TINS Club Privacy Notice
Version: 5 August 2026
1. Who is responsible for your personal data?
TINS Club is a trading name of TINS Gym B.V., established in Haarlem and registered with the Dutch Chamber of Commerce under number 42045804.
TINS Gym B.V. is the controller of the personal data described in this Privacy Notice.
For privacy questions, requests or complaints, you can contact us through the contact form on tins.club.
Our training sessions take place at PT Center, Minckelersweg 20 in Haarlem. PT Center is not automatically responsible for personal data that you provide directly to TINS Club.
2. When does this Privacy Notice apply?
This Privacy Notice applies when you:
- visit our website;
- create an account;
- book a free or paid training session;
- purchase a punch card, day pass, membership or other product;
- participate in a training session or event;
- contact us;
- participate in our referral programme;
- subscribe to marketing communications;
- voluntarily join our WhatsApp community;
- otherwise use our services.
3. What personal data do we process?
Depending on how you use TINS Club, we may process the following personal data.
Account and contact information
- first and last name;
- email address;
- telephone number;
- account number or internal customer number;
- password in encrypted form;
- communication preferences;
- language preference.
Booking and participation information
- booked training sessions;
- booking dates and times;
- attendance, cancellations and no-shows;
- used and remaining credits;
- participation in free sessions, activities and events;
- relevant communications concerning your booking.
Purchase and payment information
- products or services purchased;
- payment status;
- transaction information;
- invoice information;
- vouchers and discount codes used;
- refund and chargeback information.
We generally do not receive full payment card or bank details where payments are processed by an external payment service provider.
Referral information
- your personal referral code;
- the account connected to the referral code;
- use of the referral code;
- the status of a referral;
- issued, used and expired vouchers;
- information necessary to prevent duplicate, invalid or fraudulent referrals.
An existing member does not provide your name, email address or telephone number to TINS Club on your behalf. We receive your personal data only when you visit our website, create an account or contact us yourself.
Communication information
- messages you send us;
- questions, comments and complaints;
- communications through email, our contact form, WhatsApp or social media;
- records of marketing consent and withdrawals.
Technical and website information
Depending on our technical configuration, we may process:
- IP address;
- browser type;
- device and operating system information;
- date, time and duration of website visits;
- pages visited;
- cookie identifiers;
- security and log information.
Health and safety information
Information about injuries, physical limitations or health conditions may constitute special-category personal data.
We do not ask for a complete medical history or diagnosis. We process health information only where:
- you voluntarily provide the information;
- the information is necessary to adapt a training session safely;
- you have given explicit consent; or
- processing is necessary in an emergency to protect your vital interests.
Only provide information that is relevant to safe participation. TINS Club does not provide medical care and does not replace a doctor, physiotherapist or other healthcare professional.
Photographs and video recordings
We may take photographs or videos during training sessions or events. We only publish identifiable material for marketing, social media or our website after obtaining consent, unless the image is sufficiently general that individuals cannot reasonably be identified.
You may withdraw consent for future publication at any time.
4. Why do we process personal data?
Creating and managing an account
We process account and contact information to create, provide access to and secure your account.
Legal basis: performance of a contract or taking steps at your request before entering into a contract.
Booking and providing training sessions
We process booking, attendance and contact information to organise sessions, inform participants, manage capacity and administer credits.
Legal basis: performance of a contract.
Payments, invoices and administration
We process purchase, payment and invoice information to handle payments, allocate products, maintain our accounts and comply with tax obligations.
Legal basis: performance of a contract and compliance with a legal obligation.
Customer service and communications
We process contact and communication information to answer questions, resolve complaints and provide important information about bookings, changes or safety.
Legal basis: performance of a contract and our legitimate interest in providing appropriate customer service.
Operating the referral programme
We process referral codes, account connections and reward statuses to register participation, issue vouchers and prevent misuse.
Legal basis: performance of the referral agreement and our legitimate interest in operating a fair and fraud-resistant programme.
We do not provide the referring member with detailed information about your training sessions, payments or other activities. The member only receives the information necessary to determine whether a reward has been issued.
Sending service communications
We may send messages that are necessary for providing our services, including:
- booking confirmations;
- reminders for booked sessions;
- changes or cancellations;
- payment confirmations;
- credit and voucher information;
- safety information;
- changes directly affecting your account or purchase.
These messages are not general marketing communications.
Legal basis: performance of a contract and, where applicable, our legitimate interest.
Marketing communications
We only send newsletters, promotions or general commercial messages where:
- you have given prior consent; or
- we lawfully obtained your contact details in connection with an earlier purchase and the communication relates to our own similar services, provided that you were offered a simple opt-out both when the details were collected and in every message.
We apply the same principles to commercial communications through WhatsApp or other electronic channels.
We do not call consumers for commercial purposes without prior explicit consent.
Legal basis: consent or, only where legally permitted, the existing-customer exception for electronic marketing.
You can unsubscribe free of charge at any time.
Security and fraud prevention
We may process limited information to secure accounts and payments, investigate fraud, prevent voucher misuse and protect our rights.
