Privacy & Cookie Policy
Version 2.0. Published 1st July 2026. This policy replaces the version dated January 2023.
1. WHO WE ARE AND HOW TO CONTACT US
www.rumble-gym.com (the "Website") and the RUMBLE app are owned and operated by LCUK Management Ltd, trading as RUMBLE ("we", "our" or "us"), a company registered in England and Wales, company number 10319854, registered office Bryan Court, Seymour Place, London W1H 2NE. LCUK Management Ltd is the data controller of your personal information under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 and, where applicable, the Privacy and Electronic Communications Regulations ("PECR"), each as amended, including by the Data (Use and Access) Act 2025.
For anything relating to this policy or your personal information, contact us by email at hello@rumble-gym.com, via the contact form on our Website, or by post to RUMBLE, Ground Floor, Labyrinth Tower, Dalston Square, London E8 3GP.
2. WHAT THIS POLICY COVERS
This policy explains how we collect, use, store and share your personal information when you use our Website or app, visit or train at our studios, contact us, or otherwise interact with us. It also serves as our cookie policy (see section 9). Our bookings, accounts, payments and health declarations are managed on our behalf through Mindbody, a third-party class management platform which also powers our app; Mindbody acts as our data processor.
3. INFORMATION WE COLLECT
Information you give us: your name, contact details (email, mobile number, postal address), date of birth, account login details, health declaration information (see section 4), payment details, communications with us, and information you provide when entering promotions or events.
Information we collect automatically: your bookings, attendance and class history; purchase and billing history; technical and usage information about how you use our Website and app (IP address, device identifiers, browser type, pages viewed); and CCTV footage recorded at our studios for health, safety, security and crime prevention.
Information we receive from third parties: booking details where you book through a third-party platform or aggregator; payment confirmations and failure notices from our payment providers; and, where an account falls into arrears and we cannot reach you, updated contact details supplied by licensed tracing agents (see section 7).
Photography and video: we may take photos or film in our studios for operational and training purposes. We only use images of you for marketing or promotion with your explicit prior consent, which you can withdraw at any time.
It is important that the information we hold about you is accurate and current. Please keep your details up to date through your account or by telling us when they change.
4. HEALTH INFORMATION
Because we provide physical training, we ask you to complete a health declaration before your first class and to tell us about anything relevant that changes, such as injuries, medical conditions or pregnancy. Health information is special category data under Article 9 UK GDPR, and we process it only with your explicit consent, which we collect when you complete the declaration through our booking platform.
We use health information solely to run sessions safely: to assess whether a class is suitable for you, to allow instructors and studio managers to take account of an injury, condition or pregnancy on a need-to-know basis, and to respond to incidents. We do not use health information for marketing, and we do not share it outside the purposes above except where the law requires, or in connection with an incident (for example with emergency services, or with our insurers and advisers if a claim arises).
You may withdraw your consent at any time by contacting us. If you do, we may be unable to let you participate in classes, because we cannot run sessions safely without it.
5. HOW WE USE YOUR INFORMATION AND OUR LAWFUL BASES
We only process personal information where the law permits. The table below sets out our purposes and the lawful basis we rely on for each.
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account; providing classes, memberships, packages and facilities; managing bookings, waitlists and freezes | Performance of a contract |
| Taking payments, operating recurring billing, correcting billing errors and collecting sums properly due (see section 6 and our Terms & Conditions sections 8 to 10) | Performance of a contract; legitimate interests (being paid for services supplied) |
| Recovering arrears, including tracing and debt recovery (see section 7) | Legitimate interests (recovery of sums due) |
| Processing health declarations and running sessions safely (see section 4) | Explicit consent (Article 9(2)(a)); legal obligation in respect of health and safety incident records |
| Service communications: booking confirmations, schedule changes, payment notifications, arrears notices, changes to terms | Performance of a contract; legal obligation; legitimate interests |
| Marketing communications (see section 8) | Consent, or the PECR soft opt-in for our own similar services; legitimate interests |
| Using images of you in marketing or promotion | Explicit consent |
| Safety, security and crime prevention at our studios, including CCTV | Legitimate interests; legal obligation |
| Improving our Website, app, classes and studios, including analytics | Legitimate interests; consent where required for cookies (see section 9) |
| Establishing, exercising or defending legal claims, and complying with law, regulation and court orders | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we balance our interests against your rights and freedoms, and you have the right to object (see section 14).
