Go Out.
Privacy Policy
Effective July 16, 2026 · Last updated July 16, 2026
Go Out is a small Toronto-based team building a nightlife discovery app. This policy explains, in plain language, what we collect, why, and how you stay in control of it.
The short version
We collect your sign-in identity, precise location at the moment you check in, messages, photos you upload, and basic usage/crash data — never more than the app needs to work.
We do not sell your personal information, and we do not share it for third-party advertising.
Your location powers the map and check-ins; friends only ever see a venue pin, never your live GPS.
You can edit any field in your profile, request a full export of your data, or delete your account at any time, all from Settings.
You must be 18 or older to use Go Out.
Questions or requests? Email privacy@gooutapp.site — we aim to reply within a few business days.
1. Who we are and what this covers
Go Out ("Go Out," "we," "us") is the nightlife discovery app at gooutapp.site — live venue activity, friends' plans, and event details for the cities we cover, starting with Toronto. This policy covers the Go Out mobile app, the gooutapp.site marketing site, and anything else that links to it. It does not cover third-party sites or apps we merely link to, like a venue's own website or a Ticketmaster event page.
We operate out of Ontario, Canada, and this policy is written primarily against Canadian privacy law — PIPEDA and Quebec's Law 25 — with GDPR- and CCPA/CPRA-equivalent language included for visitors from the EU, UK, or California. For any of these laws, our privacy team at privacy@gooutapp.site acts as our designated privacy officer.
2. Information we collect
We collect three kinds of information: what you give us directly, what gets created as you use the app, and what is collected automatically by us or the processors listed in Section 5. We do not collect continuous or background location — only what is described below.
Account and identity — your phone number or Apple relay email, username, display name, avatar, and date of birth. You provide these at sign-up, and we keep them until you delete your account.
Precise location — GPS coordinates read at the moment you check in, search, or open the map, with your OS permission. We do not store the coordinate itself: only the venue you checked into is kept, and that record auto-expires after 4 hours.
Social graph and activity — friend connections, check-ins, saved venues and events, and plans you join, created as you use Go Out. Kept until you remove the item or delete your account.
Messages — direct messages you send to friends, kept until you or the recipient delete them, or the account is deleted.
Photos — your avatar and any venue photos you upload, kept until removed or your account is deleted.
Contacts (optional) — SHA-256 hashes of your phone contacts, never names or raw numbers, used only if you turn on contact sync and kept only until you turn it off or delete your account.
Device and diagnostics — device model and OS, push token, crash traces, app-usage events, and IP address, collected automatically by the app and our processors. Operational logs are typically kept for 90 days.
3. How we use your information
We use your information to:
Run the core app — create your account, show you the map and Discover feed, record check-ins, power your friend graph and chat, and remember your saved venues, events, and plans. (Necessary to provide the service you signed up for.)
Keep Go Out safe — detect abuse, enforce our Terms of Service, and act on blocks and reports. (Our legitimate interest in a safe product, balanced against your rights.)
Improve the product — understand which features people use and fix bugs, using PostHog analytics you can turn off at any time. (Your consent, where analytics is enabled.)
Reach you when it matters — push notifications for the categories you have turned on, and essential account or service messages. (Necessary to provide the service, and your notification preferences.)
Meet our legal obligations — respond to lawful requests and keep records the law requires. (Legal obligation.)
We do not use your information to show you ads, and we do not build advertising profiles from it.
4. Location data
Precise location is the most sensitive information Go Out touches, so here is the complete picture.
THE DETAILS
We request your device's precise location so the map can center on you, Discover can sort by distance, and a check-in can record which venue you're at.
We never collect continuous or background location, and we never request "Always" location access — only "While Using".
A check-in stores the venue you tapped, not a coordinate trail, and it auto-closes 4 hours after you check in, or sooner if you tap "Leave" — whichever comes first.
"Share live location with friends" is off by default. Turning it on lets friends see a pin at the venue you have checked into — never your live GPS position, and never anywhere you have not checked in.
Check-ins across everyone at a venue are combined into the live activity level shown on the map (for example, how busy a spot looks right now). This is an aggregate count for the venue, not a list of who is there.
You can turn location off entirely in your device settings. The map will no longer center on you and you will not be able to check in, but the rest of the app keeps working.
Precise location is treated as sensitive personal information under laws like California's CPRA. We only use it for the purposes above; we do not sell it, and we do not share it for cross-context advertising.
5. How we share your information
We share information in three narrow ways:
With other users — your friends see your check-ins and profile according to the visibility you choose, and anyone you message can keep what you send them.
With service providers who run our infrastructure, under contract, and only to operate Go Out — listed below. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
When the law requires it, or to protect rights and safety — for example, responding to a valid legal request or investigating a security incident.
The service providers we rely on:
Supabase — database, authentication, file storage, and realtime updates. Hosts our entire backend under contract and processes nearly all account, content, location, and media data.
Apple — Sign in with Apple, App Store distribution, and push delivery. Processes auth identifiers, your relay email, and your device push token, governed by Apple's own privacy policy.
