Privacy Notice
OutThere is operated by Hostelworld.com Limited, registered in Ireland (Company No. 337103), with its registered office at 8 Harcourt Street, Dublin 2, D02 AF58, Ireland ("Hostelworld", "we", "us"). This Privacy Notice applies specifically to the processing of personal data via the OutThere mobile application and associated services.
What we collect
- Single Sign-On (Apple & Google Sign-In): when you register or log in, we receive an account identifier and profile information, such as your name and primary email or Apple relay address. For support lookups we store a salted hash of the email, rather than the unencrypted address. Apple and Google act as independent data controllers under their own privacy policies.
- Account: how you signed in (Apple, Google or email; for email, your address), your first name, optional photo, interests, favourite artists, profile details and any Instagram or Snapchat username you add. Your artist choices are private.
- Privacy choices and activity: your matching and AI-assisted search choices, the notice version and time of each grant or withdrawal, and when you last used the account, to apply retention periods.
- Plans and connections: the events you save, go to or check in at; your answers to "Did you meet anyone?"; who can see your plans; requests, connections, crews and blocks.
- Messages and moderation: what you write in chats, reports you make or that are made about your content, moderation notices and appeals.
- Search: what you type in Ask and search. AI-assisted search processes your question only if you turn it on.
- Tickets: the whole image you upload is sent to OpenAI to check it. OutThere does not store the uploaded ticket image. We keep the event, date, ticket name and check result, and two one-way codes made with a secret key: one from the ticket's number and one from the uploaded file, so the number itself is never stored. They let us see when one ticket is used for a second account for the same event, which then goes to a person on our team. The name printed on the ticket is not read or kept. When you upload an image of your ticket, OutThere uses a secure third-party AI service provider (OpenAI) to process the image and extract the necessary details. OutThere does not permanently store the raw image on its servers. To ensure platform safety, security, and abuse prevention, our AI service provider retains the uploaded image in a secure, temporary environment for up to 30 days, after which it is automatically and permanently deleted.
- Notifications: only if you allow them. Your phone's push token is removed when you log out or delete your account.
- Location: only when you allow it. Your precise position is used for the requested distance or venue check and is not stored. With Share my night on, it is sent to our server every minute while OutThere is open, until the time you chose, and shown to the friend who has your link. It is deleted when sharing ends.
- Usage analytics: only after you accept: screens, taps, app starts and stops, errors and actions, with your account, a device ID and session ID, and the words of your Ask questions. Analytics never includes messages, photos, precise position or names. Without acceptance, the server keeps only the kind of each request (such as "save an event"), whether it worked, that you had not accepted, and the hour it was made: no account, device, session, event, person or other detail. Reject records one refusal the same way. Change your choice in Profile → Usage data.
- Service metrics: how many requests our server answers, by kind of request, how quickly, and how many fail; the server's own health; totals such as how many people signed up in a minute; and what our AI providers cost. These are counts, without your account, device, IP address or what you sent. When a request fails, we keep the kind of error and where in our code it happened, with the start of its message after quoted values, email addresses and codes are taken out, so we can fix it.
Who else processes it
Trusted providers support hosting, safety, search, email and notifications:
- Railway Corporation (USA/Netherlands): application hosting and database infrastructure, and the service metrics, located in the EU (Amsterdam).
- OpenAI, LLC (USA): automated content moderation, Ask query interpretation, ticket screening and AI-assisted taste interpretation. OpenAI retains abuse-monitoring logs for up to 30 days. We send it Ask questions, artist names and vibes only with AI-assisted search consent. Profile matching itself compares interests, artist tags and plans on our server; an AI model does not receive your whole profile. It also reads totals about how the service is doing (never about a person), to write our team a short summary.
- Resend, Inc.: transactional sign-in codes and reference-only alerts to our moderation team.
- Expo, Apple Inc. and Google LLC: push notification delivery where enabled. Notifications can include the sender's first name and a short message preview.
- Deezer and MusicBrainz: artist lookups for AI-assisted search, through our server; they receive the artist/search words, without your account or device identity.
