WESTSIDE BARBELL

PRIVACY POLICY

Digital Education Products and Services

Last updated: April 20, 2026

INTRODUCTION

Westside Barbell (“we”, “us”, “our”) respects your privacy and is committed to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you access our digital education products, courses, certifications, memberships, and related services (collectively, the “Service”) hosted on Thinkific Labs Inc.

This Privacy Policy applies to personal information we collect through our Thinkific-hosted learning platform, through our website, through email and SMS communications, and through any related services we provide.

By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, do not use the Service.

SECTION 1 – INFORMATION WE COLLECT

Personal Information You Provide Directly

When you create an account, enroll in a course, purchase a certification, join a membership, or otherwise interact with the Service, we may collect:

• Identity and contact information: name, email address, billing address, phone number

• Account credentials: username and password

• Payment information: billing address, payment card details (processed and stored by our payment processor, not by us)

• Professional information: your role (coach, gym owner, athlete, etc.), organization or affiliation, coaching credentials, and any information you voluntarily provide in course applications, intake forms, or coaching call scheduling

• Communications: messages, feedback, and inquiries you send to us, and content you post in forums, discussion groups, or course communities

Information We Collect Automatically

When you use the Service, we and our service providers automatically collect certain information, including:

• Technical data: IP address, browser type and version, operating system, device identifiers, time zone, and referring website

• Usage data: pages viewed, courses accessed, lessons completed, quiz and assessment scores, time spent on content, progress through programs, video playback data, and click activity

• Cookies and similar tracking technologies (see Section 7)

Information from Third Parties

We may receive information about you from third parties, including:

• Payment processors confirming successful transactions

• Marketing platforms that track engagement with our emails, ads, and content

• Social media platforms if you interact with us through those channels

• Analytics providers that measure Service performance

Information from Coaching Calls and Live Sessions

If you participate in 1-on-1 coaching calls, group coaching sessions, live Q&A, or any other interactive session offered as part of the Service, we may collect information shared during those sessions, including audio and video recordings where recording is disclosed in advance. Recordings may be retained for quality assurance, training, or delivery of the service you purchased.

SECTION 2 – HOW WE USE YOUR INFORMATION

We use the personal information we collect for the following purposes:

• To provide, operate, and deliver the Service you purchased, including course access, certification issuance, membership benefits, and coaching services

• To process payments, issue invoices and receipts, and manage subscriptions and renewals

• To authenticate your account and protect against unauthorized access

• To communicate with you regarding your account, purchases, course updates, and important service notices

• To respond to your questions, support requests, and coaching inquiries

• To personalize your learning experience and recommend relevant content

• To monitor and analyze usage trends to improve the Service, develop new features, and refine our content

• To send you marketing communications about our products, courses, and services, where you have provided consent or where permitted by law

• To detect, investigate, and prevent fraudulent activity, security incidents, and violations of our Terms of Service

• To comply with legal obligations, enforce our agreements, and protect our rights, property, or safety and that of our users

SECTION 3 – CONSENT

How You Provide Consent

When you provide us with personal information to complete a transaction, create an account, enroll in a course, or otherwise access the Service, we imply that you consent to our collecting and using that information for the purpose for which you provided it.

For secondary purposes, such as marketing communications, we will either ask you directly for your express consent or provide you with an opportunity to opt out. You may opt in to SMS marketing separately during checkout or account creation.

How You Withdraw Consent

If you change your mind after opting in, you may withdraw your consent for the continued collection, use, or disclosure of your personal information at any time by:

• Using the unsubscribe link in any marketing email we send you

• Replying STOP to any SMS marketing message

• Adjusting your account or communication preferences

• Contacting us at [email protected]

Please note that withdrawing consent for certain communications may not affect transactional messages necessary to deliver the Service you purchased.

SECTION 4 – HOW WE SHARE YOUR INFORMATION

We do not sell your personal information in the traditional sense. We share your personal information only in the following circumstances:

Service Providers

We share personal information with third-party service providers who perform services on our behalf. These providers are contractually required to protect your information and use it only for the purposes we specify. Our service providers include:

• Thinkific Labs Inc. (course hosting platform)

• Payment processors, including Thinkific Payments

• Email marketing platforms (including Klaviyo)

• SMS marketing providers

• Analytics and advertising platforms (including Google Analytics, Meta/Facebook)

• Customer support tools

• Cloud storage and infrastructure providers

Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information, as well as any choices you may have regarding your personal information.