Expo (EAS) — push notification delivery, processing device push tokens and notification content on US-hosted infrastructure.
Mapbox — map tiles, search, and geocoding, processing the coordinates you search or view on the map, governed by Mapbox's own privacy terms.
PostHog — product analytics, on by default and processing de-identified usage events like screens viewed or features tapped. Turn it off anytime in Settings → Product analytics.
Sentry — crash and error diagnostics, processing error traces and basic device data. Always on, so the app does not silently break.
Ticketmaster — a source of event listings, not a recipient of your data. We only pull event data from them; we never send them yours.
If Go Out is ever acquired by or merged into another company, your information may transfer as part of that deal, under terms at least as protective as this policy.
6. Analytics, crash reporting, and your choices
Product analytics (PostHog) is on by default — our legitimate interest in understanding how Go Out is used — and tracks de-identified events like screens viewed or features tapped, never message content or precise coordinates beyond what a feature needs in the moment. Turn it off anytime in Settings → Product analytics.
"Do not sell or share my data" is off by default because we do not currently sell or share your data for advertising. The toggle exists so you can register your preference in advance, as required under CCPA/CPRA and Quebec's Law 25.
Crash reporting (Sentry) stays on for every account, because a silently-crashing app is worse for everyone; we configure it to scrub obvious personal data from error reports.
7. Push notifications
If you allow notifications, your device receives a push token from Apple and Expo that we use to deliver the categories you have opted into — friend activity, plans, messages, events, and product announcements — each toggleable independently in Settings → Notifications. You can also turn off all push notifications at the OS level at any time.
8. Content you create and its visibility
Messages, your profile, and any photos you upload are content you create. Messages are visible to the people you send them to; profile and check-in visibility follow your privacy settings; a venue photo you upload is visible to anyone browsing that venue. See our Terms of Service for the license you grant us to host and display this content, and for what is not allowed.
9. Data retention and deletion
We keep your information for as long as your account is active, and for the periods described above. When you delete your account (Settings → Delete account), we run a full deletion process.
WHAT HAPPENS WHEN YOU DELETE YOUR ACCOUNT
We permanently delete your friendships, saved venues and events, messages you sent, push tokens, invites, and contact-sync hashes.
We anonymize your profile — your name, username, date of birth, and other identifying fields are scrubbed or replaced — and detach your check-ins from your identity. The check-ins themselves stay, because other people's saved nights out reference them, but they are no longer linked to you.
We retain a small set of records where the law requires it, or where deleting them would break someone else's data: consent records (proof we honored your privacy choices), security and audit logs (typically 90 days), and the other side of any conversation you were part of.
You can edit any field in your profile at any time from Settings → Account (display name, username, avatar, home city); request a full copy of your data at any time from Settings → Export my data, which generates a JSON file covering your profile, check-ins, messages, saved venues and events, plans, friendships, and preferences, and hands it to your device's share sheet; and delete your account at any time from Settings → Delete account. See our account deletion page for the full breakdown of what is deleted, anonymized, or retained, including how to request deletion without opening the app.
10. Your rights
Access and correct — see and fix your information any time in Settings, or ask us directly.
Delete — remove your account and the data described above, at any time, at no cost.
Export — request a portable copy of your data as a JSON file.
Object or restrict — tell us to stop a particular use of your data, such as analytics, using the toggles in Settings, or by emailing us.
Withdraw consent — turn off analytics or contact sync at any time; this does not affect anything already done while consent was active.
California residents additionally have the right to know, delete, and correct their personal information, to opt out of any sale or sharing of it (we do neither), and to limit the use of sensitive personal information such as precise location. We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, use the in-app controls above or email privacy@gooutapp.site. We aim to respond within the time required by applicable law, generally within 30 days.
11. International data transfers
Go Out and our service providers may process your information outside Canada, including in the United States. Where that happens, we rely on our providers' own contractual and technical safeguards to keep your information protected to a standard consistent with this policy, as required by Quebec's Law 25 and, for EU/UK visitors, the GDPR.
12. Security
We use industry-standard safeguards, including encryption in transit, role-based access controls, and database-level policies that limit who and what can read your data, even inside our own systems. No system is perfectly secure and we cannot guarantee absolute security, but we work to keep your information protected and will notify you and any required regulator if a breach puts your information at meaningful risk.
13. Age requirement
Go Out is for people 18 and older. We ask for your date of birth at sign-up and block accounts that indicate you are under 18. We do not knowingly collect personal information from anyone under 18; if we learn that we have, we will delete it.
14. Changes to this policy
We may update this policy as Go Out changes. We will update the "Last updated" date above, and for material changes, tell you in the app at least 30 days before they take effect. Continuing to use Go Out after that means you accept the update.
15. Questions and complaints
Questions, requests, or concerns about this policy or your data — email our privacy team below. If you are in Canada and are not satisfied with our response, you can complain to the Office of the Privacy Commissioner of Canada, or to Quebec's Commission d'accès à l'information if you are a Quebec resident. If you are in the EU or UK, you can complain to your local data protection authority.
privacy@gooutapp.site