How HoldMyCamp handles your data
Search and drafts
Dates, selected sites and equipment preferences are saved in your browser. Availability checks send the selected campground, dates, equipment and party information to the official provider. Shared availability results are cached for 60 seconds; they contain no account credentials.
Your account
HoldMyCamp stores your email, verification status, watches, events and reservation-attempt state in its private PostgreSQL database. Sign-in codes expire after 10 minutes and are stored as hashes. Sessions use a protected cookie and expire after 30 days.
Official park connections
Your park account password is kept encrypted (AES-256-GCM, bound to that one connection) so that, when we are about to hold a site and the park site has signed you out, we sign in again for you; we don't sign in or check the park site ahead of time. You can delete it at any time on the Accounts page, and it is deleted when you disconnect or when the park site rejects it. Each park account connection uses its own separate browser profile on our server. After we hold a site, we open your reservations page on the park site to see whether you finished the booking; its text, with emails, phone numbers and card numbers removed, is read by Anthropic's Claude to find this site and these dates, and is not kept by us beyond the result. Disconnecting stops this. A profile with a held or unresolved cart is kept until that cart is resolved.
Payment and the remote browser
HoldMyCamp does not submit park reservation payments. Recreation.gov checkout happens on the official website in your own browser. BC Parks uses the same private browser session where the hold was created. Live images and your input pass through HoldMyCamp to that official session; they are not written to application logs or stored as recordings. Payment fields belong to the official provider.
Service fees
Stripe hosts the card entry page. HoldMyCamp stores Stripe's customer, payment method and payment references, the amount, currency, hold deadlines, the card's brand, last four digits and expiry, and your booking report. We never see or store card numbers or the security code. A captured fee is based on your report or on the booking we find in your official account; it is not proof of a park booking or of a bank payout.
Product analytics
HoldMyCamp uses PostHog (servers in the United States) to count, anonymously, how the site is used and where people get stuck: pages viewed; steps such as searching, opening a campground, checking availability, signing in, connecting a park account, saving a card and starting a watch; and the codes and references of errors shown to you. Search text is sent with emails, phone numbers and long numbers removed. These counts set no cookies, store nothing in your browser and are not linked to you or your account, and PostHog discards your IP address. A browser that sends Do Not Track or Global Privacy Control is not counted, and you can turn counting off under Privacy choices.
Session replays
Only if you turn on session replays under Privacy choices, PostHog records clicks, scrolling and page layout, and links the recording to an internal account ID (never your email, phone number, park account or card details). Everything you type and all text on the page is hidden in the recording, and the remote official-browser view, park account sign-in, card entry, service fee and booking hand-off pages are never recorded.
Results recorded by our server
Our server also tells PostHog how holds, booking checks, park account connections and service fee steps turn out (for example a status or a reason code, never messages, names or account details). For people who turned on session replays these are linked to the same internal account ID; for everyone else they are anonymous counts with no ID.
Changing your choice
Use Privacy choices at the bottom of any page to turn anonymous counting off, or session replays on or off, at any time. Turning them off clears anything PostHog stored in this browser and stops linking our server's records to your account. To have analytics already collected about you deleted, contact support.
Notifications and records
Account and watch emails go to your verified address through the configured mail service. The in-app event history and notification delivery status help you understand failures. Private runtime data and database backups stay outside the source repository. This is a controlled deployment; broader public release requires documented retention and account-deletion procedures.