Legal Requirements

We may disclose your personal information if required to do so by law, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to:

• Comply with a legal obligation, subpoena, or court order

• Enforce our Terms of Service or other agreements

• Protect the rights, property, or safety of Westside Barbell, our users, or others

• Investigate and prevent fraud, security threats, or illegal activity

With Your Consent

We may share personal information with third parties when you have given us your consent to do so.

SECTION 5 – THINKIFIC AND PAYMENT PROCESSING

Our digital learning platform is hosted by Thinkific Labs Inc. (“Thinkific”). Thinkific provides the online course creation and delivery platform that allows us to sell and deliver our products and services to you.

Your data is stored through Thinkific’s data storage, databases, and application infrastructure on secure servers behind firewalls. Thinkific is based in Canada, and by using the Service you consent to the transfer of your personal information to Canada and to other jurisdictions where Thinkific’s service providers are located.

For more information on Thinkific’s privacy practices, you can review Thinkific’s Privacy Policy at https://www.thinkific.com/privacy-policy/ and their Terms of Service at https://www.thinkific.com/terms-of-service/.

Payment Processing

Payments for our digital products are processed by Thinkific Payments and other authorized third-party payment processors. Your payment card information is transmitted and processed in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Purchase transaction data is stored only as long as is necessary to complete the transaction and comply with legal, accounting, and tax requirements.

All payment gateways we use adhere to PCI-DSS standards as managed by the PCI Security Standards Council, a joint effort of Visa, MasterCard, American Express, and Discover.

SECTION 6 – THIRD-PARTY SERVICES AND LINKS

In general, the third-party providers we use will only collect, use, and disclose your information to the extent necessary to allow them to perform the services they provide to us. However, certain third-party service providers, such as payment gateways, have their own privacy policies governing the information we provide to them for purchase-related transactions.

For these providers, we recommend that you review their privacy policies to understand how your personal information will be handled.

Certain providers may be located in jurisdictions different from yours or ours. If you proceed with a transaction that involves the services of a third-party service provider, your information may become subject to the laws of the jurisdictions in which that service provider or its facilities are located.

The Service may contain links to other websites, applications, or services not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party site you visit.

SECTION 7 – COOKIES AND TRACKING TECHNOLOGIES

We and our service providers use cookies, web beacons, pixels, and similar tracking technologies to operate the Service, personalize your experience, analyze usage, and support marketing efforts. Cookies are small data files stored on your device.

Types of cookies we use include:

• Essential cookies: required for the Service to function, including authentication, session management, and shopping cart functionality

• Performance and analytics cookies: help us understand how users interact with the Service so we can improve it

• Functional cookies: remember your preferences and settings

• Marketing and advertising cookies: used by us and our advertising partners (including Meta/Facebook and Google) to deliver relevant advertising and measure campaign performance

Most web browsers allow you to control cookies through their settings. You can choose to block cookies or receive alerts when cookies are being sent. Blocking or disabling cookies may affect the functionality of the Service. Please note that because there is no consistent industry standard for responding to “Do Not Track” browser signals, we do not currently alter our data collection practices based on such signals.

SECTION 8 – DATA SECURITY

We take reasonable precautions and follow industry best practices to protect your personal information from loss, misuse, unauthorized access, disclosure, alteration, or destruction. These measures include:

• Encryption of data in transit using TLS/SSL technology

• Encryption of sensitive data at rest, including AES-256 encryption for payment-related data

• Access controls and authentication requirements for our staff

• PCI-DSS compliance for all payment processing

• Regular review of our security practices

Although we implement these safeguards, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee the absolute security of your personal information. You are responsible for maintaining the confidentiality of your account password and for any activity under your account.

SECTION 9 – DATA RETENTION

We retain your personal information for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and accounting obligations, to resolve disputes, and to enforce our agreements.

General retention periods:

• Account and course enrollment data: retained for the duration of your account and for a reasonable period after account closure to fulfill legal and tax obligations

• Transaction records: retained as required by applicable tax and accounting laws (typically 7 years)

• Marketing communications data: retained until you withdraw consent or opt out

• Course progress and certification records: retained to maintain certification validity and support future re-certification or upgrade enrollments

• Coaching call recordings and session notes: retained in accordance with the service agreement under which they were created

When personal information is no longer needed, we will securely delete or anonymize it.

