Legal
Privacy Policy
- Version
- 1.4.0
- Status
- In force
- Effective
- October 1, 2026
- Last updated
- October 1, 2026
Scope and who is responsible
This policy explains what Outrider Travel, LLC (“Outrider”, “we”, “us”) collects about you, why, who it goes to, and what you can do about it. It covers this website, the booking flow, and the emails we send you about a booking.
Outrider is based in Auburn, Alabama and is the party responsible for the information described here. The companies that store and process it on our behalf are named in section 9, we do not hide behind “trusted partners”.
It does not cover what a hotel, ski resort, rental shop, transport operator or insurer does with your information once we pass it to them to deliver your trip. They have their own policies, and their own responsibilities under them.
What we collect
Account information
Signing up creates an account with Supabase Auth, which stores your email address and a hashed password on our behalf; we never see or store your password in a readable form. Alongside it we hold your email, your name and, if you give it, your phone number.
Booking information
When you book we record which trip and tier you chose, the total price and deposit, the booking status, your group code if you are traveling with people you know, and the date you booked. Against that booking we record each payment: the amount, its status, the date it is scheduled for, when it was paid, how many charge attempts have been made, and a reference to the payment at Stripe.
Running a trip also needs information we ask for outside the checkout, names as they appear on identification, dates of birth, ability level, equipment sizing, dietary requirements, emergency contacts, and any medical condition or allergy relevant to your safety on the mountain.
Your trip page and traveler details
After you book, we send you a private link to your trip page. The link opens the page without a password, so anyone who has it can see your booking and payment schedule and use the forms on it. Please keep it to yourself. Links stop working after a while; the page can send a fresh one, and it only ever goes to the email address on your booking.
On the trip page we ask for:
- your legal name as it appears on your ID and your date of birth, which the travel insurer covering the trip needs in order to insure you;
- your phone number, and the name and phone number of an emergency contact, so trip staff can reach you and someone at home;
- your height, weight and shoe size, whether you ski or snowboard, and your ability level, so the rental shop can have your equipment ready before you arrive;
- any dietary restrictions, for meals on the trip;
- the names of up to three people you would like to room with, or that you have no preference, and the time you sent the request, because rooms are assigned in the order requests arrive;
- whether you have booked your flights.
We never send your legal name, date of birth or emergency contact by email, and the trip page does not show them back once they are saved.
Messages you send us
The contact form takes your name, email address and message and emails them to us. It is not stored in our database, the record is the email in our inbox, and the reply thread that follows.
Waitlist
Joining the waitlist stores your name, email address, mobile number and the date you joined in our database. It also stores your answer to each of the form’s two boxes (email and text messages), when you gave it, which version of their wording you saw, and the IP address and browser the form was sent from, as the record of that consent. If a link brought you to the form, we store its short tag (for example, one from an event) and campaign tags, and which form on the site you used. Your name and email address are also added to our mailing list at Resend.
A $100 code by email
Asking for a $100 code on our Telluride page stores your email address, the code we give you and when it runs out, your answer to the box asking whether we may email you about Outrider trips, when you gave it and which version of its wording you saw, the IP address and browser the request came from, and the campaign tags of the link that brought you. If you tick the box, your email address is also added to our mailing list at Resend. We also put the code in a cookie on this site so that it comes off at checkout (see section 5).
Technical information
Like any website, ours receives your IP address, your browser type and version, and the page you requested, and our host records them. See section 8.
Your visits, through the Meta Pixel
When the Meta Pixel runs (see section 5), it sends Meta the address of the page you are viewing and of the page you came from, your IP address, your browser and device type, and the identifiers in its cookies. It also tells Meta when you join the waitlist or ask for a $100 code, when you reach the card form for a new booking, and when you make a booking’s first payment, with the amount. It does not send your name, email address, phone number, card details or anything you type into a form.
Payment information and Stripe
Your card details go directly to Stripe. Outrider never receives, sees or stores your full card number, expiry date or security code.
The card fields on our checkout page are not ours: they are served by Stripe inside a frame on the page, and what you type into them is sent from your browser straight to Stripe. It does not pass through our servers and it is not written to our database. Stripe is a PCI DSS Level 1 service provider, and using it this way is what keeps card data out of our systems entirely.
