8 Total
2 High severity
5 Medium severity
1 Low severity
Summary

This document establishes Peloton's practices for collecting, using, and sharing personal information from users of its fitness equipment, mobile application, and website. The policy authorizes collection of fitness and health data including heart rate, workout performance metrics, and body weight information, and permits disclosure of personal information to advertising partners and third parties for marketing purposes. California residents are authorized to opt out of the sale or sharing of personal information through account privacy settings or a designated link on the website.

Technical / Legal Breakdown

This document is Peloton's consumer-facing Privacy Policy, governing the collection, use, disclosure, and retention of personal data across its hardware products (Bike, Tread, Row), digital platform, mobile applications, and website, with legal basis rooted in consent, contractual necessity, and legitimate interests depending on jurisdiction. The policy states that Peloton collects a broad range of personal data including identifiers, fitness and health-related metrics (heart rate, workout output, body weight), geolocation data, device and usage data, financial information, and user-generated content, and the terms authorize sharing this data with service providers, business partners, affiliated companies, and third-party advertisers for purposes including marketing and analytics. Notable among the policy's provisions is its collection of health and fitness data that, while not constituting protected health information under HIPAA in this consumer context, nonetheless carries significant sensitivity; the policy also asserts broad behavioral analytics and advertising data sharing practices, including through cookies and tracking technologies, that engage state-level consumer privacy frameworks beyond CCPA. The policy engages CCPA/CPRA for California residents, GDPR and UK GDPR for EU and UK users respectively, and Canada's PIPEDA for Canadian users, with jurisdiction-specific rights sections addressing deletion, portability, correction, and opt-out of sale or sharing of personal information. Material compliance considerations include the sensitivity of fitness and biometric-adjacent data collected through connected hardware, the adequacy of consent mechanisms for behavioral advertising, and the cross-border data transfer arrangements required for Peloton's multi-jurisdiction operations.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial
High — 2 provisions
Medium — 5 provisions
Low — 1 provision

Monitoring

Peloton has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Children's Data and Age Restrictions and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
HIPAA
United States Federal
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured April 19, 2026 06:18 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000220
Version ID CA-V-000751
SHA-256 dc94d4de5c0a32807ebe04a1fad05e9914d9dffe0165262b81083c5a41020389
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans