Legal
Privacy Policy
Effective: 7 May 2026 · Last updated: 9 July 2026
Plain-English summary: We collect the minimum we need to run the site (cookies, your IP, what you searched, what you saved). We never sell your data. You can ask to see, correct, or delete everything we have on you. We comply with the GDPR, the UK GDPR, the CCPA/CPRA, the LGPD, PIPEDA, the Australian Privacy Principles, and the Israeli Privacy Protection Law.
This Privacy Policy describes how GayOut ("we", "us", "our") collects, uses, discloses, and protects information when you visit gayout.com, use any subdomain, mobile-friendly page, API, or related service (together, the "Service"). By using the Service, you agree to the practices described here. If you do not agree, please do not use the Service.
Contents
- Who we are & how to contact us
- Information we collect
- Sensitive data & your safety
- How we use your information
- Legal bases (GDPR/UK GDPR)
- When we share information
- Third-party services we use
- Cookies & similar technologies
- International data transfers
- Data retention
- Security
- Your rights
- Region-specific rights (GDPR / CCPA / LGPD / PIPEDA / APP / Israel)
- Children's privacy
- Do Not Track & GPC
- Changes to this policy
- Complaints & supervisory authorities
1. Who we are & how to contact us
GayOut is operated by ACTV-TEC Ltd. ("the Operator"), a company organised under the laws of the State of Israel. References to "we", "us", or "GayOut" mean the Operator and its affiliates.
For any privacy question, request, or complaint, please write to our Privacy Contact:
- Privacy inquiries: privacy@gayout.com
- General contact: info@gayout.com
- Postal address: available on written request to privacy@gayout.com
We have not appointed a formal Data Protection Officer under Article 37 GDPR because the Service does not carry out large-scale processing of special categories of data as its core activity. The Privacy Contact above is your single point of contact for all data-protection questions.
2. Information we collect
2.1 Information you give us
- Hotspot submissions: name, address, phone, website, email, opening hours, photos, and descriptions you submit when listing a venue.
- Reviews and tips: the text, ratings, and any photos you post.
- Account & magic-link emails: the email address you use to manage a hotspot or to receive a one-time login link.
- Newsletter sign-ups: your email address.
- Payment information for Promoted/Premium subscriptions: handled directly by PayPal — we never receive or store your full card number; we only receive a subscription identifier and limited transaction metadata.
- Communications: messages you send to support@gayout.com or info@gayout.com.
2.2 Information collected automatically
- Device & technical data: IP address, browser type and version, operating system, screen size, language preference, time zone.
- Usage data: pages viewed, links clicked, search queries, time spent, referring URL.
- Cookies and similar technologies: see Section 8.
-
Approximate location (IP-based): when you visit any page of the Service, our
homepage automatically resolves your approximate location so we can order the "LGBTQ+ Near You"
widget and the nearby-events strip against the closest cities in our directory. This happens
without a prompt — it is not the browser's precise GPS. The resolution uses up to three
parallel sources:
- a lookup on our own server that maps your IP to the nearest city we already list;
- the free public endpoint ipapi.co (see Section 2.3);
- a
gayout_nm_v1entry we write to your browser's localStorage so a return visitor sees the same result without the network round-trip.
ipapi.co, or disable JavaScript. Precise device GPS is a separate step: it is only used if you click "Share location" on the "Near Me" prompt, and only after your browser shows its own permission dialog.
2.3 Information from third parties
- Google Sign-In (if used): your name, email, and profile picture (with your consent).
- Google Places, TripAdvisor: publicly available venue information used to enrich our directory.
-
ipapi.co (Kaloyan Kovachev, EU/BG — see their privacy policy):
we send your IP address to their public IP-to-location endpoint to obtain approximate city-level
coordinates for the "Near You" personalisation described in Section 2.2. The provider states that
it does not log IP-to-location lookups for identification purposes. The lookup runs from your
browser, not from our server — meaning the request originates from your IP directly. If this
transfer concerns you, block
ipapi.coat the browser level and the site keeps working (personalisation falls back to server-side IP resolution). - Resend: email delivery and bounce metadata for transactional emails.
- PayPal: subscription status and payment events via webhooks.