6. PAYMENTS AND BILLING
Payments are processed by our payment and direct debit providers. We do not store full payment card numbers on our own systems; card details are held by our providers on a tokenised basis so that recurring membership fees, class fees and sums you owe can be collected under the payment authority in our Terms & Conditions. We keep records of transactions, renewals, failed payments and corrections (including billing errors and their resolution) for the periods in section 12, because we need them to administer accounts, resolve disputes and meet accounting obligations.
7. RECOVERY OF SUMS DUE
If your account falls into arrears and we cannot resolve the position with you directly, we may share the personal information reasonably necessary (such as your name, date of birth, last known contact details and the account and payment history relevant to the debt) with: licensed tracing agents, to confirm your current address where we have reason to believe our records are out of date; debt collection providers; our professional advisers; and the courts and parties to proceedings, where a claim is issued. We rely on our legitimate interest in recovering sums properly due for services supplied. We may also receive information back from these providers, such as a confirmed current address.
We do not sell personal information, and we require recovery providers to handle personal information securely and in accordance with data protection law. Where an account is closed with sums outstanding, we continue to hold and process the information relevant to the debt until the matter is resolved and for the retention period in section 12.
8. MARKETING
We may send you marketing about our classes, studios, events and offers by email where you have consented, or where you are an existing customer and the message is about our own similar services (the PECR "soft opt-in"), in which case you are given the chance to opt out when we collect your details and in every message. You can opt out at any time using the unsubscribe link in any email, through your account preferences, or by contacting us at hello@rumble-gym.com. Opting out of marketing does not stop service communications such as booking confirmations, payment notifications or arrears notices, which we need to send to run your account.
9. COOKIE POLICY: COOKIES AND SIMILAR TECHNOLOGIES
This section is our Cookie Policy. Where our Website, app or Terms & Conditions refer to a "Cookie Policy", they mean this section.
9.1 What cookies are. A cookie is a small text file placed on your device when you visit a website. Similar technologies include pixels, tags, local storage and software development kits (SDKs) in apps. We use "cookies" below to cover all of these.
9.2 The three categories we use.
Strictly necessary cookies are required for the Website and app to function (for example login, booking, security and cookie-preference cookies) and do not require consent.
Limited analytics and functionality cookies collect statistical information about how the Website is used, or remember your preferences, to help us improve our services. Following the changes made by the Data (Use and Access) Act 2025, these limited categories can be used without prior consent, provided we tell you about them and give you a straightforward way to opt out, which we do through our cookie controls.
Advertising and other non-essential cookies, including those set by third parties such as Google and Meta, are used to analyse usage and to deliver and measure advertising. These are only placed with your consent, and you can change your choices at any time through the cookie controls or your browser settings. For advertising measurement we may share pseudonymised identifiers (such as cookie IDs or hashed email addresses) with these providers, which operate under their own privacy policies.
9.3 The cookies we use. The table below lists the cookies and similar technologies in use on our Website and app. Typical durations are as published by the relevant provider.
| Cookie / technology | Provider | Category | Purpose | Typical duration |
|---|---|---|---|---|
| Session and booking cookies | RUMBLE / Mindbody | Strictly necessary | Keeping you logged in, holding your booking selections, security | Session |
| _ga and ga container cookies | Google Analytics 4 | Analytics | Statistical measurement of how the Website is used (visits, pages, sources) | Up to 2 years |
| Google Tag Manager | Analytics infrastructure | Loads and controls the tags above according to your consent choices; does not itself profile you | Not applicable | |
| _gcl_au (and the _gcl_ls local storage entry) | Advertising | Linking clicks on our Google ads to actions on the Website (conversion measurement) | Up to 3 months | |
| _fbp (and _fbc where you arrive from an ad) | Meta (Facebook / Instagram) | Advertising | Delivering and measuring our advertising on Meta platforms | Up to 3 months |
| Mindbody booking widgets | Mindbody / Mixpanel | Strictly necessary / analytics | Powering the in-page booking, membership and account widgets, and measuring widget performance | Per Mindbody's policy |
| App SDKs | Mindbody | Strictly necessary / analytics | Operating the RUMBLE app (bookings, accounts, notifications) and app performance | Per Mindbody's policy |
This table is kept in line with a periodic scan of the Website and app; if a listed technology is retired or a new one added, we update this section.
