Privacy policy

How Outside collects, uses, and protects personal data across our conversational dining platform.

1. Who we are

Outside (“we”, “us”, or “our”) provides conversational ordering, menu, and payment software for hospitality businesses. This privacy policy explains how we collect, use, store, and share personal data when you use tryoutside.app, business.tryoutside.app, our APIs, and related services (together, the “Services”).

Outside acts as a data controller for accounts and platform operations. When a guest orders or chats at a restaurant using Outside, we typically process that guest data as a processor on behalf of the restaurant (the business customer), which decides how guest orders are fulfilled.

2. Personal data we collect

Guest and diner data may include: name, email address, phone number, order and cart details, special instructions, booking details (name, contact details, guest count, date/time, notes), chat messages with the conversational menu, selected allergen preferences used to filter recommendations, budget preferences inferred or stated during chat, favourites, ratings and comments, and opaque guest session tokens used to keep cart and chat continuity.

Customer and staff account data may include: name, email, phone number, encrypted password, business profile details (business name, contact email and phone, branding assets), branch addresses (including geolocation where provided), staff invitation emails, notification preferences (including order updates and marketing flags), and authentication identifiers for supported sign-in methods.

Payment-related data includes order amounts, currency, payment status, and Stripe payment identifiers (such as PaymentIntent IDs and client secrets). We do not store full payment card numbers or CVV on Outside systems. Card and wallet details are collected and processed by Stripe.

Business payout configuration may include bank account details submitted by operators for payouts or onboarding, where that feature is used. Those details are stored separately from guest card checkout.

Technical data includes IP addresses and sign-in metadata for authenticated staff or users where our auth stack records them, device or browser information needed to operate sessions, and application error or diagnostic events when monitoring is enabled.

When a guest opens a live shop, we record a first-party visit for that restaurant. This may include IP address, an approximate city and country derived from that IP, page path, referrer, locale, timezone, and a visitor identifier derived from IP and user agent. We do not ask the browser for GPS location. These records are shown to the restaurant on their dashboard so they can understand guest traffic.

3. How we collect data

We collect data directly when you create an account, invite staff, configure a business, place an order, submit booking details, send chat messages, set allergen filters, or contact us.

We also collect data automatically through session cookies and guest tokens required to operate the Services, first-party shop visit logs described above, and from payment and AI processors when those services return status or recommendation results needed to complete an order or chat response.

4. How we use personal data

We use personal data to: provide conversational menus, carts, kitchen routing, and checkout; authenticate users and staff; maintain guest cart and chat sessions; apply allergen and budget filtering during recommendations; process payments through Stripe Connect; send transactional email such as staff invitations and account-related messages; geocode or store branch addresses; host menu and brand images; show restaurants first-party visit and location metrics on their dashboard; monitor reliability and security; and communicate about the Services you request.

We do not sell personal data.

5. AI processing

Conversational menu features may send guest chat content, selected allergen preferences, and relevant menu context to our AI provider (currently OpenAI) to classify requests and compose recommendations. Product menu text may also be embedded and stored as vectors on our systems to support retrieval.

Do not include unnecessary sensitive personal data in free-text chat or special instructions. Allergen selections are preference filters used to exclude matching menu items; they are not a medical diagnosis and should not be treated as a complete clinical record.

6. Cookies and similar technologies

We use cookies and similar technologies that are required to operate the Services, including: authentication session cookies for signed-in guests and staff (via our auth provider), and client-side guest tokens for cart continuity (`outside_cart_token`) and chat continuity (`outside_chat_token`), typically retained for about 30 days.

Shop visit analytics are first-party and do not add a marketing cookie. Approximate location is inferred from IP on our servers. For more detail see our Cookie Policy.

7. Who we share data with

We share personal data with service providers that help us operate Outside, including: Stripe (payments and Connect onboarding), OpenAI (conversational menu processing), hosting and storage providers (including DigitalOcean for application hosting, databases, and image storage), email delivery (SMTP), mapping/geocoding providers when addresses are used, and optional error-monitoring or tracing tools when configured for a given environment.

Restaurant staff and operators of the venue you order from can access order, booking, and related guest details needed to fulfil service. We may also disclose data if required by law or to protect the rights, safety, and integrity of Outside, our customers, or guests.

8. Multi-tenant isolation

Business data is scoped by business tenancy in our systems so one hospitality brand’s operational data is not available to another brand’s staff under normal operation. Guest carts, chats, and orders are associated with the shop or business context in which they were created.

9. International transfers and retention

Our processors and hosting providers may process data in the United Kingdom, European Economic Area, United States, or other countries where they operate. Where required, we rely on appropriate transfer mechanisms offered by those providers.

We retain personal data for as long as needed to provide the Services, meet legal and accounting obligations, resolve disputes, and enforce agreements. Guest session tokens, chat history, orders, and account records are retained according to operational needs and customer agreements.

10. Security

We use technical and organisational measures designed to protect personal data, including encrypted passwords, token-based authentication, tenant scoping, rate limiting on sensitive endpoints, filtered logging of secrets and payment fields, and payment card handling by Stripe rather than storing card PANs ourselves. No method of transmission or storage is completely secure. See our Security page for a fuller description of our practices.

11. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, to object to certain processing, and to data portability. Guests should usually contact the restaurant they ordered from for order-specific requests; you can also contact us and we will help route the request.

You can update notification preferences where the product exposes them, and you can clear browser cookies or guest tokens to end a local guest session (this may abandon an in-progress cart or chat).

12. Children

The Services are intended for use by hospitality businesses and adult guests. We do not knowingly collect personal data from children for marketing purposes. If you believe a child has provided personal data inappropriately, contact us and we will take appropriate steps.

13. Changes and contact

We may update this privacy policy from time to time. The updated version will be posted on this page with a revised effective date.

Privacy questions or requests: [email protected], or use our Contact page. For security vulnerabilities, see the Security page.

Effective date: 4 August 2026.