Outzone Sagl ("Outzone", "we", "us") operates the Outzone mobile app and website, a platform for event discovery, ticketing and light social features. This Policy explains what personal data we process when you use Outzone, why, who we share it with, and what rights you have. We process your data in accordance with the Swiss Federal Act on Data Protection (revFADP/nFADP, in force since 01.09.2023) and its Ordinance (OPDa) and, where applicable to users in the European Union/EEA, the General Data Protection Regulation (EU) 2016/679 (GDPR).
If there is any divergence between the Italian and English versions of this Policy, the Italian version prevails.
1. Data controller
The controller of your personal data is:
Outzone Sagl Via Grumo 31, 6929 Gravesano, Ticino, Switzerland Registered with the Commercial Register of the Canton of Ticino · CHE-251.077.155 Managers: Jornod Jeremy and Bovino Simone
For any matter — personal data, exercising your rights, this Policy, support or ticketing — write to us at info@outzone.app. Website: www.outzone.app.
We are not legally required to appoint a Data Protection Officer (DPO).
2. Categories of personal data we process
2.1 Data you provide directly
- Account data: username, email address and/or phone number, password (stored only in hashed form with bcrypt, never in clear text), date of birth (to verify age and apply protections for minors).
- Profile data (optional): first and last name, gender, profile photo, bio, country, preferred language, links to public social profiles (e.g. Instagram, TikTok, X, Facebook) that you choose to connect.
- Settings: account visibility level, notification preferences.
- Content you post: posts, comments, reactions, tags, saved or hidden events, event RSVPs and reviews.
- Purchases and reports: your ticket purchase history; any report or complaint about a purchase, which may contain free text you enter (and therefore, at your choice, personal data).
- Communications: messages you send us by email for support.
Outzone does not yet offer chat or private messaging (DMs): this feature is under development and not yet active. For now, your "content" is posts, comments, reactions, tags and reviews, shown according to your visibility settings. When messaging is introduced, we will update this Policy and the related data categories and retention periods.
2.2 Data collected automatically (device, session and diagnostics)
When you use Outzone we automatically collect, per session:
- Device and session data: device identifier (device_id), platform (iOS/Android/web), app and operating-system version, user-agent, and IP address. The IP address is stored in non-anonymized form (linked to your sessions in the refresh tokens) because it is needed for security, authentication and abuse prevention.
- Event interactions on the website (consent only): event-detail views, successful shares, map openings and entry into the purchase flow, together with event_id, date/time, a random pseudonymous identifier and a session identifier. These actions remain pseudonymous even when you are signed in and are not linked to your account. They are not collected if you reject statistics technologies and are not used for advertising or cross-site tracking.
- Event interactions in the mobile app (authenticated users only): event-detail views, successful shares, openings of the participant list or map and entry into the purchase flow, together with event_id, date/time and session. The app does not record these actions for users who are not authenticated. The backend verifies the account in transit to authorize the request and limit abuse, but the analytics journal stores only random pseudonymous delivery and session identifiers: it does not store
user_idor link these interactions to the account. - Functional actions recorded by the server: the same
event_actionstable may contain separate rows for saves, attendance, linked posts and completed purchases. These rows are not pseudonymous client-measurement interactions and may retainuser_idbecause they document operations requested by the user; they remain subject to the purposes and retention periods stated in this Policy. - Sign-in provider identifiers (OAuth): if you sign in with Google or Apple, we receive a stable identifier supplied by the provider (the "sub" claim) and, if you authorize it, your email address.
- Diagnostics and error data: through Sentry we collect crash and error reports (e.g. app state, error type, technical context) to detect and fix malfunctions.
- Proof of consent: the date and time you accepted this Policy (gdpr_consented_at).
Outzone does not use advertising identifiers (IDFA on iOS, AAID on Android), nor Google Analytics, Meta Pixel, Google Ads or any other ad-tracking technology. The app uses no cookies and does not track you across third-party apps or sites.
2.3 Inferred or generated data
- Feed recommendations (profiling): we generate a personalized feed based on your follows, saves, attendance, interests and an approximate location inferred from the events you attend (see section 6).
- Organizer analytics: from attendance and purchase data we generate aggregate statistics (e.g. age ranges and gender) that we make available to organizers only in anonymized form (k=5 threshold): no category is shown if it is based on fewer than 5 people.
