Privacy Policy
Last updated: September 27, 2026
Outside Eats LLC, doing business as Outside Eats ("Outside Eats," "we," "us," or "our), operates the Outside Eats website, the Outside Eats mobile apps for iOS and Android, and related services (collectively, the "Services"). The Services help people discover restaurants, farmers markets, events, openings, awards, maps, photos, and videos on and around the San Francisco Peninsula.
This Privacy Policy explains what information we collect, how we use and disclose it, how long we keep it, and the choices available to you. It applies to information collected through https://outside-eats.com, the Outside Eats apps for iOS (App Store) and Android (Google Play), mobile APIs, and related communications.
Information we collect
We collect information from you, your device, service providers, and your use of the Services.
Account and authentication information
When you create or use an account, we may collect:
- email address and password-related account information when you use email login;
- name, email address, profile information, and account identifiers provided through Apple or Google sign-in;
- authentication tokens, session information, device name, operating-system version, app version, and build information used to authenticate, secure, troubleshoot, and support the Services; and
- account preferences, notification preferences, and account status.
We do not receive your Apple or Google password. Passwords created for Outside Eats are stored as one-way password hashes rather than in readable form.
Profile and user-submitted information
If you choose to complete a profile, we may collect your display name, nickname, persona, headline, “About me” text, profile photo, home city, friend count, and related profile settings. If you have not added a profile photo, we assign you one of our illustrated stock avatars, and you can pick a different one or upload your own. If you sign in with Google, we may store a copy of the profile photo Google provides so it can be shown as your profile photo. Your home city is private: it is shown only to you and is never part of your public profile. Other public profile fields may be visible to other users as described in the app.
If you post a comment, report, block request, support request, or other content, we collect the content and the information needed to process, display, moderate, secure, and respond to it. Comments may be publicly visible with your display name and, if configured, profile photo.
Do not place an address, phone number, government identifier, financial information, health information, or other sensitive information in a public profile, comment, invitation, or other content.
Favorites, trophies, and social connections
We collect and store saved restaurants, farmers markets, and videos associated with your account. We may also store trophy achievements, counters, activity history, friend requests, accepted or removed friend connections, the members you follow and the members who follow you, and related privacy settings.
Your Bookmarks (your saved restaurants, farmers markets, and videos) are shared through the “Share my bookmarks” setting, which is on by default. While it is on, any signed-in member can see your Bookmarks on your profile and can follow you, and your display name, profile photo, and the number of places you have saved may be shown to anyone using the app, signed in or not, in member discovery features such as Local Foodies on Explore. You can turn “Share my bookmarks” off at any time in Settings. While it is off, your Bookmarks are hidden from other members except friends you have accepted, and you are not shown in member discovery. Public profile information and friend counts may be visible to other users.
When the friends feature is available, you may provide another person’s email address to send an invitation or identify an account. We use that address to process the invitation, send a service message, prevent abuse, maintain the connection, and honor suppression or opt-out requests. Please provide an email address only when you have a lawful basis and appropriate permission to do so. Do not upload address books, harvest addresses, or repeatedly invite a person who has declined.
Location information
With your permission, the app requests one-time, in-use device location. You may deny it, or later revoke it, in your device’s system settings (iOS Settings or Android Settings); the features below simply stop working without it. We never ask for background or “Always” location, and the app does not follow you while it is closed.
Restaurants Near Me. Coordinates used to sort nearby restaurants and calculate distance are used on the device and are not sent to Outside Eats’ servers for that feature.
Outside Eats Passport check-ins. When you check in at a restaurant with the Passport, the app does send your coordinates and their accuracy to our servers: a check-in only counts if you are actually at the restaurant. We keep a record of each check-in — the restaurant, the date and time, and the points awarded — for as long as you hold the account, so that your Passport, your stamps and your standing keep working and so that we can review disputed or fraudulent check-ins. Inside the app, your individual check-ins and their timestamps are visible only to you and to friends whose requests you have accepted; they are never public. A campaign leaderboard shows your display name, profile photo, points and stamp count — not the individual places you visited or when. Each campaign’s Official Rules, published with the campaign, describe the rest.
Passport photos. A photo of your meal is optional and never affects your score. A photo you add is held for review: until an Outside Eats reviewer approves it, it is shown to nobody but you. Once approved it appears on your own stamp to friends whose requests you have accepted — it is never made public, and it is never used to promote anything. A photo a reviewer denies is deleted from our storage and never shown to anyone. You can replace your photo, and deleting your account deletes them all.
Deleting your account deletes your Passport history with it, including every check-in record and any photos attached to them.