3. Sensitive data & your safety
If you are in a country where being LGBTQ+ carries legal risk: we recommend using a reputable VPN, browsing in a private/incognito window, not saving favourites to an account, and avoiding any content submission that could be linked back to you. Nothing on this Service — or on any website — can guarantee absolute anonymity if a state actor compels the disclosure of records from us, from your Internet Service Provider, or from any third-party processor listed in Section 2.3. Our Gay Travel Index and the safety banners on individual country pages exist to help you evaluate that risk before you interact.
The mere act of visiting or using this Service is not a declaration of sexual orientation, gender identity, HIV status, or any other special category of data. GayOut is an information directory; a large share of our visitors are allies, travellers researching for LGBTQ+ friends or family, journalists, academics, and tourism-industry professionals. We do not ask you to state your orientation, and we do not attempt to infer it from your activity.
However, some information you may voluntarily provide could — alone or in combination — reveal special category data under Article 9 GDPR, sensitive personal information under Section 1798.140(ae) of the CPRA, or "sensitive information" under the Israeli Privacy Protection Law and the regulations issued under it:
- Reviews and photos you post publicly. These may reveal information about you if you choose to include personal detail.
- Saved favourites and search history stored to your account could, in aggregate, form a profile suggestive of orientation.
- Newsletter sign-up associates your email address with LGBTQ+-focused content.
- Community-added listings for niche venues (cruising clubs, saunas, HIV-related services) that you submit under your name or email.
3.1 Legal basis for any sensitive processing
Where processing information you provide could involve a special category of data under Article 9 GDPR, we rely on your explicit consent, given by the deliberate act of submitting the content. You provide that consent by knowingly performing the specific action — posting a review, saving a favourite to your account, submitting a hotspot, or subscribing to the newsletter. Legitimate interests is not our legal basis for these categories.
You can withdraw consent at any time by deleting the content or your account via /delete-my-data. Withdrawal is prospective — it does not affect the lawfulness of prior processing.
Under the CPRA, we do not use or disclose sensitive personal information for any purpose that is not permitted without a right-to-limit under Section 7027 of the CCPA Regulations. You can nevertheless exercise the right to limit at any time by emailing privacy@gayout.com.
3.2 Data minimisation by design
We designed the Service so that most browsing works without an account. You can view every guide, every event, and the entire safety index anonymously. Account features — saving favourites, receiving personalised newsletters, submitting hotspots, posting reviews — are optional. If minimising your footprint matters to you, use the Service without signing in and without submitting content.
We keep the account footprint deliberately small: an email address is the only identifier we require to create one. We do not ask for a real name, date of birth, phone number, or profile photo. You can use a pseudonymous email address (for example, ProtonMail or a burner address) if you prefer.
3.3 Third-party disclosure of sensitive data
We do not sell sensitive personal information, and we do not disclose it for behavioural advertising. The only processors that receive data capable of revealing sensitive information are the ones listed in Section 7 — each under a written processor agreement — and only to the minimum extent necessary to run the specific feature you use.
4. How we use your information
- Operate, maintain, and improve the Service.
- Display venue listings, events, photos, and reviews.
- Order the "LGBTQ+ Near You" widget and the nearby-events strip against the cities closest to your approximate IP location, so a first-time visitor sees locally relevant content without having to type their city. See Section 2.2 for how this is derived.
- Enable account-free authentication via magic links and Google Sign-In.
- Process Promoted and Premium subscriptions and send transactional emails.
- Detect and prevent fraud, abuse, spam, and security threats.
- Comply with legal obligations and respond to lawful requests.
- Send service announcements (rare) and the optional newsletter (only if you sign up).
- Generate aggregated, de-identified analytics — for example, monthly visitors per city.
5. Legal bases (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR:
- Performance of a contract — when you submit a hotspot, subscribe, or use a paid feature.
- Legitimate interests — to operate the Service, prevent fraud, improve features, and personalise on-page content against your approximate IP-derived location (Section 2.2) so travel guidance defaults to somewhere near you rather than a random capital. This interest is balanced against your rights and freedoms; you can object to IP-based localisation by blocking
ipapi.coin your browser or by objecting via the contact address below, and we will fall back to a non-personalised view for your session. - Consent — for non-essential cookies, the newsletter, and any optional features you explicitly enable. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation — to comply with tax, accounting, anti-money-laundering, or law-enforcement requirements.
