CampGrid is designed to minimize family data. This Policy must be completed with verified retention periods, hosting locations and operator details before publication.
1. Controller and contact
The controller is information awaiting verification, located at 58 rue de Monceau, 75008 Paris, France. Privacy questions and rights requests may be sent to jlr.venturescorp@gmail.com or information awaiting verification.
The DPO or privacy contact, where applicable, is information awaiting verification.
The EU representative, if GDPR Article 27 requires one, is information awaiting verification. A verified not-applicable determination must be recorded instead of silently omitting this field.
2. Scope
This Policy covers CampGrid public pages, accounts, private household planning, support, transactional email, billing integration and first-party analytics. A linked third-party service applies its own policy to processing it controls.
3. Data we process
Depending on how you use CampGrid, we process:
- Account data: email, encrypted display name, locale, timezone, role, verification and authentication status.
- Security data: hashed session and one-time tokens, authentication timestamps, hashed user-agent information, audit events and abuse-prevention signals.
- Household data: encrypted household, child and home labels; age group; member roles and colors.
- Planning data: custody patterns and exceptions, coverage intervals, availability, care options, statuses, costs, transport responsibility, deadlines, encrypted notes and proposals.
- Collaboration data: invitations, responses, comments, notifications and safe audit history.
- Billing data: Stripe customer, Checkout, subscription, price, invoice, refund and dispute identifiers and statuses; CampGrid does not store full card numbers.
- First-party analytics: pseudonymous identifier, event type, locale, page, coarse device category, referrer host, campaign parameters and approximate country; no full IP address or family content.
- Support and incident data: messages you send, troubleshooting metadata and records needed to handle a security report or legal request.
4. Children's information
CampGrid has no child accounts. Adults may enter limited child-related planning information. We encourage a first name, nickname or age group rather than a full legal identity or exact birth date.
The MVP is not intended for medical data, photographs, identity documents, court documents or real-time geolocation. Remove unnecessary information and contact us if such data was entered by mistake.
5. Purposes and legal bases
We process account and planning data to perform the contract and provide requested collaboration, calculation, export and support functions. We process billing data to perform the subscription contract and meet accounting, tax and fraud-prevention obligations.
We process proportionate security logs, service health and privacy-preserving analytics for legitimate interests in protecting and improving CampGrid, subject to balancing, minimization and an opt-out where required. We rely on consent only when a feature or local law requires it.
We may process limited records to comply with law, establish or defend legal claims, respond to authorities or protect vital interests in an exceptional emergency.
6. Sources
Most data comes directly from you or another authorized household member. Stripe supplies billing status; Cloudflare and the hosting stack supply network and security metadata; your browser supplies locale, device and campaign information.
7. Who receives data
Household content is shared with active members according to their role. Administrators do not receive automatic access to family content.
Vetted processors receive only what they need for hosting, network protection, payments, transactional email and encrypted backups. The current list and purposes are in the Subprocessors page.
We may disclose information when legally required, to protect rights and safety, or in a corporate transaction with appropriate confidentiality and notice. We do not sell family data or share it for behavioral advertising.
8. Hosting and international transfers
Core family data is stored in information awaiting verification and encrypted backups are stored in information awaiting verification, once those facts are operationally verified.
Cloudflare and Stripe may process network or payment data internationally. Where required, transfers use an applicable adequacy decision, contractual safeguards or another lawful mechanism described by the processor.
9. Retention
We keep data only for a defined purpose and period. Active account and household data is kept while the service is used. Deletion enters the verified deletion workflow in docs/DATA_RETENTION.md.
Security, billing, tax, dispute and incident records may have different periods required by law or needed to establish legal claims. Analytics is aggregated or deleted on its stated schedule. Backups expire through rotation and are not used as an active archive.
10. Security
Measures include encrypted transport, server-side authorization, secure session cookies, token hashing, application encryption for selected family fields, audit logs, restricted administration and encrypted backups once deployed.
No system is risk-free. Security details and current limitations are described without claiming end-to-end encryption or absolute protection in the Security & Privacy page.
11. Your rights
Subject to applicable conditions, you may request access, correction, deletion, restriction, portability and objection, and may withdraw consent without affecting earlier lawful processing.
Send a request to jlr.venturescorp@gmail.com. We verify identity proportionately, respond within the legal timeframe and explain any lawful limitation. You may complain to information awaiting verification at information awaiting verification or another competent authority.
12. Export, correction and deletion controls
Authorized users can correct current planning data and obtain supported exports. Account deletion must explain its effect on other members and remove or irreversibly anonymize family content unless a specific legal obligation requires limited retention.
13. Cookies and analytics
CampGrid uses essential session, security and language storage and first-party analytics only as described in the Cookie Policy. It does not use advertising cookies, fingerprinting or cross-site tracking.
14. Incidents
We document personal-data breaches, assess risk and notify the competent authority and affected people when required. The internal response process is documented in docs/SECURITY_INCIDENT_RESPONSE.md.
15. Changes and contact
We will update the effective date and provide appropriate notice for material changes. Contact jlr.venturescorp@gmail.com with questions.
This initial document requires review by a qualified professional. Mandatory consumer rights continue to apply.