What we do store about a payment is:
- a Stripe customer identifier for your account;
- an identifier for the card you saved at checkout, a reference held at Stripe, not the card number itself, and not something that can be used to charge you anywhere else;
- for each payment: the amount, its status, its scheduled date, the date it was paid, the number of attempts made, and the Stripe payment identifier.
When you pay a deposit, the card you use is saved at Stripe against your customer record so that the scheduled installments described in the Terms of Service can be charged automatically. Refunds and disputes are handled through Stripe. Stripe processes your payment information as a business in its own right as well as on our behalf, under its own privacy policy, including for fraud prevention.
How we use your information
We use your information to:
- create and secure your account, and sign you in;
- take bookings, charge deposits and installments, issue refunds, and keep the accounting records a business is required to keep;
- run the trip, passing what each supplier needs in order to give you a room, a lift ticket, the right rental gear, a seat in a vehicle, a meal you can eat, and care if something goes wrong;
- email you about your booking: confirmation, receipts, a warning when a payment fails, a request to verify a payment with your bank, a link to your trip page and a reminder if something on it is still open, and practical information before departure;
- text you about your trip, if you opted in to texts on your trip page (see section 7);
- text you about Outrider trips, if you ticked the text box when you joined the waitlist (see section 7);
- answer messages you send us, and keep a record of what was agreed;
- send trip announcements to people who joined the waitlist or otherwise asked for them;
- email you a $100 code you asked for, and up to two reminders before it runs out (see section 6);
- show Outrider ads on Instagram and Facebook to people who have visited this site, and measure how those ads perform (see section 5);
- keep the site working and safe, preventing abuse, limiting how often an anonymous form can be submitted, and investigating problems;
- meet our legal obligations and defend legal claims.
We do not sell your personal information. We do share information about your visits with Meta, through the Meta Pixel, so that we can show our ads to people who have been here. Under California law that counts as sharing for cross-context behavioural advertising, and you can opt out of it; see section 5.
Email, the waitlist and marketing
Email is sent through Resend, which receives the address we are sending to and the content of the message.
Booking email is not marketing and cannot be turned off while you have a live booking: a receipt, a failed-payment warning, a request to verify a payment with your bank, your trip-page link and a reminder when something on it is still open, and pre-departure logistics are part of the service you bought. If you do not want them, cancel the booking.
Waitlist and announcement email is marketing and you can leave at any time, use the unsubscribe link in any of those messages, or email bookings@outrider.travel and we will remove you. Your address is held in our database and in our mailing audience at Resend; unsubscribing marks you unsubscribed in both.
A $100 code you ask for comes by email straight away, followed by at most two reminders before it runs out: two days before its last day, and on its last day. They stop if you use the code, book, or unsubscribe with the link in any of them. They are sent whether or not you tick the box about Outrider trips; the box decides only whether you also join the list. Each address gets one code. If an address that already has one is typed again, we email the code to that address again and do not show it on the page.
Text messages
Your trip page has a separate box for text messages. It is not ticked for you, and booking does not depend on it. If you tick it, we record that you agreed, when, and which version of the wording you saw, and we use the mobile number you give us to send you automated texts about your trip: logistics, reminders and answers to your questions. Message frequency varies, and message and data rates may apply. Reply HELP for help, or STOP at any time to stop them. The program is described in the Terms of Service.
The waitlist form has its own box for texts about Outrider trips. It is not ticked for you, and joining the list does not depend on it. If you tick it, we record that you agreed, when, and which version of the wording you saw, and we may use the mobile number you give us to send you automated marketing texts about Outrider trips. Message frequency varies, and message and data rates may apply. Reply HELP for help, or STOP at any time to stop them.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. We do not sell, rent or share your mobile number, your text-message opt-in or your consent with anyone for their own marketing. Text messaging opt-in data and consent are excluded from every kind of sharing described in section 9, and will not be shared with any third party, apart from the text-messaging service that sends our texts on our behalf, which may use them only to deliver our messages.
