The short version

Privacy

We collect the minimum we need to tell you when a campsite opens up — your email, and your phone number only if you choose text alerts. We don’t sell your information and we don’t share your phone number or texting consent with anyone for marketing. We use privacy-first product analytics (PostHog, with your IP address turned off) to understand how the product is used — there are no advertising or cross-site trackers anywhere, and if your browser sends a Global Privacy Control or Do Not Track signal we don’t load analytics at all. You can see, download, or delete your data anytime: use Manage my data, reply STOP to a text, use the unsubscribe link in any email, or write [email protected]. The rest of this page is the honest detail.

Last updated 23 July 2026

Who we are

CampingSorted is a small, solo-built campsite-availability alert service operated by CampingSorted LLC (Washington, USA). We watch the parks you ask us to and notify you when a site frees up. For anything about your data, the fastest route is a real human: [email protected].

What we collect, and why

We collect only what each thing you do actually requires:

If you create an account (coming with the app — not yet live), we also receive a Firebase account identifier to tie your session to your identity. We store all raw contact details (email, phone, Firebase identifier) in an isolated, access-controlled database — the “vault” elsewhere on this page — that our analytics infrastructure cannot read into. It is held in Google Cloud’s US multi-region today. Access is limited to the verified account holder and, in limited support/legal-compliance cases, to the founder with mandatory audit logging.

Behavioral analytics (pseudonymous). We measure how people move through the product — which features they use, where they get stuck, whether an alert leads to a booking — using PostHog, configured with IP collection off. Events are keyed by a pseudonymous identifier that can’t be linked back to you without the vault; your name, email, and phone are never sent to PostHog. We do not track you across other websites and we do not use this data for advertising. If your browser sends a Global Privacy Control or Do Not Track signal, we don’t load PostHog for that browsing session.

Error reports. When a page here hits a JavaScript error — or your browser blocks something the page tried to load — your browser sends us a short diagnostic report so we can fix it: the error message, a stack trace, the script and line it came from, and the path of the page you were on (never the query string). It goes to us, not to any third party, and it is not analytics. These reports are meant to describe the bug, not you — we don’t put your details in them, and we cap how many a page can send.

We do not store your IP address in our application, your device or browser fingerprint, or your full name. One thing you don’t hand us directly: if you send feedback or report a problem, we keep your browser’s user-agent string alongside your note, because “it’s broken” is hard to reproduce without knowing the browser. We use a hidden anti-spam field on our forms; if it’s filled in (which only automated bots do), we discard the submission.

How you consent to messages — and how you opt out

We only message you because you asked us to. When you sign up or turn on a channel, you give express consent for that channel:

You can withdraw consent for any channel at any time and we’ll stop — promptly, and at no cost. Opting out of alerts is separate from deleting your data; you can do either or both (see “Your choices and rights”).

Who we share it with (and who we don’t)

We do not sell, rent, or share your information with anyone for their own marketing. In particular, your phone number and your SMS opt-in (consent) are never shared with third parties or affiliates for marketing or promotional purposes.

To actually run the service we rely on a few service providers (“processors”), who may only handle your data to perform the task we hired them for:

If we ever add another processor, we’ll list it here before it touches your data. We may also disclose information if required by law (e.g. a valid legal request), which we’ll narrow to what’s required.

We never sell your activity

Your searches, watches, alert events, and whether you ended up booking are a first-party asset we use only to make our product better — alert quality, coverage prioritization, and future features. This activity is never sold, never shared with any third party, and never fed into any separate data product, including to the park agencies whose public availability we watch.

Cookies and tracking

We run privacy-first product analytics across campingsorted.com — marketing pages and the signed-in app alike — using PostHog, with IP-address collection turned off and events keyed to a pseudonymous identifier (never your name or email), as described under “Behavioral analytics” above. PostHog keeps that identifier in your browser’s local storage — not a cookie. There is no advertising, social-media, or cross-site tracking script on the page, and nothing follows you to other sites. The signed-in app uses the minimum session storage needed to keep you logged in.

Do Not Track (DNT) and Global Privacy Control (GPC). We honour both as an opt-out: if your browser sends a GPC signal (navigator.globalPrivacyControl) or a DNT signal, our analytics script does not load PostHog for that browsing session — nothing is captured or sent. (Error reports are separate and still apply — see “What we collect” above.) We also do not sell or share your personal information for cross-context behavioral advertising regardless of these signals — that stance is unconditional, not signal-dependent.

Where it’s stored, and how long we keep it

Here is where each kind of data lives.

DataWhereRegion
Raw contact details: verified email, phone, account identifierGoogle Cloud Firestore (isolated, access-controlled database)United States
Pseudonymous analytics (behavioral events keyed by a random id)PostHog (US region), exported to Google BigQueryUnited States
Watch data (parks, sites, dates) and account stateGoogle Cloud FirestoreUnited States
Pre-launch email signupsCloudflare Workers KVCloudflare global edge

Cross-border transfers. Your contact details and watch data are stored in Google Cloud in the United States, where they are subject to US law. Pre-launch signup emails are held by Cloudflare at its global edge network, which may place them outside your country. If you use the service from Canada, these are cross-border transfers, and we disclose them here. Pseudonymous analytics events are likewise processed and stored in the United States (PostHog’s US region and our BigQuery).

How long we keep it. We keep your data only as long as we need it for the service you asked for, or until you ask us to delete it — whichever comes first. Our messaging providers keep their own delivery logs for a limited period (Twilio’s default to roughly 13 months); when you ask us to delete your data we also request deletion/redaction from them, and where a provider can only purge on its own schedule we’ll tell you the window. When you delete your account, the vault records, identity mappings, and behavioral events tied to your pseudonymous id are purged in a cascade (see “Manage my data” below).

Retention schedule. Here is how long we hold each type of data.

Data type How long we keep it
Vault PII — verified email, phone number, account identifier Until you request deletion or close your account, whichever comes first
Watch data — parks, sites, dates, alert preferences For the duration of your active service relationship; purged in the deletion cascade on request
Pseudonymous behavioral analytics (PostHog events keyed to a random identifier) Retained until you delete it or close your account; purged in the deletion cascade on request.
Consent records — fact of consent or withdrawal, channel, date (no message content) For the duration of the service relationship and a limited period afterward, then deleted or anonymized.
Messaging provider delivery logs — Twilio (SMS), SendGrid (email) Per processor; Twilio defaults to approximately 13 months; we request deletion or redaction on your DSAR request where the provider allows it
Pre-launch email signups (Cloudflare KV) Until the launch-list purpose is fulfilled or until you ask us to remove you
Feedback and bug reports (your note, your email if you gave one, the page, your browser’s user-agent) 180 days, then deleted automatically

Your choices and rights

You have rights over your personal information. The specifics depend on where you live, but we honor these rights regardless of your location. You can ask us to:

The fastest way to exercise these is Manage my data (see the step-by-step below), or email [email protected].

California residents — CCPA / CPRA

If you are a California resident you have the right to know the categories and specific pieces of personal information we collect and the parties we share it with; to delete it; to correct it; to data portability; to opt out of sale or sharing (we do not sell your personal information and do not share it for cross-context behavioral advertising); to limit the use of sensitive personal information (your mobile number — see below); and to non-discrimination for exercising any of these.

Canadian residents — PIPEDA and Québec Law 25

If you are a Canadian resident you have the right of access (we respond within 30 days), correction, withdrawal of consent, data portability (Law 25), the right to de-indexing / be forgotten (Law 25), and the right to be informed about automated decisions with significant effects. Our position is that we provide notifications and the booking decision is always made by you. Our commercial messages comply with Canada’s Anti-Spam Legislation (CASL). Our privacy officer is the founder (Eric Broyhill, [email protected]).

Data minimization and pseudonymization

We keep analytics data-minimized. Two controls are active today: (1) IP addresses are not collected — PostHog is configured with IP collection off, so your IP is not stored in or linked to any behavioral data; (2) analytics are pseudonymous — events are linked to a random identifier, not your name or email, and the link to your real identity exists only in the vault. When we open a queryable analytics surface, it additionally enforces a minimum group size, so a data point that could single you out is suppressed or generalized rather than exposed.

