Last Updated October 29, 2025

  1. Sources of Personal Data
  2. Types of Personal Data We Collect
  3. How We Use Personal Data
  4. How We Disclose Personal Data
  5. Cookies
  6. Data Security and Data Retention
  7. Children’s Privacy
  8. External Links
  9. Contact Information
  10. SMS Specific Disclosure
  11. Supplemental U.S. State Privacy Disclosures

NHHR together with its subsidiaries and affiliates (collectively, “Company,” “us,” “we,” or “our”) is committed to protecting the privacy of Personal Data (i.e., information reasonably related to a specific individual). This Privacy Policy describes how we process Personal Data collected through our websites, social media accounts, mobile applications, and other online interactions and communications such as email (collectively, our “Digital Properties”); when you visit one of our physical clubs (our “Facilities”); and through other online and offline interactions.

This Privacy Policy applies to information we collect about individual consumers, such as general website visitors and current and prospective club members and guests (“Individuals”) as well as information we collect about the personnel of our business partners, including vendors and business customers, in business-to-business interactions (“Business Contacts”). However, this Privacy Policy does not apply to information about our current/former employees, applicants, and other individuals who interact with us for employment-related purposes. This Privacy Policy also does not apply to data that we handle on behalf of and under the instructions of our business customers.

Whenever you interact with us on behalf of another individual or entity, such as if you refer a friend to us, you must obtain their consent (or have the legal authority without consent) to share their Personal Data with us.

Changes: The Company reserves the right to at any time revise this Privacy Policy without prior notice. If the Company changes its privacy practices, an updated Privacy Policy will be posted to reflect those changes and the effective date of the revised Privacy Policy will be set forth therein. You are bound by any such revisions and should therefore periodically visit this Privacy Policy..

  1. Sources of Personal Data

We collect Personal Data about you from the following sources:

A. Directly from you. We may collect Personal Data you provide to us directly, such as when you contact us through our Digital Properties; interact with us in person, sign up for offers; visit a Facility; enroll as a member or participate in a multi-person membership that includes you as a member; check in at a Facility as a guest; participate in sweepstakes or contests or other interactive activities; submit content to be posted on our Digital Properties; purchase products or services; participate in a fitness assessment or similar service; register for a class; complete online forms or surveys; sign up for an account or other services; or communicate with us, including our customer service team.

B. Data collected automatically and through Cookies. We may automatically collect information or inferences about you, such as through cookies, pixels, tags, scripts, and other tracking technologies (collectively, “Cookies”), when you interact with our Digital Properties. This may include information about how you use and interact with our Digital Properties, information about your device, and internet usage information.

C. From third parties. We may collect Personal Data from third parties, such as service and content providers; our affiliated companies and subsidiaries; other members and guests; analytics and advertising or marketing partners; social media companies; your employer, insurer, or other group to, e.g., obtain discounted services, rewards, or reimbursement, or in connection with a third-party program offering the right to access our Facilities (“Third-Party Offer”), but solely for the business purpose of facilitating the provision of such access or discounts, rewards, reimbursements, or other incentives to you under the Third-Party Offer; other business partners; or other parties who interact with us.

D. From publicly available sources. We may collect Personal Data about you from publicly available sources, such as public profiles and websites.

We may combine information that we receive from the various sources described in this Privacy Policy, including third party sources, and use or disclose the combined information for the purposes identified below.

  1. Types of Personal Data We Collect

We may collect the following types of Personal Data about you. Except as otherwise specified, we may collect this Personal Data from both Individuals and Business Contacts:

A. Identifiers, such as your name, email address, physical address, telephone number, business contact information, and device identifiers (e.g., cookie IDs and IP address).

B. Records about you, such as signatures; physical characteristics or a description of you, including height and weight; the content, timing and method of communications you have with us, such as online chats, calls, and emails; financial information, including credit or debit card numbers; and information you share with or upload to our Digital Properties, such as reviews and comments.

C. Demographic information, such as age (including birthdates) and gender.

D. Commercial information, such as information related to your transactions; products or services purchased, obtained, or considered; subscription information; or other purchasing or consuming histories or tendencies.

E. Internet or other electronic network activity information, such as your browsing history, search history, preference information (including language, marketing and purchasing preferences), account settings (including any default preferences), and other information regarding your interactions with and use of the Digital Properties. For more information about Cookies, please see Section 5.

