A clear trail for your information

Privacy

Make a Camplist (“Camplist”) is built for camping plans, not people-watching. Here is what we collect, why we need it, and how you can pack it up and remove it.

Effective: September 4, 2026. Last updated: September 14, 2026.

The plain version

We collect the small amount of information needed to organize a trip, keep the right campers connected, and protect access. We do not sell personal information, run advertising profiles, or send marketing email. Shared trip plans are visible to the crew; your Personal list stays private unless you choose to share it with the Host and Planners.

What we collect

Trip plans

Trip names, dates, destinations, optional weather locations, campers, roles, packing, groceries, meals, activities, Personal lists, notes, and progress.

Your camp identity

Your display name, selected badge, trip memberships, and whether you are a Camper, Planner, or Host.

Access details

Essential session identifiers, your protected recovery email, one-time access challenges, a password hash if you add a password, and provider identity details if you connect Google or Microsoft.

Safety signals

Network information such as IP address for throttling, security, and suggesting a starting pricing region, plus route-based service logs, status, timing, and trace identifiers.

For a connected provider, Camplist keeps the provider name, issuer, subject identifier, and the email address shown on your Account page. We do not store Google or Microsoft access tokens. A provider email is a sign-in label only: it does not replace your Camplist recovery email or grant access to a trip.

We do not ask for your live device location, an address book, payment information, government identification, biometrics, or advertising interests. The Pricing page may use the IP address already included with a web request to estimate a country and suggest a currency. This does not request browser location permission, and you can always change the suggestion. If a trip Host optionally selects a weather location, Camplist stores that selected trip-level location and its coordinates so it can retrieve an integrated forecast; trip members can see it. A one-time device-location hint may be used only after you ask us to improve search results, and is never stored. Camplist is not a medical record or medication-management service. Keep Personal Item labels general and do not add medication names, doses, diagnoses, medical instructions, financial information, or identification details.

How we use information

  • Run the trip-planning and checklist features you choose to use.
  • Show each crew the right shared plan and keep role permissions in place.
  • Send requested access links, six-digit codes, and essential service messages. These are not marketing emails.
  • Prevent guessing, spam, fraud, and unauthorized access.
  • Provide limited technical support, security help, and incident response using identity, email, trip-name, role, membership, recent activity, list totals, and deletion-status information.
  • Diagnose outages and improve reliability using operational telemetry that replaces private URL values with generic route labels.
  • Meet legal obligations and respond to valid legal process when required.

Who sees and processes it

Your trip crew

People on a trip can see the shared plan, camper display names and badges, and shared checklist progress for that trip. Your Personal list starts private. If you choose to share it, only the Host and Planners can view it, and only you can change it. Hosts steward Personal lists for Managed Campers and campers who have not joined yet. Hosts can see whether another camper is browser-only, awaiting access setup, or protected, but they do not receive the camper’s full verified email address from Camplist.

Limited operator support

The Camplist operator may access identity, email address, trip name, dates, role, membership state, access state, and deletion status when needed for technical support, security, or incident response. The desk also shows recent activity and aggregate list totals and completion counts (not the items themselves) to understand whether setups are being used. A quiet account may simply be between camping seasons; we do not automatically delete accounts for inactivity. The operator can remove a camper from a selected trip, delete a trip, or delete an account and its hosted trips after reviewing a confirmation. These actions are audited. Email addresses are normally masked and require a deliberate, audited reveal. This private Support Desk does not expose destinations, invite codes, access secrets, or Packing, Grocery, Meal, Activity, or Personal-list contents. Support information is not used for advertising, marketing, sale, or profiling.

Service providers

Camplist uses Microsoft Azure to host the application and database, suggest a country from a request IP, provide maps and weather, send transactional access email, and monitor reliability. If you choose Google or Microsoft sign-in, that provider receives the authorization request and returns identity details needed to recognize the provider account you approved. Camplist does not receive or store your provider password. These providers process information under their own privacy and security terms.

Other disclosure

We do not sell or rent personal information. We may disclose limited information when the law requires it, to protect Camplist and its users, or as part of a business transfer with appropriate safeguards and notice.

Children’s data: a firm boundary

Children under 13 may not use Camplist directly. They may not hold an interactive identity, receive an access email, use a magic link, or select a profile badge. An adult may include them only as a Managed Camper, which has no application access.

For a Managed Camper, use a first name or nickname and only the ordinary packing or Personal-list details the adult needs. Keep Personal Items general. Do not add a child’s email, precise location, school, medication details, diagnoses, health instructions, or other sensitive information.

Campers aged 13 to 17 may use Camplist only with permission and supervision from a parent or guardian. Where local law sets a higher consent requirement-including parental-authority consent for a minor under 14 in Quebec-that rule applies. The Host is responsible for inviting and supervising younger campers in their crew.

