Privacy notice
Two sets of people give data to PitchDesk, and the law treats them differently. This notice keeps them separate rather than blurring them together.
Last updated 21 August 2026.
The short version
- If you run a campsite, we are the controller for your account data: your name, email, login and billing.
- For your campers' bookings, you are the controller and we are your processor. We only handle that data to run the service for you.
- Card numbers never reach us. Stripe handles them.
- Three sub-processors: Cloudflare for hosting and the database, Stripe for payments, Brevo for email. We tell you 30 days before that changes.
- We do not sell data, do not market to your campers, and run no analytics or advertising trackers.
- Two cookies, both strictly necessary, which is why there is no cookie banner.
- Campers should ask their campsite first, because the campsite decides.
This box is a summary, not the agreement. The sections below are what counts.
1. Two different relationships
PitchDesk sits between two sets of people, and UK GDPR treats them differently. Getting this straight is the whole of this notice.
| The data | Controller | What PitchDesk is |
|---|---|---|
| The campsite owner's own account: name, email, password, phone, billing record | PitchDesk | Controller |
| A camper's booking: name, contact details, dates, party, vehicle, notes | The campsite | Processor, acting on the campsite's instructions |
| Card details | Stripe, and the campsite as merchant | Nothing. Card numbers never reach us |
In practice: if you run a campsite and want to know what we do with your data, read part one. If you have booked a holiday and want to know what happens to your data, read part two and then talk to the campsite you booked with.
2. Part one: your account data, where we are the controller
This part applies to campsite owners and anyone else with a PitchDesk login.
What we collect
- Account details: your name, email address, phone number and a hash of your password. We never store the password itself.
- Site details: your campsite's name, address, postcode, what3words, contact details, photos and the words you write for your guests.
- Billing: your Stripe customer and subscription identifiers, the status of your subscription, and payment records. Your card is held by Stripe, not by us.
- Technical: your session record, the IP address and browser you logged in from, and server logs.
- Support: the emails you send us and our replies.
Why, and on what lawful basis
| What for | Lawful basis |
|---|---|
| Running your account and providing the software you signed up for | Performance of a contract |
| Taking the £7.99 a month and keeping the billing record | Performance of a contract, and legal obligation for the tax record |
| Service emails: your trial ending, a failed payment, a security notice, a change to these terms | Performance of a contract, and legitimate interests in keeping you informed |
| Keeping accounts secure, spotting abuse, preventing fraud | Legitimate interests in protecting the service and its users |
| Working out what to build next, using how the product is actually used | Legitimate interests in improving the software, balanced against your privacy |
| Marketing email about PitchDesk itself | Consent, or the soft opt-in for existing customers. Every one has an unsubscribe link that works |
| Keeping records for tax and accounting | Legal obligation |
How long we keep it
- Account and site data: while your account is open, and for 30 days after it closes.
- Backups: rolled off within a further 35 days.
- Billing and tax records: six years from the end of the accounting period, because HMRC requires it.
- Email delivery logs: 12 months.
- Session records: 30 days from last use.
- Support correspondence: two years.
Who we do not share it with
We do not sell your data. We do not share it with advertisers. We do not run advertising or analytics trackers on our own site. The only third parties involved are the suppliers listed in section 5, who handle it for us and not for themselves.
3. Part two: your campers, where the campsite is the controller
When a camper books, the campsite decides what to ask for and what to do with the answers. That makes the campsite the controller and PitchDesk the processor. Our data processing agreement is the contract that governs it, and it applies to every account automatically.
What we handle on the campsite's behalf
- The camper's name, email address, phone number, postal address and postcode.
- The stay: arrival, departure, pitch type and pitch, and the party, meaning adults, children, infants, dogs and vehicles.
- Unit details where the campsite asks for them: caravan or motorhome type, length, vehicle registration, and a club membership number.
- Notes and requests the camper types in, and notes the owner adds afterwards.
- Payment references from Stripe, the amount paid, the balance due and its status. Not the card number.
- The mandate record. Where a balance is to be taken from the card later, we store the exact wording the camper was shown, the exact amount, the exact date, the Stripe identifiers, and the moment they agreed. Not a tick, the words. That record is what makes the later payment authorised, so it has to be kept.
- Which version of the campsite's terms the camper accepted, and when, together with the cancellation ladder that was in force at that moment. The ladder is the money term, so it is stored with the booking rather than read back from the campsite's current settings, and a campsite that changes its policy later cannot change what an existing guest agreed to.
- The IP address the booking was made from. We record it against the booking to stop one person holding a whole field of pitches with repeated part-finished checkouts, and because it is part of the evidence of what was agreed and when.
What we do with it
Only what is needed to run the booking: store it, show it to the campsite, price the stay, work out availability, send the confirmation and reminders, take the payment through the campsite's own Stripe account, and collect the balance on the day the campsite has set.
The calendar feed
A campsite can publish its bookings as a calendar feed, so the dates show up in whatever else it uses, and so a listing site can see what is free. That feed contains, for each booking, the guest's surname, the booking reference, the dates, the pitch and the number of adults and children. It does not contain a full name, an email address, a phone number or anything about the payment.
Because it carries a name, the feed has its own private key: sixteen random bytes, generated for each campsite, that appear nowhere on any public page. It is deliberately not the public key that identifies the booking widget, because that one sits in plain sight in the code a campsite pastes into its own website. Asking for the feed with the widget key returns nothing at all.
The honest residual risk is worth stating rather than glossing. The feed URL is an address, not a login, so anyone the campsite gives it to can read guest surnames and dates for as long as they hold it, and there is no way to see who has used it. It is meant to be handed to a channel or a calendar deliberately, one at a time, and not pasted anywhere it might be indexed or forwarded. A campsite that thinks an address has got out can have a new key issued, and the old one stops working immediately.
