Boxing JourneyFRBook

Privacy policy

This English version is provided for convenience only. The French version of this policy is the official version and prevails in the event of any discrepancy. Consulter la version française

This policy is that of Services de Boxe Journey inc. (NEQ 1177 0925 91), carrying on business under the name Boxing Journey, at 6002 boulevard des Grandes-Prairies, Saint-Léonard (Québec) H1P 1A5.

Centre Sportif Ludus (NEQ 1169 2373 11) is a separate business. The information described in this policy is collected by Services de Boxe Journey inc., which is also the company you contract with and that collects your payments.

It sets out what personal information we collect on boxingjourney.ca, why we collect it, who it is disclosed to, how long we keep it and how you exercise your rights. It is written to be read, not endured: if a sentence is unclear, write to us and we will explain it.

Person in charge of the protection of personal information

This function is exercised by the person with the highest authority within the company, as section 3.1 of the Act respecting the protection of personal information in the private sector provides by default. It has not been delegated. Were it ever delegated, the delegation would be made in writing, as that section requires, and the name published here would change.

Requests for access, requests for rectification, withdrawals of consent and complaints all go to this person.

What we collect and why

We collect only what we need to sell you what you are buying and to answer you. You provide this information yourself, by filling in a form or by paying; we do not buy it and we do not gather it elsewhere. The one exception is the browsing tracking described below, which only runs if you accept it.

  • When you pay for a shop order, the Stripe payment page collects your name, email, billing address and phone number. The billing address is what GST and QST are calculated from; the phone and email are how we tell you your order is ready for pickup at the gym.
  • When you enrol, we create a Stripe customer record in your name, with your email and phone number, along with the membership you chose.
  • With every order travel the details of what you bought — item, size, colour, quantity — so that the right order is handed to you.
  • Through the contact form, we receive your first name, your email and the message you write, and your last name and phone number if you give them, in order to reply. They are sent to GoHighLevel, our customer relationship management system, where your message opens a conversation that we answer by email or, if you gave your number, by text message. This is done to answer you and does not depend on cookies.
  • Through browsing tracking, if you accept it, on the site’s public pages, a GoHighLevel (LeadConnector) tool records the pages you view, the time spent on each, the page you came from and campaign parameters, and the forms you submit, to link an inquiry to a contact record. See Cookies and tracking technologies.
  • By the simple fact of visiting the site, our host keeps the usual technical logs for a limited time: IP address, browser, page requested. They serve security and fault diagnosis, never profiling.

We do not sell personal information, to anyone, ever. Nor do we use it to make a decision about you based exclusively on automated processing.

You may withdraw your consent to the use or disclosure of your information by writing to us. Some processing cannot stop without ending the service: we cannot take a payment without passing it to our payment processor, nor hand over an order without knowing who to hand it to.

Who your information is disclosed to

Five providers process information on our behalf. Each receives only what its function requires.

  • Stripe — payment, subscription and invoice processing. United States and Ireland. No card number touches our servers: the payment page is hosted by Stripe.
  • Netlify — site hosting and receipt of contact-form submissions. United States.
  • Fliip — class booking and membership management, on its own platform and under its own privacy policy, published at centresportifludus.fliipapp.com/home/policy. Chambly, Québec; data hosted on AWS.
  • GitHub — the repository holding the site’s content. That is where an edit made in the gym’s editing tool is stored. United States.
  • GoHighLevel (LeadConnector) — customer relationship management: receiving contact-form messages and replying by email or text message, tracking browsing on the site (if you accept it) and linking inquiries to a contact record. United States.

We also disclose information where the law requires it, or to assert a right before a court.

Your information is processed outside Québec. Stripe, Netlify, GitHub and GoHighLevel operate their services from the United States and, for Stripe, Ireland. Information entrusted to them is therefore stored and processed there, and may be subject to the laws of those countries. Before entrusting information to a provider outside Québec, we assess whether the protection it affords is adequate in light of generally recognised principles, and we frame it by contract.

Retention and destruction

We keep each category of information for as long as the purpose that justified collecting it requires, then we destroy it. The periods we apply are these:

  • Sales and membership records (name, contact details, purchases, invoices): six years after the end of the fiscal year concerned, which is what federal and Québec tax law require of accounting records.
  • Membership file (current membership, health declaration, parental authorisation): for the duration of the membership, then three years, the general limitation period under article 2925 of the Civil Code of Québec.
  • Messages received through the contact form: twelve months after the last reply, unless they become part of a sales record. The copy sent to GoHighLevel, and the conversation that follows, keep to the period below.
  • Contact record and tracking data in GoHighLevel (messages and conversations; pages viewed, where you came from and forms submitted if you accepted tracking): 24 months after your last interaction with us — a tracked visit, a form, a message or an appointment. We check this every quarter, so a record may remain up to three months past that period. If you ask for it to be deleted, it is deleted within thirty days of your request.
  • Server technical logs: kept by our host for a short period — on the order of thirty days — then overwritten automatically.

