Privacy
Notice
What we collect on this website, why, and what you can ask us to do about it.
Not final — pending review
This page is a draft prepared for Climb Anytime. It has not yet been reviewed or approved by El Dorado Social Ventures, Inc. or by its legal counsel, and it must be reviewed before launch. Nothing here should be relied on as a final statement of the company's policy or as legal advice.
Reviewers: anything that could not be verified against the live system or the venue's documented operations has been deliberately left out rather than guessed at. Gaps are marked in the text.
Draft prepared July 2026
1. Who we are
Climb Anytime is operated by El Dorado Social Ventures, Inc., which is the personal information controller for the data described in this notice.
- Registered office: 8th Floor Gateway Tower, Limketkai Center, Lapasan, Cagayan de Oro City, Philippines
- Gym: 2L South Concourse, Limketkai Mall, Lapasan, Cagayan de Oro City
- Email: eldoradosocialventuresinc@gmail.com
This notice is written to meet the requirements of the Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations.
2. What this notice covers
It covers this website and the online account and booking system behind it. It does not describe the paperwork you complete in person at the gym — the front-desk registration and climbing waiver are handled at the venue and are a separate process. See our waiver page for what to expect on your first visit.
3. What we collect
When you create an account
- Your name
- Your email address
- Your mobile or phone number — optional; you can leave it blank
- A password, which is held in encrypted form by our authentication provider. We never see or store your password ourselves.
When you book a session
- The session, trainer, date and time you selected
- The number of people in your party
- Any notes you choose to type into the optional notes box
- The status of the booking, and the date it was cancelled if you cancel it
Please do not put health information, ID numbers, or other sensitive details in the notes box. It is a free-text field for practical requests only.
If you hold a membership
- Which plan you are on, its status, and the current period start and end dates
- Visits remaining, where the plan is a limited-visit one
- Your position on a waitlist, if you join one
Technical data
Our website host and our booking API automatically process ordinary connection data — such as your IP address, the page or endpoint requested, and error information — to serve the site, keep it available, and investigate faults and abuse. We do not use this to build a profile of you and we do not combine it with your account.
What we do not collect on this website
We do not ask for or store, through this website or your online account: your date of birth or age, your home address, an emergency contact, a government ID, a photograph of you, or any health or medical information. We also do not handle card, bank or e-wallet details — see section 6.
4. Cookies, analytics and what is stored in your browser
This website does not use cookies. It sets none of its own, and it loads no third-party scripts. There is no analytics, no advertising, no tracking pixel and no session-recording tool on this site. Our fonts are served from our own domain rather than from a font provider, so no third party is contacted when a page loads.
The site does use your browser's own local storage, purely to keep you signed in and to avoid losing your place. Nothing there is sent anywhere except to our own booking API:
- Your sign-in tokens and their expiry time, plus a small copy of your account details (name, email, role) so the page can greet you without a round trip. These stay until you log out.
- An unfinished booking or membership selection, stored only for the current browser tab and discarded after one hour, so that logging in part-way through does not lose your choices.
Logging out clears the sign-in items. Clearing your browser's site data removes all of them.
5. Why we use your data
- To give you an account and let you sign in securely.
- To take and manage your bookings, including showing you your upcoming and past sessions and letting you cancel.
- To run memberships, including checking your entitlement and remaining visits.
- To let staff serve you at the gym — the front desk can see your booking so your spot is held and check-in is quick.
- To contact you about your account where you have asked us to, such as sending a password-reset link.
- To keep the service secure and working, including fault diagnosis and preventing misuse.
We rely on the fulfilment of our contract with you (giving you the service you asked for), our legitimate interests in operating and securing the gym and its booking system, and compliance with legal obligations. We do not use your data for marketing without your consent, and we do not sell it.
6. Payments
We do not take payment online. Booking a session reserves your spot; you pay for your pass or membership at the front desk when you arrive. This website has no checkout, and no card, bank or e-wallet details are collected or stored by it.
7. Who else handles your data
We use these service providers, all acting as our processors on our instructions:
- Supabase — provides the database that stores your account, bookings and membership records, and the authentication service that manages your login credentials and sends password-reset emails.
- Cloudflare — hosts this website and runs the booking API at the network edge.
- Resend — delivers the booking emails described in section 9 (password-reset emails are sent by Supabase). It receives your email address and the contents of those messages.
We do not share your personal data with anyone else. We do not sell it, rent it, or give it to advertisers or data brokers. We would disclose data only where we are legally required to — for example under a valid order from a court or a government authority with jurisdiction — or where it is necessary to establish or defend a legal claim.
8. Where your data is processed
Our database is hosted by Supabase in the Asia-Pacific (Singapore) region, and Cloudflare operates a global network, so requests may be handled at locations outside the Philippines. Where personal data is transferred abroad, we remain accountable for it and require our providers to protect it under their standard data-processing terms.
9. Emails we send
This system sends you a password-reset link when you ask for one, and transactional emails about your own bookings — a confirmation when you book and a notice when a booking is cancelled. When you make a booking, the details needed to prepare for your visit (your name, the session, and the time) are also sent to the venue's front desk. We do not send newsletters or marketing email from this website. Your booking reference is also shown on screen, and your bookings are always visible in your account.
10. How long we keep it
We keep your account, booking and membership records for as long as is needed for the purposes described in this notice — that is, while your account is active and afterwards for as long as we need the records to run the business, resolve disputes, and meet our legal, tax and accounting obligations. When a record is no longer needed for any of those purposes, we delete it or render it anonymous.
11. How we protect it
- All traffic between your browser, this website and our booking API is encrypted in transit.
- Passwords are managed by our authentication provider and are never stored by us in readable form.
- Access to customer records is restricted to staff accounts that need it to do their job.
- The site is served with strict security headers that block third-party scripts and framing.
No system is perfectly secure, but if a breach occurs that is likely to seriously affect you, we will notify you and the National Privacy Commission as the Data Privacy Act requires.
12. Your rights
Under the Data Privacy Act you have the right:
- To be informed — to know that your personal data is being collected and why.
- To access — to obtain a copy of the personal data we hold about you, and details of how it is processed.
- To rectification — to have inaccurate or incomplete data corrected. You can change your name and phone number yourself in your account.
- To erasure or blocking — to have your data removed or withheld from further processing in the circumstances the law allows.
- To object — to object to processing, including where processing is based on consent that you withdraw.
- To data portability — to obtain a copy of the data you gave us in a commonly used, machine-readable format.
- To damages — to be indemnified for damage sustained because of inaccurate, incomplete, outdated, false, unlawfully obtained or unauthorised use of your personal data.
- To lodge a complaint — to complain to the National Privacy Commission if you believe your rights have been infringed.
These rights also extend, in the circumstances set out in the law, to your lawful heirs and assigns.
13. How to make a request
Email eldoradosocialventuresinc@gmail.com with the subject line "Data Privacy Request", and tell us what you would like us to do. We may need to confirm your identity before we act, so that we do not disclose your data to someone else. We will respond as promptly as we reasonably can.
If you are not satisfied with how we handle your request, you may bring the matter to the National Privacy Commission.
14. Changes to this notice
If we change how we handle personal data, we will update this page and change the date at the top. Where a change materially affects you, we will make that clear.