The short version
Privacy
We collect the minimum we need to tell you when a campsite opens up — your email, and your phone number only if you choose text alerts. We don’t sell your information and we don’t share your phone number or texting consent with anyone for marketing. We use privacy-first product analytics (PostHog, with your IP address turned off) to understand how the product is used — there are no advertising or cross-site trackers anywhere, and if your browser sends a Global Privacy Control or Do Not Track signal we don’t load analytics at all. You can see, download, or delete your data anytime: use Manage my data, reply STOP to a text, use the unsubscribe link in any email, or write [email protected]. The rest of this page is the honest detail.
Who we are
CampingSorted is a small, solo-built campsite-availability alert service operated by CampingSorted LLC (Washington, USA). We watch the parks you ask us to and notify you when a site frees up. For anything about your data, the fastest route is a real human: [email protected].
What we collect, and why
We collect only what each thing you do actually requires:
- Your email address — to send you the beta invite and the availability alerts you asked for, and to reach you about your account or this service.
- Your mobile phone number — only if you choose to receive text (SMS) alerts. We use it solely to send the alerts and service messages you opted into (and the confirmation/HELP/STOP replies that go with them). Texting is optional; leave it off and we never ask for or store a number. We support mobile numbers in the United States and Canada only.
- The parks, sites, and dates you watch — so we know what to watch and what to alert you about. This is your trip data; see “We never sell your activity” below.
- The date and time you signed up or created a watch, and a source label (which page you came from).
- An approximate country (a two-letter country code), to understand roughly where interest is coming from.
- If you buy a paid plan — your payment is handled by our processor Stripe. We receive a confirmation, a payment reference, and the email tied to the purchase — never your card number, which stays with Stripe.
If you create an account (coming with the app — not yet live), we also receive a Firebase account identifier to tie your session to your identity. We store all raw contact details (email, phone, Firebase identifier) in an isolated, access-controlled database — the “vault” elsewhere on this page — that our analytics infrastructure cannot read into. It is held in Google Cloud’s US multi-region today. Access is limited to the verified account holder and, in limited support/legal-compliance cases, to the founder with mandatory audit logging.
Behavioral analytics (pseudonymous). We measure how people move through the product — which features they use, where they get stuck, whether an alert leads to a booking — using PostHog, configured with IP collection off. Events are keyed by a pseudonymous identifier that can’t be linked back to you without the vault; your name, email, and phone are never sent to PostHog. We do not track you across other websites and we do not use this data for advertising. If your browser sends a Global Privacy Control or Do Not Track signal, we don’t load PostHog for that browsing session.
Error reports. When a page here hits a JavaScript error — or your browser blocks something the page tried to load — your browser sends us a short diagnostic report so we can fix it: the error message, a stack trace, the script and line it came from, and the path of the page you were on (never the query string). It goes to us, not to any third party, and it is not analytics. These reports are meant to describe the bug, not you — we don’t put your details in them, and we cap how many a page can send.
We do not store your IP address in our application, your device or browser fingerprint, or your full name. One thing you don’t hand us directly: if you send feedback or report a problem, we keep your browser’s user-agent string alongside your note, because “it’s broken” is hard to reproduce without knowing the browser. We use a hidden anti-spam field on our forms; if it’s filled in (which only automated bots do), we discard the submission.
How you consent to messages — and how you opt out
We only message you because you asked us to. When you sign up or turn on a channel, you give express consent for that channel:
- Text (SMS): you enter your own mobile number and tick the consent box before any text is sent. Message frequency varies (you only hear from us when a site you’re watching opens, plus the occasional service notice). Message and data rates may apply. Reply STOP to any text to unsubscribe immediately, or HELP for help.
- Email: every email identifies us as the sender and carries a working unsubscribe link.
- Push (in the app, when available): controlled by your device’s notification settings.
You can withdraw consent for any channel at any time and we’ll stop — promptly, and at no cost. Opting out of alerts is separate from deleting your data; you can do either or both (see “Your choices and rights”).
Who we share it with (and who we don’t)
We do not sell, rent, or share your information with anyone for their own marketing. In particular, your phone number and your SMS opt-in (consent) are never shared with third parties or affiliates for marketing or promotional purposes.
To actually run the service we rely on a few service providers (“processors”), who may only handle your data to perform the task we hired them for:
- Cloudflare — hosts the website and stores the signup list. As the host, Cloudflare also processes basic connection information (including your IP address) at its edge to deliver and protect the site, even though our application doesn’t store it.
- SendGrid (Twilio Inc.) — used to send the emails you signed up for (sign-in / verification and the availability alerts). We also use Google Workspace for our own support inbox, so if you email us directly your message is handled there.
