Privacy Policy
This Privacy Policy explains how Campsty ("we", "us", or "our") collects, uses, and protects your personal data when you use our platform. We are committed to complying with the General Data Protection Regulation (GDPR) and applicable national data protection laws.
1. Data Controller Identity
The data controller responsible for your personal data is Campsty (the "Platform"). For questions about this policy or your personal data, contact us at privacy@Campsty.com.
We do not currently have a formal Data Protection Officer (DPO) requirement but will appoint one if processing activities require it under Article 37 GDPR.
2. Data We Collect
We collect the following categories of personal data:
- Authentication data: name, email address, profile photo, and authentication credentials. Authentication is managed through Auth.js-backed account storage.
- Contact data: phone number, where voluntarily provided in your account profile.
- Account and platform data: your account role (camper or campsite owner), subscription tier, and account status flags (for example, whether submissions are restricted following platform moderation).
- Booking data: reservation details including campsite, pitch type, check-in/check-out dates, number of guests, booking status, cancellation reason and who cancelled, the platform booking fee charged, and email reminder timestamps sent in connection with your booking.
- Payment data (via Stripe): billing name, billing address, and payment method details. Card numbers are never stored on our servers — Stripe handles all payment processing as a PCI-DSS-certified processor. If a payment dispute arises, dispute identifiers and status are also stored.
- Booking communications: messages exchanged between campers and campsite owners within the platform messaging system (booking message content, sender, and timestamps).
- Chatbot and support data: conversation content you share with our automated support chatbot, including chat session identifiers, the text content of support tickets you submit (subject, description, and any messages exchanged with support staff), and ticket status records linked to your account.
- Reviews and ratings: review text, star ratings, and owner replies that you submit about a campsite following a completed stay.
- User-submitted location content: if you contribute a wild camping spot or motorhome stop (ställplats) to the platform, we store the name, description, photos, and precise GPS coordinates (latitude and longitude) you provide, linked to your account.
- Voting activity: upvote and downvote actions on campsites, wild camping spots, and ställplatser, linked to your account.
- Usage and analytics data: pages visited, interactions, device type, browser, and approximate geographic region derived from IP address. IP addresses are not stored in identifiable form beyond session duration.
- Campsite owner data: business name, contact email and phone, website, bank account information for payouts (via Stripe Connect), listing content (descriptions, photos, pricing, amenities), and staff invitation email addresses for team members added to manage a campsite.
- Bot-prevention data (via hCaptcha): when you submit certain forms on the platform, hCaptcha verifies that you are a human. This involves processing behavioural and device signals by hCaptcha (Intuition Machines, Inc.) on our behalf. No hCaptcha challenge data is stored on our servers beyond the outcome of verification.
3. Legal Basis for Processing
We process your personal data on the following legal bases under Article 6 GDPR:
- Contract performance (Art. 6(1)(b)): processing necessary to create your account, execute bookings, facilitate payments, and deliver the services you have requested.
- Legitimate interests (Art. 6(1)(f)): fraud prevention, platform security, bot prevention (hCaptcha), spam and abuse moderation, improving our services, and operating the chatbot support function.
- Legal obligation (Art. 6(1)(c)): retaining transaction records for tax and accounting purposes as required by applicable law.
- Consent (Art. 6(1)(a)): for optional marketing communications and for non-essential cookies — you may withdraw consent at any time via account settings or the cookie preference centre.
4. Data We Share
We share your personal data only as described below:
- With campsite owners: when a booking is confirmed, we share the relevant booking details (guest name, contact information, dates, pitch, number of guests, total booking amount) with the campsite owner or their authorised staff so they can fulfil your reservation.
- Owner replies to reviews: when a campsite owner replies to your review, their reply is displayed publicly alongside your review on the campsite listing.
- With third-party processors: we share data with the processors listed in Section 6. These parties act under our instructions and are bound by data processing agreements.
- Legal disclosure: we may disclose personal data if required to do so by law, court order, or regulatory authority.
- We do not sell your personal data to third parties.
5. Data Retention
We retain personal data only as long as necessary for the purposes stated:
- Account data: retained for the lifetime of your account plus 30 days after deletion, after which it is permanently removed.
- Booking records: retained for 7 years from the booking date to comply with tax and accounting obligations. Booking communications (messages) are retained for the same period as the associated booking.
- Payment records: retained according to Stripe's data retention policies (typically 7 years for financial records).
- Reviews and ratings: retained while your account is active and for 30 days after account deletion. Reviews contribute to campsite quality information and are retained even if a booking is cancelled, unless you request erasure.
- Chatbot and support data: chat messages and support tickets are retained for 12 months from the date of the conversation, then deleted.
