Back to Air MicroservicesThe Outdoor Club

Privacy Policy

Effective Date: July 31, 2026
In short

The Outdoor Club is a private app for a club and its members. Everything it holds about you, you typed in or chose to share. There is no advertising, no analytics, no tracking and no profiling anywhere in the app, and we do not sell or rent your data to anyone. What you enter is visible to the clubs you belong to — not to the public, and not to other clubs. You can leave a club or close your account from inside the app at any time, and you get a real choice about what happens to the things you wrote.

1. Who we are and what this covers

This Privacy Policy describes how Air Microservices LLC ("we," "us," or "our") handles personal data in The Outdoor Club mobile application ("The Outdoor Club" or the "App"). It covers the App and the backend service it talks to. It does not cover anything your club does outside the App.

For members in the European Economic Area and the United Kingdom, Air Microservices LLC is the data controller for the purposes of the UK GDPR and the EU General Data Protection Regulation. Your club's administrators also make decisions about your data within the App — see section 5.

2. How the App is organised, and why it matters here

The Outdoor Club holds many clubs in one service. You cannot browse it: you either found a club yourself or an administrator invited you by email address. A club sees only its own data, enforced in the database rather than only in the App.

You may belong to more than one club. Your profile, your garage and your documents belong to you rather than to any one club, and each club you belong to can see them. Everything else — posts, outings, the club ledger, positions on the map — belongs to a single club and is never visible from another.

3. What we collect

All of it is entered by you or produced by your own use of the App. None of it is bought, inferred, scraped or obtained from third parties.

Account and profile

  • Required: email address and password. The password is handled by our authentication provider and is stored only as a salted hash — we never see or store it in readable form.
  • Required to complete joining: your full name, phone number, city, gender and t-shirt size. The app will not let you finish setting up your membership without them, and the first two cannot be cleared afterwards.
  • Optional: a profile photo, your profession, the year you started going on outings, the year you joined the club, and a federation or association membership number.
  • Birthday: optional, and day and month only. The App deliberately has no field for the year, so it never learns your age.
  • Blood group: optional. Collected for one reason — so that whoever is with you on an outing can give it to a paramedic. This is health data and is treated as a special category of personal data, which is why it is asked for rather than demanded: the picker carries a "Prefer not to say" option, you can complete your membership without it, and you can clear it again at any time from your profile.
  • Emergency contact: optional.A name and a phone number, offered rather than demanded and clearable at any time. This is somebody else's personal data, which is the main reason it is not compulsory — please make sure they are content for you to give it to your club, and tell them where it is.

Documents

  • One identity document: required. Uploading one is a condition of completing your membership — the App says so plainly at that step and will not let you past it. Any government-issued document is accepted: a passport, a national identity card, or a driving licence. The App does not ask for one in particular, because clubs differ and a walking club has no reason to want a licence. Members of a club meet in person, travel together to remote places, and share their live position with one another for the length of an outing; one document on file is what lets a club's administrators satisfy themselves that the person arriving is the person they invited.
  • A second identity document: optional.
  • Any other papers you choose to add: optional — a passport, a medical certificate, a federation card, vehicle registration and insurance papers.

Nothing you upload is checked or verified.The App stores the file and shows it to the people listed in section 6. There is no automated reading of the document, no identity-verification service, and no third party is sent it. We say "on file", never "verified", and you should not treat another member's document as having been confirmed by us.

Identity documents are a special category of personal data in some jurisdictions. How they are stored, and who can retrieve them, is set out in section 7. How long they are kept is set out in section 12.

Vehicles

  • Optional. Make, model, year and registration plate of each vehicle you add, plus any documents you attach to it. Your garage may stay empty, and vehicles can be added or removed at any time.

Location

  • Precise position, including in the background — but only while you have turned sharing on, and only for the one club you are currently viewing. This is covered in full in section 6.
  • Places you search for when planning an outing or setting a club's base location. See section 8 for who receives those searches.

Things you and your club create

  • Posts, photos, comments, reactions, poll votes, and the members you tag in a post.
  • Outings: titles, descriptions, routes, waypoints, itineraries, who enrolled, who was checked in, and which vehicle they brought.
  • Money: entries in the club ledger and shared outing expenses — title, amount, category, date, description and any receipt image. The App records what a club spent; it never takes a payment. See Terms, section 10.
  • Reports you file about a post or comment, and the outcome an administrator recorded.
  • Club material: the club's name, crest, colours, base location, founding year, contact email, documents, artwork and rules.