3. Purposes and legal bases
The table below maps each purpose to its GDPR legal basis (Art. 6/9) and to the corresponding position under the FADP. For private controllers the FADP treats processing as lawful in principle and requires a justification (consent, overriding interest or law) only where the processing would otherwise breach the data subject's personality (Art. 30–31 FADP); stating a GDPR basis for each purpose satisfies both laws.
| Purpose | GDPR legal basis | FADP position |
|---|---|---|
| Account creation and management, authentication (incl. Google/Apple sign-in) | Art. 6(1)(b) – contract | Lawful (contract performance, Art. 31(2)(a)) |
| Ticket purchase, delivery and validity | Art. 6(1)(b) – contract | Lawful (contract) |
| Payment processing, fraud prevention and anti-money-laundering (via Stripe) | Art. 6(1)(b) contract + 6(1)(c) legal obligation (AML) + 6(1)(f) legitimate interest (fraud) | Lawful (contract + legal duty) |
| Transactional emails (receipts, notices) and OTP codes via email/WhatsApp | Art. 6(1)(b) – contract | Lawful (contract) |
| Customer support, handling of complaints, disputes and chargebacks | Art. 6(1)(b) contract + 6(1)(f) legitimate interest | Lawful (contract + overriding interest) |
| Security, abuse prevention, audit logging and diagnostics | Art. 6(1)(f) – legitimate interest | Overriding interest (Art. 31) |
| Retention of financial and ticketing records for accounting/tax obligations | Art. 6(1)(c) – legal obligation | Law (Art. 31) |
| Social features (posts, comments, reactions, tags, reviews) and profile visibility | Art. 6(1)(b) contract + 6(1)(f) legitimate interest | Lawful (contract / overriding interest) |
| Personalized recommendation feed (profiling, see sec. 6) | Art. 6(1)(f) – legitimate interest | Overriding interest |
| Pseudonymous collection of event interactions on the website | Art. 6(1)(a) – consent | Consent |
| Pseudonymous collection of event interactions in the app, with authentication required, for aggregate analytics and service improvement | Art. 6(1)(f) – legitimate interest | Overriding interest / statistical purposes (Art. 31(2)) |
| Aggregate analytics and service improvement (non-personal/anonymized) | Art. 6(1)(f) – legitimate interest | Overriding interest / statistical purposes (Art. 31(2)) |
| Event import from public content of Instagram business accounts | Art. 6(1)(f) – legitimate interest (public business content, not buyer data) | Overriding interest / publicly available data |
| Service notifications (push) and email receipts | Art. 6(1)(f) legitimate interest, with opt-out | Overriding interest |
| Transfer to US processors for the above purposes | Basis above + Art. 46 GDPR safeguard (DPF/SCCs) | DPF adequacy (Art. 16) or SCCs (Art. 16(2)) |
Providing data marked as mandatory (e.g. email/phone, password, date of birth to create an account; identity to buy a ticket) is necessary to use the service: without it we cannot create your account or complete the purchase.
4. Recipients of data
We carefully distinguish between processors (providers that process data only on our behalf and on our instructions, under Art. 9 FADP / Art. 28 GDPR) and independent controllers (parties that determine their own purposes and means and are accountable under their own privacy policy).
4.1 Event organizers — independent controllers
Each organizer receives the data needed to run its event and admit attendees, and is an independent controller for those purposes. Payment-data visibility depends on the model shown at checkout:
- Organizer sale: the charge is associated with the organizer's Stripe Connect account. The organizer is the seller and merchant of record and receives payment-linked identification data from Stripe, including the buyer's name.
- Outzone-managed sale: Outzone Sagl is the seller and merchant of record and processes purchase, payment, refund and dispute data. The organizer has no Stripe account connected for that event and receives no payment data from Stripe; it still receives from the Platform only the data needed to run the event and admit the attendee.
Outzone and organizers are independent controllers, each for its own purposes, under an agreement (DPA) signed with Outzone.
4.2 Providers acting as processors
| Provider (entity) | Role / purpose | Location and transfer |
|---|---|---|
| Infomaniak Network SA | Hosting of the application and backups (processor) | Switzerland (Geneva/Winterthur) – no transfer outside CH |
| Self-hosted MinIO | Object storage (profile photos, event and post images) on Swiss infrastructure | Switzerland |
| Stripe (Stripe Technology Company Ltd / Stripe Payments Europe Ltd, IE; Stripe, Inc./LLC, US) | Payment and payout processing, subscription and dispute management | Ireland + USA – DPF + SCCs (see sec. 5). Stripe is also an independent controller for fraud/AML/compliance |
| Resend (Plus Five Five, Inc.) | Delivery of transactional emails and OTP codes via email | USA – DPF/SCCs |
| Meta Platforms (WhatsApp Business Platform) | Delivery of OTP codes via WhatsApp | USA + EU – DPF/SCCs; messages retained ≤30 days encrypted |
| OpenRouter, Inc. (and downstream LLM providers) | Analysis of public Instagram business content to import events | USA/distributed – SCCs; by default does not store prompts |
| CARTO / OpenStreetMap | Map tile provider (receives your IP address when a map loads) | Switzerland/EU |
| Google reCAPTCHA | Anti-spam protection of website forms | USA – DPF/SCCs |
| Sentry (Functional Software, Inc.) | App crash and error diagnostics (processor) | USA – DPF/SCCs |
With all processors we have in place (or are signing) data-processing agreements requiring processing only on instruction, confidentiality, security, prior approval of sub-processors with change notice, breach assistance, and deletion/return of data at the end.