F. Non-precise geolocation data, such as your location as derived from your IP address or Wi-Fi.

G. Audio, electronic, visual, or other sensory information for safety and security purposes, to support employee training, and to improve services, such as photographs and audio/video recordings collected, for example, through call center recordings, and through cameras used at our Facilities.

H. Professional or employment-related information, such as job title; organization; professional licenses, credentials, or affiliations; and other professional information.

I. Sensitive Personal Data, including the following:

  1. Driver’s license number.
  2. Precise geolocation, to, for example, provide you location-based services and content. You may be able to allow or deny access to your device’s location by changing your device’s location settings, but if you choose to deny such access, we may not be able to provide you with location-based services and content.
  3. Information about your health.
  4. How We Use Personal Data

We may use Personal Data for the following purposes:

A. To provide you or your company products and services, such as making our Digital Properties and other products and services available to you, including registering, verifying, and maintaining your account with us; providing and delivering you the goods and services you request, including in connection with reserving class times or scheduling personal training appointments or issuing passes or facilitating our rewards programs; maintaining our business relationship with you; coordinating sweepstakes and contests; providing customer service; processing or fulfilling orders and transactions (including processing payments); verifying customer information and eligibility for certain programs or benefits; recognizing you and your devices (for example, when you check-in at a Facility); communicating with you, such as in connection with renewing your membership, updating your account information, soliciting feedback, or responding to requests, complaints, and inquiries; providing or facilitating discounts, benefits, and other services in connection with Third-Party Offers; enabling easier future onboarding; and providing similar services or otherwise facilitating your relationship with us.

B. For our internal business purposes, such as day-to-day operation of our business; maintaining internal business records, such as accounting, document management and similar activities; supporting employee training; enforcing our policies and rules; management reporting; auditing; and IT security and administration.

C. For our internal research and product improvement purposes, such as verifying or maintaining the quality or safety of our products or services; better understanding use of our products and services; improving our products or services; designing new products and services; evaluating the effectiveness of our advertising or marketing efforts (for example, to measure views of ads, viewability, clicks, registrations, interactions, purchases, or other “conversion” events); and debugging and repairing errors with our systems, networks, and equipment.

D. For legal, safety or security reasons, such as complying with legal, reporting, and similar requirements; investigating and responding to claims against us, our personnel, and our customers; fulfilling contractual obligations; for the establishment, exercise or defense of legal claims; protecting our, your, our customers’, and other third parties’ safety, property or rights; detecting, preventing, and responding to security incidents and health and safety issues (including managing spread of communicable diseases); and protecting against malicious, deceptive, fraudulent, or illegal activity.

E. In connection with a corporate transaction, such as if we acquire assets of another business, or sell or transfer all or a portion of our business, product lines, divisions, or assets, including through a sale in connection with bankruptcy and other forms of corporate change.

F. For marketing and targeted advertising, such as marketing our products or services or those of our affiliates, business partners, or other third parties. For example, we may use Personal Data we collect to personalize advertising to you (including by developing product, brand, or services audiences and identifying and matching you across devices/sites/services, including connecting your online activity on our Digital Properties with your use or purchase of Facilities); to gather demographic information; to analyze interactions with us or our Digital Properties; or to send you newsletters, surveys, questionnaires, promotions, discounts or promotions, or information about events or webinars, including through email and text message. You can unsubscribe from our email marketing via the link in the email, from our text marketing by responding “STOP,” “UNSUBSCRIBE,” or “OPT OUT” to a text message, or in either case by contacting us using the information in Section 9 below. Note that you cannot opt-out of transactional communications, unless otherwise required by law.

We may use anonymized, de-identified, or aggregated information for any purpose permitted by law.

  1. How We Disclose Personal Data

We may disclose Personal Data to third parties, including the categories of recipients described below:

A. Affiliates and subsidiaries, including parent entities, corporate affiliates, subsidiaries, business units, and other companies that share common ownership.

B. Service providers that work on our behalf to provide the products and services you request or support our relationship with you, such as IT providers, internet service providers, data and web hosting providers, software service providers, email marketing providers, payment processing companies, data analytics providers, security vendors, customer relationship management providers, and companies that provide business support services, financial administration, or event organization.

C. Professional consultants, such as accountants, lawyers, financial advisors, and audit firms.

D. Vendors necessary to complete transactions you request, such as shipping companies and logistics providers.

E. Law enforcement, government agencies, and other recipients for legal, security, or safety purposes, such as when we share information to comply with law or legal requirements, to address national security concerns, to enforce or apply our Terms & Conditions and other agreements or policies, and to protect our, our customers’, or third parties’ safety, property, or rights.