If an adult learns that a child under 13 has direct access, the adult should use the in-app deletion control right away. Deleting the identity signs out its devices and removes its direct connection to trips.

Cookies and browser storage

Make a Camplist uses cookies and browser storage to keep your access to trips working, protect sign-in, and remember your choices. We do not use them for advertising or tracking you across websites.

  • Trip access: a browser cookie keeps you connected to your trips, including trips without an account. It lasts up to 180 days, but access expires after 30 days without activity. The account sign-in cookie lasts up to 30 days. Signing out or ending a session can end access sooner.
  • Sign-in security: security cookies help protect your requests. Some last for the browser session; others are used briefly while you sign in with a provider such as Google.
  • Your choices: browser storage remembers your language, pricing currency, weather display choice, and whether you have seen a list-mode tip. It also remembers where to return after email sign-in. These saved choices have no automatic expiry.
  • Quick checklist: your answers and checklist changes are saved in this browser, with no automatic expiry. You can start over from the checklist or clear the site data in your browser.
  • Next Time notes: when a note cannot be sent, it stays in this browser until it is sent successfully or removed. Signing out also clears these waiting notes.

You can clear cookies and site data in your browser settings. This can end your access from this browser, reset your choices, and remove your quick checklist or notes that have not been sent. It does not delete trips saved on our servers.

To return to saved trips, sign in to your account or use an access email or recovery key you have already set up. Without a recovery option, you may not be able to return to trips linked only to this browser.

How long we keep things

  • Active trips: kept while the Host keeps them. A trip ending does not automatically erase the crew’s lists.
  • Deleted trips: become unavailable immediately and are scheduled for permanent removal from the working database within 30 days.
  • Personal-data deletion: removes the identity, credentials, Personal lists, and live sessions immediately. Hosted trips are placed into the same 30-day deletion queue.
  • Access challenges: links and codes stop working after 15 minutes. Host-issued pending access invitations stop working after seven days. Expired security records are removed after a short abuse-prevention period, normally within 30 additional days.
  • Queued access mail: encrypted delivery details are cleared after sending or giving up, within the 15-minute sending window during normal operation. Short-lived delivery and resend-control records are removed after 24 hours.
  • Account sessions: expire after 30 days without meaningful activity or 180 days from sign-in, whichever comes first, and can be revoked sooner with Sign Out Everywhere. Expired or revoked session records are scheduled for removal within 30 days.
  • Support audit records: searches, detail views, email reveals, and support deletions are recorded without search text, email addresses, or response contents and retained for up to 90 days.
  • Operational telemetry: retained for up to 90 days unless a shorter period is configured.

Encrypted database backups age out on the hosting provider’s backup schedule. Deleted information may remain in a protected backup until that copy is overwritten, and is used only for disaster recovery.

Your access, correction, and deletion choices

Most choices are available without sending Camplist an email:

  • Open Account to download a JSON copy of your personal Camplist data.
  • Manage your profile, optional password, and connected Google or Microsoft sign-ins. Connecting one does not change your recovery email.
  • Use Sign Out Everywhere to revoke every active device session.
  • Delete an individual trip from Trip Settings if you are its Host.
  • Delete your Camplist account from Account. Trips you Host become unavailable; on trips hosted by someone else, your membership and personal checklist are removed.

Data deletion is permanent from the app and cannot be undone. The confirmation screen explains the impact before anything is removed.

How we protect the trail

Camplist uses encrypted transport, protected email storage, keyed address lookup, hashed passwords and access secrets, revocable sessions, role checks on the server, rate limits, private real-time trip channels, and privacy-safe logs.

No online service can promise perfect security. Keep invitation links, magic links, and signed-in devices within the people you trust.

Changes and privacy questions

We may update this notice as Camplist changes or the law develops. The date at the top will move when the changes are meaningful, and an in-app notice may be used when appropriate.

Questions about privacy, account access, or a connected provider can be sent to campdirector@makeacamplist.com. Please do not send passwords, access links, confirmation codes, or invitation codes.

Subscriptions and optional email

When subscriptions launch, Stripe Managed Payments will handle paid transactions as Merchant of Record through Link. Camplist keeps your plan, access start and end dates, billing currency where applicable, and limited reconciliation records needed to provide your access; we do not store card credentials.

Trip reminders and Camping tips are separate optional choices, off unless you explicitly choose them. You can save your choices now in Account for these future emails. We keep a history of consent and withdrawal. You can stop optional emails without signing in from an email's unsubscribe link. Necessary account, security and billing messages remain separate. We do not use open-tracking pixels or build advertising profiles.