Destruction is final. When a period has run, the information is deleted or irreversibly anonymised; anonymised information is no longer personal information and is no longer covered by this policy.

At GoHighLevel, a deleted record remains restorable for 60 days — we do not restore it — and is then permanently erased; GoHighLevel’s backup copies are kept for about seven days. Pages viewed by a visitor who never gave us their contact details are not linked to any record: GoHighLevel shows them to us only in aggregated, anonymised form, and we cannot associate them with a person.

Within the company, only those who need it to do their work have access to your information: the person named above, and coaches or administrative staff for what concerns membership and handing over orders. That person keeps the list of those accesses up to date.

Your rights

At any time and free of charge, you may:

  1. Know what information we hold about you, obtain a copy of it, and be informed of the categories of persons within the company who have access to it, the retention period, and the contact details of the person in charge.
  2. Have corrected any information that is inaccurate, incomplete or equivocal.
  3. Withdraw your consent to the disclosure or use of your information, for the future.
  4. Request that dissemination cease, or that a hyperlink giving access to information be de-indexed, where the dissemination causes you serious injury and the law allows it.
  5. Receive, in a structured and commonly used technological format, the computerised information you yourself provided to us, or ask that it be communicated to a third party.

Write to the person named in the Person in charge section. We answer within thirty days of the request. A refusal is given in writing with reasons, cites the provision of law it rests on, and tells you what recourse you have.

Cookies and tracking technologies

GoHighLevel tracking. It is off by default: nothing is loaded or recorded until you click “Accept cookies” in the banner shown on your first visit. If you accept, every public page of the site — but not the staff area — loads a GoHighLevel (LeadConnector) tracking script, served from link.msgsndr.com, which sends data to backend.leadconnectorhq.com, in the United States. The script records:

  • the pages you view and the time spent on each;
  • the page you came from and, where present, the campaign (UTM) parameters in the link you followed;
  • the forms you submit on the site, including the contact form (first name, last name, email, phone, message).

It is used to learn how visitors find the site and to link an inquiry to a contact record in our customer relationship management system. To recognize your visit from one page to the next, it sets a cookie belonging to our site and stores a session identifier in your browser’s storage (localStorage and sessionStorage).

Changing your mind. The “Cookie preferences” button at the bottom of every page reopens the banner. If you withdraw your permission, the tracking cookie and identifier are erased from your browser and the script stops running. You can also block cookies and site data for boxingjourney.ca in your browser settings, or clear the site’s data after your visit. To have tracking data already collected about you deleted, write to the person named in the Person in charge section.

Your choice. Your answer to the banner is stored in your browser’s local storage, under the key ludus-consent, with its date. It is not sent to us. We ask again after twelve months.

Shop cart. The contents of your cart are stored, under the key ludus-cart, in your device’s local storage. They stay on your device, are never sent to us until you go to checkout, and disappear if you clear your browser’s data.

Security

  • The site is served entirely over HTTPS, with the security headers that stop it being loaded or hijacked by a third party.
  • No payment card data touches our servers. The payment page belongs to Stripe, and it is Stripe that receives, processes and stores it.
  • Access to the content editing tool is by invitation only, through named accounts.
  • The keys and secrets the site needs to run are held outside the code, encrypted with our host.

These measures are proportionate to the sensitivity of the information, its purpose and its quantity, as section 10 of the Act requires.

Confidentiality incidents

We keep a register of confidentiality incidents, as section 3.8 of the Act requires. Recorded in it is any unauthorised access to, use of or disclosure of information, any loss of information, and any other breach of its protection.

Where an incident presents a risk of serious injury, we promptly notify the Commission d’accès à l’information and every individual concerned, and we take reasonable measures to reduce the risk and to prevent it recurring.

Complaints

A complaint about the handling of your personal information goes first to the person named above. We acknowledge it, examine it, and give you our conclusions and the measures taken in writing, within a reasonable time.

If our answer does not satisfy you, you may apply to the Commission d’accès à l’information du Québec, cai.gouv.qc.ca.

Changes to this policy

Any change to this policy is published on this page, and notice of that change is published on the site in clear and simple language.

Effective 6 September 2026.