- Twilio Inc. — used to send the text (SMS) alerts you opted into. To deliver a text, your number is necessarily passed to Twilio and on to the mobile carriers (and the registry carriers use to verify legitimate senders) — that is simply how a text message reaches your phone, and it is done only to deliver the messages you asked for, never for marketing.
- Stripe — processes payments if you buy a paid plan. Stripe receives the email and payment details needed to take the payment and handles your card information directly under its own privacy policy; we never receive or store your card number.
- PostHog — product analytics (US region). PostHog processes only pseudonymous event data with your IP turned off; your email, phone, and raw identity are never sent to it. PostHog is bound by a signed Data Processing Agreement limiting its use to analytics on our behalf. If your browser sends a Global Privacy Control or Do Not Track signal, we don’t load PostHog for that session.
- Google Cloud / Firebase — infrastructure, authentication, and data storage. Our application data lives in Google Cloud under our account, in the US multi-region: both the locked-down contact-details database and the pseudonymous analytics layer (behavioral events exported from PostHog).
- Google Vertex AI / Gemini — not in use today. If we ever enable it, it would only be for limited, operator-initiated support and compliance work (for example, helping respond to a support request or a privacy request), and only once a Google Data Processing Agreement — including no-training terms — is on file. See “How AI is (and isn’t) used” below.
- Google Workspace — our support inbox. If you email us directly, your message is handled there.
If we ever add another processor, we’ll list it here before it touches your data. We may also disclose information if required by law (e.g. a valid legal request), which we’ll narrow to what’s required.
We never sell your activity
Your searches, watches, alert events, and whether you ended up booking are a first-party asset we use only to make our product better — alert quality, coverage prioritization, and future features. This activity is never sold, never shared with any third party, and never fed into any separate data product, including to the park agencies whose public availability we watch.
Cookies and tracking
We run privacy-first product analytics across campingsorted.com — marketing pages and the signed-in app alike — using PostHog, with IP-address collection turned off and events keyed to a pseudonymous identifier (never your name or email), as described under “Behavioral analytics” above. PostHog keeps that identifier in your browser’s local storage — not a cookie. There is no advertising, social-media, or cross-site tracking script on the page, and nothing follows you to other sites. The signed-in app uses the minimum session storage needed to keep you logged in.
Do Not Track (DNT) and Global Privacy Control (GPC). We honour both
as an opt-out: if your browser sends a GPC signal
(navigator.globalPrivacyControl) or a DNT signal, our
analytics script does not load PostHog for that browsing session — nothing is
captured or sent. (Error reports are separate and still apply — see “What
we collect” above.) We also do not sell or share your personal information for
cross-context behavioral advertising regardless of these signals — that stance
is unconditional, not signal-dependent.
Where it’s stored, and how long we keep it
Here is where each kind of data lives.
| Data | Where | Region |
|---|---|---|
| Raw contact details: verified email, phone, account identifier | Google Cloud Firestore (isolated, access-controlled database) | United States |
| Pseudonymous analytics (behavioral events keyed by a random id) | PostHog (US region), exported to Google BigQuery | United States |
| Watch data (parks, sites, dates) and account state | Google Cloud Firestore | United States |
| Pre-launch email signups | Cloudflare Workers KV | Cloudflare global edge |
Cross-border transfers. Your contact details and watch data are stored in Google Cloud in the United States, where they are subject to US law. Pre-launch signup emails are held by Cloudflare at its global edge network, which may place them outside your country. If you use the service from Canada, these are cross-border transfers, and we disclose them here. Pseudonymous analytics events are likewise processed and stored in the United States (PostHog’s US region and our BigQuery).
How long we keep it. We keep your data only as long as we need it for the service you asked for, or until you ask us to delete it — whichever comes first. Our messaging providers keep their own delivery logs for a limited period (Twilio’s default to roughly 13 months); when you ask us to delete your data we also request deletion/redaction from them, and where a provider can only purge on its own schedule we’ll tell you the window. When you delete your account, the vault records, identity mappings, and behavioral events tied to your pseudonymous id are purged in a cascade (see “Manage my data” below).
Retention schedule. Here is how long we hold each type of data.
| Data type | How long we keep it |
|---|---|
| Vault PII — verified email, phone number, account identifier | Until you request deletion or close your account, whichever comes first |
| Watch data — parks, sites, dates, alert preferences | For the duration of your active service relationship; purged in the deletion cascade on request |
| Pseudonymous behavioral analytics (PostHog events keyed to a random identifier) | Retained until you delete it or close your account; purged in the deletion cascade on request. |
| Consent records — fact of consent or withdrawal, channel, date (no message content) | For the duration of the service relationship and a limited period afterward, then deleted or anonymized. |
| Messaging provider delivery logs — Twilio (SMS), SendGrid (email) | Per processor; Twilio defaults to approximately 13 months; we request deletion or redaction on your DSAR request where the provider allows it |
| Pre-launch email signups (Cloudflare KV) | Until the launch-list purpose is fulfilled or until you ask us to remove you |
| Feedback and bug reports (your note, your email if you gave one, the page, your browser’s user-agent) | 180 days, then deleted automatically |
Your choices and rights
You have rights over your personal information. The specifics depend on where you live, but we honor these rights regardless of your location. You can ask us to:
- Show you what we hold about you (access / know).