Technical

  • Push notification token: an identifier for the app installation on your device, stored only if you allow notifications. See section 9.
  • Device name: stored alongside that token, so the record is recognisable. It is never sent anywhere.
  • Server logs: our backend provider records request metadata, including IP addresses, for security and troubleshooting.

4. What we do not collect

  • No analytics or crash-reporting SDKs. The App contains no Google Analytics, no Firebase Analytics, no Crashlytics, no Sentry, and nothing comparable. We do not measure how you use the App.
  • No advertising and no tracking. There are no ad networks, no advertising identifiers, and no tracking of you across other apps or websites. We do not build profiles and we make no automated decisions about you.
  • No address book, no calendar, no microphone, no camera roll scanning. The App never reads your contacts or your calendar and does not record audio. When you pick a photo or a file, it receives only the file you chose.
  • No age or date of birth, as explained above.
  • We never sell, rent or trade your personal data, and we do not share it for anybody else's marketing.

5. Who can see your data

Nothing in the App is public. Visibility is enforced by row-level security rules in the database, so a request for another club's data is refused by the database itself rather than merely hidden by the App.

  • Members of your clubcan see your profile — including your blood group, emergency contact and garage if you filled them in, and your vehicles' papers — along with your posts, your outing enrolments and your position on the map while you are sharing it. This is the point of the app: a club that cannot see who is riding with it cannot look after them.
  • Your identity documents are narrower. Your identity document and any other papers you attach to your profile are visible only to you and your club's administrators — not to ordinary members, and not to the treasurer. They are collected so that whoever runs the club can satisfy themselves that the person turning up to an outing is the person they invited, and that is the only reason anybody else sees them. An administrator keeps that access if they suspend a member, since a suspension does not undo the check the club admitted them on.
  • Club administrators can additionally invite and remove members, change what a member may do, pin or remove posts and comments, act on reports, and close the club. An administrator can see the profile of a member they have suspended.
  • Treasurers and administratorscan see and edit the club ledger. A treasurer gets no access to anybody's identity documents: keeping the books has nothing to do with a member's passport.
  • Other clubs you belong tosee your profile and your garage, because those belong to you rather than to a club — and their administrators, like the first club's, can see your identity documents. They see nothing of another club's posts, outings, ledger or map.
  • Clubs you do not belong to see nothing about you at all.
  • Platform administrators.A small number of accounts operated by Air Microservices LLC can select any club on the platform in order to support and moderate the service, and while doing so have the powers of an administrator of that club. Such an account is protected by mandatory two-factor authentication, and it is not counted as a member of the club — it never appears on the club's map. We use this only where it is necessary to run the service, to resolve a fault, or to meet a legal obligation.

6. Location, in detail

Location is the most sensitive thing the App handles, so it is worth being precise about.

  • It is off until you turn it on. Sharing is never enabled by default. You start it from the map screen, and you can stop it there at any time.
  • Why it exists: so that the members of a club can see each other on a map during an outing — to regroup, to catch up, and to find somebody who has stopped.
  • It continues in the background. With your permission the App keeps reporting your position while it is not on screen, because a map that only updates when somebody is staring at their phone is no use on a ride. Your device will show its own indicator while this is happening.
  • One club at a time. Your position is reported to the single club you were viewing when you turned sharing on. If you switch clubs, the App checks that the club it is reporting to is still the one you have selected, and stops rather than reporting your position to a club you did not choose.
  • Only your latest position is kept — one record per member, overwritten each time. The App keeps no history, no route log and no trail of where you have been.
  • Turning sharing off deletes that record, and your pin disappears from every other member's map. Until you turn it off, your last reported position remains visible to your club even if it is some hours old, so stop sharing when your outing ends.
  • Withdrawing permission. You can revoke location access in your device settings at any time. Nothing else in the App depends on it.

7. Documents and files

Profile photos, post photos and club artwork are stored so that they can be displayed to your club without a delay, and the links to them are not individually access-controlled.

Identity documents, vehicle papers and expense receipts are stored differently.They are held in private storage and cannot be fetched with a plain link. When somebody entitled to view one opens it, the service issues a short-lived signed link for that single file, which expires shortly afterwards. Who is entitled differs by kind: identity documents are yours and your administrators', vehicle papers are visible to your club, a receipt is visible to the club whose ledger it belongs to, and a club's own documents to that club's members.

One limitation is worth stating rather than glossing over. Other members of your club can see thatyou have supplied an identity document — the app records a reference to the file against your profile, and that reference is visible to the club. What they cannot do is open it: retrieving the file needs a signed link, and the service issues one only to you and to your club's administrators. So the existence of a document is club-visible; its contents are not.

