Camper is a business-to-business service. When your employer or another organization (a “Customer”) provides your information to Camper—for example via SCIM from an identity provider—that Customer is typically the controller (or “business”) of that workforce data, and Camper processes it on the Customer’s instructions under our Data Processing Agreement. This Policy also describes data we control ourselves (for example marketing leads and our own account administration). For product security posture, see the Trust Center.
1. Who we are
Camper (“Camper,” “we,” “us,” or “our”) operates https://getcamper.io, the application at https://app.getcamper.io, related APIs (including SCIM and webhooks), and documentation. Contact: hello@getcamper.io. Privacy requests: same address with subject line “Privacy Request,” or security@getcamper.io for security-sensitive matters.
If you use Camper through your organization, please also contact your organization’s administrator for requests that relate to directory or resource data they control.
2. Scope and roles
- Customer workforce / directory data. When a Customer connects an IdP (SCIM), configures org structure, or links SaaS resources, Camper processes personal data as a processor / service provider on behalf of the Customer.
- Account and billing data. Data about Customer operators who sign in to Camper, and commercial billing records, is processed by Camper as a controller / business as needed to operate the Service and our contract.
- Marketing site and leads. Information submitted on get-started forms or sent to our contact emails is processed by Camper as a controller to respond to inquiries and evaluate access requests.
- Not covered. Third-party products you connect (Google Workspace, Slack, Jira, GitHub, Microsoft 365, your IdP, etc.) have their own privacy policies. Camper does not control how those providers process data outside the Service.
3. Categories of personal data we process
Depending on how the Service is used, we may process:
- Identity and directory data pushed by a Customer’s IdP over SCIM (or limited legacy directory paths): work email, display name, external IdP identifiers, employment-related attributes the Customer maps (for example division, department, team), group memberships used for org placement, status (active/staged/etc.), role attributes used for operator elevation, and profile snapshots as provided by the IdP.
- Org and access configuration: org unit trees, resource links and policies, pins/exceptions, membership desired and observed state, and related audit/event records (who did what, when).
- Resource metadata from connected systems you link: resource names and identifiers, membership lists (often emails or provider user ids), and operational status. We do not design the Service to store file contents, message contents, or calendar event contents inside those resources.
- Credentials and secrets you supply for integrations: OAuth tokens, API keys, SCIM bearer tokens, service-account material, and similar secrets—stored sealed at rest using per-tenant envelope encryption.
- Account authentication data: operator name and email, password hashes (where password login is used), email OTP / verification codes (short-lived), passkey credentials, TOTP secrets where enrolled, SSO configuration, session tokens, IP address, and user agent associated with sessions.
- Billing and commercial data: plan and band, identity samples used for metering, Action usage events, invoices, payment status, and payment-method references handled by our payment processor (Stripe). We do not store full payment card numbers on Camper systems when Stripe Checkout / Elements are used.
- Lead and support data: email, company name, optional IdP, org-size bucket, free-text notes, and source of signup requests; support correspondence you send to us.
- Technical logs: application and infrastructure logs needed to operate and secure the Service. We engineer against writing secrets into logs and job queues.
Data we intentionally do not collect as product content: the contents of documents, chat messages, or calendar events in systems Camper manages; consumer advertising profiles; or precise mobile geolocation.
4. Sources of data
- Directly from you (forms, account settings, support email).
- From Customer administrators and Authorized Users.
- From Customer identity providers via SCIM (or configured directory integrations).
- From third-party systems the Customer connects (APIs for membership and resource metadata).
- From authentication providers the user chooses (for example Google social sign-in or Customer-configured SAML/OIDC IdPs).
- From our payment processor regarding payment status and customer objects.
- Automatically from browsers and clients (session and security metadata).
5. How we use personal data
We process personal data to:
- Provide, operate, maintain, and secure the Service (directory ingest, desired-state computation, reconcile, provisioning, audit, My Access, notifications where enabled).
- Authenticate users, maintain sessions, enforce roles and tenant isolation, and prevent abuse (including rate limiting and suspension).
- Meter usage, determine pricing bands, bill platform fees and overages, perform dunning, and keep financial records.
- Respond to signup requests, provide customer support, and communicate service-related notices (security, billing, material product or terms changes).
- Improve reliability and product quality using operational metrics and aggregated or de-identified information where feasible.
- Comply with law, enforce our Terms, and protect rights, safety, and security.
We do not sell personal information for money. We do not use Customer directory data for third-party advertising. As of the effective date, the marketing site does not run third-party advertising or behavioral analytics trackers; if that changes, we will update this Policy and the Trust Center.
