Privacy Policy
Version 1.4 · 2026-08-03 · AI-drafted, founder-reviewed; lawyer review scheduled at the €5k-MRR unlock.
Who we are
Camp44 ("we") provides the online booking system used by the campground
you are booking with. For your booking data, **the campground is the data
controller** and Camp44 is its processor (see our Data Processing
Agreement). For the account data of campground operators, Camp44 is the
controller.
The controller of operator account data (GDPR Art. 13(1)(a)):
| Entity | Camp44 — Gergő Miklós, sole trader |
| Contact | privacy@camp44.com (postal address on request, and published here before the first live park) |
| Data protection officer | Not appointed — none of the Art. 37(1) triggers apply. Privacy questions go to the contact above. |
The controller of GUEST data is the campground you booked with — its legal
name, registered address and VAT number are on your booking confirmation and on
its invoice. Ask them first; we will always help them answer.
What we process, why, and on what legal basis
| Data | Purpose | Legal basis |
| Name, email, phone, party composition | Creating and managing your booking | Contract performance (Art. 6(1)(b) GDPR) |
| Payment status and references (never card numbers — those go directly to the payment provider) | Collecting payment, deposits, refunds | Contract performance |
| Identity and travel-document data of your party (where collected) | Statutory guest registration with national/local authorities (e.g. Alloggiati Web in Italy, fiche de police in France, Meldeschein in Germany) | Legal obligation (Art. 6(1)(c)) |
| Invoicing data | Issuing legally required invoices and bookkeeping | Legal obligation |
| Email delivery logs | Making sure transactional messages (confirmation, payment, cancellation) arrive exactly once | Legitimate interest (Art. 6(1)(f)) |
| Vehicle plate (optional) | Barrier/gate automation at parks that use it | Contract performance |
| Marketing preference | Only if you opt in at checkout | Consent (Art. 6(1)(a)) — revocable anytime |
How long we keep it (retention schedule)
These windows are enforced in software by automated deletion sweeps — the
same values the code runs on:
| Data class | Retention |
| Guest-registration records (police/statistics) | Per country: FR 183 days from arrival · IT 30 days (the transmitted data is deleted once the Alloggiati receipt is issued; the receipt itself is kept 5 years) · NL 3 years · DE 365 days · BE 7 years · AT 7 years from the register entry · ES 3 years · PT 1 year from the departure communication, after which destruction is required by law · HR 365 days · SI deleted once 31 December of the year after your stay has passed · CZ 6 years from the last entry in the house book · SE 183 days · DK exactly 2 years from entry (Danish law sets both a minimum and a maximum) · NO/GB/IE 365 days · in the UNITED STATES and CANADA the period is set by your state or province and we apply that one: South Carolina 5 years, Pennsylvania and New York 3 years, Maine and Florida 2 years, Minnesota, Wisconsin, Massachusetts, Illinois, Prince Edward Island and Yukon 1 year, and 3 years elsewhere in the US |
| Invoices and financial ledger | Statutory bookkeeping periods (NL 7 years · DE 8 years for invoices since 2025 per BEG IV, 10 for other books · FR 10 years) — these are immutable legal records and survive erasure requests (Art. 17(3)(b)) |
| Email delivery logs | 730 days |
| Booking and guest profile data | For the duration of the business relationship; anonymized on erasure request |
Your rights
Access, rectification, erasure, restriction, portability, objection — ask the
campground you booked with, or us. Two are worth explaining honestly:
- Erasure: we anonymize your personal data everywhere it is not legally
required to persist. Issued invoices, the financial ledger and
statutory-retention registration records remain (Art. 17(3)(b)); everything
about them that can be anonymized is.
- Access (DSAR): you receive a machine-readable export of everything we
hold about you.
You can complain to your supervisory authority.
Recipients
Payment providers (the campground's own Stripe or Mollie account — your money
goes to the campground, not to us), email delivery (Resend), hosting (see the
subprocessor page), and the authorities listed above where registration is a
legal duty.
Transfers
Application hosting runs in EU regions. Two subprocessors process data outside
the EEA today and we say so plainly rather than claim otherwise: our **database
(Neon)** currently runs in the United States (aws-us-east-1) — an EU-region
project is provisioned before the first live park — and **transactional email
(Resend)** is US-based. Both transfers rest on the EU Standard Contractual
Clauses. The subprocessor page carries the current, dated list and is updated
the day a region changes.