One consequence is worth stating plainly: on Android, a PDF cannot be displayed by the operating system inside an app, so a PDF you open in the App is rendered through Google's document viewer, which means Google receives that file in order to draw it. Images and PDFs on iOS are rendered on your device and are not sent to anybody. If you would rather Google never received a document, upload it as an image rather than a PDF, or view it on iOS.

You can delete any document you uploaded, from your profile or your garage, at any time — with one exception. The single identity document required for membership can be replaced but not removed while your account is open, because supplying one is a condition of belonging to a club; it is deleted when you close your account. See section 12.

8. Processors and other recipients

We keep this list short deliberately. Everything the App talks to is named here.

  • Supabase, Inc.— our database, authentication, file storage and server functions. This is where your data lives. Supabase also sends the App's invitation and password-reset emails, and keeps server logs including IP addresses. Supabase acts as our processor under a data processing agreement.
  • Expo (650 Industries, Inc.)— relays push notifications to your device. It receives the notification's title and text and your device's push token. Only used if you allow notifications.
  • Google (Firebase Cloud Messaging) on Android and Apple (Apple Push Notification service) on iOS — deliver that notification the last step to your device, and likewise see its title and text.
  • Google (Docs viewer) — receives a PDF you open on Android, in order to render it. See section 7.
  • OpenStreetMap Foundation — receives the text you type when searching for a place, in order to return matching locations, and on Android serves the map tiles, which reveals the area of the map you are looking at. Your IP address is visible to it in both cases.
  • unpkg (Cloudflare, Inc.) — serves the mapping library used by the Android map, and sees your IP address when it loads.
  • Apple (MapKit) — renders the map on iOS.
  • Google Maps or Apple Maps — when you tap to open a waypoint for directions, the App hands that destination to the maps app you choose. That is a deliberate act on your part each time.
  • Apple and Google, as app stores — handle distribution and updates under their own privacy policies. We receive no personal data about you from either.

We may also disclose data where we are legally required to, or to establish or defend legal claims. If we ever transfer the service to another company, we will say so here before it happens.

9. Notifications

If you allow notifications, the App registers your device so the service can reach it. You are asked once; if you decline, the App works normally and simply tells you nothing while it is closed. You can change your mind in your device settings.

A notification contains what it needs to be useful, which means real content leaves our service and passes through Expo and then Google or Apple. Concretely, we send notifications when a member joins or leaves your club, when you are tagged in a post, when a post is addressed to the whole club — in which case up to 160 characters of that post travel with it — when money is recorded in the club ledger, including the amount and what it was for, and when an outing you enrolled on sets off.

Your push token is deleted when you sign out, so a phone that changes hands stops receiving another member's notifications. A record of a notification we sent is kept for up to 30 days and then deleted.

10. Where your data is stored

The database and file storage are hosted by Supabase, Inc. in its Mumbai, Indiaregion. Server functions run on Supabase's serverless platform.

Air Microservices LLC is established in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your personal data is therefore transferred outside your country — to India, where it is stored, and to the United States and elsewhere insofar as we and the recipients named in section 8 process it. Neither India nor the United States is the subject of a UK or EU adequacy decision that covers these transfers, so we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable) in our agreements with our processors. You may ask us for further information about these safeguards using the contact details below.

11. Why we are allowed to process it

For members in the EEA and the UK, our legal bases are:

  • Performance of a contract — your account, your club membership, and the features you use: outings, the feed, the ledger.
  • Consent — location sharing, notifications, and the optional parts of your profile. Each of these is genuinely a choice: declining any of them leaves the rest of the App working, and you may withdraw consent at any time, which takes effect immediately and does not affect anything done beforehand.
  • Explicit consent, for special category data — your blood group, and any medical document you choose to upload. Both are optional in the full sense: you can complete a membership without either, nothing else in the App behaves differently if you decline, and clearing or deleting one withdraws that consent immediately, with no effect on anything done beforehand. That is deliberate, because consent that is a condition of being allowed in is not consent at all.
  • Your identity document is the exception, and it is worth being plain about it: uploading one is required to complete a membership, so it is not offered on the basis of consent. We process it as necessary for the membership itself — a club whose members meet in person, travel together and share their live position has a real interest in establishing who they are admitting. It is ordinary personal data rather than a special category, and the club's administrators are the only people who can open it. If you would rather no club held one, do not complete a membership; if you have joined and changed your mind, closing your account deletes it.
  • Legitimate interests — keeping the service secure and available, preventing abuse, and handling reports about content.
  • Legal obligation — where the law requires us to retain or disclose something.