- Correct inaccurate information.
- Export your data in a portable format.
- Delete your data — permanently. See “How to exercise them” below for exactly what we do automatically and what we do by hand today.
- Stop messaging you — reply STOP to any text, use the unsubscribe link in any email, or write to us. You can withdraw consent for any channel at any time at no cost.
The fastest way to exercise these is Manage my data (see the step-by-step below), or email [email protected].
California residents — CCPA / CPRA
If you are a California resident you have the right to know the categories and specific pieces of personal information we collect and the parties we share it with; to delete it; to correct it; to data portability; to opt out of sale or sharing (we do not sell your personal information and do not share it for cross-context behavioral advertising); to limit the use of sensitive personal information (your mobile number — see below); and to non-discrimination for exercising any of these.
Canadian residents — PIPEDA and Québec Law 25
If you are a Canadian resident you have the right of access (we respond within 30 days), correction, withdrawal of consent, data portability (Law 25), the right to de-indexing / be forgotten (Law 25), and the right to be informed about automated decisions with significant effects. Our position is that we provide notifications and the booking decision is always made by you. Our commercial messages comply with Canada’s Anti-Spam Legislation (CASL). Our privacy officer is the founder (Eric Broyhill, [email protected]).
Data minimization and pseudonymization
We keep analytics data-minimized. Two controls are active today: (1) IP addresses are not collected — PostHog is configured with IP collection off, so your IP is not stored in or linked to any behavioral data; (2) analytics are pseudonymous — events are linked to a random identifier, not your name or email, and the link to your real identity exists only in the vault. When we open a queryable analytics surface, it additionally enforces a minimum group size, so a data point that could single you out is suppressed or generalized rather than exposed.
Security measures
We take concrete steps to protect your personal information. Here is a plain-language description of the safeguards in place, consistent with PIPEDA Principle 7 and Québec Law 25:
- Isolated contact store. Raw contact details (email address, phone number, account identifier) are stored in a dedicated, access-controlled database that our analytics infrastructure cannot read into. No analytics service holds credentials to the vault, and no vault service holds credentials to the analytics layer.
- Encryption at rest. Data in the vault is encrypted at rest with AES-256, using keys managed by our cloud provider (Google Cloud).
- Least-privilege service accounts. Access is split between separate service accounts with the minimum permissions each task requires: the service that can join analytics records cannot read contact details, and vice versa. One exception, which we would rather state than gloss: the deployment automation that creates and manages both stores necessarily holds administrative access to each. It runs only on audited, branch-pinned deployments — never in response to anything you do — but it is a system that can reach both sides.
- Encryption in transit. All connections between our services use TLS (version 1.2 minimum, 1.3 where available).
- Singling-out protection (k-anonymity floor). Built and tested; it protects the queryable analytics surface (the cohort views we open in a later phase), which suppresses any data point belonging to a group smaller than a minimum threshold, so a user whose watch history would be uniquely identifiable is generalized or withheld rather than exposed. The raw events captured today carry no name, email, or IP.
- Audit logging. Any access to raw personal data by the founder in support or legal-compliance cases is logged. These audit logs are retained separately and are not erased by a user data-deletion request.
The security design is guided by the OWASP Application Security Verification Standard (ASVS) Level 2 for services that handle personal information.
How AI is (and isn’t) used with your data
What we use AI for. In limited, operator-initiated support and compliance contexts — for example, to help respond to a support request or carry out a privacy (DSAR) review — personal information may be processed by an approved AI provider under a Data Processing Agreement (DPA). The only approved providers are a locally-run model (no network egress, data stays on the founder’s machine) and Google Vertex AI / Gemini via Google’s cloud infrastructure. Neither is in use yet. Before any of your information reaches Gemini, we will have a Google Data Processing Agreement on file limiting use to processing on our behalf — we do not have one today, and until we do, that path stays off.
What we never do. Your personal information is:
- Never used to train any AI model. The locally-run model cannot — it never leaves the founder’s machine. For Gemini we will confirm the no-training terms in writing as part of the DPA above before that path is ever switched on.
- Never sent to a general or third-party chat AI, including Anthropic / Claude. The AI assistant the founder uses for day-to-day work does not have access to the vault or to raw personal data. This is enforced by credential and network isolation: vault credentials are not available to the general AI process, and the output of any secure analysis goes to a local, access-controlled file on the founder’s machine — never back into any AI model’s context.