Server logs, security and rate limiting
Our site runs on Vercel and our database is hosted by Supabase. Both keep server logs, which record IP addresses, timestamps, requested URLs and error details. Those logs exist to keep the service running and to let us diagnose problems, and they are held for as long as those providers retain them.
The waitlist, the $100 code and the contact forms are open to anyone, so they are rate limited. To do that we store a short-lived record keyed to the IP address the request came from (and, for the $100 code, to the email address typed), counting how many submissions it has made recently (within the past day at most). It is used for nothing else, not for analytics, not for profiling, not for advertising.
How long we keep information
We keep booking, payment and correspondence records for as long as we need them to run the trip, to meet tax, accounting and insurance obligations, and to defend a legal claim. Account information is kept while your account exists. Waitlist addresses, and addresses that asked for a $100 code, are kept until you unsubscribe or ask us to remove you.
Your choices and your rights
Whatever jurisdiction you are in, you can ask us to do the following, and we will do it or explain why we cannot:
- tell you what information we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your information, subject to what we must keep for legal, tax and accounting reasons, a completed booking cannot simply be erased;
- stop sending you marketing email;
- stop sharing your visits with Meta for advertising, which you can also do yourself with the switch in section 5;
- stop texting you, which you can also do by replying STOP;
- stop using your card for future installments, though this does not cancel the booking or what you owe under it.
Email bookings@outrider.travel with what you want, from the address on your account so we can tell it is you. We aim to respond within 30 days. We will not treat you differently for exercising any of this.
California residents
If you live in California, the California Consumer Privacy Act as amended by the CPRA gives you rights to know what personal information is collected about you and how it is used and shared, to obtain a copy, to correct it, to delete it, to opt out of its sale or sharing, and to limit the use of sensitive personal information, along with a right not to be discriminated against for exercising them.
The categories we collect, why, and who receives them are described throughout this policy, identifiers and contact details, commercial information about your bookings and payments, internet activity in the form of server logs and, through the Meta Pixel, the pages you visit here, and, where you give it to us for a trip, health information. We do not sell personal information. We do share it, as the CPRA uses the word, in one way: the Meta Pixel sends Meta information about your visits here so that we can show you our ads. You can opt out with the switch in section 5, reached from the “Your privacy choices” link at the foot of every page, and we honor Global Privacy Control signals as an opt-out. To make any other request, use the contact route in section 11.
Visitors from the EEA and the UK
This site is aimed at travelers in the United States, and your information is stored and processed there. If you are in the European Economic Area or the United Kingdom and the GDPR applies to our handling of your information, we rely on these legal bases: performance of a contract for booking and running your trip; legitimate interests for keeping the site secure and defending claims; consent for marketing email; and legal obligation for tax and accounting records. We do not run the Meta Pixel for visitors whose device is set to a European time zone (section 5). You also have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your data protection authority.
Children
Outrider trips are sold to adults. This site is not directed at children, and we do not knowingly collect personal information from anyone under 18 through it. If a minor travels as part of a group, the adult who books provides the information about them and is responsible for it. If you believe a child has given us information directly, email bookings@outrider.travel and we will delete it.
Security
Traffic to this site is encrypted in transit. Passwords are hashed by our authentication provider and are never visible to us. Card details never reach our systems at all. Access to booking and payment records in our database is restricted by row-level security so that a signed-in traveler can read their own records and no one else’s, and the writes that create bookings and payments are made only by the server.
No system is perfectly secure, and we do not promise that ours is. If a breach affects your information we will notify you and the relevant authorities as the law requires. Use a strong, unique password and tell us at once if you think someone else has been in your account.
Changes to this policy
We may update this policy. Each version carries a version number and the dates it was updated and took effect, at the top of this page. Where a change materially affects how we handle information we already hold about you, we will tell you directly rather than quietly republishing the page.
How to reach us
Outrider Travel, LLC, Auburn, Alabama. Privacy questions and requests: bookings@outrider.travel.
Written requests can be sent to 145 East Magnolia Avenue, Auburn, Alabama 36830.
Related documents: Terms of Service and Assumption of Risk.
Privacy Policy, v1.4.0, last updated October 1, 2026
Questions about this document, or a request about your own information, go to bookings@outrider.travel. Outrider Travel, LLC is based in Auburn, Alabama.