Privacy policy

for the CampSecure™ app and the website campsecure.app

Version / last updated: July 2026 (29 July 2026)

1. Controller

Controller within the meaning of the EU General Data Protection Regulation (GDPR):

Bernd Maier
Regentenstr. 5b
51063 Cologne
Germany
Email: info@campsecure.app

2. General

We take the protection of your personal data seriously. The CampSecure™ app is built on a “privacy by design” approach.

The app processes personal data primarily on your device only. There is no central storage at CampSecure™ and no transmission of app content to servers operated by the provider (CampSecure™) or to us.

Alarm function in brief: Location, camera and microphone are used only on your device to provide security and alarm features. CampSecure™ does not receive this data. In an alarm you may—only if you configure this in the app—send selected information (e.g. timestamp, photo, location) via email through your own SMTP server to addresses you enter (typically yourself). Neither we nor CampSecure™ are recipients or intermediaries of that alarm content.

Personal data means any information relating to an identified or identifiable person.

3. Processing in the app

3.1 Sensitive permissions (Android) – local use only

The app may request the following Android permissions. They serve the alarm and security features and are processed only on your device. Raw data is not transmitted to CampSecure™ servers, the app provider or us:

  • Location (precise / approximate): optional, to determine and display location and—only if you enable it in the app and include it in recipient content—to add location details to alarm messages.
  • Camera: to capture photos when an alarm triggers; processing is local. Images are sent only if you configure email notifications with photo; recipients are only the email addresses you enter.
  • Microphone: for local audio analysis / sound detection for the alarm feature. No recording for advertising; no audio transmission to CampSecure™ or us. Any local buffering depends on the app implementation on your device; we do not store it centrally.
  • Notifications and optional foreground service: for reliable alarms and status display as required by Android (e.g. visible notification while monitoring). These support the UI and do not transmit data to us.

3.2 Other locally processed data

The app also processes the following mainly or exclusively on your Android device:

  • Sensor data (e.g. acceleration, motion) and audio analysis results
  • Camera captures when an alarm triggers (see 3.1)
  • Location data where you grant it (see 3.1)
  • Email configuration (incl. SMTP credentials; encrypted in the Android Keystore)
  • PIN (stored encrypted)
  • Alarm logs and app settings (local)

This data is not transmitted to CampSecure™ servers or to us.

Legal basis: Art. 6(1)(b) GDPR (performance of contract / use of the app)

3.3 Email notifications (user-controlled)

If you enable and configure notifications, the following data may be sent from your device in an alarm via services you choose (scope depends on your settings):

  • Timestamp
  • Photo (if included)
  • GPS coordinates (if enabled and included)
  • Other content you allow in the app

Transmission is only via email (SMTP) through your SMTP account to the email addresses you enter—often yourself or people you name. CampSecure™ does not operate a mail server and has no access to content or recipients. Your SMTP provider and any intermediate mail servers process under their own terms.

We and CampSecure™ are not recipients of this alarm data, do not operate an intermediary cache for it and do not analyse these contents. No data is passed to us through these channels.

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

4. No CampSecure™ cloud; no provider access to app data

CampSecure™ does not operate cloud infrastructure to store your app data (location, camera, microphone, alarm media, logs). We do not centrally collect data or track your use of the app for advertising or profiling.

Personal data from the app is not sent to CampSecure™ servers or to us unless you separately use the website (e.g. contact form) or email us—the purposes then are as described there.

Third parties involved in delivery (e.g. Google when installing via Play Store or your SMTP provider) process data under their own terms and only in connection with transmissions you initiate.

5. Website campsecure.app

The following applies to personal data processed when you visit or use our website. Libraries such as Bootstrap and Font Awesome as well as the web fonts we use are served locally from our server.

5.1 Hosting and server log files

The website runs on a web server under the domain campsecure.app. The hosting provider processes technical access data (server logs) to deliver, secure and troubleshoot the site, in particular:

  • IP address
  • date and time of the request
  • requested URL / file
  • browser type and operating system (if transmitted)
  • referrer URL (if transmitted)
  • response status code

Purpose: technical operation, security (e.g. detecting attacks), error diagnosis.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation).

Retention: logs are typically deleted or anonymised after 7–14 days unless longer retention is needed to investigate security incidents.

5.2 SSL/TLS encryption

The website is served over HTTPS with SSL/TLS encryption to protect data in transit between your browser and our server against unauthorised reading or alteration.

5.3 Cookies and browser storage

We do not use a cookie consent banner and do not use Google Analytics or our own tracking or marketing cookies.

Technically necessary processes (e.g. HTTPS session, server-side rate limiting based on hashed IP addresses) do not rely on lasting analytics cookies from us. On some subpages a language preference may be stored locally in the browser (localStorage for the user guide) without transfer to analytics providers.

