for the CampSecure™ app and the website campsecure.app
Version / last updated: September 2026 (15 September 2026)
Controller within the meaning of the EU General Data Protection Regulation (GDPR):
Bernd Maier
Regentenstr. 5b
51063 Cologne
Germany
Email: info@campsecure.app
We take the protection of your personal data seriously. The CampSecure™ app is built on a “privacy by design” approach.
The app processes personal data primarily on your device only. There is no central storage at CampSecure™ and no transmission of app content to servers operated by the provider (CampSecure™) or to us.
Alarm function in brief: Location, camera and microphone are used only on your device to provide security and alarm features. CampSecure™ does not receive this data. In an alarm you may—only if you configure this in the app—send selected information (e.g. timestamp, photo, location) via the channels you choose: email through your own SMTP server and/or Telegram to the chat you have paired. Neither we nor CampSecure™ are recipients or intermediaries of that alarm content.
Personal data means any information relating to an identified or identifiable person.
The app may request the following Android permissions. They serve the alarm and security features and are processed only on your device. Raw data is not transmitted to CampSecure™ servers, the app provider or us:
The app also processes the following mainly or exclusively on your Android device:
This data is not transmitted to CampSecure™ servers or to us.
Legal basis: Art. 6(1)(b) GDPR (performance of contract / use of the app)
If you enable and configure notifications, the following data may be sent from your device in an alarm via services you choose (scope depends on your settings):
You can use Telegram, email, or both. The channels are independent of each other.
Email is sent via SMTP through your SMTP account to the email addresses you enter—often yourself or people you name. CampSecure™ does not operate a mail server and has no access to content or recipients. Your SMTP provider and any intermediate mail servers process under their own terms.
If you enable and pair Telegram, alarm messages are sent via the Telegram service to the chat you have paired. Telegram is an independent service; Telegram’s terms and privacy policy apply. The operator of CampSecure™ is not a recipient of those chat contents.
We and CampSecure™ are not recipients of this alarm data, do not operate an intermediary cache for it and do not analyse these contents. No data is passed to us through these channels.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
CampSecure™ does not operate cloud infrastructure to store your app data (location, camera, microphone, alarm media, logs). We do not centrally collect data or track your use of the app for advertising or profiling.
Personal data from the app is not sent to CampSecure™ servers or to us unless you separately use the website (e.g. contact form) or email us—the purposes then are as described there.
Third parties involved in delivery (e.g. Google when installing via Play Store, your SMTP provider, or Telegram if you use that channel) process data under their own terms and only in connection with transmissions you initiate.
The following applies to personal data processed when you visit or use our website. Libraries such as Bootstrap and Font Awesome as well as the web fonts we use are served locally from our server.
The website runs on a web server under the domain campsecure.app. The hosting provider processes technical access data (server logs) to deliver, secure and troubleshoot the site, in particular:
Purpose: technical operation, security (e.g. detecting attacks), error diagnosis.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation).
Retention: logs are typically deleted or anonymised after 7–14 days unless longer retention is needed to investigate security incidents.
The website is served over HTTPS with SSL/TLS encryption to protect data in transit between your browser and our server against unauthorised reading or alteration.
We do not use a cookie consent banner and do not use Google Analytics or third-party tracking or marketing cookies.
Technically necessary processes (e.g. HTTPS session, server-side rate limiting based on hashed IP addresses) do not rely on lasting analytics cookies from us. On some subpages a language preference may be stored locally in the browser (localStorage for the user guide) without transfer to analytics providers.
When third-party content loads (YouTube, hCaptcha; see below), those providers may set cookies or similar technologies and/or process your IP address. Fonts are hosted locally on our server (no Google Fonts request). See each provider’s privacy notice.
To measure reach and conversion on our landing pages (especially Caravan Salon), we store selected usage events in a SQLite database on our own server. This is first-party measurement; we currently do not use Google Analytics or Google Tag Manager for this.
Data per event: event name, timestamp, page path, optional UTM parameters and CTA label, device type (mobile/tablet/desktop), and a pseudonymous session ID from browser sessionStorage (recognisable within a browser session, without name or email). This event database does not store IP addresses or a full user agent string.