- Never used for advertising, profiling, or any third-party benefit. Any AI processing is strictly for internal support and compliance tasks.
Exercising your rights — how “Manage my data” works
Use Manage my data (or email [email protected] with “Privacy request” in the subject). The self-serve flow is not live yet — today, email us and we will action your request by hand. Here’s what happens either way:
- We verify it’s you. We email a one-time, expiring link to the address on file. Opening it confirms you control that inbox — we can’t fulfill a request without this, because responding to an unverified request could expose someone else’s data. (For push-only setups with no email, those records are deleted automatically after a fixed period.)
- Access & download. We email you a structured export of the information we hold — contact details, watch data, and a summary of your behavioral events. We never show the raw export on a web page.
- Delete. We delete your information across the vault, identity mappings, and behavioral events (including prior-session ids). Removal from our analytics tool and from Twilio and SendGrid is not automated, and neither is the rest of the cascade yet — we run it by hand and tell you what was removed.
- Withdraw consent. You can withdraw marketing consent and we’ll stop those messages; we keep an append-only record of the consent and the withdrawal as our legal evidence (it contains no message content, just the fact, the channel, and the date).
Sensitive personal information
Under the California Privacy Rights Act (CPRA), certain information is “sensitive.” Of what we collect, only your mobile phone number qualifies — used solely to deliver the SMS alerts and service messages you opted into, never for any other purpose and never shared for marketing. We do not collect Social Security numbers, financial account numbers (Stripe handles payment data under its own policy), precise geolocation, or any racial, religious, health, biometric, or private-communication data.
Categories of personal information we collect (CCPA disclosure)
We run privacy-first analytics: the pseudonymous behavioral events and inferences below are keyed to a random identifier with your IP turned off, and are never sold or shared. The error reports and the feedback user-agent described earlier on this page are separate from analytics.
| Category | What | Purpose | Sold / shared? |
|---|---|---|---|
| Identifiers | Email; phone (if chosen); push endpoint; account id | Service delivery, verification, account management | No |
| Internet / network activity | Pseudonymous behavioral events (IP off) | Product improvement, funnel analytics | No |
| Geolocation | Two-letter country code (approximate) | Understanding coverage demand | No |
| Commercial information | Payment reference (via Stripe) | Account management | No |
| Inferences drawn from PI | Pseudonymous funnel / conversion profile | Product improvement | No |
| Sensitive PI | Mobile phone number (if chosen) | SMS alert delivery only | No |
Automated decision-making
When a campsite matching your watch criteria becomes available, our system automatically sends you an alert. This processing is automated — a computer matches your watch configuration against availability data without a human reviewing each individual match. However:
- Alert delivery does not make any legal, financial, or otherwise significant decision about you. It decides only whether to notify you of an opening; the decision to book or not is always yours.
- No automated logic denies you service, applies a different price, or assigns you a score based on your personal data.
If you have questions about any automated processing that affects you, or you would like a human to review it, write to [email protected].
Business transfers
If CampingSorted LLC is involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of its assets, personal information we hold may be transferred as part of that transaction. Any successor entity would be bound by this privacy policy. If a transaction would result in a materially different use of your personal information, we will notify you and, where required by applicable law, give you a meaningful choice before your data is used in a new way.
Children
CampingSorted isn’t directed at children, and we don’t knowingly collect information from anyone under 16.
Privacy Officer
CampingSorted has designated a Privacy Officer responsible for the organization’s compliance with applicable privacy legislation, including PIPEDA and Québec Law 25 (Art. 3.1). The Privacy Officer is the founder:
- Title: Privacy Officer, CampingSorted LLC
- Contact: [email protected]
You may direct privacy complaints, access requests, or questions about this policy to the Privacy Officer. If your concern is not resolved to your satisfaction, you may escalate to the relevant supervisory authority:
- Canada (federal): Office of the Privacy Commissioner of Canada — priv.gc.ca
- Québec: Commission d’accès à l’information (CAI) — cai.gouv.qc.ca
- California: California Privacy Protection Agency (CPPA)
Governing law
CampingSorted is operated by CampingSorted LLC, a limited liability company organized under the laws of the State of Washington, USA. This privacy policy and any dispute about our privacy practices are governed by the laws of Washington State, without regard to its conflict-of-law provisions — and without limiting any statutory privacy rights you hold as a California resident under CCPA / CPRA, as a Canadian resident under PIPEDA or Québec Law 25, or as a resident of any other jurisdiction whose privacy laws apply to you by force of law.
Changes to this page
As the product grows (accounts, the app, paid plans), this page will grow with it. When it changes materially we’ll update the date at the top, and we’ll never quietly broaden how we use data you’ve already given us.