6. When we share information
We do not sell personal information. We share only as needed to operate the Service:
- Service providers who process data on our behalf under contract and confidentiality (PayPal, Resend, Anthropic, Google, OpenStreetMap, our hosting provider).
- Public listings — content you submit to a public hotspot or review is visible to all visitors.
- Legal compliance — when required by law, court order, or to protect rights, property, or safety.
- Business transfers — in the event of a merger, acquisition, or sale of assets, your information may be transferred. You will be notified before any transfer changes how this Policy applies.
7. Third-party services we use
The following processors may receive your data when you use the Service. Each operates under its own privacy policy:
- PayPal — payments and subscriptions. Policy
- Resend — transactional email delivery. Policy
- Anthropic — AI processing for the Trip Planner and for guide translations. Anthropic receives the text you type into the Trip Planner and any editorial content we send it for translation, and processes it under a commercial API agreement that prohibits training on customer inputs. Please do not include personal information — your legal name, home address, phone number, ID numbers, or details about people you know — in the Trip Planner box. If you do, that text is transmitted to Anthropic exactly as you wrote it. Anthropic's data-handling practices are published at anthropic.com/legal/privacy.
- Google — Maps API, Places API, optional Google Sign-In, Google Analytics (if enabled). Policy
- TripAdvisor — venue data and reviews via API.
- hCaptcha — bot protection on submission forms.
- OpenStreetMap Foundation — map tiles for the world map.
- fonts.bunny.net — privacy-friendly fonts (no user tracking).
For B2B partners: if you are a venue chain, integrator, ticketing platform, or other business partner that requires a formal Data Processing Agreement under Article 28 GDPR (or an equivalent contract under your applicable law), please review our standard DPA template at https://www.gayout.com/dpa and contact privacy@gayout.com to execute it.
8. Cookies & similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, and (where you consent) measure usage.
- Essential cookies — strictly necessary for sign-in, fraud protection, and core features. Cannot be disabled.
- Functional cookies — remember your language, dark mode, and saved favourites.
- Analytics cookies — only with your consent. We use Google Analytics with anonymised IPs and short retention.
- Marketing cookies — only with your consent. Used to measure the effectiveness of any campaigns.
You can manage cookies through our cookie banner or your browser settings. Disabling cookies may break certain features (e.g., sign-in, locally stored favourites).
9. International data transfers
Your information may be processed in Israel, the European Union, the United States, and other countries where our service providers are located. Where we transfer personal data outside the EEA, the UK, or other regions with data-protection laws, we rely on appropriate safeguards:
- Standard Contractual Clauses approved by the European Commission.
- EU–US Data Privacy Framework (where the recipient is certified).
- Adequacy decisions (e.g., Israel benefits from an EU adequacy decision for commercial transfers).
- Other lawful mechanisms permitted under applicable laws.
10. Data retention
- Hotspot submissions: the business listing itself is retained as long as it is live (or as long as the venue exists) because a public directory needs a stable historical record. When you exercise your right to erasure, the personal data associated with the submission — your submitter email, name, IP address, and any other identifier tying you to the record — is deleted, and the listing itself continues as an anonymised community entry with no link back to you. If you want the listing itself removed as well, tell us in the same request and we will assess it against the legitimate interests of the venue owner and the community.
- Reviews: retained as long as the venue exists; you can request deletion of your own reviews.
- Magic-link tokens: 7 days. Manage sessions: 30 days.
- Subscription records: retained for up to 7 years to comply with tax and accounting laws.
- Email logs: 90 days, then aggregated.
- Server logs: 30 days unless an investigation is ongoing.
- Backup copies: rotated every 90 days.
11. Security
We use industry-standard security measures, including TLS 1.3 in transit, hashed and salted authentication tokens, encrypted database fields for sensitive data, regular vulnerability scanning, and role-based access controls. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
12. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate information.
- Erasure — request deletion ("right to be forgotten").
- Restriction — pause processing while we resolve a dispute.
- Portability — receive your data in a machine-readable format.
- Object — to processing based on legitimate interests, including direct marketing.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint with a supervisory authority (Section 17).