Purpose: marketing control and funnel analysis.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in reach and conversion measurement).
Retention: raw events are generally deleted or aggregated into daily totals after 12 months.
You can send us messages via the website contact form. Data is sent over HTTPS to our own endpoint on campsecure.app and delivered to us by email (SMTP via our mail server for the campsecure.app domain). There is no transfer to EmailJS or similar form services.
Data processed:
Form contents are not stored permanently in a website database; they remain in the email delivered to us and are kept only as long as needed to handle your request.
Purpose: handling your enquiry.
Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps / enquiry) and/or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).
To reduce automated spam, the contact form embeds the hCaptcha widget. When the captcha is shown or used, your browser connects to hCaptcha’s servers; technical data (including IP address and browser information) may be processed. On submit, the captcha response is sent to our server and verified server-side via the hCaptcha API.
Provider: Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA – https://www.hcaptcha.com/privacy
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and spam). Transfers to the USA may rely on appropriate safeguards (including standard contractual clauses); see hCaptcha’s privacy notice.
On selected pages (especially home pages) you may optionally use the CampSecure™ AI assistant. Use is voluntary; you decide whether to use the feature. The assistant answers product and usage questions based on our knowledge sources.
Purpose: automated answering of questions and support for website users via the CampSecure™ AI assistant.
Technical flow: Merely loading the website or opening the chat window does not call Mistral AI. Only when you send a message does your browser talk to our server (campsecure.app). Only our server then calls the Mistral AI API (Browser → CampSecure server → Mistral API, endpoint https://api.mistral.ai/v1/chat/completions, model ministral-8b-2512). The browser does not communicate directly with Mistral. API keys and system configuration stay on our server and are not exposed in the browser. Before forwarding, we check the request technically (including max. 1,000 characters, abuse protection, rate limit).
CampSecure does not operate its own AI base model. The underlying language model is provided by Mistral AI. CampSecure provides the user interface, system instructions and integration.
Legal basis: Art. 6(1)(f) GDPR. Legitimate interest: providing a convenient automated information and support feature on the website.
What is sent to Mistral AI when you use the chat?
Please do not enter confidential or sensitive information in the chat. AI-generated answers may contain mistakes.
IP address and rate-limit data are processed on our server (including hashed in technical logs) and are not included in the chat payload to Mistral AI. Lead/newsletter/billing data and optional interest signup in the chat use a separate endpoint and are not merged into the AI context.
Storage by us: We do not keep chat content in a permanent conversation database. Conversation history exists only briefly in browser memory (tab/session) for follow-up questions. Technical server logs for the chat contain no question/answer text and no Mistral response bodies (only technical metrics such as HTTP status, error category, length fields) and otherwise follow server-log retention (see 5.1).
Recipient / AI service: Mistral AI (API at api.mistral.ai). Mistral AI is an EU-based provider; concrete processing follows Mistral’s current contractual and privacy terms for the API access we use. Whether and to what extent an Art. 28 GDPR processor agreement or further contractual safeguards apply to our account is under ongoing review and documentation. We do not claim the integration is categorically “GDPR compliant”.
Please note: Replies are generated automatically and may contain mistakes. They do not replace individual advice. Do not enter special-category data or credentials. AI may also have been used to support individual texts and illustrations on the site; published content is reviewed before release.
Non-use: Simply do not use the AI chat if you do not want this processing. Other website features remain available. Contact: info@campsecure.app.
In the chat widget and here we state clearly:
The AI labelling remains visible in the chat widget and is not only placed in this privacy policy.
If you ask in the chatbot to be kept informed about CampSecure™ (e.g. newsletter, tester, purchase interest), we process:
Data is stored in a SQLite database on our web server (not publicly accessible). Before activation we send a confirmation email (double opt-in). You may withdraw consent at any time (unsubscribe link in the email or message to us); the record is then deleted or mailing stopped.
No external newsletter service (e.g. Mailchimp) is used. Email is sent via our SMTP account for the campsecure.app domain.
