Campigo Platform Privacy Policy
The data controller is Sales Strategy sp. z o.o., ul. Wielicka 42/B3, 30-552 Kraków, Poland, VAT ID (NIP) 6793347953, REGON 543243475, KRS 0001205301, share capital PLN 5,000. Contact for data protection matters: info@campigotravel.com. Version 1.0, effective as of September 9, 2026.
1. Data controller
The controller of personal data of Users of the website campigotravel.com (the "Platform") is: Sales Strategy sp. z o.o. (a Polish limited liability company) with its registered office at ul. Wielicka 42/B3, 30-552 Kraków, Poland, Tax ID (NIP): 6793347953, Statistical ID (REGON): 543243475, National Court Register (KRS): 0001205301, share capital: PLN 5,000 (the "Controller" or "we") For matters relating to the protection of personal data, please contact us at: info@campigotravel.com.
2. Basic information about the Platform
Campigo is an online marketplace connecting people seeking to rent campervans, caravans, and camping accommodation with people offering such services. A detailed description of how the Platform operates is set out in the Terms of Service. To provide our services, we use the infrastructure and services of third parties, in particular: • Sharetribe — the marketplace software provider on which the Platform is built (accounts, listings, bookings, messages), • Stripe — a payment services provider, including Stripe Connect (splitting payments with Owners) and Stripe Identity (Guest identity verification). Details regarding these entities as data recipients are described in Section 6.
3. What data we process and for what purpose
3.1. Creating and maintaining an Account We process: first and last name, e-mail address, password (in encrypted form), Account type (individual/business), and, for a Business Account, the company name, address, and tax ID. Purpose: conclusion and performance of the agreement for the provision of electronic services (creating and maintaining an Account), enabling use of the Platform. Legal basis: Article 6(1)(b) GDPR (necessary for the performance of a contract to which the data subject is party, or to take steps prior to entering into a contract). 3.2. Bookings and transactions We process: booking data (dates, selected Offer, selected Add-ons), transaction billing data (amounts, currency, payment status — without full payment card data, which is processed solely by Stripe), and the content of messages exchanged between a Guest and an Owner within a given Booking. Purpose: conclusion and performance of the rental/booking agreement between Users, enabling communication between the parties to a booking, issuing the Payment Confirmation. Legal basis: Article 6(1)(b) GDPR (performance of a contract) and Article 6(1)(c) GDPR for data necessary for accounting and tax purposes (see Section 7). 3.3. Guest identity verification (Stripe Identity) Before booking a campervan, a Guest may — voluntarily — undergo an identity verification process carried out directly by Stripe Identity: submission of a photograph of an identity document/driving licence and a "selfie" photograph for comparison. Completing this verification is not a condition for making a booking (see §8 of the Terms of Service) — a Guest may skip it and present the required documents directly to the Owner upon vehicle handover instead. Important: the document photograph and selfie are submitted directly to Stripe Identity and processed by that entity — the Controller does not have access to, and does not store, these photographs on its own servers. Only the verification result (verified / not verified / in progress) is received by the Controller. Purpose: making it easier to confirm a Guest's identity before vehicle handover (at the Guest's own request), reducing the risk of fraud. Legal basis: Article 6(1)(a) GDPR (the Guest's voluntary consent, expressed by starting the verification process) and — for the Controller's retention of the verification result itself — Article 6(1)(f) GDPR (the Controller's and Owners' legitimate interest in reducing the risk of abuse). Biometric data (the facial image used for matching) is processed solely by Stripe Identity as a separate controller for that process, in accordance with its own privacy policy — we recommend reviewing it before undergoing verification. 3.4. Owner verification A User applying for Verified Owner status submits: a description of the vehicle/site, contact details, and scans/photographs of supporting documents (e.g. vehicle registration certificate, proof of insurance, a document confirming the right to offer a camping pitch). These documents are stored on Sharetribe's infrastructure in the form of an unpublished submission, not publicly visible — access is limited to the User who submitted them and authorized Controller representatives assessing the request. These documents are never visible to other Platform Users nor accessible via public, unauthenticated queries to the system. Purpose: assessing a User's entitlement to offer a given vehicle/site, reducing the risk of unreliable listings. Legal basis: Article 6(1)(f) GDPR (the legitimate interest of the Controller and Guests in ensuring the reliability of Offers published on the Platform) and Article 6(1)(b) GDPR to the extent the request is necessary to conclude the agreement granting Owner-feature access. 