Privacy Policy
WhatsOutsyde
Last updated: 27 August 2026
1. Who we are
WhatsOutsyde (“we”, “us”, “our”) is a map-first platform that helps people discover places, events, and experiences in Jamaica and connect with local operators, guides, drivers, and businesses.
For the Jamaica Data Protection Act, 2020 and, where they apply, UK/EU data-protection law, WhatsOutsyde is the data controller of personal data described in this policy. We are based in Jamaica. A Jamaican-qualified lawyer has not yet signed this policy; it describes how the live product actually stores data today.
Privacy contact: jasonhinds1977@gmail.com
2. Information we collect
We collect only what the product needs. Data lives in our Postgres database (Supabase), in files you upload (Storage), in short-lived security logs, and — on your device — in cookies and local storage. We do not run a separate advertising profile.
We collect:
- Account: email, password hash (held by our auth provider — we never store your password in plain text), Google or Apple sign-in identifiers if you use them, display name, avatar, role (visitor, operator, guide, or business), optional group fitness, language choice, rewards points, and (for hosts) membership fields
- Guest booking contact: name, email or phone you type, dates, party size, and notes — even if you have no account. Guests must confirm an email with a one-time code before we accept a booking request
- Bookings and enquiries: listing snapshot, status (pending, confirmed, declined, cancelled, completed), book mode (request or instant), payment status (unpaid or pay-the-operator; we do not take a card for experiences yet), operator notes
- Trips and saves: named trip plans, stop coordinates, time of day, notes, shared-link token, saved places, and saved addresses (including Mapbox place ids)
- Reviews: star rating, optional comment and photo, only after you have booked or enquired through the app
- Live events: RSVPs, clips you upload, likes/shares
- Guides, transfers, packages: tour-request and transfer-request details, package enquiries
- Messages: contact form, incident reports (the operator is not told you reported them from that form), privacy requests
- Marketing opt-in: newsletter email if you subscribe; business-follower email if you follow a venue
- Usage counters: listing views, WhatsApp taps, trip-adds (counts, not a marketing dossier)
- Location: stay town you pick, optional “use my location”, precise coordinates you save on trips/transfers (see below)
- Technical and security: IP address, request metadata, TLS handshake fingerprints supplied by the CDN (JA3/JA4 — not invented from your User-Agent), login lockouts, and hashed one-time codes
Location and maps. Stay town and “use my location” are approximate, to show what is nearby and estimate drive times. Saved places, trip stops, and transfer destinations store the coordinates and any address you enter so directions and a driver can work. Saved places and trips are visible only to you (and to people you share a trip link with). We do not sell location data or use it for advertising.
Maps and search. Search terms and coordinates needed for a map or route go to Mapbox, outside Jamaica. We send only what that request needs.
Airport transfers. Nearby transport partners are alerted to a general area and party size. Your exact drop-off and contact stay with WhatsOutsyde until we connect you with a driver.
One-time email codes. For guest bookings (and for changing a password while signed in) we email a 6-digit code. We store a hash of that code against your email and purpose — not the code itself. Codes expire in about 10 minutes; too many wrong guesses locks that check. Signed-in users skip the booking code.
On your device. Essential cookies keep you signed in and stop cross-site request forgery (`trod_csrf` plus our auth cookies). Local storage remembers language, stay town, fitness, cookie choice, and similar first-open flags. Analytics and Google Translate run only after you opt in.
3. How we use your information
We use your information to:
- Run the map, account, bookings, trips, events, and host tools
- Pass a booking or enquiry to the operator and email you a confirmation when we have an address
- Prove a guest email with a one-time code before a request is stored
- Show in-app notifications and reminders about your bookings
- Keep the service secure (rate limits, lockouts, TLS fingerprints, abuse logs)
- Process host membership payments through Stripe if you buy a plan — we do not store full card numbers, and experience bookings are still paid to the operator directly
- Send transactional email (codes, booking notices). Newsletter and venue follow-mail only if you asked
- Improve the product using coarse usage counts, not advertising profiles
4. Legal bases for processing
Under the Jamaica Data Protection Act, 2020 we process personal data fairly, for specified purposes, only as much as needed, and with appropriate security. Where UK or EU/EEA law also applies, we use these legal bases:
- Contract: creating an account, processing a booking or RSVP, sending the codes and notices that booking needs, providing trips and host tools you asked for
- Legitimate interests: security and abuse prevention (IP, TLS fingerprint, lockouts), showing nearby places from the stay you picked, and limited product understanding. You can object (see rights below)
- Consent: non-essential cookies (translation / analytics), optional device location, newsletter, and following a venue. You can withdraw in Cookie settings or by unsubscribing
- Legal obligation: tax or lawful requests; host membership records if Stripe is used
5. How we share information
We do not sell your personal information.
