Privacy Policy

Last Updated & Effective: 6/21/2026

Notice to Users

This Privacy Policy ("Policy") explains how OutOut Ltd. ("OutOut", "we", "us", or "our") collects, uses, discloses, and safeguards your information when you use our mobile application (the "App"), our website goingoutout.app (the "Site"), and any related services (collectively, the "Services"). By accessing or using the Services, you signify that you have read, understood, and agree to our collection, storage, use, and disclosure of your personal information as described in this Policy and our Terms of Service.

1. Information We Collect

We collect information about you in three primary ways: information you provide directly to us, information we collect automatically when you use our Services, and information from third parties.

1.1 Information You Provide Directly

  • Account Registration Data: Name, email address, date of birth (for strictly enforced age verification), phone number, and password.
  • Profile Information: Photographs, biographical text, gender identity, university affiliations, and user-generated handles.
  • Payment & Transaction Data: When purchasing tickets, you may provide billing information. Note: Payment processing is handled by secure third-party processors (e.g., Stripe, Apple Pay, Google Pay). We do not store raw credit card numbers on our servers.
  • Communications: Data contained in customer support requests, feedback forms, or direct communications with our team.
  • User-Generated Content: Reviews, ratings, "Going" statuses, saved venues, and comments.

1.2 Information Collected Automatically

  • Precise Location Data: With your explicit, opt-in consent (via iOS/Android permissions), we collect GPS and Wi-Fi-based location data to provide hyper-local venue and event recommendations. You can revoke this at any time in your device settings.
  • Device & Telemetry Data: IP addresses, MAC addresses, device identifiers (IDFA/AAID), operating system, browser type, battery level, network connection type, and App version.
  • Usage & Engagement Data: Timestamps of logins, pages viewed, buttons clicked, crash logs, ticket viewing duration, and interaction metrics with venues and other users.
  • Cookies & Tracking Technologies: Web beacons, SDKs, pixel tags, and cookies used to analyze platform stability and optimize marketing. See our Cookie Policy for detailed specifications.

1.3 Information From Third Parties

If you choose to link, create, or log in to your OutOut account with a third-party service (e.g., Apple, Google, Facebook), we may receive information about you or your connections from that service, in accordance with their privacy policies.

2. How We Use Your Information

We process your data strictly for the following purposes, relying on valid legal bases under applicable data protection laws (including GDPR and CCPA):

  • Service Provisioning (Contractual Necessity): To create accounts, process ticketing transactions, deliver mobile tickets via QR codes, and facilitate access to venues.
  • Personalization (Legitimate Interest): To run algorithmic recommendations, tailoring the "Picked for You" carousel and suggesting events based on your historical interactions and demographic profile.
  • Social Features (Consent/Contract): To allow you to connect with friends, broadcast your attendance ("Going"), and view who is attending specific events.
  • Safety & Security (Legitimate Interest & Legal Obligation): To authenticate users, prevent fraudulent ticketing, enforce community guidelines, combat spam, and ban malicious actors. We use automated systems to detect anomalous account behavior.
  • Analytics & Improvement (Legitimate Interest): To debug software, analyze crash reports, and optimize the user interface.
  • Marketing & Promotions (Consent): To send you push notifications or emails regarding upcoming events, exclusive ticket drops, or partner promotions. You may opt out unconditionally.

3. How We Share & Disclose Information

We do not sell your personal data to data brokers. However, providing our Services requires sharing data with specific entities:

  • Venues and Event Organizers: When you purchase a ticket or RSVP to an event, we share your name, age verification status, and ticketing ID with the respective venue to facilitate entry, guest list management, and security. Venues are strictly prohibited from using this data for unauthorized marketing.
  • Other OutOut Users: Depending on your privacy settings, your public profile and your RSVP statuses ("Going", "Interested") are visible to the OutOut community or your approved friends.
  • Service Providers & Processors: We share data with enterprise-grade infrastructure providers (e.g., Supabase for database hosting, AWS/GCP for computing, SendGrid/Postmark for emails) under strict Data Processing Agreements (DPAs).
  • Legal & Regulatory Authorities: We may disclose your information if legally required by a subpoena, court order, or warrant, or if we believe in good faith that disclosure is necessary to protect the safety, rights, or property of OutOut, our users, or the public.
  • Business Transfers: In the event of a merger, acquisition, bankruptcy, or sale of assets, user data may be transferred to the acquiring entity subject to the continuity of this Policy.

4. Data Retention & Deletion

We retain your personal information only as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required by law (e.g., tax, accounting, or legal defense).

  • Active Accounts: Data is kept while your account remains active.
  • Account Deletion: Upon your request to delete your account, we will purge your profile, location history, and social connections within 30 days. However, transactional records (ticket purchases) may be retained for up to 7 years for financial compliance.
  • Banned Accounts: If you are banned for violating our Terms, we retain a cryptographic hash of your device identifier and email to prevent circumvention of the ban, grounded in our legitimate interest to maintain platform safety.

5. Your Privacy Rights (GDPR & CCPA)

Depending on your jurisdiction (e.g., the EU, UK, or California), you are afforded specific, legally enforceable rights regarding your personal data:

  • Right to Access: You may request a comprehensive export of all personal data we hold about you.
  • Right to Rectification: You may correct inaccurate or incomplete data directly within the App.
  • Right to Erasure ("Right to be Forgotten"): You may request the permanent deletion of your data.
  • Right to Restrict/Object to Processing: You may object to our reliance on legitimate interests for processing your data (e.g., profiling for recommendations).
  • Right to Data Portability: You may request your data in a structured, machine-readable format.
  • California Privacy Rights (CCPA): California residents have the right to opt-out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. We do not sell your data.

To exercise any of these rights, email privacy@goingoutout.app with the subject line "Data Subject Request". We must verify your identity before fulfilling the request and have 30 days to respond legally.

6. International Data Transfers

OutOut is headquartered in the United Kingdom. If you use our Services from outside the UK, your data will be transferred to, stored, and processed in the UK and potentially the US (where some of our infrastructure providers operate). We rely on adequacy decisions, Standard Contractual Clauses (SCCs), or the UK International Data Transfer Agreement (IDTA) to ensure your data receives equivalent legal protection.

7. Children's Privacy

The Services are strictly intended for users who are 18 years of age or older (or the legal age of majority in your jurisdiction for entering nightlife venues). We do not knowingly collect personal information from individuals under 18. If we become aware that a minor has provided us with personal data, we will immediately and permanently terminate the account and delete the associated data.

8. Changes to this Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal obligations. We will notify you of material changes via an in-app alert, push notification, or email prior to the changes taking effect. Continued use of the Services post-update constitutes acceptance of the revised Policy.

9. Contact the Data Protection Officer

If you have any questions, concerns, or legal disputes regarding this Privacy Policy or our data processing activities, please contact our Data Protection Officer (DPO):

OutOut Ltd. - Legal & Privacy Department

Email: legal@goingoutout.app or privacy@goingoutout.app