- Apple, Google and OpenStreetMap: maps and, for Apple and Google, sign-in. Ticket sellers receive your visit if you follow a ticket link. Instagram receives a story only when you share it.
- Support email providers: Cloudflare forwards support mail and Google holds the team's mailbox, including appeals and deletion requests. Manual ticket review uses the check result; we do not ask you to email the ticket image.
Where personal data is transferred outside the EEA to processors in countries without an applicable EU adequacy decision, Hostelworld uses safeguards such as standard contractual clauses approved by the European Commission.
Why we use your data
- Contractual necessity (Article 6(1)(b) GDPR): create and manage your account, facilitate group and direct chats, enable ticket checks, process connection requests and display plans.
- Legitimate interests (Article 6(1)(f) GDPR): safety moderation, restricted reported-content records, enforcing bans, preventing fraudulent sign-ups, defending legal claims, anonymous service counts, and service metrics to run OutThere reliably and securely (Recital 49).
- Your consent (Article 6(1)(a) GDPR): push notifications, live location sharing, optional analytics, event and people matching, and AI-assisted Ask search.
Withdrawal of consent
Each optional feature has its own choice. Matching and AI-assisted search start off, and accepting analytics alone does not enable them. Change either in Profile → Privacy choices, change analytics in Profile → Usage data, stop Share my night in the app, and withdraw notification or location permission in your device settings. Withdrawal does not affect processing lawfully carried out before it. You can also contact dataprotectionofficer@hostelworld.com.
Event and people recommendations
Only with matching consent, we suggest events and potential connections using your selected interests and artists, shared or similar artists and genres, and the line-ups of events you have saved or marked as going to. People matches require both people to opt in. Meet suggestions favour more shared visible plans, then a taste match, more upcoming plans and stronger shared taste; names break remaining ties. Without matching, shared-attendance lists use visible upcoming saved or going events and alphabetical order, without a taste score. Private plans, blocks and connection visibility are respected. For You event suggestions favour genre overlap with your saved or going events; ties favour events with a photo, then the earlier start. Events with people of a similar taste are ordered by the number of visible matching attendees. These are suggestions; they do not determine your eligibility for the service.
AI-assisted search interprets the artists, vibe and filters in your question, then ranks programme events by direct artist appearances, similar artists and musical tags. Date, location, price and availability filters narrow results. Edit Your taste, change the search or filters, or turn the relevant feature off in Privacy choices. Search continues with programme data and simple rules when AI-assisted search is off.
User-generated content and public chat feeds
OutThere provides event chats, crew feeds and direct messaging for social discovery. Event chat content is accessible to other people with access to that event chat; crew content is accessible to its members. Avoid sharing sensitive information such as financial details, home addresses or real-time locations in group feeds. You control direct connections and can block or report users.
Automated screening and decision-making
We use automated algorithms and third-party AI models, including OpenAI, to screen messages, request notes, profile text, first names, meetup titles, times and places, crew names, photos and tickets before or shortly after transmission. High-risk violations are blocked before delivery. Clear violations in reported messages may be removed automatically when a second person reports them too or our automatic message check also flags them; every other report, profile reports included, goes to a human moderator.
Ticket images are checked for the event, its date and time, and basic ticket format: a visible barcode or QR code. The name printed on a ticket is not read. A ticket already used for another account for the same event goes to a person on our team. This does not validate authenticity, access an official ticketing database, or guarantee a valid or unused ticket. A check that doesn't pass says so without naming the rule it missed; after a third, a person on our team looks at it.
Account suspensions, permanent bans and appeals are decided by our human moderation team. Automated strike thresholds flag an account for review rather than suspend it. Automated systems do not permanently terminate accounts.
You have the right not to be subject to solely automated decisions that produce legal or similarly significant effects where Article 22 GDPR applies. If content is blocked or restricted in error, request human review in Profile → Notices or email appeals@hostelworld.com under our internal complaint procedure.
