Privacy policy
What we collect, why we collect it, who else sees it, where it is stored, how long we keep it, and how to make us delete it. Written to be read.
Last updated 22 September 2026
Who is responsible for your data
the company operating OUTLY — trading as OUTLY — decides how and why your personal data is used, which makes us the controller.
Questions, requests and complaints about your data go to our support address.
What we collect
When you send an enquiry: your name, phone number, email address, travel dates, number and type of travellers, hotel or pickup area, any dietary preference, any special request you type, your budget band, and the experiences you were looking at.
When you sign in: your phone number and the one-time code we send you, plus the profile and preferences you choose to save.
Automatically: pages viewed, searches and filters used, the approximate country your request came from, a shortened one-way fingerprint of your IP address, your browser's user-agent string, and the identifiers described in our cookie policy — including the advertising click identifiers (for example from Google or Meta) that were attached to the link you arrived on.
- We do not collect card or bank details on this site — no payment is taken here
- We do not ask for passport or Emirates ID details unless a specific operator requires them for your booking, and then only for that booking
- We do not knowingly collect data about children; traveller counts by age band are not the same as a child's identity
Why we use it, and on what basis
To answer your enquiry, check availability with the operator, confirm your booking, send confirmations and trip messages, and support you when something goes wrong. This is necessary to take steps at your request and to perform our contract with you.
To meet tax and accounting obligations — UAE VAT records in particular — which is a legal obligation.
To keep the site secure, prevent spam and abuse, and measure how well the product works. This is our legitimate interest, balanced against your privacy: security data is minimised and analytics identifiers are not used to build a profile for sale.
To send marketing messages, and to message you on WhatsApp — both only with your consent, which you can withdraw at any time without affecting the service you have already booked.
Dietary, medical and accessibility information
A dietary preference or a medical or mobility note can reveal something sensitive about you. We ask for it only so the operator can act on it, we pass it only to the operator delivering your experience, and we use it for nothing else. If you would rather not type it here, tell us on WhatsApp or leave it out and we will ask the operator generically.
Who else sees your data
The operator delivering your experience receives what they need to deliver it: traveller names, counts, pickup point, date and time, and any requirement you told us about.
The companies that run our technology see data only as part of running it, under contract, and may not use it for their own purposes.
- Vercel — website and application hosting (Mumbai, India region)
- Neon — database hosting (United States, Ohio region)
- Resend — transactional email delivery
- MSG91 — delivery of sign-in codes by SMS
- Pexels — stock photography shown on the site (no personal data is sent to them)
- Our WhatsApp messaging provider, named here before we switch WhatsApp messaging on
- Payment providers, named here before we begin taking payment on this site
Where your data is stored, and who reaches it
Our website runs in Mumbai, India, and our database is hosted in the United States. That means your data is transferred outside the UAE and, for European visitors, outside the EEA. We rely on our contracts with those providers — which include the standard data-protection terms they publish — to keep the same protections travelling with the data.
Our staff in the United Arab Emirates and in India access customer data to answer enquiries and deliver bookings. Access requires an individual account with two-factor authentication, is limited to what a role needs, and every action on a customer record is written to an audit log.
WhatsApp, email and marketing
Messages about an enquiry or a booking you made — confirmations, day-of details, changes — are service messages, sent because you asked us for something.
Marketing messages are separate and require you to opt in. Replying STOP, or turning the setting off in your account, ends them; we action it immediately and it does not affect your existing bookings.
WhatsApp messages are carried by Meta's WhatsApp Business Platform. Meta processes them under its own terms; we send the minimum needed to answer you.
We do not sell your phone number, email address or any other personal data.
How long we keep it
Enquiries that never became bookings, and anything we classified as spam: 24 months, then deleted.
Bookings, invoices and payment records: seven years, because tax and accounting law requires it. If you ask us to delete your data before then, we remove the personal details and keep the financial record with your identity stripped out.
Message logs and analytics events: 24 months. Records of the consents you gave: for as long as you could raise a complaint about a message we sent. Our internal audit log is kept as the security record.
Your rights
You can ask us for a copy of everything we hold about you, correct it, ask us to delete it, object to us using it for marketing or analytics, or ask us to restrict how we use it. Signed-in customers can export their data and request deletion from Profile settings; everyone else can ask us by email.
Send requests to our support address. We answer within 30 days.
A deletion request removes your personal details from our systems. Financial records required by law are retained with your identity replaced by an irreversible marker, and entries in our append-only audit and consent logs are kept because they are the evidence that we handled your data correctly.
Security
Data is encrypted in transit and at rest. Staff accounts require two-factor authentication and are rate-limited and locked after repeated failures. Sensitive fields are masked from staff who do not need them, IP addresses are stored only as a one-way hash, and every change to a customer record is written to an immutable audit log.
No system is perfect. If a breach affects your data and is likely to put you at risk, we will tell you and the relevant regulator, as the law requires.
Cookies
Our cookie policy explains every cookie and identifier we set, and how to refuse the non-essential ones.
Changes
We update this policy when what we do changes. The date at the top is the last change. Material changes are announced on the site before they take effect.
Rather just ask?
Policies are policies. If you have a specific situation, message us and we'll tell you exactly where you stand — usually within about 30 minutes.
Replies in about 30 minutes · 10am – 6pm Gulf Standard Time, Monday to Saturday
See also: Cancellation policy · Price promise · FAQ