9.4 Managing cookies. You can change your choices at any time through our cookie controls on the Website, and most browsers let you block or delete cookies through their settings. Blocking some cookies may affect how the Website works, and blocking strictly necessary cookies may prevent booking. More information about cookies generally is available at www.allaboutcookies.org.
10. WHO WE SHARE INFORMATION WITH
We do not sell personal information. We share it only where necessary, with: Mindbody, which operates our booking, account, payment and health declaration systems and powers our app; our payment and direct debit providers; our email and communications platforms; analytics and advertising providers as described in section 9; licensed tracing agents, debt collection providers and the courts as described in section 7; our professional advisers (legal, accounting, insurance); our insurers, where relevant to an incident or claim; prospective purchasers or sellers and their advisers in the event of a business sale or restructuring, under appropriate confidentiality; and public authorities, regulators and law enforcement where the law requires. All service providers process personal information on our instructions and under contracts requiring appropriate security.
11. INTERNATIONAL TRANSFERS
Some of our providers, including our booking platform, process personal information outside the UK, including in the United States. Where personal information is transferred outside the UK, we ensure a lawful transfer mechanism is in place: transfers to countries covered by UK adequacy regulations (including the EEA); transfers to US organisations certified under the UK Extension to the EU-US Data Privacy Framework; or, otherwise, the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with any necessary supplementary measures.
12. HOW LONG WE KEEP INFORMATION
We keep personal information only as long as we need it for the purposes described in this policy, and then delete or anonymise it. Our standard periods are:
| Category | Retention period | Why |
|---|---|---|
| Account, membership, booking and attendance records | 6 years after your account closes | Contract administration; the limitation period for legal claims |
| Payment, billing and billing-error records | 6 years after the transaction or account closure | Accounting and tax obligations; limitation period |
| Arrears and recovery files | Until the matter is resolved, then 6 years | Limitation period; conduct of claims |
| Health declarations and incident records | Duration of your relationship with us, then 3 years (longer if an incident or claim requires) | Safe session delivery; personal injury limitation period |
| CCTV footage | Typically up to 30 days, longer only where retained for an incident, claim or lawful request | Safety, security and crime prevention |
| Marketing preferences and mailing data | Until you opt out, or after 24 months of inactivity | Respecting your choices |
| General enquiries | 12 months after our last exchange | Customer service |
13. SECURITY AND BREACHES
We use appropriate technical and organisational measures to protect personal information, including encryption in transit, access controls and reputable hosting and platform providers. No internet transmission can be guaranteed fully secure, but once we receive your information we apply safeguards designed to prevent unauthorised access, disclosure, alteration or loss. If a personal data breach occurs that is likely to result in a risk to you, we will notify the ICO and, where required, you, in accordance with our legal obligations.
14. YOUR RIGHTS
You have the right to: access the personal information we hold about you; have inaccurate information corrected; have information deleted in certain circumstances; restrict or object to processing, including an absolute right to object to direct marketing; receive certain information in a portable format; and withdraw consent at any time where processing is based on consent, without affecting processing already carried out. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
To exercise any right, contact us at hello@rumble-gym.com or via the contact form. We will respond within one month of receiving your request, or tell you if we need longer for a complex request. We may need to verify your identity before acting.
15. COMPLAINTS
If you are unhappy with how we have handled your personal information, please tell us first: you can use our website contact form at www.rumble-gym.com/contact-us or email hello@rumble-gym.com with "Data protection complaint" in the subject line. We will acknowledge your complaint within 30 days of receiving it, keep you informed of progress, and respond without undue delay, in accordance with section 164A of the Data Protection Act 2018. If you remain dissatisfied, you can complain to the Information Commissioner's Office at ico.org.uk or by telephone on 0303 123 1113.
16. CHILDREN
Our services are designed for people aged 16 and over, and 16 and 17 year olds require parental or guardian consent to train with us (see our Terms & Conditions). We do not knowingly collect personal information from anyone under 16. If you believe we hold information about a child under 16, please contact us and we will delete it.
17. CHANGES TO THIS POLICY
We may update this policy from time to time. The latest version, with its version number and publication date, will always be available on our Website and app, and we will tell account holders by email about material changes. This policy is information about how we process personal information; it does not form part of your contract with us.