F. Other entities in connection with a corporate transaction, such as if we acquire assets of another entity, or sell or transfer all or a portion of our business, product lines, divisions, or assets, including through a sale in connection with bankruptcy and other forms of corporate change.

G. Business partners that may use Personal Data for their own purposes, such as:

Advertisers, ad agencies, ad platforms and networks, customer intelligence firms, and social media platforms;

Third parties whose Cookies we use as described in our Section 5 below;

Providers of Third-Party Offers, in accordance with the terms of such Third-Party Offers for the business purpose of facilitating the provision of the Third-Party Offers. You may always request that we stop sharing such Personal Data. However, in that case, you may not be eligible to access our Facilities or Digital Properties or obtain any of the rewards, reimbursements, benefits, or other incentives offered through the Third-Party Offer.

H. The public, such as when you have an opportunity to make comments regarding us or our products that we may share with the public, including comments on our blog posts and reviews on our product pages. Any Personal Data in comments, reviews, or other content that you share in public areas of our Digital Properties may be read, collected, or used by other users or the public.

I. Entities to which you have consented to the disclosure.

Where recipients use your Personal Data for their own purposes independently from us, we are not responsible for their privacy practices or personal data processing policies. You should consult the privacy policies of those third-party services for details on their practices.

If you have opted-in to receive text messages, the Company will not share with any third parties (i) your opt-in consent to receive text messages or (ii) any mobile opt-in data you provide in response to our request to text you, except that we may share mobile opt-in data with service providers who help provide our messaging services and, if you provide the same information for other purposes (such as to enroll as a member), we may share such information in accordance with this privacy policy.

  1. Cookies

Our Digital Properties and authorized third parties use Cookies to collect information about you, your device, and how you interact with our Digital Properties. This section contains additional information about:

The types of Cookies we use and the purposes for which we use them

The types of information we collect using these technologies

How we disclose or make information available to others

Choices you may have regarding these technologies

A. Types of Cookies

We and the third parties that we authorize may use:

Cookies, which are a type of technology that install a small amount of information on a user’s computer or other device when they visit our Digital Properties.

Pixels, web beacons, and tags, which are types of code or transparent graphics that contain a unique identifier. In addition to the uses described below, these technologies provide information about interactions with our Digital Properties, (including communications such as email we may send to you) and help us customize our marketing activities. In contrast to cookies, which are stored on a user’s device hard drive, pixels, web beacons, and tags are embedded invisibly on our Digital Properties.

Embedded scripts and SDKs, which allow us to build and integrate custom experiences on our Digital Properties. Embedded scripts are temporarily downloaded onto your device from our web server, or from a third party with which we work, and are active only while you are connected to our Digital Properties and are deleted or deactivated thereafter.

We may use both first-party Cookies, which are set by us, and third-party Cookies, which are set by other parties. Some of the Cookies we use may last solely for your browsing session and are deleted when you close your browser, while others are persistent and stored after you close your browser.

B. Purposes for Using Cookies

We and authorized third parties use these technologies for purposes including:

Strictly Necessary, such as determining when you are signed in, determining when your account has been inactive, providing you with privacy disclosures and choices, and for troubleshooting and security purposes (including preventing fraud and malicious behavior);

Functionality/Personalization, such as remembering language preferences and pages and products you have viewed in order to enhance and personalize your experience when you visit our Digital Properties;

Performance/Analytics, such as analyzing how our websites are used to understand which pages within our Digital Properties are most popular and how users move around them. For example, we use Google Analytics to help us improve the user experience. Google Analytics may use Cookies to perform their services. To learn how Google Analytics collects and processes data, please visit https://policies.google.com/technologies/partner-sites;

Targeting/Advertising, such as conducting advertising and content personalization on our Digital Properties and those of third parties, tracking activity over time and across properties to develop a profile of your interests and advertise to you based on those interests (“interest-based advertising”), providing you with offers and online content that may be of interest to you, and measuring the effectiveness of advertising campaigns and our communications with you—including identifying how and when you engage with one of our emails. In some cases, third-party advertising technology services may send out “bid requests,” which may contain information about the visitor such as IP address or device ID or hashed e-mail address, to its partners in order to find advertisers that are willing to “bid”” on an ad placement (or may themselves bid on ad placements on third-party properties as well, including on our behalf).