Photos, calendar, and device permissions
If you choose to use the related feature, the app may request access to:
- your camera or photo library to select or capture a profile photo, or a photo of what you ordered when you check in with the Passport — that photo is optional and is never required to earn a stamp;
- your calendar to add an event that you expressly choose to add; and
- notifications to send account, invitation, moderation, or service-related messages and, if enabled, other app notifications.
The app does not receive access to these features merely because the permission exists. iOS and Android control the permission request, and you may change any of them later in device settings.
Push notifications
If you turn notifications on, the app registers with Apple’s and Google’s push services and receives a push token, which we store against your account so that we can send you the notification. On both platforms the token is issued by Firebase Cloud Messaging, a Google service. You can turn notifications off in the app’s Account settings, or in your device settings, at any time; nothing in the app requires them.
Video and usage information
The app records video-play activity so we can provide video features, synchronize account activity, award trophies, measure engagement, prevent abuse, and improve the Services. Depending on how you use the app, this may include:
- video identifier, start time, watched duration, video duration, completion status, loop count, and source;
- session identifier and device identifier;
- app, operating-system, and device information; and
- an account identifier when you are signed in.
Guest activity may be recorded with device and session identifiers without being associated with a named account. We do not use this information to serve targeted advertising.
Sponsored placements. The video feed carries occasional sponsored slides, labelled “Sponsored,” promoting a restaurant or a feature on Outside Eats. Outside Eats sells and serves them itself: there is no third-party advertising network in the app, no advertising identifier (Apple’s IDFA or the Android Advertising ID) is requested or used, and nothing about you is shared with a sponsor. We count how often a sponsored slide was shown and how often its button was tapped, recorded alongside the video-play information above, so that we can report to the sponsor and decide what to run next. We do not use it to serve targeted advertising or to track you across other apps or websites.
Information stored on your device
The app stores certain information locally so it can launch quickly, remember your choices, and function during temporary network interruptions. Depending on your use, local storage may include:
- cached restaurant, market, event, opening, award, and video content;
- cached account profile and Favorites information;
- trophy and activity state;
- profile-image cache and app preferences; and
- an account session token, held in the iOS Keychain or, on Android, in encrypted device storage.
Local storage is controlled by your device. Deleting the app, clearing app data where supported, signing out, or using the app’s account controls may remove some local information, but server-side information is governed by this Policy and our deletion procedures.
Website cookies and analytics
The website stores necessary preferences in your browser, including search or city filters, maps-provider preference, saved restaurants or markets when you are not signed in, and your analytics consent choice.
The website uses Google Analytics only after you affirmatively opt in through the website analytics notice. If you decline or ignore the notice, Google Analytics is not loaded. When enabled, Google Analytics may collect information such as pages viewed, search terms, device/browser information, approximate location derived by the provider, and online identifiers. It is used to understand website usage and improve the Services, not to serve targeted advertising. Review Google’s privacy materials for its independent processing practices.
The app’s video-play measurement is separate from the website’s optional Google Analytics and is described above. The iOS and Android apps do not load Google Analytics.
Technical and communications information
When you access the Services, we and our service providers may receive IP address, browser or device type, operating system, app version, language, timestamps, referring or exit pages, crash or diagnostic information, and security or fraud signals. We use this information to deliver content, maintain security, diagnose failures, prevent abuse, and operate the Services.
How we use information
We use information to:
- provide, authenticate, personalize, maintain, and secure the Services;
- synchronize accounts, Favorites, profiles, trophies, and friend connections;
- display public profiles, comments, and other content as configured by the feature;
- process friend invitations and send account, security, invitation, moderation, and service communications;
- provide nearby-restaurants, map, directions, event-calendar, video, and sharing features;
- store, optimize, display, and deliver profile photos and other permitted content;
- measure video and website usage, troubleshoot problems, improve features, and understand aggregate trends;
- filter, investigate, respond to, and enforce rules concerning reports, blocks, comments, invitations, and other abuse;
- detect, prevent, and investigate fraud, spam, unauthorized access, security incidents, and unlawful activity;
- comply with legal obligations, respond to lawful requests, protect rights and safety, and enforce our agreements; and
- perform other purposes disclosed at the time information is collected or with your direction.
Apart from the Passport check-in history described above — which exists because you asked us to stamp your Passport at a named restaurant — we do not use device location to build a location history, and we do not collect location at all while the app is closed.
How we disclose information
We do not sell personal information. We do not share personal information with third parties for cross-context behavioral advertising or targeted advertising.