3.5. Payments, Stripe Connect, and Deposits We process data necessary to settle payments (amounts, transaction statuses, Stripe transaction identifiers) and, for Owners, data necessary to set up a Stripe Connect settlement account (submitted directly to Stripe as part of its onboarding process, outside the Platform). For a card Deposit, we process information on authorization status (held / released / captured) — without the underlying card data. Purpose: processing payments, paying out funds to Owners, administering Deposits. Legal basis: Article 6(1)(b) GDPR. 3.6. Preferences: language and display currency We store, in cookies (described in a separate Cookie Policy), the User's chosen (or default) language version of the Platform and display currency. On a first visit, if the User does not yet have a saved preference, we determine the default language and currency based on the approximate country derived from the User's IP address — a query is sent to an external geolocation service (freeipapi.com). The IP address is used once, for the sole purpose of determining the country, and is not stored by us — only the result (the default language/currency selected) is stored in a cookie on the User's device. Purpose: matching the default display language and currency to the User. Legal basis: Article 6(1)(f) GDPR (legitimate interest in matching displayed content without requiring a manual selection) — the User may change the language and currency manually at any time. 3.7. Location of Offers on the map To display Offers on an interactive map, the textual address/location provided by an Owner in an Offer is sent to an external geocoding service (OpenStreetMap / Nominatim) to determine geographic coordinates. This process concerns the Offer's address, not the personal data of Platform visitors. Legal basis: Article 6(1)(f) GDPR (legitimate interest in presenting Offers on a map). 3.8. Currency converter To display an indicative price conversion, we use the publicly available, free API of the National Bank of Poland (NBP). Queries to this API do not contain or disclose any personal data of Users. 3.9. Analytics (Google Analytics 4) and marketing The Platform provides a cookie consent management mechanism (a cookie banner), described in detail in the Cookie Policy, allowing the User to make an informed, voluntary choice regarding analytics and marketing cookie categories. The Platform uses the Google Analytics 4 tool (provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), which processes data about the use of the Platform (pages visited, traffic source, approximate country/city-level location derived from an anonymized IP address, device and browser type, visit duration) to produce aggregate visit statistics. This tool is activated only for Users who have given consent in the cookie banner (the "Analytics" category, or "Accept all") — without such consent, no data is sent to Google. Legal basis: Article 6(1)(a) GDPR (voluntary consent), together with the provisions of Polish electronic communications law governing the storage of, or access to, information already stored on the User's terminal equipment. Consent may be withdrawn at any time via the "Manage cookie preferences" link in the Platform's footer, without affecting the lawfulness of processing carried out before its withdrawal. Recipient: Google Ireland Limited (as part of the Google group, including Google LLC based in the United States) — see Section 9 regarding transfers of data outside the European Economic Area. Retention period on Google Analytics' side: in accordance with Google Analytics 4's retention settings (by default 14 months for event-level data). The Platform currently does not use any third-party marketing or advertising tools (e.g. Meta Pixel, LinkedIn Insight Tag, or similar) — none are implemented in the Platform's code as of the date of this update, regardless of the choice a User makes in the "Marketing" category of the cookie banner. The Controller plans to implement such tools in the future — before their actual activation, this Privacy Policy and the Cookie Policy will be updated to name the specific tool implemented, the scope of data processed, the recipient, and the retention period, in accordance with the rules described in Section 11. 3.10. PESEL number (DAC7 obligation) From Owners who are natural persons not conducting business activity (Private Account), we collect a PESEL number (Polish national identification number), provided by the User in their Account settings before publishing their first Offer. Purpose: fulfilling the obligation to collect identification and tax data from Owners and to report it annually to the competent authority, under the act implementing Council Directive (EU) 2021/514 (DAC7) — see §23 of the Terms of Service. Legal basis: Article 6(1)(c) GDPR (necessity to comply with a legal obligation to which the Controller is subject). Recipient: the Head of the National Revenue Administration (Szef Krajowej Administracji Skarbowej), to the extent and within the timeframes required by DAC7 rules. The PESEL number is not disclosed to other Platform Users or to any other third parties. Retention period: for the duration of the reporting obligation (generally, for as long as the User holds Owner status) and additionally for the statute-of-limitations period applicable to tax liabilities under the Polish Tax Code. 