C.Types of Data Collected

These Cookies collect data about you and your device, such as your IP address, location (both approximate and precise), cookie ID, device ID, Ad ID, operating system, device type, device settings and other device information, browser used, pages viewed, bounce rates, email open rates and links clicked therein, search queries, referring/exit pages, user agent string, login information, and information entered into webforms, and information about how you interact with our Digital Properties (such as pages on our Digital Properties that you have viewed).

D. Disclosures of Data

We may disclose information to third parties or allow third parties to directly collect information using these Cookies on our Digital Properties, such as social media companies, advertising networks, companies that provide analytics (including providers of ad tracking and reporting services), security providers, and others that help us operate our business and Digital Properties.

E. Your Choices

As described in Section 10 below, residents of certain states may be able to disable Cookies that constitute a “sale,” “sharing,” or “targeted advertising,” as those terms are defined under applicable laws.

In addition, you may be able to control how we use Cookies through other mechanisms. Please be aware that if you disable the use of Cookies, the functionality of our Digital Properties may be negatively impacted, and certain areas or features may not display or work correctly. If you change computers, devices, or browsers; use multiple computers, devices, or browsers; or delete your Cookies, you may need to repeat this process for each computer, device, or browser.

Interest-Based Advertising. Some of the third parties we work with participate with the Digital Advertising Alliance (“DAA”) or the Network Advertising Initiative (“NAI”). The DAA and NAI provide mechanisms for you to opt out of interest-based advertising performed by participating members at https://youradchoices.com/ (or for mobile apps at https://youradchoices.com/appchoices) and https://optout.networkadvertising.org/. Opting out of interest-based advertising will not opt you out of all advertising, but rather only interest-based advertising from data partners and other advertising partners that participate in a self-regulatory program. If you are using a mobile device, you can manage interest-based ads on your device by adjusting the settings provided by your device manufacturer or the operating system provider: Manage settings on iOS devices; and Manage settings on Android devices. To the extent we use Google, Facebook, Instagram, TikTok, or X for advertising purposes, please see these links provided by these respective companies to understand some of their privacy choices.

Browser Settings. You can also refuse or delete Cookies using your browser settings. If you want to disable the use of certain specific Cookies or remove them from your device, you can disable or delete them using your browser settings. Please be aware that not all Cookies can be deleted through browser settings. Please refer to your browser’s Help instructions to learn more about how to manage Cookies, or use the following links for instructions for commonly used browsers: Apple Safari; Google Chrome; Microsoft Edge; and Mozilla Firefox.

Do Not Track. Some browsers have incorporated Do Not Track preferences. At this time, we do not honor Do Not Track signals.

  1. Data Security and Data Retention

Although we maintain industry standard security safeguards, no security measures or communications over the Internet can be 100% secure, and we cannot guarantee the security of your information.

We retain the categories of Personal Data above as reasonably necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. In many situations, we must obtain all, or a portion, of your personal information to comply with legal obligations, resolve disputes, enforce our agreements, protect against fraudulent, deceptive, or illegal activity, or for another one of our business purposes.

  1. Children’s Privacy

Our Digital Properties are intended for individuals 18 years of age and older. The Digital Properties are not directed at, marketed to, nor intended for, children under 18 years of age. The Company does not knowingly collect Personal Data of children under the age of 13, except in the limited cases where a parent or guardian purchases Kids Klub (babysitting) services for a child under the age of 13 and, on behalf of such child, provides certain identifiers such as the child’s name or allows the photographing of such child to facilitate the child’s use of such services. If the Company becomes aware of a child under the age of 13 providing personal information directly, we will attempt to delete that information. If you believe that we have inadvertently collected Personal Data from a child under the age of 18, please contact us at the address in Section 9 below, and we will take prompt steps to delete the information.

  1. External Links

Our Digital Properties may contain links to external sites or other online services that we do not control, including those embedded in third party advertisements or sponsor information. If you decide to access online services linked to on our Digital Properties, you do so entirely at your own risk. The Company does not guarantee that you will receive an alert when you leave the Digital Properties and it is your responsibility to determine when you have left the Digital Properties. We are not responsible for the privacy practices or data collection policies of such third-party services. You should consult the privacy policies of those third-party services for details on their practices.

  1. Contact Information

If you have questions regarding this Privacy Policy, or if you would like to request to opt out of future communications from a Company business or particular program, please contact by clicking on the “Contact” link on our Digital Properties or by writing to us at:

Attn: NHHR Club, 100 Elm Street, North Haven, CT, 06473

  1. NHHR SMS Messaging Opt-In Policy

After opting in, you can cancel the SMS service at any time. Just text “STOP” to the phone number. After you send the SMS message “STOP” to us, we will send you an SMS message to confirm that you have unsubscribed. After this, you will no longer receive SMS messages from us. If you want to join again, message the phone number START. In the event that you opt out of receiving messages, we may still send messages to you in emergency circumstances in the event that we need to contact you or provide you with information on an emergency basis.