- User-submitted location content (wild camping spots / ställplatser): retained while the submission is active. If you delete your account, submitted spots are anonymised (submitter link removed) rather than deleted, to preserve the community-contributed map data.
- Google Analytics data: aggregated and anonymised within 90 days; raw event/session data retained for no more than 30 days and collected only after analytics cookie consent.
For full details of our retention periods, including automated enforcement and your rights, see our Data Retention Policy.
6. Third-Party Processors
We share data with the following third-party processors, each bound by data processing agreements and GDPR-compliant safeguards:
- Auth.js-backed account storage — authentication and user management data stored in our application database.
- Stripe — payment processing and payouts (Stripe Connect). Stripe holds EU–US Data Privacy Framework certification and processes data under Standard Contractual Clauses. Stripe may process data on infrastructure in the United States.
- Neon — serverless PostgreSQL database. We store data in the EU (eu-west-1 region). Neon, Inc. is a US company; transfers are covered by Standard Contractual Clauses.
- Vercel — application hosting and edge functions. Vercel, Inc. is a US company that processes request metadata (including IP addresses) at edge locations globally, including in the United States. Transfers are covered by Standard Contractual Clauses and Vercel's DPA.
- Mapbox — map rendering for campsite and spot location display. Mapbox, Inc. is a US company; usage telemetry and map tile requests may be processed by Mapbox under their own privacy policy. Transfers are covered by Standard Contractual Clauses.
- Google Analytics 4 (Google Ireland Ltd / Google LLC) — consent-gated aggregate usage analytics. Google may process analytics identifiers and event metadata under the EU–US Data Privacy Framework and Standard Contractual Clauses; analytics cookies are not set unless you opt in.
- hCaptcha (Intuition Machines, Inc.) — bot prevention and CAPTCHA verification on form submissions. hCaptcha is a US company; data processed during challenge verification may be transferred to the United States under Standard Contractual Clauses. hCaptcha's Privacy Policy.
7. International Data Transfers
We store your primary data in the European Union (Neon database, eu-west-1 region). However, several of our processors are headquartered in the United States and may process personal data on US-based infrastructure:
- Neon, Vercel, Mapbox, and hCaptcha are US-headquartered companies. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism for personal data sent to these processors.
- Stripe holds EU–US Data Privacy Framework certification and uses Standard Contractual Clauses for data transfers.
You may request a copy of the applicable transfer safeguards by contacting us at privacy@Campsty.com.
8. Cookies
We use cookies and similar technologies to operate the platform. At present, we only set strictly necessary cookies (authentication and session management) and functional cookies (your language preference stored in NEXT_LOCALE, and a chatbot session identifier in chatbot_session_id). These are set without a consent prompt because they are essential to delivering the service you have requested.
Analytics cookies for Google Analytics 4 are off by default and are only loaded after you actively opt into analytics in the cookie banner or cookie settings. You can withdraw or update your preferences at any time; when analytics consent is absent or withdrawn, the analytics script is not loaded. We do not set advertising or marketing cookies.
Third-party services embedded in the platform (Stripe for payment checkout, hCaptcha for bot prevention, and Mapbox for maps) may set cookies on their own domains when those features are used. These are described in our Cookie Policy, which also contains the full cookie inventory.
9. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of access (Art. 15): request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): request deletion of your personal data where there is no legitimate reason for us to continue processing it. Note that we may retain certain data where required by law (e.g., financial records).
- Right to restriction of processing (Art. 18): request that we restrict how we use your data in certain circumstances.
- Right to notification (Art. 19): where you have exercised your right to rectification, erasure, or restriction of processing, we will notify each recipient to whom your personal data has been disclosed, unless this proves impossible or involves disproportionate effort.
- Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): object to processing based on our legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making (Art. 22): we do not make decisions about you based solely on automated processing that produce significant legal or similarly significant effects. If this changes, we will update this policy and inform you accordingly.
To exercise any of these rights, contact privacy@Campsty.com. We will respond within 30 days (extendable by a further two months for complex requests, with notice).
You also have the right to lodge a complaint with your national supervisory authority. Examples include: Integritetsskyddsmyndigheten (IMY) in Sweden, Datatilsynet in Norway, Datatilsynet DK in Denmark, and Tietosuojavaltuutetun toimisto in Finland. A full list of EU/EEA supervisory authorities is available on the European Data Protection Board website.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. The 'Last updated' date at the top of this page indicates when the policy was last revised. Continued use of the platform after the effective date constitutes acceptance of the updated policy.
11. Contact / DPO
For any questions, requests, or complaints regarding your personal data or this Privacy Policy, contact us at:
We aim to respond to all privacy requests within 30 days in accordance with GDPR requirements.