Privacy policy
Last updated 11 September 2026
ASHER LABS LTD (company no. 17085554), registered in England and Wales, is the controller for personal data processed by Be Outside. We collect the minimum needed to plan trips well, and we never sell your data.
1. Who we are
Be Outside is a product of ASHER LABS LTD, a company registered in England and Wales under number 17085554. We are the data controller for the personal data described below.
Contact us at privacy@be-outside.app. We will give our registered office address on request.
2. What we collect
Account — name, email address, username and date of birth. Date of birth confirms you meet the minimum age and filters age-restricted activities; it is never shown on your profile. If you sign in with Google we also record which provider you used.
Profile— your home area as a place name and coordinates, your interests, difficulty preference, and your distance and currency units. The home area is what puts “trips near you” in the right part of the country.
Trips — itineraries, the places and dates in them, packing lists, shared costs, and the crew on each trip. Costs are amounts and descriptions you type; we never see a bank account.
Invitations — when you invite someone, we store the email address you gave us so we can send the invitation and remind them once. That address belongs to them, not to you, so please only invite people who expect to hear from you.
Billing — if you subscribe to Plus, Stripe processes the payment. We store your Stripe customer and subscription identifiers, the plan, and when the period ends. We never receive or store card details.
Technical — a record of when you last signed in, and errors your browser or the app reports to us. Error reports are configured to exclude personal data.
Analytics — only if you accept analytics cookies. Nothing is loaded and no request is made until you do. See the cookie policy.
3. Why we process it, and on what basis
To provide the service (contract) — your account, your trips, the plans we build, invitations you send, and the emails that carry them.
To take payment (contract) — Plus subscriptions, through Stripe.
To keep the service working and secure (legitimate interests) — error monitoring, abuse prevention, and the reminder emails about your own unfinished trips. You can switch those off in Settings or unsubscribe from any email footer.
Analytics (consent) — only after you accept, and withdrawable at any time in Settings.
4. Who else processes it
People on a trip can see its itinerary, packing list, costs and crew. If you make a trip public, its plan and kit list become readable by anyone with the link and can appear in Explore — the costs and the crew list stay private.
These processors act on our instructions only:
- Clerk — accounts, sign-in and passwords. Clerk holds your credentials; we never see them.
- Stripe — subscription payments and card details.
- LiteAPI (Nuitée) — hotel bookings and their payments, if you book a stay. The card details you enter for a stay go to them, not to us.
- Resend — sending the emails described above.
- Sentry — error reports, with personal data switched off.
- Google — Places and Routes, to look up activity details and travel times, and Analytics if you accepted it.
- Geoapify, OpenTripMap, Photon and OpenStreetMap — place search and the activity catalogue.
We do not sell personal data, and we do not share it with advertisers.
5. How long we keep it
Account and trip data is kept while your account is open. Deleting your account removes your Clerk identity first, then your profile, trips, invitations and notifications.
One thing survives deletion on purpose: if an email address has unsubscribed, we keep that address on a suppression list. Otherwise deleting an account would quietly make somebody eligible for email again — from a trip invitation sent by a different person, for example. That list holds the address and nothing else.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or move it to another service. You can also withdraw consent at any time where we relied on it.
Deleting your account is self-service in Profile, under Danger zone, and takes effect immediately. Notification and email preferences are in Settings. For anything else — including a copy of your data, which we do not yet offer as a download — email privacy@be-outside.app and we will respond within one month.
If you think we have handled your data badly, you can complain to the Information Commissioner’s Office at ico.org.uk. We would rather you told us first.
7. Security
Sign-in is handled by Clerk, so Be Outside never receives or stores your password. Your session travels in a cookie that JavaScript cannot read, over HTTPS only, and every request to our API is verified against Clerk before it touches your data.
Requests to the site carry a content security policy and the usual protective headers. No system is perfectly secure, but we would rather tell you what we actually do than list reassuring words.
8. Age
You need to be at least 13 to hold an account, which is why we ask for your date of birth during setup and check it server-side. That is the age of digital consent in the UK. If you believe a younger child has created an account, tell us and we will remove it.
9. International transfers
Some of the processors above operate outside the UK. Where personal data leaves the UK we rely on UK adequacy regulations or the International Data Transfer Addendum to the Standard Contractual Clauses.
10. Changes
If we change how we use personal data in a way that affects you, we will say so here and update the date at the top. Material changes will also be emailed to you.