We may disclose information in the following circumstances:
Service providers and infrastructure
We disclose information to vendors that process it on our behalf to host databases, operate APIs, store and deliver media, send email, provide security and monitoring, process analytics, support authentication, and maintain the Services. Current infrastructure includes Amazon Web Services; Cloudflare and Cloudflare R2; Google (Firebase Cloud Messaging, which delivers push notifications to the iOS and Android apps and assigns your installation of the app a push token and an installation identifier); Brevo (transactional email); and other vendors that may change over time. Vendors may process information only for authorized business purposes under appropriate contractual restrictions.
Authentication and integrated services
If you choose Apple or Google sign-in, we exchange information with the selected provider as needed to authenticate your account. If you open directions, watch third-party video, view map content, use sharing, or follow an external link, Apple Maps, Google Maps, YouTube, OpenStreetMap, the relevant social/share service, or another provider may receive information directly from your device. Their own policies govern their processing.
Other users and public content
Public profile fields and comments may be visible to other users. Your Bookmarks are visible to other signed-in members while “Share my bookmarks” is on, and to friends you have accepted while it is off, as described above. Reports and blocks may be shared internally with reviewers or disclosed when reasonably necessary to investigate abuse, protect safety, or comply with law.
Legal, safety, and business transactions
We may disclose information when reasonably necessary to comply with law, legal process, or government requests; enforce our agreements; protect users, the public, or our rights; investigate fraud or security incidents; or support a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets.
Data retention
We retain information only for as long as reasonably necessary for the purposes described in this Policy, including:
- account information while your account is active and for a reasonable period afterward for security, fraud prevention, legal compliance, and dispute handling;
- profile content, comments, Favorites, and friend records until you delete them, remove them, close your account, or we remove them under our rules, subject to backup, legal, safety, and enforcement needs;
- friend-invitation email addresses and suppression records long enough to deliver invitations, prevent repeated unwanted invitations, honor opt-outs, investigate abuse, and comply with law;
- video-play and website analytics for the period needed to provide metrics, improve the Services, maintain auditability, and produce aggregate reporting; and
- logs, backups, security records, and support records for periods appropriate to security, reliability, legal, and operational needs.
When information is no longer reasonably necessary, we delete it, de-identify it, or aggregate it. Deleted information may remain temporarily in backups or be retained when necessary for legal claims, security, fraud prevention, or safety.
Your choices
You may:
- decline or revoke location, camera, photo-library, calendar, or notification permissions through your device’s system settings (iOS Settings or Android Settings);
- decline website Google Analytics or clear your browser’s site data to reset the choice;
- edit profile information through account settings;
- turn “Share my bookmarks” off in Settings to keep your Bookmarks from other members (except friends you have accepted) and out of member discovery;
- remove Favorites, comments, friends, follows, or invitations where the feature provides those controls;
- block users and report users, comments, profiles, invitations, or other content through available in-app tools;
- sign out or delete your account through the app’s account controls; and
- unsubscribe from optional marketing messages. Transactional, security, account, invitation, and moderation messages may still be sent when necessary to provide the Services.
California privacy rights
California privacy law may provide additional rights depending on whether Outside Eats is subject to the applicable thresholds and requirements. Subject to legal exceptions, California residents may have rights to know about personal information collected, used, disclosed, or sold; request deletion; correct inaccurate information; limit certain uses or disclosures of sensitive personal information; opt out of sale or sharing; and receive equal treatment for exercising privacy rights.
We do not sell personal information or share it for targeted advertising. If our practices change, we will provide any required opt-out mechanism, including recognition of applicable browser-based signals.
To submit a privacy request, email info@outside-eats.com with the subject “California Privacy Request” or write to:
Outside Eats LLC
1259 El Camino Real
Unit #1145
Menlo Park, CA 94025
We may need to verify your identity before completing a request. We will use information submitted for verification only as reasonably necessary to process the request. You may use an authorized agent where permitted by law. We will not discriminate against you for exercising applicable privacy rights.
Children’s privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information, we will take reasonable steps to delete it. Contact us at info@outside-eats.com if you believe this has occurred.
Security
We use reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information, including encrypted transmission, access controls, protected credential storage, and security monitoring. No method of transmission, storage, or processing is completely secure, and we cannot guarantee absolute security.
Third-party sites and services
The Services may link to or integrate with third-party sites, maps, video hosts, authentication providers, social platforms, restaurants, event organizers, and other services. We do not control their privacy practices. Review their policies before providing information or using their services.
Changes to this Policy
We may update this Policy from time to time. We will post the revised Policy and update the “Last updated” date. If a change is material, we may provide additional notice through the Services, by email, or by another legally appropriate method.
Contact
Questions, privacy requests, and concerns may be sent to:
Outside Eats LLC
1259 El Camino Real
Unit #1145
Menlo Park, CA 94025
info@outside-eats.com