Legal basis: our legitimate interest in protecting our services, participants and business.
Legal obligations and disputes
We may process personal data where necessary to comply with legal obligations, handle legal disputes, investigate fraud or establish, exercise or defend legal claims.
Legal basis: compliance with a legal obligation and legitimate interests.
5. Required and voluntary information
Information required to create an account, process a booking or handle a payment is mandatory. Without this information, we may be unable to provide the relevant service.
Marketing consent, participation in the WhatsApp community, disclosure of health information and consent for identifiable images are voluntary, unless certain health information is necessary for responsible participation in a specific session.
Refusing or withdrawing marketing consent does not affect access to regular TINS Club services.
6. Who do we share personal data with?
We may share personal data with carefully selected service providers, including:
- website and hosting providers;
- account, booking and membership administration systems;
- payment service providers;
- email and communications providers;
- cloud storage and security providers;
- accountants and administrative service providers;
- IT support providers;
- legal and professional advisers;
- competent public authorities where disclosure is legally required.
These parties only receive the information necessary for their task. Where a party acts as our processor, we enter into a data processing agreement.
We do not sell personal data.
7. WhatsApp community
Participation in a TINS Club WhatsApp group is voluntary and is not required to book or purchase training sessions.
When you join a WhatsApp group, other group members may see your telephone number, profile name, profile picture and messages, depending on your WhatsApp settings.
WhatsApp and Meta also independently process personal data under their own privacy terms. TINS Club does not have full control over this processing.
Do not share sensitive or medical information in a group chat. You may leave the group at any time.
8. Transfers outside the European Economic Area
Some technical service providers may process data outside the European Economic Area.
Where this occurs, we ensure that a valid transfer mechanism is in place, such as:
- an adequacy decision adopted by the European Commission;
- approved Standard Contractual Clauses;
- another safeguard permitted by law.
Where relevant, we assess additional technical and organisational safeguards.
9. How long do we retain personal data?
We do not retain personal data for longer than necessary for the purpose for which it was collected, unless a legal retention obligation or legal interest requires a longer period.
We generally apply the following periods:
- account information: for the duration of the active account and up to 24 months after the last activity;
- booking and attendance information: up to 24 months after the relevant session;
- enquiries and general correspondence: up to 12 months after completion;
- financial records, invoices and payment information: at least 7 years in accordance with Dutch tax retention requirements;
- referral information: up to 24 months after completion, rejection or expiry of the reward;
- evidence of marketing consent: while the consent is used and up to 5 years after the last commercial message;
- minimal suppression information: for as long as necessary to prevent further unwanted marketing;
- relevant health information: during the active training relationship and up to 3 months afterwards, unless an incident or legal dispute requires longer retention;
- incident and claim information: for as long as reasonably necessary to handle or support a claim;
- unused photographs and video recordings: generally up to 3 months;
- published media: until it is no longer relevant or consent for future digital publication is withdrawn;
- technical logs: generally up to 12 months, unless a security incident justifies longer retention.
Information forming part of our tax records may continue to be retained for the statutory period after your account is deleted.
10. Cookies and similar technologies
We may use functional cookies that are necessary to operate and secure the website.
When you open a referral link, we place a functional first-party cookie containing the referral code used (valid for a maximum of 30 days). This cookie is needed to attribute a referral to the correct referrer when an account is created.
Limited analytics cookies with little or no impact on privacy may be used without prior consent where permitted by law.
Tracking, advertising and other non-essential cookies are only placed after you have given consent.
You can change your preferences through the cookie settings on our website. Removing cookies through your browser may affect certain website functions.
11. How do we protect personal data?
We take appropriate technical and organisational measures, including where appropriate:
- access restrictions;
- strong authentication;
- encrypted connections;
- secure storage;
- logging and monitoring;
- backups;
- restrictions on employee and supplier access;
- periodic reviews of security measures.
No system is completely secure. If a security incident occurs, we assess whether notification to the Dutch Data Protection Authority and affected individuals is required.
12. Automated decision-making
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
Automated checks may be used to identify duplicate accounts, suspicious payments or possible voucher misuse. You may request human review of a final reward rejection.
13. Your privacy rights
Subject to the GDPR, you have the right to:
- receive information about our processing;
- access your personal data;
- correct inaccurate information;
- request erasure;
- request restriction of processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- receive data in a portable format;
- withdraw consent;
- request human review of relevant automated decisions;
- lodge a complaint with the Dutch Data Protection Authority.
Withdrawal of consent does not operate retroactively. Processing lawfully carried out before withdrawal remains lawful.
You can submit a request through the contact form on tins.club. We may request additional information to verify your identity. We generally respond within one month.
14. Children
Individuals under the age of 18 may only create an account, make a purchase or participate in the referral programme with the permission of a parent or legal guardian.
We do not knowingly direct marketing at children under 16 or knowingly collect their information without appropriate permission.
If we discover that data has been collected without the required permission, we will delete it as soon as reasonably possible.
15. Changes
We may amend this Privacy Notice when our services, systems or legal obligations change.
The latest version will be published on tins.club. We will notify active users through an appropriate channel if material changes are made.