We may share information with:
- The operator, guide, or driver on a booking, tour request, or transfer — name, contact, dates, party, notes you typed
- Anyone you share a trip link with (the plan you chose to share)
- Service providers listed below, only to run the feature that needs them
- Authorities if required by law
The processors we actually use today:
- Supabase — accounts, Postgres (including bookings, trips, OTP hashes, security events), and file storage. Row-level security limits what a signed-in browser can read
- Vercel — hosts the website and serverless APIs
- Mapbox — maps, geocoding, directions
- Resend — transactional email (password codes, booking codes, booking notices, contact form)
- Stripe — host membership only, if you pay. Not used for experience checkout today
- Google or Apple — only if you sign in with them
- Google Translate — only after you opt in to non-essential cookies
- Anthropic (Claude) — optional AI concierge / trip draft. Only the text you type is sent; we do not send your name, email, or booking contact. Under the provider’s API terms, that text is not used to train their models
We do not currently run a separate advertising or marketing-cookie product. Analytics cookies stay off until you turn them on in Cookie settings.
6. International data transfers
We are based in Jamaica. Hosting, database, maps, email, sign-in, payments, and AI may process data in the United States, the UK, the EU, or other countries.
For Jamaica DPA transfers we rely on those providers’ contractual and security safeguards. Where UK or EEA law applies we also rely on Standard Contractual Clauses or an adequacy decision where one exists. Counsel should still confirm these transfer tools.
7. How long we keep data
We keep personal data only as long as we need it:
- Account and profile: while the account is open. Delete my account removes the login, profile, listings you created, events, guide profile, gift claims, and uploaded listing photos. Bookings you made are anonymised (name and contact cleared, unlinked from your user id) so an operator can still see that a slot was requested — not your identity
- Guest bookings and enquiries: while needed to complete the request, then typically up to 24 months for questions or disputes
- One-time codes: hash stored until it expires (about 10 minutes) or is overwritten; not used for marketing
- Security events and lockouts: typically up to 90 days, longer only to investigate abuse
- Saved places, saved addresses, and trip plans: in your account until you delete them or the account. Inactive precise-location rows may be purged after 24 months
- Reviews: while the listing remains, or until we remove them for policy reasons
- Payment records (membership): as tax and Stripe rules require
- Newsletter / followers: until you unsubscribe or we delete the account
- On your device: cookie choice and first-open flags until you clear site data
Backups may hold a copy for a short time after deletion, then they expire.
8. Your rights under GDPR
Jamaica’s Data Protection Act gives you rights to fair processing, access, correction, and to complain to the Office of the Information Commissioner. If UK or EU/EEA data protection law applies to you, you also have the following rights:
- Right of access — ask for a copy of the personal data we hold about you
- Right to rectification — ask us to correct inaccurate or incomplete data. You can also update your name and photo in Account
- Right to erasure (“right to be forgotten”) — ask us to delete your data. You can delete your account in Account → Delete my account. Some anonymised booking rows may remain for the operator’s records
- Right to restrict processing — ask us to limit how we use your data in certain cases
- Right to data portability — ask for a copy of data you provided to us, in a common format
- Right to object — object to processing based on legitimate interests, including limited analytics and security profiling such as rate-limits
- Rights related to automated decision-making — we do not use solely automated decisions that have legal or similarly significant effects on you. Map ranking, rate limits, and review gates are not that kind of decision
- Right to withdraw consent — where we rely on consent (for example non-essential cookies), you can change that in Account → Cookie settings
These rights are not always absolute. We will explain if we cannot fully meet a request, and why.
9. How to exercise your rights
You can:
- Update your account details in the app (Account)
- Delete your account in the app (Account → Delete my account)
- Send a privacy request in the app (Account → Privacy request) — access, correction, or a question
- Manage cookies (Account → Cookie settings, or Cookie settings on this page)
- Email us at jasonhinds1977@gmail.com
Please tell us which right you want to use and enough detail for us to find your account or guest booking (usually the email you used). We may need to confirm it is you. We aim to reply within one month.
10. Cookies and similar technologies
We use essential cookies and similar technologies to keep you signed in and to make the app work. Analytics cookies stay off until you Accept all or turn Analytics on in Cookie settings.
Essential (always): login/session cookies from our auth provider; the CSRF cookie (`trod_csrf`); first-open choices stored on the device. Non-essential (only after opt-in): Google Translate and any future basic analytics. We do not use marketing cookies today.
11. Children’s privacy
The app is not intended for children under 16. Host (operator, guide, business) accounts are for adults 18 and over. We do not knowingly collect personal information from children.
12. Complaints
If you are unhappy with how we use your data, please contact us first at jasonhinds1977@gmail.com so we can try to put it right.
You also have the right to lodge a complaint with a supervisory authority. In Jamaica that is the Office of the Information Commissioner. In the EU/EEA it is the data protection authority in your country. In the UK it is the Information Commissioner’s Office (ico.org.uk).
13. AI features
Some optional features use artificial intelligence to help you — the AI trip-planner and the “Ask WhatsOutsyde” concierge. These are clearly labelled as AI features when you use them.
When you use them, the text of the request you type is sent to our AI provider (Anthropic) to generate a response. We do not send your name, email, or account details, and under our provider’s API terms your request is not used to train their models. AI responses are generated automatically and can be inaccurate or incomplete, so please confirm important details (prices, times, safety, availability) with the operator before relying on them.
We do not use AI to make decisions that have a legal or similarly significant effect on you. Using the AI features is entirely optional.
14. Changes
We may update this Privacy Policy from time to time. The updated version will be posted in the app with a new “Last updated” date.
15. Contact
For privacy questions or requests: jasonhinds1977@gmail.com
In the app: Account → Privacy request, or Account → Delete my account.