Camp Denman
Privacy
What we collect, why, who processes it, and how to get it corrected, exported, or deleted — in plain language.
Effective Privacy Notice, version 2026-08-13.
The policy in plain language
Version 2026-08-13.
What we collect
Account: your email, display name, sign-in provider identity, optional birth date (used only for age-appropriate features), roles, and consent records. Guardians linked to camp participants: contact details and the linkage itself.
Camp admissions and bookings: application answers, reservation and payment records (payment cards are handled by Stripe; we never store card numbers), and the dietary, accessibility, and emergency details you provide for a camp stay.
Contact and calls: when you contact us, apply, host a program, or book a call, we collect the details you submit — contact information, program interests, project details, accessibility or other requirements, preferred dates, and call topics.
Your work: files you upload to your Vault, work you generate, versions, sharing and publication choices, and the prompts and settings of generation jobs — kept as receipts you can see. Digital Twin recordings and provisioning carry their own consent, visibility, and revocation controls shown in the product; we do not use a recording or provision a Twin without them.
Messages: private conversations and calls are carried by our communications provider; message content is stored to show you your own history and for safety review when something is reported.
Usage: server logs bounded for operations and security. Browser analytics run only if you opt in on the public site; if allowed, analytics can include the page requested, referrer, browser and device details, IP address, and random visitor and session identifiers. Reopen Cookie settings at any time from the footer of the camp pages that offer the analytics choice — choosing essential only stops future analytics and removes the site's analytics identifiers on your next request.
What we use it for
Operating Virtual Studio and the camp; delivering what you purchase; metering and showing you generation receipts; safety and moderation (including the under-18 messaging limits); legal obligations; and product improvement using aggregate, non-identifying measures.
We do not sell personal information. We do not use your private Vault content to train models.
Who touches it (processors)
Stripe — payments, subscriptions, and tax. Your billing name, address, and country live with Stripe.
Paradise Modern — our operations provider: transactional email, SMS, private messaging and call transport, AI model routing, and opt-in analytics collection. Calls and AI requests are attributed to Camp Denman's account with them.
Named AI model providers — receive the prompt and reference inputs of a generation you run, under each tool's disclosed provider.
DigitalOcean — hosting, databases, and private object storage. Currently hosted in DigitalOcean's United States region, protected contractually; we are migrating hosting to DigitalOcean's Toronto, Canada region.
Google — only if you sign in with Google.
Providers can operate in Canada, the United States, or other locations where their services run. We may also disclose information when required by law or when reasonably necessary to protect a person, the service, or Camp Denman.
Minors
Accounts are for members 13 and older; camp participants under 18 are supported through guardian linkage and staff supervision features. Members without a recorded adult birth date get minor-safe defaults — notably staff-only messaging and reviewed posting in moderated rooms.
Minors' likenesses and voices are never used in generative or biometric tooling. Guardians may contact us at any time to review or remove their teen's data.
Retention and deletion
Account and Vault content is kept while your account is active. Trash is recoverable for 30 days, then purged.
When an account is deleted, personal data is removed or de-identified within 30 days, except records we must keep — payments, safety incidents, consent evidence — for their legal retention periods. Backups roll off on a fixed schedule after deletion.
Security
Server-side authorization on every access path, private-by-default object storage with expiring signed links, encrypted transport, least-privilege credentials, and audit logging of sensitive administrative actions. No online system can promise absolute security.
Your rights and how to reach us
Access, correction, export, and deletion requests — and withdrawal of consent for future optional use, such as analytics: privacy@campdenman.com. We answer within 30 days, and may need to verify your identity before disclosing or changing a record. A request may be limited where we must retain a record for safety, accounting, legal, fraud-prevention, or dispute purposes — we explain any such limit in our response. You may also complain to the Office of the Privacy Commissioner of Canada or the BC OIPC.
We will post changes here and note material changes prominently. General contact: hello@campdenman.com · Camp Denman Society, 2325 Northwest Road, Denman Island, BC V0R 1T0.