When third-party content loads (YouTube, hCaptcha; see below), those providers may set cookies or similar technologies and/or process your IP address. Fonts are hosted locally on our server (no Google Fonts request). See each provider’s privacy notice.

5.4 Contact form

You can send us messages via the website contact form. Data is sent over HTTPS to our own endpoint on campsecure.app and delivered to us by email (SMTP via our mail server for the campsecure.app domain). There is no transfer to EmailJS or similar form services.

Data processed:

  • name
  • email address
  • message text
  • technical request data (e.g. language/page, timestamp)
  • hashed IP address (abuse prevention / rate limiting; included in the internal notification email)

Form contents are not stored permanently in a website database; they remain in the email delivered to us and are kept only as long as needed to handle your request.

Purpose: handling your enquiry.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps / enquiry) and/or Art. 6(1)(f) GDPR (legitimate interest in answering enquiries).

5.5 hCaptcha

To reduce automated spam, the contact form embeds the hCaptcha widget. When the captcha is shown or used, your browser connects to hCaptcha’s servers; technical data (including IP address and browser information) may be processed. On submit, the captcha response is sent to our server and verified server-side via the hCaptcha API.

Provider: Intuition Machines, Inc., 350 Alabama St, San Francisco, CA 94110, USA – https://www.hcaptcha.com/privacy

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in preventing abuse and spam). Transfers to the USA may rely on appropriate safeguards (including standard contractual clauses); see hCaptcha’s privacy notice.

5.6 Website chatbot (AI assistant / DeepSeek)

On selected pages (especially home pages) you may optionally use the CampSecure™ AI assistant. It answers product and usage questions based on our knowledge sources.

Flow: Your message is sent via HTTPS to our web server (campsecure.app), checked technically (max. 1,000 characters, abuse protection, rate limit) and then forwarded to the DeepSeek API (https://api.deepseek.com/v1/chat/completions, model deepseek-chat) to generate a reply. API keys and system configuration stay on our server and are not exposed in the browser.

What is sent to DeepSeek?

  • your current chat message (the text you enter)
  • optionally a short conversation history from browser memory (max. last 10 messages; not stored permanently by us)
  • a system prompt with our local knowledge base (product/FAQ/user-guide text)—without your master data such as name or email unless you type them into the chat yourself

IP address and rate-limit data are processed on our server (hashed in technical logs) and are not included in the chat payload to DeepSeek.

Storage by us: We do not keep chat content in a permanent conversation database. Short-lived technical logs (error/security logs with IP hash, history length, character counts) may be created and follow server-log retention (see 5.1).

Storage / use by DeepSeek: The recipient is Hangzhou DeepSeek Artificial Intelligence Co., Ltd., People’s Republic of China. Under DeepSeek’s privacy policy, content sent via the API may be processed and stored in the PRC; DeepSeek states that it retains personal data as long as needed to provide the services and for other purposes listed in its policy (including operation, security and, where applicable, model improvement—details and data-subject rights: DeepSeek Privacy Policy, contact e.g. privacy@deepseek.com). We have no direct erasure control beyond our own systems.

Processor / third country: This is a transfer to a third country without an EU Commission adequacy decision. Whether an Art. 28 GDPR processor agreement and/or Art. 46 GDPR standard contractual clauses are in place with DeepSeek is under ongoing review and documentation; we currently rely on Art. 6(1)(f) GDPR (legitimate interest in optional website support), noting that use is voluntary and that sensitive data must not be entered. Do not use the chat if you do not agree to a transfer to China.

Purpose: information and support about CampSecure™ on the website.

Legal basis: Art. 6(1)(f) GDPR; use of the chat is voluntary.

Please note: Replies are generated automatically and may contain mistakes. They do not replace individual advice. Do not enter special-category data or credentials. AI may also have been used to support individual texts and illustrations on the site; published content is reviewed before release.

Objection: Do not use the chatbot if you do not want this processing. Contact: info@campsecure.app.

5.7 Interest list / email updates (double opt-in)

If you ask in the chatbot to be kept informed about CampSecure™ (e.g. newsletter, tester, purchase interest), we process:

  • email address (required)
  • name (optional)
  • interest and optional vehicle type
  • time and wording of consent, confirmation and unsubscribe tokens, consent version
  • hashed IP address and truncated user agent (abuse prevention)

Data is stored in a SQLite database on our web server (not publicly accessible). Before activation we send a confirmation email (double opt-in). You may withdraw consent at any time (unsubscribe link in the email or message to us); the record is then deleted or mailing stopped.

