* LEGAL / 002

PRIVACY POLICY

LAST UPDATED: JULY 18, 2026

01

WHAT WE COLLECT

ARTISTS — name, email, artist name, slug, social links, Stripe Connect account ID.

EVENT DATA — titles, dates, venues, flyer images.

TRANSACTION DATA — ticket purchases, amounts, Stripe payment intent IDs.

FAN DATA — name and email of ticket buyers, linked to the purchasing artist.

TECHNICAL DATA — OUTSYDE automatically receives limited technical information needed to operate and secure the platform, such as IP address, browser type, device information, and server logs. This is not used for behavioral tracking.

We do not collect payment card numbers — these go directly to Stripe.

02

HOW WE USE IT

To operate the platform: create accounts, process payments, send ticket confirmations.

To send transactional emails: ticket QR codes, presale notifications, event reminders.

We also use data to maintain platform security, prevent fraud, and comply with legal obligations.

We do not use your data for advertising. OUTSYDE products are ad-free.

03

WHO WE SHARE IT WITH

STRIPE — payment processing and artist payouts. We share transaction data required for Stripe Connect to function.

RESEND — transactional email delivery. We share recipient email and ticket details required to send confirmation emails.

SUPABASE — our database infrastructure. Data is stored on Supabase servers.

Because our service providers operate infrastructure in multiple locations, your information may be processed in countries other than your own.

We do not sell data to any third party. Ever.

04

FAN DATA AND ARTIST RESPONSIBILITY

Artists receive the attendee information collected through their event's ticket purchases and access it through their OUTSYDE dashboard. Artists use that information to manage their events and communicate with attendees.

Artists remain responsible for handling fan data in compliance with applicable privacy laws (CAN-SPAM, GDPR, etc). OUTSYDE provides the tools — the artist is the data controller for their fans.

05

DATA RETENTION

ACTIVE — data retained while account is active.

DELETED — artist profile and event data deleted within 30 days.

Transaction records retained for 7 years for legal and tax compliance. Fan purchase records retained per artist request up to 3 years.

Certain information may be retained longer where necessary to comply with legal obligations, prevent fraud, resolve disputes, or enforce our agreements.

06

YOUR RIGHTS

You can request a copy of your data at any time.

You can request deletion of your account and associated data.

You can request correction of inaccurate data, and, where applicable, an export of your data in a portable format.

EU/UK residents have additional rights under GDPR — contact us at legal@outsydeapp.com.

California residents have rights under CCPA — contact us at legal@outsydeapp.com.

07

CHILDREN'S PRIVACY

OUTSYDE is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If we learn we've collected data from a child under 13, we'll delete it.

08

COOKIES

OUTSYDE uses only essential cookies — for authentication, account sessions, security, and fraud prevention. No tracking cookies. No advertising pixels. No third-party analytics.

09

SECURITY

Data is encrypted in transit (TLS) and at rest (Supabase AES-256).

Access to production systems and personal data is limited to authorized personnel with a legitimate business need.

We recommend artists use strong unique passwords and enable 2FA on their email accounts.

10

EMAIL COMMUNICATIONS

Transactional emails — ticket confirmations, event reminders, receipts, and security notices — are necessary to use OUTSYDE and can't be turned off while your account is active. If we introduce marketing emails in the future, you'll be able to unsubscribe from those at any time.

11

CONTACT

Privacy questions or data requests — legal@outsydeapp.com.