This privacy policy has been compiled to provide our users with information about how Xponential Fitness (“we”, “our”, “us”) uses their ‘Personal Information’ (“PI”). Please read this privacy policy carefully to get a clear understanding of how we collect, use, protect or otherwise handle your PI when you visit our website or blog, or use our app.

NOTE:  If you are a California resident, please refer to Xponential Fitness’s Privacy Notice for California Residents.



We collect certain identifiers or contact information from you in the course of using the site or our app.  In particular, when ordering or registering on our site, as appropriate, you may be asked to enter your name, email address, phone number, city/state/zip code or other details to help you with your experience.


We collect information directly from you when you fill out a form or enter information on our site.


We may use the information we collect from you in the following ways:

  • To contact you regarding scheduling, class reminders, promotions, specials, or in other ways related to the Xponential Fitness business;
  • To provide to third parties that may contact you on behalf, in connection with the Xponential Fitness business;
  • To administer a contest, promotion, survey or other site feature; and/or
  • To send periodic emails regarding your orders or other products and services.

As discussed below in the “CAN SPAM” section, we may also send you marketing materials via email to provide you the latest information on all the products and services that we offer.  For more information about these activities, please see below.


While no security is perfect and we cannot guarantee the security of any data we hold, we do take a number of steps designed to protect the security and confidentiality of your PI and make your visit to our site as safe as possible.  These include:

  • Use of Malware Scanning, and other efforts to identify potential security holes and known vulnerabilities.
  • Restricting access to your PI to a limited number of persons who have appropriate access rights to such systems and are required to keep the information confidential. 
  • All sensitive/credit information you supply is encrypted via Secure Socket Layer (SSL) technology.
  • All transactions are processed on our behalf through a gateway provider and are not stored or processed on our servers.


Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your Web browser (if you allow) that enables the site’s or service provider’s systems to recognize your browser and capture and remember certain information. For instance, we use cookies to help us remember and process the items in your shopping cart. They are also used to help us understand your preferences based on previous or current site activity, which enables us to provide you with improved services. We also use cookies to help us compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future.

We use cookies to:

  • Understand and save user’s preferences for future visits;
  • Keep track of advertisements; and
  • Compile aggregate data about site traffic and site interactions in order to offer better site experiences and tools in the future. 
  • We may also use trusted third-party services that track this information on our behalf.

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser (like Internet Explorer) settings. Each browser is a little different, so look at your browser’s “Help” menu to learn the correct way to modify your cookies.

If you disable cookies, some features of our website may be disabled. It will turn off some of the features that make your site experience more efficient and some of our services will not function properly.

However, you can still place orders even if you disable cookies. 
Location or IP address information


In addition to some of the scenarios already described, we may share certain information with service providers and others that process or store data on our behalf, such as with our website hosting partners and other parties who assist us in operating our website. We only do this so long as those parties agree to keep this information confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property, or safety. 

However, aggregate or otherwise de-identified visitor information may be provided to other parties for marketing, advertising, or other uses.


We do not include or offer third party products or services on our website.


How does our site handle do not track signals?

We honor do not track signals and do not track, plant cookies, or use advertising when a Do Not Track (DNT) browser mechanism is in place.

Does our site allow third party behavioral tracking?

It’s also important to note that we do not allow third party behavioral tracking.


When it comes to the collection of personal information from children under 13, the Children’s Online Privacy Protection Act (COPPA) puts parents in control. The Federal Trade Commission, the nation’s consumer protection agency, enforces the COPPA Rule, which spells out what operators of websites and online services must do to protect children’s privacy and safety online.

Our website and apps are not designed for, and we do not specifically market to, children under 13.


The Fair Information Practices Principles form the backbone of privacy law in the United States and the concepts they include have played a significant role in the development of data protection laws around the globe. Understanding the Fair Information Practice Principles and how they should be implemented is critical to comply with the various privacy laws that protect personal information.

In order to be in line with Fair Information Practices we will notify users of our website within (7) business days should a data breach occur.

We also agree to the individual redress principle, which requires that individuals have a right to pursue legally enforceable rights against data collectors and processors who fail to adhere to the law. This principle requires not only that individuals have enforceable rights against data users, but also that individuals have recourse to courts or a government agency to investigate and/or prosecute non-compliance by data processors.


The CAN-SPAM Act sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

We collect your email address in order to:

  • Send information, promotions, marketing information, business information, respond to inquiries, and/or other requests or questions;
  • Market to our mailing list or continue to send emails to our clients after the original transaction has occurred; and
  • Share your information with our third party providers to market our business to you.

Consistent with the requirements of CAN SPAM and relevant regulations, we will:

  • Refrain from using false, or misleading subjects or email addresses;
  • Identify the message as an advertisement or commercial message in some reasonable way;
  • Include the physical address of our business in the message;
  • Monitor any third party email marketing services we may use for compliance;
  • Allow users to unsubscribe by using the link at the bottom of each email by following the requisite instructions; and 
  • Honor opt-out/unsubscribe requests in a timely fashion.  Once a user unsubscribes, they will be promptly removed from ALL correspondence.


If there are any questions regarding this privacy policy, you may contact us using the following information:
Xponential Fitness
17877 Von Karman Ave.
Irvine, California 92614
United States

Updated January 2022