Get a copy of your data: visit /my-data for a self-service export. You'll receive a one-time email link, then can download every record we hold about you as a machine-readable JSON file.
Self-service deletion (right to erasure): visit /delete-my-data. We email you a confirmation link, you review what will be deleted, then type DELETE to confirm. Your personal data is anonymised immediately; backup copies are purged within 30 days.
To exercise any other right, email privacy@gayout.com. We respond within the timeframes required by the law that applies to your request (for example, one month plus a possible two-month extension under the GDPR; 45 days under the CCPA/CPRA), and we will notify you of any need for extension before it takes effect.
13. Region-specific rights
European Economic Area & United Kingdom (GDPR / UK GDPR)
You have all the rights listed in Section 12. The Data Controller is ACTV-TEC Ltd. (Israel). To reach us in connection with GDPR / UK GDPR matters, write to privacy@gayout.com. Where Article 27 GDPR would require the appointment of a representative in the Union, we will appoint one on request from a supervisory authority and update this page with their contact details.
California, USA (CCPA / CPRA)
If you are a California resident, you have the right to: know what personal information we collect; delete it; correct inaccuracies; opt out of sale or sharing (we do not sell or share your information for cross-context behavioural advertising); limit use of sensitive personal information; and not be discriminated against for exercising your rights. Authorised agents may submit requests with proof of authorisation. Email privacy@gayout.com with subject "California Privacy Request".
Brazil (LGPD)
You have the rights to confirmation of processing, access, correction, anonymisation, blocking, deletion, portability, information about sharing, revocation of consent, and review of automated decisions.
Canada (PIPEDA & provincial laws)
You may request access to your personal information, ask us to correct it, and withdraw consent (subject to legal or contractual restrictions).
Australia (Privacy Act 1988 & APPs)
You may request access to and correction of your personal information. Complaints can be made to the Office of the Australian Information Commissioner (OAIC).
Israel (Privacy Protection Law, 5741-1981, as amended)
You have a right to inspect data held about you, request corrections, and request deletion under section 14 of the Israeli Privacy Protection Law. We operate the Service in compliance with the Law and the regulations issued under it, including the obligations that entered into force under Amendment 13 (2024). Where the Law requires a database to be registered with the Registrar of Databases, we maintain the required registrations; contact privacy@gayout.com for the current registration number and status.
South Africa (POPIA), Switzerland (FADP), Japan (APPI), South Korea (PIPA), India (DPDP Act)
Where these laws apply to you, we extend equivalent rights of access, correction, and deletion. Contact privacy@gayout.com.
14. Children's privacy
The Service is intended for adults aged 18 or older. We do not knowingly collect personal information from anyone under 16 (or under 13 in the United States, per COPPA). If you believe a child has provided us information, please contact us and we will delete it promptly.
15. Do Not Track & Global Privacy Control
We do not currently respond to Do Not Track ("DNT") browser signals, because no industry standard for DNT compliance exists. We also do not automatically honour the Global Privacy Control ("GPC") signal at the network layer. Because we do not sell personal information and do not share it for cross-context behavioural advertising (see Section 6), a GPC signal has no practical effect for the current Service; if you nevertheless want an explicit record that you have exercised any right associated with the GPC signal — including the CPRA right to opt out of sale/sharing and the right to limit use of sensitive personal information — email privacy@gayout.com and we will log it on your account. If we introduce features that would make the GPC signal operative (for example, third-party advertising cookies), we will update this section and honour the signal at that time.
16. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent version. Where a change materially affects your rights, we will give reasonable advance notice — for example, by email (if we have your address) or by a prominent notice on the site — in accordance with the requirements of applicable law.
17. Complaints & supervisory authorities
If you have a complaint, please email privacy@gayout.com first. You also have the right to lodge a complaint with a data-protection authority:
- EU: the supervisory authority of your member state — list here.
- UK: Information Commissioner's Office — ico.org.uk
- California: California Privacy Protection Agency (CPPA).
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD).
- Canada: Office of the Privacy Commissioner of Canada (OPC).
- Australia: Office of the Australian Information Commissioner (OAIC).
- Israel: Privacy Protection Authority (PPA).
© 2026 GayOut. This Privacy Policy is provided for informational purposes and does not constitute legal advice. If you require legal counsel, please consult a qualified attorney.