6. Legal bases (EEA/UK and similar regimes)
Where GDPR/UK GDPR or similar laws apply, we rely on:
- Contract — to provide the Service to Customers and operate accounts.
- Legitimate interests — to secure the Service, prevent abuse, improve reliability, and communicate about related offerings, balanced against individual rights.
- Legal obligation — tax, accounting, and lawful requests.
- Consent — where required (for example certain cookies or optional marketing), which you may withdraw prospectively.
- For processor activities, the Customer’s lawful basis for instructing Camper (often legitimate interests or contract with their workforce).
8. International transfers
Camper is operated from the United States. If you access the Service from outside the U.S., your data will be processed in the U.S. (and in any other regions where our subprocessors operate). Where required, we use appropriate transfer mechanisms (such as Standard Contractual Clauses) as set out in our Data Processing Agreement and subprocessor arrangements.
9. Retention
- Account and Customer Data are retained for the life of the tenant relationship and a commercially reasonable period thereafter for export, backup rotation, dispute resolution, and legal compliance, then deleted or de-identified.
- Sessions and verification codes expire on short schedules (sessions are time-bounded; OTP/verification values expire).
- Billing records are retained as required for tax and accounting.
- Lead form submissions are retained as needed to evaluate and respond to requests, and for a limited period thereafter unless you ask us to delete them where we can.
- Security and application logs are retained for operational periods appropriate to investigation and reliability, then aged out.
Customers may request deletion of a tenant subject to the Terms of Service and any legal retention duties. Residual encrypted backups may persist for a limited window before purge.
10. Security measures
Measures currently implemented in the product and infrastructure include:
- Per-tenant data encryption keys for sealing credentials (AES-256-GCM) with binding to tenant/connection context; master key wrapping and rotation capability.
- Tenant isolation enforced in the data access layer.
- Credentials kept out of asynchronous job payloads; workers unseal at execution time.
- Authentication options including email OTP, passkeys, TOTP on password paths, and enterprise SSO (SAML/OIDC) where configured.
- Session management with revocation; suspension controls for accounts.
- Audit/activity trails for provisioning and operator actions.
Camper is in private preview and, as of the effective date, does not hold SOC 2, ISO 27001, or similar third-party attestations. Engineering controls exist in the codebase; independent audit attestation may follow. Do not rely on unstated certifications.
No security program is perfect. Please report vulnerabilities to security@getcamper.io.
12. Your rights and choices
Depending on your location and role, you may have rights to access, correct, delete, export, restrict, or object to certain processing, or to withdraw consent. How to exercise:
- Customer workforce data — contact your organization’s Camper administrator or privacy contact first; we will support the Customer in responding as required by our contract and law.
- Your operator account — use in-product account settings where available, or email hello@getcamper.io.
- Marketing leads — email us to request deletion of a signup request we control, subject to anti-abuse and legal retention needs.
We may need to verify your identity and authority (for example that you are authorized to act for a Customer). We will not discriminate against you for exercising rights under applicable law. You may lodge a complaint with a supervisory authority where those laws apply.
13. U.S. state privacy disclosures (including California)
If you are a resident of California or another U.S. state with a comprehensive privacy law, this section supplements the Policy.
- We process the categories of personal information described in Section 3 for the business purposes in Section 5.
- We do not “sell” personal information and do not “share” it for cross-context behavioral advertising as those terms are commonly defined under the CCPA/CPRA.
- We do not use or disclose sensitive personal information for purposes other than those permitted for providing the Service (for example account authentication credentials).
- Authorized agents may submit requests as permitted by law, subject to verification.
- For workforce data processed solely on a Customer’s behalf, please direct requests to that Customer; we act as a service provider / processor.
14. Children
The Service is directed to business users and organizations. We do not knowingly collect personal information from children under 16. If you believe we have done so, contact us and we will take appropriate steps to delete it.
15. Automated decision-making
Camper automates membership and resource reconciliation according to rules and policies configured by the Customer. Those automations can affect access to Customer-managed systems. Camper does not perform consumer credit, hiring, or similarly protected automated decision-making about individuals for Camper’s own purposes. Customers are responsible for appropriate human oversight of their provisioning policies.
16. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the revised Policy with a new effective date on this page and, for material changes affecting Customers, provide additional notice when required (email or in-product). Continued use of the Service after the effective date means the updated Policy applies, except where applicable law requires otherwise.
17. Contact
Privacy questions and requests: hello@getcamper.io
Security: security@getcamper.io
Related: Terms of Service · DPA · Trust Center · Help