Legal
Privacy Policy
Effective: August 13, 2026 · Last updated: August 13, 2026
This Privacy Policy explains how Mia Fencing LLC (“Mia Fencing,” “we,” “us,” or “our”) collects, uses, stores, shares, and otherwise processes personal data in connection with the website https://miafencing.com, the member portal, the manager portal, school and after-school programs, lead and trial request forms, WhatsApp handoffs, electronic waivers, and related services (collectively, the “Services”). We process personal data in accordance with applicable law, including the EU General Data Protection Regulation (GDPR) where it applies, and we provide California Consumer Privacy Act (CCPA/CPRA) notices where relevant. We do not sell personal data.
1. Data controller
The data controller responsible for the processing described in this Policy is Mia Fencing LLC, a limited liability company organized under the laws of the State of Florida, United States. Our principal online presence is https://miafencing.com. For privacy inquiries, please contact privacy@miafencing.com.
Where we act solely as a processor for a partner school, after-school provider, or other organization (for example, when importing class rosters or managing enrollments on their behalf under contract), that organization remains the controller for the data it provides to us, and we process such data only on documented instructions, subject to our agreements and applicable law.
2. Scope of this Policy
This Policy applies to personal data processed through our public website, authentication and account systems, membership and billing flows, member and manager portals, school and after-school program administration, marketing and trial lead capture, WhatsApp-related handoffs initiated via our forms or links, electronic liability waivers, and communications we send by email or other channels in connection with the Services.
It does not apply to third-party websites, apps, or services that we do not control, even if they are linked from the Services (including WhatsApp, payment pages hosted by Stripe, or social platforms). Those third parties process data under their own policies.
3. Categories of personal data we process
Depending on how you interact with us, we may process the following categories of personal data:
- Identity and contact data: name, email address, phone number, postal or billing address, preferred language/locale, and similar identifiers.
- Account and authentication data: login credentials (stored in hashed or otherwise secured form by our authentication provider), account identifiers, session tokens, and security-related metadata.
- Membership, enrollment, and program data: membership status, class or school affiliation, schedule preferences, attendance-related information where recorded, and program notes needed to deliver fencing instruction and club operations.
- Payment and billing data: payment status, invoice references, subscription or membership plan details, and limited payment metadata. Card numbers and sensitive payment credentials are processed by Stripe; we do not store full card numbers on our systems.
- Lead and trial data: information submitted via trial, contact, or lead forms (including interest in programs, preferred schedule, school or location, and free-text messages).
- Waiver and health-related declarations: acknowledgements, signatures, guardian consents, and statements you provide in electronic waivers. We ask only for information reasonably necessary for participation and risk management; please do not submit unnecessary medical detail.
- Minor and parent/guardian data: a child’s name and age or date of birth where needed for enrollment, and parent/guardian contact and consent information.
- Technical and usage data: IP address, device and browser type, approximate location derived from IP, pages viewed, referrer, timestamps, cookie identifiers (including locale preference), and diagnostic logs.
- Communications content: emails, form messages, and WhatsApp handoff context you choose to share with us.
- Imported operational data: roster, membership, or related records imported from Gymdesk or similar club-management tools where we migrate or synchronize operational data.
4. Children and minors
Mia Fencing offers programs for children and young athletes. We process a minor’s personal data only as needed to provide fencing instruction, enrollment, safety, waivers, and related club services, typically with involvement of a parent or legal guardian.
Parents and guardians are responsible for ensuring that information submitted about a child is accurate and that they have authority to provide consent and enter into waivers on the child’s behalf. Where required by law, we rely on parental consent or another appropriate legal basis for processing children’s data. We do not knowingly use children’s data for unrelated advertising profiling, and we do not sell children’s personal data.
If you believe we have collected a child’s data in a manner inconsistent with this Policy or applicable law, contact us at privacy@miafencing.com and we will take appropriate steps to investigate and, where required, delete or restrict the data.
5. Sources of personal data
We obtain personal data from:
- You directly, when you create an account, submit a form, purchase or manage a membership, sign a waiver, contact us, or use the member or manager portals.