Security measures

We take concrete steps to protect your personal information. Here is a plain-language description of the safeguards in place, consistent with PIPEDA Principle 7 and Québec Law 25:

The security design is guided by the OWASP Application Security Verification Standard (ASVS) Level 2 for services that handle personal information.

How AI is (and isn’t) used with your data

What we use AI for. In limited, operator-initiated support and compliance contexts — for example, to help respond to a support request or carry out a privacy (DSAR) review — personal information may be processed by an approved AI provider under a Data Processing Agreement (DPA). The only approved providers are a locally-run model (no network egress, data stays on the founder’s machine) and Google Vertex AI / Gemini via Google’s cloud infrastructure. Neither is in use yet. Before any of your information reaches Gemini, we will have a Google Data Processing Agreement on file limiting use to processing on our behalf — we do not have one today, and until we do, that path stays off.

What we never do. Your personal information is:

Exercising your rights — how “Manage my data” works

Use Manage my data (or email [email protected] with “Privacy request” in the subject). The self-serve flow is not live yet — today, email us and we will action your request by hand. Here’s what happens either way:

Sensitive personal information

Under the California Privacy Rights Act (CPRA), certain information is “sensitive.” Of what we collect, only your mobile phone number qualifies — used solely to deliver the SMS alerts and service messages you opted into, never for any other purpose and never shared for marketing. We do not collect Social Security numbers, financial account numbers (Stripe handles payment data under its own policy), precise geolocation, or any racial, religious, health, biometric, or private-communication data.

Categories of personal information we collect (CCPA disclosure)

We run privacy-first analytics: the pseudonymous behavioral events and inferences below are keyed to a random identifier with your IP turned off, and are never sold or shared. The error reports and the feedback user-agent described earlier on this page are separate from analytics.

CategoryWhatPurposeSold / shared?
IdentifiersEmail; phone (if chosen); push endpoint; account idService delivery, verification, account managementNo
Internet / network activityPseudonymous behavioral events (IP off)Product improvement, funnel analyticsNo
GeolocationTwo-letter country code (approximate)Understanding coverage demandNo
Commercial informationPayment reference (via Stripe)Account managementNo
Inferences drawn from PIPseudonymous funnel / conversion profileProduct improvementNo
Sensitive PIMobile phone number (if chosen)SMS alert delivery onlyNo

Automated decision-making

When a campsite matching your watch criteria becomes available, our system automatically sends you an alert. This processing is automated — a computer matches your watch configuration against availability data without a human reviewing each individual match. However:

If you have questions about any automated processing that affects you, or you would like a human to review it, write to [email protected].

Business transfers

If CampingSorted LLC is involved in a merger, acquisition, financing, reorganization, or sale of all or a portion of its assets, personal information we hold may be transferred as part of that transaction. Any successor entity would be bound by this privacy policy. If a transaction would result in a materially different use of your personal information, we will notify you and, where required by applicable law, give you a meaningful choice before your data is used in a new way.

Children

CampingSorted isn’t directed at children, and we don’t knowingly collect information from anyone under 16.

Privacy Officer

CampingSorted has designated a Privacy Officer responsible for the organization’s compliance with applicable privacy legislation, including PIPEDA and Québec Law 25 (Art. 3.1). The Privacy Officer is the founder:

You may direct privacy complaints, access requests, or questions about this policy to the Privacy Officer. If your concern is not resolved to your satisfaction, you may escalate to the relevant supervisory authority:

Governing law

CampingSorted is operated by CampingSorted LLC, a limited liability company organized under the laws of the State of Washington, USA. This privacy policy and any dispute about our privacy practices are governed by the laws of Washington State, without regard to its conflict-of-law provisions — and without limiting any statutory privacy rights you hold as a California resident under CCPA / CPRA, as a Canadian resident under PIPEDA or Québec Law 25, or as a resident of any other jurisdiction whose privacy laws apply to you by force of law.

Changes to this page

As the product grows (accounts, the app, paid plans), this page will grow with it. When it changes materially we’ll update the date at the top, and we’ll never quietly broaden how we use data you’ve already given us.

← Back to CampingSorted