Our Privacy Policy

Effective date: 24 August 2026

Movement Health Clubs is the operated by Integrated Fitness Group Pty Ltd, Casuarina Rec Club Pty Ltd, Temple Fitness Group Pty Ltd and Gym4 Pty Ltd. This policy applies to each of these companies. In this policy, Movement, we, us and our refer to those companies.

We are committed to handling personal information responsibly and transparently. This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct your information or make a privacy complaint.

We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For health information handled in New South Wales, we also comply with the Health Records and Information Privacy Act 2002 (NSW) and the Health Privacy Principles.

1. What personal information we collect

The information we collect depends on how you interact with us and the services you use. It may include:

  • identity, contact, emergency-contact and parent or guardian information;

  • membership, booking, attendance, access, participation and transaction records;

  • health and other sensitive information relevant to safe participation or a health service, including medical conditions, injuries, medication, exercise history, health goals and accessibility needs;

  • photos, videos, CCTV footage, communications, enquiries, feedback and complaints;

  • eligibility and verification information, including evidence of a concession, professional qualification or residence;

  • website, app and device activity, including IP address, device identifiers and interactions with our digital services; and

  • recruitment, contractor, volunteer and workplace information.

Eligibility evidence may include a student or pensioner card, fitness-industry credential or limited residence evidence. We seek to collect only what is reasonably necessary. Where practical, we may verify a document and record the outcome rather than retain a complete copy.

We generally collect sensitive information, including health information, with consent where consent is required. We may collect information without consent where permitted or required by law. If requested information is not provided, we may be unable to provide a service, assess safe participation, process a membership or respond fully to a request.

This policy applies to prospective and unsuccessful job applicants, contractors and volunteers. Some records about current or former employees may be exempt from the Australian Privacy Principles where the employee-record exemption applies. Other workplace laws and Movement practices may still apply.

2. How we collect personal information

We may collect personal information:

  • directly from you through membership, casual-visit, cancellation, suspension or service forms, waivers, consultations, bookings, purchases, surveys, phone calls, email, messages, our website or apps;

  • when you enter or use our premises, including through attendance, access-control and CCTV systems;

  • from a parent, guardian, emergency contact or person acting with your authority;

  • from trainers, practitioners, contractors, referral partners or related service providers involved in providing a service to you;

  • from payment processors, membership and booking platforms, technology providers, marketing platforms and other service providers; and

  • from publicly available sources or as otherwise authorised or required by law.

Where required, we provide a collection notice at or before collection. This policy does not replace a specific collection notice or consent request.

3. Why we collect, hold, use and disclose information

We may handle personal information to:

  • provide and administer memberships, facility access, bookings, classes, coaching, fitness, aquatic, adjunct-care (crèche) and other requested services;

  • assess suitability and support health, safety, accessibility, child safety and emergency response;

  • process payments, manage accounts and prevent or investigate fraud, misuse or unlawful activity;

  • communicate with you and manage enquiries, feedback, complaints and service changes;

  • operate, secure, maintain and improve our clubs, services, website, apps and business processes;

  • conduct analytics, planning, research and service development using the minimum information reasonably necessary;

  • send marketing where permitted by law and manage communication preferences;

  • recruit and manage workers and contractors; and

  • comply with legal, regulatory, insurance, audit and risk-management obligations.

We use or disclose personal information for the purpose for which it was collected, for related purposes you would reasonably expect, with consent, or where otherwise permitted or required by law. We only use health information for direct marketing where the consent required by law has been given.

4. Who we disclose information to

Where reasonably necessary, we may disclose personal information to:

  • our authorised staff, contractors, trainers and practitioners;

  • providers of membership, booking, access-control, payments, accounting, communications, hosting, cloud storage, security, analytics, advertising and professional services;

  • insurers, auditors, legal advisers, regulators, emergency services and law-enforcement bodies;

  • a parent, guardian, authorised representative or emergency contact where permitted; and

  • another person or organisation where you consent or disclosure is authorised or required by law.

Material providers include GymMaster for membership administration, Ezypay for payment administration, Microsoft for business systems, Trainerize for fitness and nutrition services, Squarespace for our website, and Zapier, which transfers information submitted through our cancellation, casual and suspension forms to GymMaster. We require providers to handle information only for authorised purposes and with appropriate safeguards.

