Privacy Policy

Last Updated: December 17, 2025

To receive updates to this policy, you may contact our Privacy Officer at info@longevitylounge.ca. We will notify active members of material changes prior to their implementation.

1. Who We Are

Longevity Lounge Inc. ("we," "us," "our") is the organization responsible for the processing of your personal information. We operate out of London, Ontario, providing wellness services including sauna, cold plunge, and red light therapy.

This Policy covers longevitylounge.ca, our mobile applications, and our in-studio operations. For any questions or concerns about this Privacy Policy, you can contact us at info@longevitylounge.ca.

2. Changes to This Policy

We may update this Privacy Policy from time to time for operational, legal, or regulatory reasons. When we do so, we will:

  • Post the revised version on our website with a clearly indicated “Last updated” date;
  • Notify active members by email before material changes take effect;
  • Maintain an accessible archive of prior versions for transparency.

3. What Data Do We Collect?

We apply the principle of data minimization and collect only the information that is necessary for the purposes described in this Policy.

A. Identity & Contact Data

To create your account and manage bookings, we collect Identity Data (Name, Date of Birth, Username) and Contact Data (Email address, Phone number, Mailing address).

B. Health & Wellness Data

As a wellness spa, we collect Sensitive Health Data strictly related to your safety and service suitability. This includes contraindications (e.g., heart conditions, pregnancy) relevant to sauna or cold plunge use, and your preferences for service intensity.

C. Financial & Transaction Data

We collect purchase history, membership status, and billing addresses. Note: We do not store full credit card numbers on our local servers. All payment card data is processed exclusively by our certified third-party provider, Nuvei, which is PCI-DSS compliant.

D. Technical & Usage Data

When you interact with our website or video content (via Wistia), we collect technical data including your IP address, browser type, and engagement metrics (e.g., video views, page clicks).

4. Why We Process Your Data (Purpose & Consent)

We process your personal data strictly for business purposes in line with PIPEDA. The table below outlines why we use your data and the basis for doing so:

Purpose
Activities
Consent Basis
Service Delivery
Booking appointments, checking you in, managing memberships via WellnessLiving.
Contractual Necessity (We need this to provide the service you bought).
Safety & Suitability
Reviewing health forms to ensure you can safely use the sauna/cold plunge.
Express Consent (You explicitly provide health data for this safety check).
Payments & Billing
Processing monthly membership fees, drop-in payments, and refunds via Nuvei.
Implied Consent (Necessary to complete the transaction).
Marketing (CASL)
Sending newsletters, promotions, and updates via Mailchimp.
Express Consent (Opt-in) OR Implied Consent (Existing business relationship, valid for 2 years).
Analytics
Monitoring website usage and video engagement via Google Analytics & Wistia.
Implied Consent (Non-sensitive usage data for improvement).
Security
Maintaining audit logs, verifying age requirements (15+), and fraud prevention.
Legitimate Interest (Protecting our business and users).

5. Cookies & Tracking Technologies

We use cookies and tracking pixels to ensure the proper functioning of our website and to measure engagement.

  • Essential Cookies: Required for login and booking functionality.
  • Advertising Cookies: We work with Google Ads and Meta (Facebook) to display advertising based on your interests. You may opt-out of this tracking via the Digital Advertising Alliance of Canada.

6. Who Sees Your Data?

We disclose personal data only to the extent necessary. We do not sell your data. We share data with the following categories of third-party service providers (Processors):

  • Booking & CRM: WellnessLiving (to manage your profile).
  • Payments: Nuvei (to process cards).
  • Marketing: Mailchimp (to send emails).
  • Video & Analytics: Wistia, Google, Meta.

International Transfers:

Many of our providers maintain servers in the United States. Please be aware that your personal information may be transferred to, stored, and processed in a foreign country (e.g., USA), where it may be accessible to law enforcement of that jurisdiction.

7. How Long We Keep Data

We keep personal data for no longer than necessary. We apply the following retention periods:

Data Category
Retention Period
Client Account Data
Retained while the account is active, plus 2 years after inactivity (to allow for easy reactivation).
Financial Records
7 years from the transaction date (Required by CRA for tax/accounting purposes).
Health Waivers
Retained for 7 years following the last visit (For liability and insurance defence).
Marketing Lists
Retained until you unsubscribe. Once unsubscribed, your email is moved to a "Suppression List" indefinitely to ensure we do not contact you again.
Video Analytics
26 months (Standard Google/Wistia retention settings).

8. Your Rights

Under Canadian privacy laws, you have the following rights:

  1. Access: You may request a copy of the personal information we hold about you.
  2. Correction: You may request correction of any inaccurate data.
  3. Withdraw Consent: You may unsubscribe from marketing or withdraw consent for data processing at any time (subject to legal/contractual restrictions).
  4. Deletion: You may request the deletion of your account, subject to our need to keep financial/legal records.

To exercise these rights, contact our Privacy Officer at info@longevitylounge.ca. We will respond within 30 days.

9. Security

We implement robust technical safeguards including SSL encryption, secure payment tokens (PCI-DSS), and restricted staff access to health data. While we strive for maximum security, no method of transmission over the Internet is 100% secure.

10. Glossary

To help you understand this policy, we have defined key terms below:

  • CASL: Canada's Anti-Spam Legislation, which governs how we send commercial electronic messages (marketing emails).
  • Express Consent: Permission you give explicitly, either in writing or by checking a box.
  • Implied Consent: Permission assumed based on your actions (e.g., buying a membership implies consent to process your credit card).
  • PCI-DSS: The Payment Card Industry Data Security Standard. A security standard for organizations that handle branded credit cards.
  • PIPEDA: The Personal Information Protection and Electronic Documents Act. The federal privacy law for private-sector organizations in Canada.
  • Suppression List: A list of email addresses that have opted out of marketing. We keep this list to ensure we don't email you by mistake.

MEDICAL DISCLAIMER

The content provided by Longevity Lounge Inc. is for informational purposes only. It is not intended to be a substitute for professional medical advice. Participation in sauna, cold plunge, and other wellness activities involves physical risk. By using our services, you acknowledge that you are doing so voluntarily and at your own risk.

Let's Stay Connected

Receive weekly notes from Longevity Lounge, such as new offerings, promotions and helpful reminders for optimal wellbeing.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.