- Parents, guardians, or authorized adults acting on behalf of a minor athlete.
- Partner schools, after-school programs, or organizations that enroll participants and share necessary roster or contact information under appropriate arrangements.
- Service providers that support our operations (for example, authentication, hosting, payments, and email delivery), which may generate technical or transactional data.
- Imports or synchronizations from Gymdesk or comparable systems when we migrate historical or operational club data.
- Publicly available sources only where relevant and lawful (for example, verifying a business contact you provide).
6. Purposes of processing and legal bases (GDPR Art. 6)
Where the GDPR applies, we process personal data only when a legal basis under Article 6 supports the processing. The main purposes and corresponding bases are:
- Providing the website and core Services (account access, member portal, manager portal, program information): performance of a contract (Art. 6(1)(b)) or legitimate interests in operating a secure fencing club platform (Art. 6(1)(f)).
- Memberships, enrollments, billing, and Stripe payment processing: performance of a contract (Art. 6(1)(b)); related accounting and tax records: legal obligation (Art. 6(1)(c)) where applicable and/or legitimate interests (Art. 6(1)(f)).
- Lead, trial, and contact form handling, including WhatsApp handoff to continue the conversation: steps prior to entering a contract (Art. 6(1)(b)) and/or legitimate interests in responding to inquiries (Art. 6(1)(f)); where required, consent (Art. 6(1)(a)).
- Electronic waivers and participation risk acknowledgements: performance of a contract / steps to participate (Art. 6(1)(b)), legitimate interests in safety and liability management (Art. 6(1)(f)), and where required consent (Art. 6(1)(a)), including parental consent for minors.
- School and after-school program administration: performance of a contract with you or the partner organization (Art. 6(1)(b)) and legitimate interests in delivering programs (Art. 6(1)(f)).
- Service communications (schedules, account notices, payment reminders): contract (Art. 6(1)(b)) and/or legitimate interests (Art. 6(1)(f)).
- Marketing emails where not strictly transactional: consent (Art. 6(1)(a)) or soft opt-in / legitimate interests where permitted by law (Art. 6(1)(f)), with an unsubscribe option.
- Security, fraud prevention, debugging, and integrity of Auth sessions: legitimate interests (Art. 6(1)(f)) and, where applicable, legal obligation (Art. 6(1)(c)).
- Locale preference via the mia_locale cookie and similar essential preferences: legitimate interests in providing a usable localized experience (Art. 6(1)(f)) and/or consent where required for non-essential cookies (Art. 6(1)(a)).
- Compliance with legal requests, claims, and regulatory duties: legal obligation (Art. 6(1)(c)) and/or legitimate interests in establishing, exercising, or defending legal claims (Art. 6(1)(f)).
You may object to processing based on legitimate interests where the GDPR provides that right, and you may withdraw consent at any time where processing is consent-based, without affecting the lawfulness of processing before withdrawal.
7. Recipients and processors
We share personal data only with recipients who need it to operate the Services or as required by law. Categories of recipients include:
- Hosting and application delivery: Vercel (website and application hosting).
- Database, authentication, and related backend services: Supabase (including database storage and Auth cookies/sessions).
- Payments: Stripe (payment processing for memberships and related charges).
- Email delivery: Resend and/or Supabase email facilities for transactional and service messages.
- Club operations / migration tools: Gymdesk or similar providers when we import or reconcile membership and roster data.
- Communications channels you choose: WhatsApp (Meta) when you continue a conversation via WhatsApp handoff; WhatsApp processes data under its own terms.
- Partner schools and after-school organizations, where they are involved in your enrollment or program delivery.
- Professional advisers (legal, accounting) under confidentiality obligations, and authorities when legally required.
We require processors to process personal data only on our instructions (or as required by law), to implement appropriate security measures, and to observe confidentiality. We do not sell personal data and we do not share personal data for cross-context behavioral advertising as those terms are commonly defined under CCPA/CPRA.
8. International transfers
Mia Fencing LLC is established in the United States. Personal data submitted through the Services is typically processed and stored in the United States and may be accessed by our team and providers in the U.S. or other countries where they operate.
Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses (SCCs) (and UK/Swiss equivalents where applicable), together with supplementary measures as needed, and on other lawful transfer mechanisms recognized under applicable law.
You may request information about the safeguards applicable to a specific transfer by contacting privacy@miafencing.com.
9. Retention periods
We retain personal data only for as long as necessary for the purposes described in this Policy, including to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Typical retention practices include:
- Account and membership records: for the life of the account/membership relationship and for a reasonable period thereafter (generally up to 3–7 years) for operational continuity, audits, and legal claims, unless a longer period is required by law.
- Payment and billing records: generally 7 years or as required by tax and accounting rules.
- Lead and trial form submissions: generally up to 24 months after last meaningful contact, unless you become a member (in which case data may be retained under membership rules) or you request earlier deletion where applicable.
- Electronic waivers and related acknowledgements: for the duration of participation and for a period thereafter aligned with applicable limitation periods for personal injury or contract claims (often several years; we may retain longer if a claim is pending).
- Security logs and technical diagnostics: typically 30–180 days, unless needed longer to investigate incidents.
- Marketing consents and suppression lists: for as long as needed to honor opt-outs and demonstrate compliance.
- Cookies and similar technologies: as described in our Cookie Policy (session cookies expire when the browser closes; persistent cookies such as locale preference may last for a defined period).
When retention is no longer necessary, we delete or irreversibly anonymize the data, subject to backup cycles and legal holds.
10. Security measures
We implement technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. These measures include, as appropriate: encrypted transport (HTTPS/TLS), access controls and role-based permissions for the manager portal, authentication managed via Supabase Auth, least-privilege practices, monitoring and logging, and contractual security obligations with processors such as Vercel, Supabase, and Stripe.
No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your account credentials and for using strong, unique passwords. Please notify us promptly at privacy@miafencing.com if you suspect unauthorized access to your account.
11. Your rights (GDPR and CCPA)
Depending on your location and applicable law, you may have the following rights:
- GDPR (EEA/UK and similar regimes where applicable): right of access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing based on legitimate interests or to direct marketing; withdrawal of consent; and the right to lodge a complaint with a supervisory authority.
- CCPA/CPRA (California residents): right to know/access categories and specific pieces of personal information collected; right to delete; right to correct inaccurate personal information; right to opt out of “sale” or “sharing” for cross-context behavioral advertising (we do not sell personal information and do not share it for such advertising); right to limit use of sensitive personal information where applicable; and right to non-discrimination for exercising privacy rights.
- Other U.S. state privacy laws may provide similar rights; we will honor applicable requests as required by law.
To exercise these rights, email privacy@miafencing.com with sufficient information to verify your identity and describe your request. We may ask for additional information to confirm you are the data subject or an authorized agent. We will respond within the timeframes required by law. If we deny a request in whole or in part, we will explain the reasons where permitted.
12. Automated decision-making
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects about you within the meaning of GDPR Article 22. Membership eligibility, class placement, and similar operational decisions involve human review as appropriate. Fraud and security filters operated by us or our providers (for example, Stripe Radar or authentication rate limits) may automatically flag or block suspicious activity; you may contact us to seek review of an automated security block that affects your access.
14. Third-party services and links
The Services may contain links to or integrations with third parties, including Stripe Checkout or Customer Portal, WhatsApp, email clients, school websites, and social media. Those services are governed by their own privacy policies. We are not responsible for their practices. We encourage you to review their policies before providing personal data to them.
15. Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or the Services. The “Effective date” and “Last updated” fields at the top of this document will indicate when the Policy last changed. Material changes will be highlighted on the website or communicated by appropriate means (for example, email to account holders) where required by law. Continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes to the extent permitted by applicable law.
16. Contact
For questions, requests, or complaints regarding this Privacy Policy or our processing of personal data, contact Mia Fencing LLC at privacy@miafencing.com. Website: https://miafencing.com.
If you are in the EEA or UK and believe we have not adequately addressed your concern, you may lodge a complaint with your local data protection supervisory authority. California residents may also contact the California Privacy Protection Agency or the California Attorney General as applicable.