4.3 Parties acting as independent controllers
- Stripe (for fraud, loss prevention, authentication, regulatory/AML obligations, analytics): see stripe.com/privacy.
- Event organizers (see sec. 4.1).
- Google Sign-In (Google Ireland Ltd / Google LLC), if you sign in with Google: acts as an independent controller under policies.google.com/privacy; we receive only the profile data you authorize.
- Apple "Sign in with Apple" (Apple Inc. / Apple Distribution International Ltd), if you sign in with Apple: independent controller under www.apple.com/legal/privacy; it provides us a unique identifier and, at your choice, name and email (possibly a "Private Relay" address).
Outzone does not sell your personal data to third parties for marketing.
5. Cross-border transfers
Your data is hosted in Switzerland (Infomaniak + self-hosted MinIO, with Swiss backups): we consider this a positive for your privacy. Some providers, however, are located outside Switzerland. The destination countries are: Switzerland (CH), European Union/EEA and United States (US).
- CH↔EU/EEA flows are free thanks to mutual adequacy recognition; no transfer mechanism is needed for Swiss hosting.
- The United States is not generally considered adequate under the FADP. For US providers we rely, where available, on the EU-US and Swiss-US Data Privacy Framework (DPF) certification; where unavailable, on Standard Contractual Clauses (SCCs) with the Swiss addendum under Art. 16(2) FADP / Art. 46 GDPR.
You may request further details on transfers and a copy of the safeguards applied by writing to info@outzone.app.
6. Geolocation
Our approach to location is lean and honest:
- No device location is stored on Outzone's servers.
- We store the event-venue coordinates, set by organizers, to display events on the map.
- If you grant the optional, approximate, foreground-only location permission, we use it on the device to center the map and show you nearby events. Outzone does not collect or store your device's location.
- We do not yet use background location. A background-location feature is planned — not yet active — to recommend nearby events in real time and to provide organizers with aggregated, anonymized attendance statistics. It will require your explicit opt-in consent (off by default), will be revocable at any time, and when it launches we will update this Policy with its purposes, legal bases and retention periods.
- An approximate location may also be inferred from the events you attend (sec. 2.3).
You can revoke the location permission at any time in your operating-system settings (iOS: Settings › Privacy & Security › Location Services; Android: Settings › Location). Revocation does not affect use of features that do not require location.
7. Privacy controls and visibility
You control the visibility of your profile and content.
- Account visibility levels: Public, Friends, or Private.
- Public: profile, activity and events visible to other users.
- Friends: profile, activity and events visible only to users with whom you have a confirmed (mutual) friend connection.
- Private: your profile is not visible to or discoverable by others.
- Privacy by default: adult accounts (18+) are set to Public; minor accounts (16–17) are set to Private and cannot switch to Public (see sec. 9).
- Notifications: push notifications and email receipts are on by default and you can turn them off (opt-out) in your settings.
- App-interaction measurement: it is enabled automatically only during authenticated sessions; the app does not record these actions for people who use it without an account. To object to this processing based on legitimate interest, write to info@outzone.app: we will assess your request under Art. 21 GDPR.
Regardless of visibility, the organizer of an event for which you buy a ticket receives the data needed to run the event, as described in sec. 4.1.
8. Profiling and automated decisions
- Recommendation feed. We personalize your feed by ranking content based on your follows, saves, attendance, interests and an approximate location. This is profiling, but it produces no legal effects and does not similarly significantly affect you.
- No self-service opt-out. At present no self-service tool is available to turn off feed ranking. You may nonetheless object to this processing by writing to info@outzone.app, and we will assess your request under Art. 21 GDPR.
- Automated decisions. The only area where we make automated decisions is fraud prevention and security. In relation to such decisions you always have the right to obtain human review, express your view and contest the decision (Art. 21 FADP / Art. 22 GDPR).