Purpose: sending the information you requested about CampSecure™.
Legal basis: Art. 6(1)(a) GDPR (consent). Consent wording and confirmation time are logged.
We use web fonts (including Inter, Montserrat, Playfair Display, Caveat, Anonymous Pro). Font files are served locally from our server at campsecure.app.
Page loads do not connect to Google Fonts (fonts.googleapis.com / fonts.gstatic.com). No font data is sent to Google.
Home pages embed YouTube videos via iframe in privacy-enhanced mode (domain www.youtube-nocookie.com). Loading the embed still connects your browser to YouTube/Google; usage data (including IP address) may be processed and cookies may be set—even without a YouTube account. The nocookie mode reduces but does not eliminate Google’s processing.
Provider: Google Ireland Limited / YouTube, LLC.
Purpose: showing product/explainer videos.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in multimedia information).
Google/YouTube privacy: https://policies.google.com/privacy
CampSecure™ operates a company page on Facebook. The platform provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.
When you visit our Facebook page, Meta processes visitors’ personal data (e.g. usage data and Page Insights), whether or not you are logged in. Details: https://www.facebook.com/privacy/policy/.
For Insights data there is joint controllership between us and Meta Platforms Ireland Limited under the Facebook Page Controller Addendum: https://www.facebook.com/legal/terms/page_controller_addendum.
Personal data you send us via Facebook (e.g. messages or comments) is used solely to handle your enquiry.
Purpose: company presence, communication, evaluation of aggregated page statistics (where provided by Meta).
Legal basis: Art. 6(1)(f) GDPR; for voluntary contact also Art. 6(1)(b) and/or (f) GDPR.
CampSecure™ operates a business profile on Instagram. The provider is likewise Meta Platforms Ireland Limited (address as in 5.10).
When you visit our Instagram profile, Meta processes users’ personal data (including usage data and Insights). Details: https://www.facebook.com/privacy/policy/ and Meta’s Instagram help/privacy information.
Where Meta provides Insights for our business profile, there is joint controllership under Meta’s applicable Insights terms (see also the Page Controller Addendum / corresponding Meta arrangements).
Messages or comments you send us via Instagram are used solely to handle your request.
Purpose / legal basis: as in section 5.10 (Art. 6(1)(f) GDPR; for enquiries also (b)/(f)).
We currently do not use Google Analytics, Google Tag Manager or Google Maps on the website. If that changes, this privacy policy will be updated accordingly.
The app is downloaded and, where applicable, purchased via the Google Play Store. Google LLC then processes personal data under its own terms (e.g. Google account, device and usage information, install, updates, crash reports if allowed).
For paid purchases, payment data is processed solely by Google Play. The app provider does not receive card or bank details.
Short disclosures in the Play Console should match this policy; if anything conflicts, this page is the full statement for the website and app.
Google privacy policy: https://policies.google.com/privacy
App data is stored only locally and removed on delete/reset/uninstall as the OS provides—without server-side backup by CampSecure™.
Contact form content: only as long as needed to handle the request (email inbox).
Chat messages: no permanent conversation archives (see 5.6).
Interest list: until withdrawal, unsubscribe or erasure request, at most as long as needed for the purpose.
Server logs: see 5.1.
You have in particular the right to:
To exercise your rights, a simple message to info@campsecure.app is sufficient.
Right to lodge a complaint: You may complain to a supervisory authority.
Lead authority (NRW, Germany): State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia – https://www.ldi.nrw.de
The app uses Android security features. Sensitive data (e.g. PIN, SMTP credentials) is stored encrypted in the Android Keystore.
App location, camera and microphone data—outside email alarms you trigger—are not transmitted to us (sections 3 and 4).
The website uses HTTPS. The chatbot and form/lead APIs are protected server-side (including rate limits and origin checks). Mistral AI and SMTP credentials are not placed in the frontend.
We may update this privacy policy when the law, the app or the website changes. The current version is on this page with the date at the top. Please review it when you use our services again.
This privacy policy is reviewed regularly and adjusted to technical or legal changes.