5. Overseas disclosure

Some service providers may store, access or process personal information outside Australia. Depending on the services used, overseas recipients are likely to be located in New Zealand, the United States, Canada, India, Brazil and European countries. Provider locations may change. Where required by law, we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.

6. Artificial intelligence and automated tools

We may use approved artificial intelligence or automated tools to support administrative work, analysis, communications and service improvement. Where those tools handle personal information, our privacy and security controls apply. We do not authorise staff to enter identifiable personal information, particularly sensitive or health information, into publicly available generative AI tools.

We may use automated features within Trainerize to generate suggested meal plans or workout programs based on information such as goals, dietary preferences, fitness level, activity and progress. Our team reviews suggestions before providing or relying on them. They are not medical advice, diagnosis or treatment. Seek appropriate professional advice for medical conditions, injuries or specialised dietary needs.

7. Website, apps, cookies and analytics

Our website and digital services use cookies, tags, pixels and similar technologies to operate services, remember preferences, measure use, maintain security and support marketing. We use Squarespace Analytics and Google Analytics to understand website use, Google reCAPTCHA to protect forms from misuse, and Meta Pixel to measure advertising performance and understand interactions with our website.

You can manage optional cookies through the cookie banner displayed on our website or through your browser settings. Blocking technologies may affect functionality. Links to third-party websites or apps are governed by those parties' privacy practices.

8. CCTV and club security

We use CCTV at our clubs for safety, security, incident management and the protection of people and property. Footage is accessed only by authorised people and may be disclosed where permitted or required by law. CCTV footage is generally retained for up to three months. Footage relating to an incident may be exported and retained for longer where reasonably necessary to investigate the incident, respond to a claim, protect a person's safety or meet legal obligations.

9. Children and young people

We may collect personal information about children and young people who use our memberships, programs, facilities or adjunct-care services. This may include identity and contact information, parent or guardian details, images, attendance and booking information, health or support information, and records relating to safety concerns or incidents.

Where consent is required, we consider whether the young person has sufficient understanding and maturity to provide it. We may seek consent or involvement from a parent or guardian where appropriate. We limit access and disclosure to what is reasonably necessary for providing services, protecting safety and meeting legal obligations.

10. Direct marketing

We may use contact details to send information about Movement services, offers and events where permitted by law. You can opt out at any time by using the unsubscribe option in a message or contacting us. Service and safety messages are not marketing and may still be sent where necessary.

11. Data quality, security and retention

We take reasonable steps to keep personal information accurate, complete and up to date, and to protect it from misuse, interference, loss and unauthorised access, modification or disclosure. Safeguards may include access controls, staff training, contractual controls, monitoring, secure facilities and technical measures.

We retain personal information only for as long as needed for lawful business purposes and legal obligations, then securely destroy or de-identify it where permitted. NSW law imposes minimum periods for some health records: generally seven years after the last health service for information collected from an adult, and until age 25 for information collected while the person was under 18. Other records may have different requirements.

If an eligible data breach occurs, we will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.

12. Accessing or correcting your information

You may ask for access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us below and tell us what information your request concerns. We may need to verify your identity.

We will respond within the periods required by law. If we refuse access or correction, we will generally give written reasons and available complaint options. We do not charge to make a request. We may charge a reasonable cost for providing access where permitted by law and will tell you beforehand.

13. Privacy complaints

If you believe we have mishandled your personal information, contact our Privacy Contact in writing. Describe what happened, the information involved and the outcome you seek. We will investigate and aim to respond within 30 days, subject to the complexity of the matter.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner. For health information handled in New South Wales, you may also be able to complain to the Information and Privacy Commission NSW or the NSW Civil and Administrative Tribunal, as applicable.

14. Contact us

Privacy Contact: Managing Director

Email: privacy@movementhealthclubs.com.au

Postal address: Movement Health Clubs, PO Box 742, Browns Plains QLD 4118

General contact and club details: movementhealthclubs.com.au/contact-us

15. Changes to this policy

We may update this policy when our practices, services or legal obligations change. The current version will be published on our website with its effective date. Material changes will be communicated where appropriate.