NHHR desires to send two types of SMS messages to you.
Informational messages providing updates about NHHR; its facilities; its programs; and other informational messages to keep you abreast of information that may impact your use or enjoyment of our facilities and programs; and
Promotional messages advertising opportunities, discounts, and programs in which you may be interested.
If you are experiencing issues with the messaging program you can reply with the keyword HELP for more assistance, or you can get help directly at info@nhhrct.com.
Carriers are not liable for delayed or undelivered messages
As always, message and data rates may apply for any messages sent to you from us and to us from you.
NHHR does not share or sell SMS opt in, or phone numbers for the purpose of SMS
Our Privacy Policy will govern the terms of data that we obtain from you in connection with our SMS Messaging Policy, which is available here: Privacy Policy | NHHR https://nhhrct.com/pp-html/

  1. Supplemental U.S. State Privacy Disclosures

A. Data Subject Rights

Depending on our relationship with you (i.e., whether you are an Individual or a Business Contact), and in which state you reside within the United States (such as California, Colorado, Oregon, or Delaware), you may have certain rights regarding Personal Data that you can exercise via emailing us at northhavenclub@gmail.com

Right to Know. You may have the right to obtain confirmation regarding whether we are processing your Personal Data and to access that personal information, including the right request information about the categories of Personal Data we have collected about you, the categories of sources from which we collected the Personal Data, the purposes for collecting, selling, or sharing the Personal Data, and to whom we have disclosed your Personal Data and why. You may also request the specific pieces of Personal Data we have collected about you. Oregon and Minnesota residents may also request a specific list of third parties to whom we disclose your Personal Data.

Right to Delete. You may have the right to request that we delete Personal Data that we have collected about you.

Right to Correct. You may have the right to request that we correct inaccurate Personal Data that we maintain about you.

Right to Opt Out of Sale, Sharing, and Targeted Advertising. You may have the right to opt out of selling, sharing, and targeted advertising (as such terms are defined under applicable laws). We do not knowingly sell data about minors under 18. You can exercise the Right to Opt Out of Sale, Sharing, and Targeted Advertising by accessing the “Your Privacy Choices” link and following the instructions on the webpage

To the extent required by law, we will honor opt-out preference signals sent in a format commonly used and recognized by businesses, such as an HTTP header field or JavaScript object. We will process opt-out preference signals at the browser level for computers and mobile devices.

We will not discriminate against you for exercising your privacy rights. However, if the exercise of these rights limits our ability to process Personal Data (such as in the case of a deletion request) in certain contexts, we may no longer be able to provide you certain related products and services or engage with you in the same manner

Locating Your Information and Verifying Your Identity: To process rights requests, we may need to obtain information to locate you in our records or verify your identity depending on the nature of the request.

For Requests to Opt-Out of Sale, Sharing, and Targeted Advertising: We collect your email to locate you in our records.

For Requests to Know, Delete, and Correct: We collect information necessary to verify your identity and that you are a resident of a state that provides for these rights, including name, mailing address, email address, zip code, member key tag number, truncated payment information, and relationship to the Company. In some cases, we may request different or additional information, including a signed declaration that you are who you say you are. We will inform you if we need such information.

Sensitive Personal Data: We only use and disclose Sensitive Personal Data for the following purposes: (i) performing services or providing goods reasonably expected by an average consumer; (ii) detecting security incidents; (iii) resisting malicious, deceptive, or illegal actions; (iv) ensuring the physical safety of individuals; (v) for short-term, transient use, including non-personalized advertising; (vi) performing or providing internal business services; (vii) verifying or maintaining the quality or safety of a service or device; or (viii) for purposes that do not infer characteristics about you.

By participating in any of the above promotional programs, you agree that the benefits are reasonably related to the value of the Personal Data collected and retained.

Participation in our promotional programs is always optional, and you can terminate program participation at any time as explained in the applicable program terms. You can also contact us at northhavenclub@gmail.com to unsubscribe or cancel your participation in any program.

Who we are

Suggested text: Our website address is: https://nhhrct.com.

Comments

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.

If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select “Remember Me”, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.

If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

Suggested text: If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.

For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Suggested text: Visitor comments may be checked through an automated spam detection service.