SECTION 10 – YOUR PRIVACY RIGHTS

General Rights

You have the right to:

• Access the personal information we hold about you

• Request correction of inaccurate or incomplete information

• Request deletion of your personal information, subject to legal exceptions

• Withdraw consent for marketing communications

• Request a copy of your personal information in a portable format

• Object to or restrict certain processing activities

To exercise any of these rights, contact us at [email protected]. We will respond to your request within the time frames required by applicable law.

California Residents (CCPA and CPRA Rights)

If you are a California resident, the California Consumer Privacy Act (“CCPA”), as amended by the California Privacy Rights Act (“CPRA”), provides you with additional rights:

• Right to know what personal information we collect, use, disclose, and sell or share

• Right to delete personal information we have collected from you

• Right to correct inaccurate personal information

• Right to opt out of the sale or sharing of your personal information

• Right to limit the use and disclosure of sensitive personal information

• Right to non-discrimination for exercising your CCPA rights

Do Not Sell or Share My Personal Information

We do not sell personal information in exchange for money. However, our use of certain advertising cookies and pixels (including Meta/Facebook and Google advertising) may constitute “sharing” of personal information for cross-context behavioral advertising under California law. California residents may opt out of this sharing by emailing [email protected] with the subject line “Do Not Sell or Share My Personal Information” or by enabling the Global Privacy Control (GPC) signal in a supported browser.

To submit a CCPA request, email [email protected]. We will verify your identity before fulfilling your request and respond within 45 days, with a possible 45-day extension where reasonably necessary.

European Economic Area, United Kingdom, and Switzerland Residents

If you are located in the EEA, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR) or equivalent laws, including the rights listed above. Our legal basis for processing your personal information includes:

• Performance of a contract when delivering the Service you purchased

• Your consent for marketing communications and optional features

• Our legitimate interests in operating, securing, and improving the Service

• Compliance with legal obligations

You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your personal information in accordance with applicable law.

SECTION 11 – AGE OF CONSENT AND CHILDREN’S PRIVACY

The Service is intended for adults. By using the Service, you represent that you are at least the age of majority in your state, province, or country of residence.

We do not knowingly collect personal information from children under 13 years of age (or the equivalent age in your jurisdiction, such as 16 in the European Economic Area). If you are a parent or guardian and you believe your child has provided us with personal information, please contact us at [email protected]. We will take steps to delete such information from our records.

Thinkific’s platform is not intended for use by minors, and under Thinkific’s terms of use, the storage of personal information of minors is prohibited.

SECTION 12 – INTERNATIONAL DATA TRANSFERS

Westside Barbell is based in the United States. Thinkific is based in Canada. Our service providers may be located in the United States, Canada, the European Economic Area, or other jurisdictions.

By using the Service, you consent to the transfer of your personal information to the United States, Canada, and other jurisdictions where we or our service providers operate. These jurisdictions may have data protection laws that differ from those in your country of residence. Where required by law, we implement appropriate safeguards such as Standard Contractual Clauses for international transfers.

SECTION 13 – MARKETING COMMUNICATIONS

With your consent, we may send you marketing communications by email or SMS about our products, courses, certifications, memberships, events, and related content.

You can opt out of marketing communications at any time by:

• Clicking the unsubscribe link at the bottom of any marketing email

• Replying STOP to any marketing SMS message

• Contacting us at [email protected]

Even if you opt out of marketing communications, we may still send you transactional messages related to your account, purchases, course access, and service updates.

SECTION 14 – CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this Privacy Policy at any time. Changes and clarifications will take effect immediately upon posting on our Service. If we make material changes, we will notify you by email, through a notice on the Service, or by other reasonable means prior to the changes taking effect.

It is your responsibility to review this Privacy Policy periodically. Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of those changes.

If our business is acquired by or merged with another company, your personal information may be transferred to the new owners so that we can continue to provide the Service to you.

SECTION 15 – QUESTIONS AND CONTACT INFORMATION

If you would like to access, correct, amend, or delete any personal information we hold about you, withdraw consent, submit a privacy-related request, register a complaint, or request more information, please contact our Privacy Compliance Officer at:

Westside Barbell

Attn: Privacy Compliance Officer

705 Hadley Dr

Columbus, Ohio 43228

United States

Email: [email protected]