone call recordings.
- “Inferences.” Inferences drawn from any of the Personal Information listed above to create a profile about, for example, an individual’s fitness level, regimen, goals, and preferences.
We collect this Personal Information from you and the third-party devices you have chosen to integrate with our Services and from our data analytics providers, third-party ad networks, and joint marketing partners.
Use of Personal Information
We may use this Personal Information for the purposes described in “Use of Personal Information” and “Other Uses and Disclosures,” above.
Disclosure of Personal Information
We share Personal Information with the following categories of third parties:
- “Service Providers.” Our trusted third party service providers carry out activities at our direction, such as website hosting, data analysis, payment processing, order fulfillment, information technology and related infrastructure provision, customer service, email delivery, auditing, and other services.
- “Connected Applications.” If you enable third-party products or applications, such as Apple Health or Strava, to track your workouts with our Equipment, Apps, or other Services, we share Personal Information with the providers of those third-party products and applications.
- “Ad Networks.” We share Personal Information with third-party ad networks to permit them to serve advertisements regarding goods and services that may be of interest to you when you access and use the Services and other websites or online services.
- “Promotion Sponsors.” We share Personal Information with third-party sponsors of sweepstakes, contests, and similar promotions.
- “Equipment Owner.” When you log in to your account on Equipment that you do not own, we share your Personal Information with the Equipment owner; in this case, the information shared with the Equipment owner may include your name, email, Equipment use history and metrics.
- “Public Audience.” When you post information and materials on message boards, chat, profile pages, blogs and other services on which you are able to post. Please note that any information you post or disclose through these services will become public information.
- “Legal Authorities.” We may share Personal Information to cooperate with public and government authorities, including law enforcement, and to protect and defend our legal rights and those of others.
In the preceding 12 months, we disclosed for our operational business purposes the following categories of Personal Information to the following categories of third parties:
|Categories of Personal Information||Disclosed to Which Categories of Third Parties for Operational Business Purposes|
|Identifiers||Service Providers; Connected Applications; Equipment Owner; Social Media; Public Audience; Legal Authorities|
|Customer Records Information||Service Providers; Equipment Owner; Social Media; Public Audience; Legal Authorities|
|Protected Class Information||Service Providers; Connected Applications|
|Transaction Information||Service Providers; Social Media|
|Online Use Information||Service Providers; Connected Applications; Equipment Owner; Social Media; Public Audience|
|Geolocation Data||Service Providers; Connected Applications; Equipment Owner; Social Media; Legal Authorities|
|Audio/Video Data||Service Providers; Connected Applications; Social Media; Public Audience; Legal Authorities|
Sale of Personal Information
We have not “sold” Personal Information for purposes of the CCPA, including, to our knowledge, the Personal Information of minors under 16. For purposes of this Addendum, “sold” or “sale” means the disclosure of Personal Information for monetary or other valuable consideration, subject to certain exceptions.
Your CCPA Rights
Requests to Know and Delete
If you are a California resident, you may make the following requests:
(1) “Request to Know”
You may request that we disclose to you the following information covering the 12 months preceding your request:
- The categories of Personal Information we collected about you and the categories of sources from which we collected such Personal Information;
- The specific pieces of Personal Information we collected about you;
- The business or commercial purpose for collecting Personal Information about you; and
- The categories of Personal Information about you that we otherwise shared or disclosed, and the categories of third parties with which we shared or to which we disclosed such Personal Information (if applicable).
(2) “Request to Delete”
You may request that we delete Personal Information we collected from you.
To make a Request to Know or Request to Delete, please contact us at Tonal Systems, Inc. 617 Bryant St, San Francisco, CA 94107 or 855.698.6625 or email@example.com. We will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the Personal Information subject to the request. We may need to request additional Personal Information from you, such as name, email address, state of residency, and zip code, in order to verify your identity and protect against fraudulent requests. If you maintain a password-protected account with us, we may verify your identity through our existing authentication practices for your account and require you to re-authenticate yourself before disclosing or deleting your Personal Information. If you make a Request to Delete, we may ask you to verify your request before we delete your Personal Information. We will respond to your Request to Know or Request to Delete consistent with applicable law.
Right to Non-Discrimination
You have the right to be free from unlawful discrimination for exercising your rights under the CCPA.
If you want to make a request as an authorized agent on behalf of a California resident, you may use the submission methods noted above. As part of our verification process, we may request that you provide, as applicable:
- Proof of your registration with the California Secretary of State to conduct business in California;
- A power of attorney from the California resident pursuant to Probate Code sections 4000-4465;
- Written permission that the California resident has authorized you to make a request on the resident’s behalf. This permission must be signed (via physical or e-signature) by the California resident.
If you are making a Request to Know or a Request to Delete on behalf of a California resident and have not provided us with a power of attorney from the resident pursuant to Probate Code sections 4000-4465, we may also require the resident to:
- Provide you with a written permission signed by the resident to make the Request to Know or Request to Delete on the resident’s behalf;
- Verify the resident’s own identity directly with us;
- Directly confirm with us that the resident provided you permission to submit the Request to Know or Request to Delete.
Please contact us at firstname.lastname@example.org, if you have any questions regarding this CCPA Addendum.