Organizers and their staff who create accounts; participants (campers, parents/guardians, volunteers, staff) whose information an organizer enters or who sign up; and viewers who open a public camp link.
Account information — organizer name, email, and password (stored only as a salted hash). Payments are processed by Stripe; CampHQ never sees full card numbers.
Camp information entered by organizers or participants — name, email or phone, grade, gender, bunkmate requests, and bus/cabin/team/group assignments.
Health & emergency information (if the organizer enables it) — allergies, medications, dietary needs, and emergency contacts. We treat this as sensitive and use it only to run that camp.
Photos — organizers may upload photos or link an external shared album they host. Technical data — standard logs used to operate and secure the service. We do not sell personal information or use it for advertising.
To provide and secure the service for the organizer's camp, authenticate users, enforce access permissions, process the organizer's payment, send service messages, and comply with law.
CampHQ is built and sold for camp organizers, not for children. CampHQ processes camp participant information on the organizer's documented instructions, in order to provide the service. Separately, CampHQ processes account, billing, security, and service-administration information for its own purposes, as described elsewhere in this policy. Organizers are responsible for establishing a lawful basis for submitting participant information and for obtaining any required permissions. That allocation does not limit CampHQ's own obligations under applicable law. Everything in a camp is there because an organizer put it there or invited someone to enter it. A participant reaches a roster one of two ways: an organizer enters them, or they sign themselves up through the organizer's registration link or QR code. Either way the camp belongs to the organizer, and the organizer is responsible for who is on their roster and for obtaining any required verifiable parental consent for participants who are minors, however those participants were added.
We do not use participants' information to build profiles, to advertise, or to sell, and we do not review or use camp data for any purpose beyond running the service for that organizer. Where an organizer is a school or acts for one, camp information may be an education record under FERPA and CampHQ acts as a "school official," using the data only to provide the service. Parents may contact their organizer to review, correct, or delete a child's information, and we will assist.
CampHQ has an optional AI importer: an organizer can drop in a document (a roster spreadsheet, a camp booklet, a schedule, a packing list, a medication list or MAR sheet, or a photo, screenshot, or PDF of one) and have CampHQ read it into structured camp records instead of typing it in by hand. The same AI feature can draft a registration form from a description or from a photo of an existing paper form.
What is sent, and to whom. When an organizer uses this feature, the file or its text content is sent from our server to the Anthropic API (Anthropic, PBC), which we use as a service provider to read it. Whatever is in the document is what gets sent, and because organizers upload real camp paperwork, that can include campers' personal information and, in the case of a medication or health sheet, allergies, medications, and emergency contacts. Word, PowerPoint, OpenDocument, RTF, and EPUB files are converted to text inside the organizer's own browser first, so for those formats only the extracted text is sent. Spreadsheets, PDFs, and photos are sent as text or as the file itself.
Why, and what is not done with it. The only purpose is to extract structured data (people, assignments, schedule blocks, list items, form fields) and return it to the organizer for review before anything is saved. The information is not used to train AI models: Anthropic does not train its models on data submitted through its API by default. We do not use this feature for advertising or profiling, and nothing in it is sold. Organizers who prefer not to use AI can enter or import camp data without it.
Only as needed to run the service: with the organizer and users they authorize; with service providers under contract (Supabase for database, authentication, and storage; Vercel for hosting and server-side processing; Stripe for payments; Anthropic for the AI importer described above; and our email provider for invites and digests); for legal reasons; or in a business transfer subject to this policy. We do not sell personal information.
We keep camp data for as long as the organizer's account is active. We do not run any automatic post-camp deletion schedule, so a camp's information stays in place after the camp ends until an organizer removes it. Organizers are in control: they can delete an individual participant record, an entire camp, or their whole account at any time. Deleting an account is a hard delete, performed immediately and irreversibly in the live service: it removes the organizer's sign-in record and, through database cascades, the camps and participant records they own. There is no undo and we cannot restore it for you. As with any hosted service, residual copies can persist for a limited period in routine encrypted backups and system logs before those are overwritten on their normal cycle, and records held by our service providers (for example, emails already sent, or payment records at Stripe) follow their own retention. Limited billing records are kept as required by law.
Encryption in transit, hashed passwords, and server-enforced access controls (row-level security) so each user only reaches data they're permitted to see. No system is perfectly secure.
Participants should direct access, correction, or deletion requests to their organizer, who we will assist. Organizers can manage account data in-app or contact us. To exercise rights directly, email us below.
CampHQ, operated by SKATTIC LLC: privacy@camphq.app
See also the Terms of Service.