Legal

Privacy Policy

Effective Date: April 9, 2026  ·  Last Updated: April 9, 2026

Overview

Labyrinth BJJ ("we," "our," or "us") operates the website at labyrinthbjj.com and any associated mobile applications. We are committed to protecting your personal information and your right to privacy. This policy explains what data we collect, why we collect it, and the choices you have.

By using our website or apps, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.

Our business address is: 6615 West Cross Creek Bend Lane, Suite #400, Fulshear, TX 77441. You can reach us at [email protected] or (281) 393-7983.

Information We Collect

Information You Provide Directly

We collect information you voluntarily give us when you:

  • Fill out a trial class booking form (name, email, phone number, child's age/name)
  • Sign up for a membership or submit a contact inquiry
  • Purchase products or services (billing name, address, payment details — processed securely via Stripe)
  • Subscribe to our email list or SMS updates
  • Register for a competition or event

Information Collected Automatically

When you visit our website or use our app, we may automatically collect:

  • Device & browser data: IP address, browser type, operating system, device identifiers
  • Usage data: Pages visited, time on page, referring URL, click paths
  • Location data: General geographic location derived from IP address (city/state level only — we do not collect precise GPS location without explicit permission)
  • Cookies and similar tracking technologies (see the Cookies section below)

Information from Third Parties

We may receive information about you from third-party services such as Google Analytics, Meta (Facebook/Instagram) advertising pixels, and our gym management software (GymDesk) when you interact with those platforms in connection with our services.

How We Use Your Information

We use the information we collect for the following purposes:

  • To provide and manage services: Confirm trial class bookings, manage memberships, process payments, and communicate class schedules
  • To communicate with you: Send booking confirmations, schedule reminders, belt promotion updates, and administrative notices
  • To improve our website and services: Analyze usage patterns, fix bugs, and optimize the user experience
  • For marketing (with consent): Send promotional emails or SMS messages about programs, events, and offers — you can opt out at any time
  • To comply with legal obligations: Respond to lawful requests, enforce our terms, and protect the rights of our members and staff
  • For safety and liability purposes: Maintain participant waivers and emergency contact information for minors enrolled in youth programs

We do not sell your personal information to third parties. We do not use your data for automated profiling or decision-making that would have legal or significant effects on you.

Sharing & Disclosure

We share your personal information only in the following circumstances:

Service Providers

We work with trusted third-party vendors who help us operate our business. These providers only receive the minimum data necessary to perform their specific function and are contractually prohibited from using it for other purposes:

  • Stripe — Payment processing. Stripe's privacy policy governs how payment card data is handled. We never store raw card numbers on our servers.
  • GymDesk — Gym management software (class scheduling, membership records, waivers).
  • Google Analytics / Google Tag Manager — Website analytics and performance measurement.
  • Meta Pixel — Advertising effectiveness measurement (Facebook/Instagram ads).
  • Cloudflare — DNS, CDN, and security. Traffic may pass through Cloudflare's network.
  • Email/SMS providers — For sending booking confirmations and marketing communications.

Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency), or if we believe disclosure is necessary to protect the safety of any person, prevent fraud, or protect our legal rights.

Business Transfers

If Labyrinth BJJ is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. You will be notified via email and/or a prominent notice on our site of any change in ownership or uses of your personal information.

Cookies & Tracking Technologies

We use cookies and similar technologies (web beacons, pixels, local storage) to operate and improve our website. Below is a summary of the types we use:

  • Essential cookies: Required for the site to function (e.g., session state, security tokens). Cannot be disabled.
  • Analytics cookies: Help us understand how visitors use the site (Google Analytics). These collect anonymous aggregate data.
  • Marketing/advertising cookies: Used by Meta Pixel and Google Ads to measure ad performance and enable retargeting. These may track you across third-party sites.
  • Preference cookies: Remember settings like language or location to personalize your experience.

You can manage or disable non-essential cookies through your browser settings. Note that disabling certain cookies may affect site functionality. You may also opt out of Google Analytics at tools.google.com/dlpage/gaoptout and Meta ad tracking via your Facebook ad preferences.

We do not currently respond to browser "Do Not Track" signals as there is no industry-wide standard for doing so.

Data Retention

We retain your personal information for as long as necessary to provide you services, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods include:

  • Active member records: Retained for the duration of your membership plus 3 years after cancellation.
  • Trial class inquiries: Retained for 12 months if you do not enroll.
  • Payment and billing records: Retained for 7 years as required by U.S. tax law.
  • Minor participant waivers: Retained until the minor reaches age 18 plus an additional 3 years, in compliance with Texas statute of limitations rules.
  • Marketing contact lists: Retained until you unsubscribe or request deletion.
  • Analytics data: Anonymized and aggregated; retained indefinitely in aggregate form.

When data is no longer needed, we securely delete or anonymize it.

Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

  • Right to access: Request a copy of the personal information we hold about you.
  • Right to correction: Ask us to correct inaccurate or incomplete information.
  • Right to deletion: Request that we delete your personal data, subject to legal retention requirements.
  • Right to opt out of marketing: Unsubscribe from emails at any time using the "unsubscribe" link in any email, or reply STOP to any SMS. You can also contact us directly.
  • Right to data portability: Request your data in a structured, commonly used format.
  • Right to lodge a complaint: If you are in the EU/EEA, you may file a complaint with your local supervisory authority. U.S. residents may contact the FTC at ftc.gov.

To exercise any of these rights, please email us at [email protected]. We will respond within 30 days.

Children's Privacy (COPPA Compliance)

Because Labyrinth BJJ offers youth programs for children as young as age 3, we take the privacy of children very seriously and comply with the Children's Online Privacy Protection Act (COPPA).

Under Age 13

We do not knowingly collect personal information directly from children under age 13. All information for children under 13 must be provided by a verifiable parent or legal guardian. When enrolling a child under 13, we collect:

  • Child's name, date of birth, and age/belt level
  • Parent/guardian name, email address, phone number, and billing information
  • Emergency contact information and any relevant health disclosures

This information is used solely to manage the child's enrollment, ensure their safety, and communicate with parents. We do not use children's information for advertising or share it with third parties for marketing purposes.

Parents and guardians may review, update, or request deletion of their child's information at any time by contacting us at [email protected].

Ages 13–17

Teens ages 13–17 may use our website and app, but account creation and membership enrollment still require parent or guardian consent. We treat teen users' data with the same protections applied to children under 13.

Parental Controls

If you believe we have inadvertently collected information from a child under 13 without verifiable parental consent, please contact us immediately and we will promptly delete it.

Security

We implement industry-standard technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • TLS/SSL encryption for all data transmitted between your browser and our servers
  • Cloudflare DDoS protection and WAF (Web Application Firewall)
  • Payment card data handled exclusively by Stripe, which is PCI-DSS Level 1 certified
  • Access controls limiting staff access to personal data on a need-to-know basis
  • Regular security reviews and updates

No method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. In the event of a data breach that creates a risk of harm, we will notify affected individuals as required by applicable law.

Third-Party Services & Links

Our website may contain links to third-party websites (e.g., jits.gg for competition stats, IBJJF, YouTube video embeds) and our booking flow may redirect to third-party platforms. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party sites you visit.

Third-party services integrated into our platform that may collect data independently include:

Texas Residents

Labyrinth BJJ is headquartered in Fulshear, Texas. If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act (TDPSA), which took effect July 1, 2024.

Texas residents have the right to:

  • Know what personal data we collect and how it is used
  • Access and correct personal data we hold about you
  • Delete personal data you have provided to us
  • Opt out of the sale of personal data (we do not sell personal data)
  • Opt out of targeted advertising using your personal data
  • Opt out of profiling in furtherance of decisions that produce legal or similarly significant effects

To submit a TDPSA request, email [email protected] with the subject line "Texas Privacy Request." We will respond within 45 days, with a possible 45-day extension if needed. If we deny your request, you may appeal by replying to our denial notice. If your appeal is denied, you may contact the Texas Attorney General's Office at texasattorneygeneral.gov.

App Store Compliance (Apple & Google)

If Labyrinth BJJ operates a mobile application distributed through the Apple App Store or Google Play Store, we comply with both platforms' developer guidelines regarding user data:

Apple App Store (iOS)

In compliance with Apple's App Store Review Guidelines and App Privacy requirements:

  • We provide an accurate App Privacy Nutrition Label in the App Store disclosing all data collected and its purpose
  • We do not use any data collected via Apple's frameworks for advertising or tracking without explicit App Tracking Transparency (ATT) consent
  • We honor ATT opt-out requests — if you decline tracking permission, we will not share your IDFA or use cross-app data
  • We comply with Apple's guidelines on minimum necessary data collection — our app does not request permissions beyond what is needed
  • If our app offers in-app purchases, payment is processed via Apple's secure IAP framework or Stripe — no card data is stored in-app

Google Play Store (Android)

In compliance with Google Play's User Data policy:

  • We disclose all data collection in our Data Safety section in the Play Store listing
  • We comply with Google's prominent disclosure requirements before collecting sensitive data
  • We do not use the Android Advertising ID (AAID) for interest-based advertising without user consent
  • We honor Android's permission model — we request only permissions necessary for core app functionality
  • Our app complies with Google's policy on device and network abuse and does not collect data in the background beyond what is necessary and disclosed

Push Notifications

If our app sends push notifications, you may manage notification preferences at any time in your device Settings app. We only send notifications related to your enrollment, bookings, and (with consent) class announcements. We do not send unsolicited promotional push notifications.

Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Post a notice on our website for at least 30 days
  • For significant changes affecting active members, send an email notification to the address on file

Your continued use of our services after any changes to this policy constitutes your acceptance of the updated policy. We encourage you to review this page periodically.

Contact Us

If you have any questions about this Privacy Policy, wish to exercise your rights, or want to report a concern, please reach out:

Labyrinth BJJ — Privacy Inquiries

Email: [email protected]

Phone: (281) 393-7983

Address: 6615 West Cross Creek Bend Lane, Suite #400, Fulshear, TX 77441

We aim to respond to all privacy-related inquiries within 30 days.