How long we keep your data
- Active accounts: while you use the account. Accounts unused for more than 3 months following major events such as ADE are deleted automatically.
- Account deletion: your profile, photos, check-ins, active direct chats, plans, connections, ticket checks and usage records are removed from active production systems immediately. A phone that already showed your photo may keep its copy for up to a day. Our database copies are scrubbed on deletion; infrastructure backups expire within 30 days.
- Routine chat messages and request notes: deleted on a rolling 60 days basis.
- Reported content: the reported message and limited surrounding context are isolated in a restricted moderation record for 12 months from the report, solely for safety investigations, reviews, appeals and potential legal claims.
- Reports and non-content moderation logs: up to 12 months. Logs record identifiers, dates, rule and action, rather than raw message content.
- Notices and appeals: up to 12 months, or account deletion if earlier.
- Closed accounts: the account record is kept for the six-month appeal window unless you request deletion sooner. After deletion, only a salted hash of the sign-in identity remains on a restricted blocklist until 12 months after closure, then it is deleted.
- Ticket images: not stored by OutThere. OpenAI's temporary abuse-monitoring retention is up to 30 days.
- Share my night location: deleted when sharing ends. Sign-in codes expire after 10 minutes.
- Service metrics and error samples: 90 days, then deleted automatically.
- Usage analytics: deleted by 29 December 2026; Ask question text is removed after 60 days if earlier. Only anonymous readout totals remain. Daily database copies expire within 30 days and are removed by the analytics deadline.
Deleting your account
Use Profile → Delete account or the delete account page. You may also send an erasure request to dataprotectionofficer@hostelworld.com. Requests are handled within 30 days, subject to applicable rights and exceptions.
What stays after deletion
Your group messages can remain visible to other participants until their 60 days are up, permanently disconnected from your profile. System announcements are anonymised to remove your first name, for example "A user left the crew". Reports you made remain for safety purposes with the reporter identity removed.
If your account or messages were reported before deletion, a copy of the relevant thread and reported user's identifier remains in the restricted moderation record for 12 months from the report, under our legitimate safety interests. Non-content audit records remain for up to 12 months. For a permanent ban, the restricted blocklist keeps only a salted sign-in identity hash for 12 months after closure. Appeal closures at appeals@hostelworld.com.
Your rights under data protection law
You have various rights under data protection law in connection with our processing of your personal data. For example, you have the right to request a copy of your personal data that we hold and to request that we correct any errors in the personal data that we hold. These rights are subject to certain exceptions and exemptions.
You have the following rights under data protection law:
- Right to access your personal data - You have the right to request a copy of the personal data that we hold about you, together with other information about our processing of that personal data.
- Right to rectification – You have the right to request that any inaccurate data that is held about you is corrected, or if we have incomplete information you may request that we update the information so that it is complete.
- Right to erasure – You have the right to request us to delete personal data that we hold about you. This is sometimes referred to as the right to be forgotten.
- Right to restriction of processing or to object to processing – You have the right to request that we no longer process your personal data for particular purposes, or to object to our processing of your personal data for particular purposes.
- Right to data portability – You have the right to request us to provide you, or a third party, with a copy of your personal data in a structured, commonly used machine readable format.
To exercise these rights, please contact: dataprotectionofficer@hostelworld.com
Post: Hostelworld.com Limited, 8 Harcourt Street, Dublin 2, D02 AF58, Ireland.
You also have the right to lodge a complaint with the Irish Data Protection Commission ("DPC"), our lead data protection supervisory authority in Europe, or your local data protection supervisory authority, if you are unhappy with our processing of your personal data. Details of how to lodge a complaint with the DPC can be found on the DPC's website. The DPC takes complaints in writing, on its online form, not by phone. For questions, you can call the DPC on +353 1 765 0100.
Contact
For privacy questions, withdrawal and rights requests: dataprotectionofficer@hostelworld.com. Post: Hostelworld.com Limited, 8 Harcourt Street, Dublin 2, D02 AF58, Ireland. For moderation appeals: appeals@hostelworld.com.