- No behavioural advertising or marketing profiling is carried out on users under 18.
9. Minors
Outzone is intended for users aged 16 and over; we do not allow registration by anyone under 16. We chose the 16 threshold because it satisfies the digital-consent age across the EEA (Art. 8 GDPR) without requiring parental consent for 16–17-year-olds; in Switzerland the validity of a minor's consent depends on their capacity of discernment (Art. 16 Civil Code), which for ordinary use is normally recognized in a 16-year-old.
For 16–17-year-old users we apply enhanced protections:
- account visibility set to Private by default; switching to Public is not possible (a parental-consent mechanism for this is not yet available);
- no targeted advertising or marketing profiling;
- access to adults-only events subject to age verification (18+) at checkout.
We do not knowingly collect data from children under 16. If you believe a child under 16 has provided us with data, write to info@outzone.app and we will delete it.
10. Security of processing
We apply technical and organizational measures appropriate to the risk, including:
- encryption in transit (TLS/HTTPS) on all communications;
- passwords protected with bcrypt (never stored in clear text);
- JWT-based sessions and refresh tokens with revocation (including revocation on account deletion and on any block);
- role-based access control (RBAC) following the least-privilege principle;
- rate limiting and anti-abuse protections;
- parameterized queries (prepared statements) against injection;
- hosting exclusively in Switzerland with Swiss backups.
In the event of a data breach posing a high risk to your rights, we will notify the competent authority (the FDPIC and, where applicable, the relevant EU authority) and, where necessary, you.
11. Data retention
| Data category | Retention period |
|---|---|
| Account and profile data | For the duration of the relationship, until account deletion |
| Financial, ticketing and dispute/chargeback records | For the period required by law (Swiss Code of Obligations, ~10 years) |
| Security and fraud-prevention data | Up to 5 years |
| OTP codes | Consumed immediately after verification |
| Proof of consent, audit and deletion logs | Retained as evidence of compliance (see sec. 12) |
| Raw event interactions (website and app) | 180 days after receipt; automatically deleted in the next periodic cleanup cycle |
| Aggregate/anonymous statistics | Indefinitely (not personal data) |
| Session/refresh tokens | Until logout, revocation or expiry |
12. Your rights
Under the FADP and the GDPR you have the right to:
- access your data and obtain information about the processing;
- request rectification of inaccurate data;
- request erasure of your data;
- request restriction of processing;
- exercise portability of the data you provided to us;
- object to processing based on legitimate interest, including app-interaction analytics, the recommendation feed and marketing, by writing to info@outzone.app; we will assess your request under Art. 21 GDPR;
- withdraw consent at any time, without affecting the lawfulness of processing already carried out;
- lodge a complaint with the supervisory authority (see sec. 15).
A few points of honesty:
- Portability: we do not yet have a self-service export tool; we fulfil portability requests on request, by writing to info@outzone.app.
- Account deletion: you can delete your account directly in the app (Settings › Delete account) or from the web page www.outzone.app/account-deletion. Deletion tombstones your identifying data, but we retain financial and ticketing records (accounting/tax and anti-fraud), proof of consent and the deletion audit log, as required/permitted by law. The immutable sale snapshot contains no buyer personal data.
To exercise your rights, write to info@outzone.app or to Outzone Sagl, Via Grumo 31, 6929 Gravesano, Switzerland. We will normally respond within 30 days.
13. Cookies
The mobile app uses no cookies and no advertising identifiers. The website uses necessary and functional cookies/technologies and, only with consent, first-party statistics technologies for event interactions. We use no third-party analytics services or advertising technologies. Details are in the Cookie Policy.
14. Changes to this Policy
We may update this Policy in case of legal, technological or organizational changes. The last-updated date is shown at the top. For material changes we will give you notice through the Platform or by email. Notices concerning your rights will be sent by email.
15. Contact and supervisory authority
For any question, request or complaint regarding personal data:
- Email: info@outzone.app
- Address: Outzone Sagl, Via Grumo 31, 6929 Gravesano, Switzerland
You also have the right to lodge a complaint with the supervisory authority:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC/EDÖB), Feldeggweg 1, 3003 Bern — www.edoeb.admin.ch
- European Union/EEA: the competent supervisory authority in your Member State of habitual residence.
Outzone Sagl · Via Grumo 31, 6929 Gravesano, Ticino, Switzerland · CHE-251.077.155 (Commercial Register of the Canton of Ticino) info@outzone.app · www.outzone.app