No external newsletter service (e.g. Mailchimp) is used. Email is sent via our SMTP account for the campsecure.app domain.

Purpose: sending the information you requested about CampSecure™.

Legal basis: Art. 6(1)(a) GDPR (consent). Consent wording and confirmation time are logged.

5.8 Fonts (hosted locally)

We use web fonts (including Inter, Montserrat, Playfair Display, Caveat, Anonymous Pro). Font files are served locally from our server at campsecure.app.

Page loads do not connect to Google Fonts (fonts.googleapis.com / fonts.gstatic.com). No font data is sent to Google.

5.9 YouTube videos

Home pages embed YouTube videos via iframe in privacy-enhanced mode (domain www.youtube-nocookie.com). Loading the embed still connects your browser to YouTube/Google; usage data (including IP address) may be processed and cookies may be set—even without a YouTube account. The nocookie mode reduces but does not eliminate Google’s processing.

Provider: Google Ireland Limited / YouTube, LLC.

Purpose: showing product/explainer videos.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in multimedia information).

Google/YouTube privacy: https://policies.google.com/privacy

5.10 Facebook company page

CampSecure™ operates a company page on Facebook. The platform provider is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

When you visit our Facebook page, Meta processes visitors’ personal data (e.g. usage data and Page Insights), whether or not you are logged in. Details: https://www.facebook.com/privacy/policy/.

For Insights data there is joint controllership between us and Meta Platforms Ireland Limited under the Facebook Page Controller Addendum: https://www.facebook.com/legal/terms/page_controller_addendum.

Personal data you send us via Facebook (e.g. messages or comments) is used solely to handle your enquiry.

Purpose: company presence, communication, evaluation of aggregated page statistics (where provided by Meta).

Legal basis: Art. 6(1)(f) GDPR; for voluntary contact also Art. 6(1)(b) and/or (f) GDPR.

5.11 Instagram business profile

CampSecure™ operates a business profile on Instagram. The provider is likewise Meta Platforms Ireland Limited (address as in 5.10).

When you visit our Instagram profile, Meta processes users’ personal data (including usage data and Insights). Details: https://www.facebook.com/privacy/policy/ and Meta’s Instagram help/privacy information.

Where Meta provides Insights for our business profile, there is joint controllership under Meta’s applicable Insights terms (see also the Page Controller Addendum / corresponding Meta arrangements).

Messages or comments you send us via Instagram are used solely to handle your request.

Purpose / legal basis: as in section 5.10 (Art. 6(1)(f) GDPR; for enquiries also (b)/(f)).

5.12 Services not used

We currently do not use Google Analytics, Google Tag Manager or Google Maps on the website. If that changes, this privacy policy will be updated accordingly.

6. Google Play Store & payments

The app is downloaded and, where applicable, purchased via the Google Play Store. Google LLC then processes personal data under its own terms (e.g. Google account, device and usage information, install, updates, crash reports if allowed).

For paid purchases, payment data is processed solely by Google Play. The app provider does not receive card or bank details.

Short disclosures in the Play Console should match this policy; if anything conflicts, this page is the full statement for the website and app.

Google privacy policy: https://policies.google.com/privacy

7. Retention

App data is stored only locally and removed on delete/reset/uninstall as the OS provides—without server-side backup by CampSecure™.

Contact form content: only as long as needed to handle the request (email inbox).

Chat messages: no permanent conversation archives (see 5.6).

Interest list: until withdrawal, unsubscribe or erasure request, at most as long as needed for the purpose.

Server logs: see 5.1.

8. Your rights under the GDPR

You have in particular the right to:

  • access (Art. 15 GDPR)
  • rectification (Art. 16 GDPR)
  • erasure (Art. 17 GDPR)
  • restriction of processing (Art. 18 GDPR)
  • data portability (Art. 20 GDPR)
  • object to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR)
  • withdraw consent with effect for the future (Art. 7(3) GDPR)

To exercise your rights, a simple message to info@campsecure.app is sufficient.

Right to lodge a complaint: You may complain to a supervisory authority.

Lead authority (NRW, Germany): State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia – https://www.ldi.nrw.de

9. Security

The app uses Android security features. Sensitive data (e.g. PIN, SMTP credentials) is stored encrypted in the Android Keystore.

App location, camera and microphone data—outside email alarms you trigger—are not transmitted to us (sections 3 and 4).

The website uses HTTPS. The chatbot and form/lead APIs are protected server-side (including rate limits and origin checks). DeepSeek and SMTP credentials are not placed in the frontend.

10. Changes to this privacy policy

We may update this privacy policy when the law, the app or the website changes. The current version is on this page with the date at the top. Please review it when you use our services again.

This privacy policy is reviewed regularly and adjusted to technical or legal changes.