What we do not do with it
We do not market to your campers. We do not build a guest list of our own across sites. We do not sell or share it. We do not use it to train machine learning models. If we ever want to use aggregate figures, for example how many bookings a typical site takes in August, we do it with data that cannot identify a person or a site.
Why we keep the mandate record
When a camper agrees that the balance can be taken from their card on a stated date, that agreement is what makes the later payment lawful. Under the Payment Services Regulations 2017 a payer can reclaim a payment from their own bank where the authorisation did not state the exact amount, so the mandate we store names the exact amount and the exact date rather than "the balance". Keeping that record is in the campsite's legitimate interests and in the camper's, because it is also the proof of what was agreed if anyone disputes it.
How long
The campsite decides. By default we hold booking data for as long as their account is open, and delete it 30 days after the account closes. A campsite can delete an individual booking's personal data at any time, and can ask us to delete everything sooner. The mandate record and the terms snapshot are kept for as long as the booking is, because deleting them would destroy the evidence that the payment was authorised.
4. If you are a camper reading this
You booked with a campsite, not with us. The campsite decides what happens to your booking, including whether it can be changed, whether you get a refund and how long they keep your details. So:
- Ask the campsite first. Their contact details are on your confirmation email and on your booking page.
- If you cannot get a response, email us at hello@pitchdesk.co.uk. We will pass your request to the campsite and help them answer it, which is what a processor is allowed to do. We cannot decide for them.
- Your card details are handled by Stripe. They never reach PitchDesk.
- The emails you get about your booking are sent by our systems on the campsite's behalf, and are meant to look like the campsite's, because the booking is with the campsite. The sender name in your inbox is theirs, the colours are theirs, and a reply goes to their address rather than to us. Only the underlying sending domain is ours, which is why the small print at the bottom says PitchDesk supplies the software.
5. Who else touches the data
We keep this list short on purpose. These three are used for both parts of this notice, and they are the sub-processors named in the data processing agreement.
| Who | What they do for us | Where the data sits |
|---|---|---|
| Cloudflare, Inc. | Hosting, the database that holds your account and your bookings, and protection against attacks | Western Europe, with edge processing worldwide |
| Stripe Payments Europe, Ltd. | Payments. Your subscription on our account, and your guests' payments on your own connected account | Ireland, with transfers to the United States |
| Brevo (Sendinblue SAS) | Sending transactional email, including booking confirmations and reminders | European Union |
Two notes worth having.
- For your guests' payments, Stripe is not only our supplier. Stripe is also a controller in its own right for the payment, under its own agreement with the campsite. That is normal for card payments and it is why Stripe's privacy policy applies as well as this one.
- We will tell every account holder by email at least 30 days before we add or change a sub-processor, so there is time to object.
We will also disclose data if the law requires it, for example a valid court order, or to establish or defend a legal claim. If we can lawfully tell you first, we will.
6. Data leaving the UK
Your account data and your bookings are stored in Cloudflare's Western European region. Cloudflare operates a global network, so some processing, such as filtering an attack, happens at the edge location nearest the visitor.
Stripe transfers payment data to the United States. Brevo processes email inside the European Union.
Where data goes outside the UK we rely on UK adequacy regulations where they cover the country concerned, and otherwise on the International Data Transfer Agreement, or the UK Addendum to the European Commission's standard contractual clauses, together with a transfer risk assessment. Copies are available on request.
7. Cookies
We use two cookies and neither of them tracks anybody.
| Cookie | What it does | How long |
|---|---|---|
pd_session | Keeps a campsite owner logged in. HttpOnly, SameSite=Lax, Secure | 30 days |
pd_csrf | Stops a hostile website submitting a form as you | The browser session |
Both are strictly necessary, so we do not have to ask for consent and we do not show a cookie banner. There is no analytics tag, no advertising pixel and no third party script on our marketing site or on a booking page. The booking widget you embed in your own website sets no cookies at all.
8. How we protect it
Passwords are hashed with PBKDF2-HMAC-SHA512 at 210,000 iterations. Everything travels over TLS. Card details never reach our servers. The security page sets out how the whole thing is built, including the parts we have not done yet.
If there is a personal data breach affecting a campsite's guests, we tell the campsite without undue delay and in any event within 48 hours of becoming aware, with what we know and what we are doing. If it affects owner account data, where we are the controller, we report to the Information Commissioner within 72 hours where the rules require it, and tell you directly where there is a high risk to you.
9. Your rights
Under UK GDPR you can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, ask us to restrict or stop certain processing, object to processing we do on the basis of legitimate interests, ask for your data in a portable format, and withdraw consent where consent is what we relied on.
Campsite owners exercise these rights with us, at hello@pitchdesk.co.uk. We answer within one month. There is no charge. You can also export most of it yourself from your account at any time.
Campers exercise these rights with the campsite they booked with, because the campsite is the controller. We help the campsite answer within the time the law allows.
10. Complaining
Tell us first and we will try to sort it. If you are not satisfied you can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, on 0303 123 1113 or at ico.org.uk. You do not have to come to us first, but it is usually quicker.
11. Changes to this notice
If we change something that matters, we will email account holders at least 30 days beforehand and change the date at the top of this page. Small corrections are made without notice.
12. Contact
Data protection questions go to hello@pitchdesk.co.uk. We are not required to appoint a data protection officer and have not appointed one, so that address reaches the person who is responsible.
The rest of the small print
Questions about any of this go to hello@pitchdesk.co.uk and a person will answer.