12. How long we keep it

We keep your data while your account exists. Beyond that:

  • Your identity documents — for as long as your account exists, and deleted with it. We keep no copy afterwards and we do not archive them. Leaving a club does not delete them, because they are yours rather than that club's and your other clubs still rely on them — but that club stops being able to see them the moment you leave. The required document can be replaced at any time and cannot be removed outright while the account is open, since supplying one is a condition of membership; closing your account is what deletes it. Every other document — a second ID, vehicle papers, anything else you attached — can be deleted whenever you like.
  • Your latest position — until you turn sharing off, or leave the club, or close your account, whichever comes first.
  • Records of notifications sent — up to 30 days.
  • Your push token — until you sign out or turn notifications off.
  • Server logs — for the period our provider retains them, which is a matter of days.
  • Club financial records — kept by the club for as long as the club exists, even after you go. See below.

13. Leaving, and deleting your account

Both are in the App, and neither requires you to ask us.

Leaving a club— from the club screen. Your membership ends and that club stops seeing you: your position, your profile and your documents are no longer visible to it. Your account, your other clubs and your garage are untouched. You are asked what should happen to the posts and comments you wrote in that club, and you may either detach them from your name — they remain, attributed to "Former Member" — or delete them outright. If you are the club's only administrator you must first make somebody else an administrator, or close the club; otherwise the club would be left with nobody able to run it.

Closing your account — Settings → Danger Zone. This is irreversible. It ends every club membership, and deletes your login, your profile, your garage, your documents, your profile photo, your reactions, your poll votes, the record of you being tagged, your push tokens and your location record. You are asked the same question about your posts and comments, and it applies across every club.

What a club keeps.Entries in a club's ledger, shared outing expenses, receipts, and the history of outings survive your departure, with your name detached from them. A club's accounts are its own records, and one member leaving cannot rewrite them. If you believe a particular record should nevertheless be erased, write to us.

If a club closes, its posts, outings, ledger, documents and rules are deleted with it. Its members keep their accounts, their other clubs, their profiles and their garages.

If you cannot use the App — because you have lost access to the device or the account — email toc@airmicroservices.com from the address the account uses and ask us to delete it. We will verify that the request comes from you and act within 30 days.

14. Your rights

Wherever you are, you may ask us for a copy of your data, to correct it, to delete it, or to receive it in a portable form. If you are in the EEA or the UK you also have the right to restrict or object to processing, to withdraw consent at any time, and to lodge a complaint with your data protection authority — in the EEA, the supervisory authority of your country of residence; in the UK, the Information Commissioner's Office.

Much of this you can do yourself and immediately: the profile screen edits and deletes your details and documents, the map screen stops location sharing, and the settings screen closes your account. For anything else write to toc@airmicroservices.com. We will respond within 30 days and will not charge you.

We do not discriminate against anybody for exercising these rights.

15. Security

  • All traffic between the App and our service is encrypted with HTTPS. Data is encrypted at rest by our hosting provider.
  • Access is enforced in the database by row-level security, so one club's data cannot be read by another even if the App were modified or replaced.
  • Passwords are stored only as salted hashes, by our authentication provider. Nobody at Air Microservices LLC can read your password.
  • Platform administrator accounts must complete two-factor authentication with a one-time code before they can reach any club's data.
  • On your device:your signed-in session is held in the App's own private storage, which other apps cannot read. The optional biometric lock asks for your fingerprint or face when the App opens; it is a convenience that keeps a casual passer-by out, and it does not encrypt the App's data — a lost or unlocked device remains the main risk to your account, so please use a device passcode.

No service can promise perfect security. If a breach ever affects your personal data we will notify you and the relevant authority as the law requires.

16. Children

The Outdoor Club is not intended for children. It is built for adult members of riding and outdoor clubs, and it asks for a government identity document. You must be at least 18 to hold an account. We do not knowingly collect data from children, and the App never asks for an age or a date of birth. If you believe a child holds an account, tell us and we will delete it.

17. Changes to this Privacy Policy

We may update this policy to reflect changes to the App or to our legal obligations. The effective date at the top will change, and if a change materially affects how we handle your data we will tell you in the App before it takes effect.

18. Contact us

For any question about this policy, or to exercise any of your rights:

Air Microservices LLC
Email: toc@airmicroservices.com

Air Microservices LLC © 2023 - 2026. All rights reserved.