The plain version
We collect the small amount of information needed to organize a trip, keep the right campers connected, and protect access. We do not sell personal information, run advertising profiles, or send marketing email. Shared trip plans are visible to the crew; your Personal list stays private unless you choose to share it with the Host and Planners.
What we collect
Trip plans
Trip names, dates, destinations, optional weather locations, campers, roles, packing, groceries, meals, activities, Personal lists, notes, and progress.
Your camp identity
Your display name, selected badge, trip memberships, and whether you are a Camper, Planner, or Host.
Access details
Essential session identifiers, your protected recovery email, one-time access challenges, a password hash if you add a password, and provider identity details if you connect Google or Microsoft.
Safety signals
Network information such as IP address for throttling, security, and suggesting a starting pricing region, plus route-based service logs, status, timing, and trace identifiers.
For a connected provider, Camplist keeps the provider name, issuer, subject identifier, and the email address shown on your Account page. We do not store Google or Microsoft access tokens. A provider email is a sign-in label only: it does not replace your Camplist recovery email or grant access to a trip.
We do not ask for your live device location, an address book, payment information, government identification, biometrics, or advertising interests. The Pricing page may use the IP address already included with a web request to estimate a country and suggest a currency. This does not request browser location permission, and you can always change the suggestion. If a trip Host optionally selects a weather location, Camplist stores that selected trip-level location and its coordinates so it can retrieve an integrated forecast; trip members can see it. A one-time device-location hint may be used only after you ask us to improve search results, and is never stored. Camplist is not a medical record or medication-management service. Keep Personal Item labels general and do not add medication names, doses, diagnoses, medical instructions, financial information, or identification details.
How we use information
- Run the trip-planning and checklist features you choose to use.
- Show each crew the right shared plan and keep role permissions in place.
- Send requested access links, six-digit codes, and essential service messages. These are not marketing emails.
- Prevent guessing, spam, fraud, and unauthorized access.
- Provide limited technical support, security help, and incident response using identity, email, trip-name, role, membership, recent activity, list totals, and deletion-status information.
- Diagnose outages and improve reliability using operational telemetry that replaces private URL values with generic route labels.
- Meet legal obligations and respond to valid legal process when required.
Children’s data: a firm boundary
Children under 13 may not use Camplist directly. They may not hold an interactive identity, receive an access email, use a magic link, or select a profile badge. An adult may include them only as a Managed Camper, which has no application access.
For a Managed Camper, use a first name or nickname and only the ordinary packing or Personal-list details the adult needs. Keep Personal Items general. Do not add a child’s email, precise location, school, medication details, diagnoses, health instructions, or other sensitive information.
Campers aged 13 to 17 may use Camplist only with permission and supervision from a parent or guardian. Where local law sets a higher consent requirement-including parental-authority consent for a minor under 14 in Quebec-that rule applies. The Host is responsible for inviting and supervising younger campers in their crew.
If an adult learns that a child under 13 has direct access, the adult should use the in-app deletion control right away. Deleting the identity signs out its devices and removes its direct connection to trips.
How long we keep things
- Active trips: kept while the Host keeps them. A trip ending does not automatically erase the crew’s lists.
- Deleted trips: become unavailable immediately and are scheduled for permanent removal from the working database within 30 days.
- Personal-data deletion: removes the identity, credentials, Personal lists, and live sessions immediately. Hosted trips are placed into the same 30-day deletion queue.
- Access challenges: links and codes stop working after 15 minutes. Host-issued pending access invitations stop working after seven days. Expired security records are removed after a short abuse-prevention period, normally within 30 additional days.
- Queued access mail: encrypted delivery details are cleared after sending or giving up, within the 15-minute sending window during normal operation. Short-lived delivery and resend-control records are removed after 24 hours.
- Account sessions: expire after 30 days without meaningful activity or 180 days from sign-in, whichever comes first, and can be revoked sooner with Sign Out Everywhere. Expired or revoked session records are scheduled for removal within 30 days.
- Support audit records: searches, detail views, email reveals, and support deletions are recorded without search text, email addresses, or response contents and retained for up to 90 days.
- Operational telemetry: retained for up to 90 days unless a shorter period is configured.
Encrypted database backups age out on the hosting provider’s backup schedule. Deleted information may remain in a protected backup until that copy is overwritten, and is used only for disaster recovery.
Your access, correction, and deletion choices
Most choices are available without sending Camplist an email:
- Open Account to download a JSON copy of your personal Camplist data.
- Manage your profile, optional password, and connected Google or Microsoft sign-ins. Connecting one does not change your recovery email.
- Use Sign Out Everywhere to revoke every active device session.
- Delete an individual trip from Trip Settings if you are its Host.
- Delete your Camplist account from Account. Trips you Host become unavailable; on trips hosted by someone else, your membership and personal checklist are removed.
Data deletion is permanent from the app and cannot be undone. The confirmation screen explains the impact before anything is removed.
How we protect the trail
Camplist uses encrypted transport, protected email storage, keyed address lookup, hashed passwords and access secrets, revocable sessions, role checks on the server, rate limits, private real-time trip channels, and privacy-safe logs.
No online service can promise perfect security. Keep invitation links, magic links, and signed-in devices within the people you trust.
Changes and privacy questions
We may update this notice as Camplist changes or the law develops. The date at the top will move when the changes are meaningful, and an in-app notice may be used when appropriate.
Questions about privacy, account access, or a connected provider can be sent to campdirector@makeacamplist.com. Please do not send passwords, access links, confirmation codes, or invitation codes.
Subscriptions and optional email
When subscriptions launch, Stripe Managed Payments will handle paid transactions as Merchant of Record through Link. Camplist keeps your plan, access start and end dates, billing currency where applicable, and limited reconciliation records needed to provide your access; we do not store card credentials.
Trip reminders and Camping tips are separate optional choices, off unless you explicitly choose them. You can save your choices now in Account for these future emails. We keep a history of consent and withdrawal. You can stop optional emails without signing in from an email's unsubscribe link. Necessary account, security and billing messages remain separate. We do not use open-tracking pixels or build advertising profiles.