Back to Outly

Legal

Privacy Policy

This policy explains how Outly Labs Inc. collects, uses, and shares personal information when you use the Outly app, website, or venue dashboard.

Effective August 14, 2026

1. Information we collect

We collect information that is needed to operate Outly:

  • Consumer accounts: email address, first name, sign-in provider, self-reported date of birth, gender, and the server-calculated result of our 19+ eligibility check.
  • Google Sign-In: if you choose Google Sign-In, Google provides our authentication service, Supabase, with your Google account identifier, email address and verification status, display name, and profile image, if available. We use this information only to create, authenticate, and secure your account. We do not show it to venues or other users, use it for advertising, or sell it. We do not request access to Gmail, Drive, Calendar, Contacts, or other Google content.
  • Plans and activity: venues you view, your selected nightly plan, check-in attempts, location-verified check-ins, offers you open or claim, and related dates and times.
  • Check-in method: check-in requires a recent precise location sample. Our server compares the sample with the venue boundary, then discards its raw latitude and longitude. We retain the result, time, and supporting measurements needed to operate and protect check-ins.
  • Venue accounts: business and representative contact details, legal business information, venue profile content, location, hours, offers, account approval records, and subscription status.
  • Technical information: authentication cookies, IP address and server logs, browser or device information, app version, and website or app usage events.
  • Security verification:when an account action needs an anti-abuse check, Cloudflare Turnstile processes technical signals needed to distinguish legitimate use from automated abuse. Outly does not send your email, password, or other form entries to the challenge page. Depending on Cloudflare's service configuration and logs, signals can include country, browser and operating-system details, user agent, network provider, source IP address, and challenge result.
  • Reports and support: content reports, support messages, the venue or offer involved, and the information you include when contacting us.

Payment details are collected and processed by Stripe. Outly does not store full payment card numbers. If you sign in through another provider, that provider handles your password and sends us the account information you authorize it to share.

2. How we use information

We use personal information to:

  • create and secure accounts and confirm 19+ eligibility;
  • show curated venues, where people plan to go, and available offers;
  • record check-ins, verify arrival, and prevent abuse;
  • show cohort-protected crowd insights to Outly users and provide aggregated attendance and campaign analytics to venues;
  • operate venue approvals, subscriptions, support, and billing;
  • review reports and moderate unlawful, unsafe, or misleading content;
  • send service messages and, with the required consent, marketing;
  • debug, secure, measure, and improve the service; and
  • meet legal, tax, accounting, and regulatory obligations.

3. Check-ins and crowd insights

Check-in requires a recent precise location sample inside the venue boundary. If you decline location permission, no check-in is completed; you can change access in iOS Settings and try again. The sample is used for the server decision and raw coordinates are then discarded.

Going counts remain visible to Outly users. Rounded age, gender, and peak-time and typical-momentum signals remain locked until a user completes one successful location-verified check-in, which unlocks signals for every venue. Gender can appear from the first eligible attendee, age requires five eligible attendees, and an observed peak time requires five verified samples. A venue’s separately labelled typical-momentum curve is founder-curated and is not a live attendance measurement. Paid venue dashboards receive aggregated information such as planned visits, total check-ins, check-in verification methods, conversion, repeat visits, check-in times, and age or gender distributions only when group-size safeguards are met. Venues and other consumers do not receive a consumer’s name, email, date of birth, individual gender, live location, or location history.

4. When we share information

We may share limited information with:

  • Service providers that support hosting, authentication, maps, email, analytics, payments, and security, including Supabase, Mapbox, Vercel, Resend, Stripe, Cloudflare Turnstile, and enabled sign-in providers.
  • Venues through the aggregated reporting described above.
  • Campaign partners through aggregated or de-identified performance reporting. We do not give partners consumer names, email addresses, or precise location unless we clearly disclose that use and obtain any consent required by law.
  • Authorities or transaction parties where required by law, needed to protect rights and safety, or connected with a financing, merger, acquisition, or sale of the business under appropriate safeguards.

A partner offer may open an external app or website. Information collected there is governed by that partner’s privacy policy. Outly does not sell personal information. We require providers that process personal information for us to protect it in a manner consistent with this policy and applicable law.

5. Your choices and rights

  • You can manage device permissions and opt out of promotional emails at any time. We may still send account, security, billing, or offer-service messages.
  • You may request access to or correction of your personal information. Date of birth is not editable in the app because it controls eligibility; contact us if it is incorrect.
  • Consumers can delete their account in the app. Venue accounts can request deletion from dashboard settings after cancelling any active paid subscription.

When a consumer account is deleted, we remove the Auth account and analytics tied to it. We detach the direct account identifier from limited historical plans, check-ins, and claims. These operational records are pseudonymized and access-restricted; we may retain them only where reasonably required for fraud prevention, legal compliance, disputes, or financial reporting.

6. Retention and security

We keep personal information only for as long as needed for the purposes in this policy, then delete or anonymize it. Retention depends on the type of record, account status, fraud and safety needs, and legal requirements.

We use administrative, technical, and organizational safeguards designed for the sensitivity of the information. No online service can promise absolute security, so please use a unique password and protect your account credentials.

7. Age requirement

Outly consumer accounts are for people aged 19 or older. We use a self-reported date of birth to calculate eligibility; this is not identity or age-document verification. If we learn that an ineligible person created an account, we may suspend and delete it.

8. Processing outside Canada

Some service providers process information outside Canada, including in the United States. Information in another country may be subject to that country’s laws and lawful access by its authorities. Outly remains responsible for personal information transferred to providers for processing and uses contractual and other safeguards appropriate to the service.

9. Changes and contact

We may update this policy as Outly changes. We will post the revised date here and give additional notice when a change is material.

For access, correction, deletion, or a privacy concern, contact Outly’s Privacy Officer at admin@getoutly.app. Outly Labs Inc. is based in Toronto, Ontario, Canada. If we cannot resolve a concern, you may contact the Office of the Privacy Commissioner of Canada.