3.11. Newsletter A User logged in to the Platform may, in their Account settings, give voluntary consent to receive a newsletter (information about news and offers on the Platform). Purpose: sending marketing information about the Platform by electronic means. Legal basis: Article 6(1)(a) GDPR (voluntary consent) — the consent checkbox is unchecked by default, and checking it constitutes an unambiguous affirmative action. Scope of data: the email address already held as part of the Account, and a timestamp of when consent was given. Retention period: until consent is withdrawn (by unchecking the checkbox in Account settings) — consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before its withdrawal. Important: as of the effective date of this Policy, the Platform does not yet send any newsletter messages — we are collecting consents in advance of actually launching sending. Before sending is launched, in particular when connecting a third-party email service provider, this Policy will be updated to name that provider, the scope of data shared with it, and — if applicable — information on transfers of data outside the European Economic Area, in accordance with the rules described in Section 11.
4. Is providing data mandatory?
Providing the data described in Sections 3.1–3.5 is voluntary but necessary to create an Account, make a Booking, obtain Verified Owner status, or use the relevant Platform feature — without it, the corresponding feature will not be available.
5. Automated decision-making
The Controller does not make decisions concerning Users based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect them. The result of Stripe Identity verification (Section 3.3) is an input into a process in which the final decision to grant access to a Platform feature remains with the Controller, rather than a fully automated system.
6. Who we share data with
We share Users' data only with entities necessary to provide the Platform's services: • Sharetribe (Sharetribe Oy, Erottajankatu 19 B, 00130 Helsinki, Finland — marketplace platform provider); Role: Processor — hosts accounts, Offers, Bookings, messages, and verification requests; Scope of data: Account, Offer, Booking, and message data; Owner verification documents; Location: Sharetribe Oy is established in Finland (EU). Under Sharetribe's own privacy policy, data is generally not transferred outside the European Economic Area, and where such a transfer is necessary to provide the service, it takes place only with appropriate safeguards required by data protection law (in particular, standard contractual clauses) • Stripe, Inc. / Stripe Payments Europe, Limited; Role: Processor — payment processing, Stripe Connect, Stripe Identity; Scope of data: Transaction data, Owner billing data, documents and biometric data in the identity verification process; Location: European Union (Stripe Payments Europe, Limited — Ireland) and the United States (Stripe, Inc.) under standard contractual clauses approved by the European Commission • freeipapi.com (operator: FreeIPAPI, AltdorferStr 6, 40237 Düsseldorf, Germany); Role: IP geolocation service provider; Scope of data: IP address (queried once, not stored by the Controller); Location: Germany (EU) — the operator's registered location; its own privacy policy does not explicitly guarantee that API request processing occurs solely within the EU, but the limited scope of data involved (a single IP address, not retained by the Controller) makes the associated risk minimal • OpenStreetMap Foundation / Nominatim; Role: Geocoding service provider for Offer addresses; Scope of data: Textual Offer address (not the User's personal data); Location: Europe • National Bank of Poland (NBP); Role: Public, free exchange-rate API; Scope of data: No personal data shared; Location: Poland • Head of the National Revenue Administration (Szef Krajowej Administracji Skarbowej); Role: Recipient of the DAC7 tax report (a statutory obligation of the Controller); Scope of data: PESEL/NIP numbers and other Owner data required under DAC7 rules (see Section 3.10); Location: Poland • Google Ireland Limited (Google Analytics 4); Role: Processor — analysis of Platform visit statistics, activated only after consent in the cookie banner (see Section 3.9); Scope of data: Data on the use of the Platform (pages visited, traffic source, anonymized IP address, device/browser type) — no data allowing direct identification of the User; Location: Ireland (EU); data may be further processed by Google group entities, including in the United States, under standard contractual clauses approved by the European Commission • (planned for the future) marketing/advertising tool providers; Role: To be implemented in accordance with Section 3.9; Scope of data: To be defined before implementation; Location: To be defined before implementation Data may also be disclosed to: accounting/legal service providers acting for the Controller, public authorities entitled to request it under applicable law, and the other party to a Booking (Guest ↔ Owner) to the extent necessary to perform the agreement concluded (e.g. name and contact details for booking purposes, and, for a Business Account Owner, also the company name, address, and tax ID shown on the Payment Confirmation). The Controller does not sell Users' personal data to third parties.
7. How long we retain data
• Account data — for the duration of the Account and, after deletion, for the limitation period of any claims related to use of the Platform (generally 6 years from the last relevant event, with that period ending on the last day of the calendar year — the general limitation period for a Consumer's claims against a business, Article 118 of the Polish Civil Code). • Transaction billing data and Payment Confirmations — for the period required by tax and accounting law (generally 5 years counted from the end of the tax year in which the tax obligation arose, in accordance with the Polish Tax Ordinance). • Owner verification documents — for the duration of the verification process and a reasonable period thereafter, justified by the need to demonstrate that verification was properly conducted in the event of a dispute or complaint; after that period, the data is deleted or anonymized. • Stripe Identity verification result (without the underlying documents, see Section 3.3) — for as long as the Account exists, to document compliance with the verification requirement for subsequent bookings. • Content of messages tied to a Booking — for as long as the Account exists, unless deletion has been requested earlier and retention is not necessary for evidentiary purposes related to the given Booking. • PESEL number (Section 3.10) — for the duration of the DAC7 reporting obligation and the statute-of-limitations period for tax liabilities. • Newsletter consent (Section 3.11) — until withdrawn by the User.
8. User rights
Every User has the right to: • access their personal data and obtain a copy of it, • rectify inaccurate or incomplete data, • erasure of data ("the right to be forgotten"), subject to limitations arising from the Controller's legal obligations (e.g. tax retention described in Section 7), • restrict processing in the cases specified in Article 18 GDPR, • data portability, for data provided to the Controller, in a structured, commonly used format, • object to processing based on Article 6(1)(f) GDPR (legitimate interest), • withdraw consent at any time, to the extent processing is based on it, without affecting the lawfulness of processing carried out before withdrawal, • lodge a complaint with the supervisory authority — the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl). To exercise the above rights, please contact us at info@campigotravel.com. We respond to requests without undue delay, and no later than one month after receipt (extendable by a further two months in particularly complex cases, of which the User will be informed).
9. Transfers of data outside the European Economic Area
Some Third-party Providers (in particular Stripe, Inc.) may process data outside the European Economic Area, including in the United States. In such cases, the transfer takes place under mechanisms provided for in the GDPR — in particular standard contractual clauses approved by the European Commission (Article 46 GDPR), ensuring an adequate level of data protection. A copy of the relevant safeguards may be obtained by contacting the Controller at info@campigotravel.com.
10. Data security
The Controller applies appropriate technical and organizational measures to protect personal data, including: encrypted connections (HTTPS) between the User's device and the Platform, no storage of full payment card data on the Controller's infrastructure (this data is processed solely by Stripe in accordance with the PCI DSS standard), restricted access to Owner verification documents limited to authorized personnel, and reliance on established infrastructure providers (Sharetribe, Stripe) with their own documented security measures.
11. Changes to this Privacy Policy
This Policy may be updated, in particular in connection with changes in law, changes to the Platform's functionality, or the implementation of new tools (e.g. analytics — see Section 3.9). We will inform Users of material changes by publishing the update on the Platform, and, for changes materially affecting the scope of processing, additionally by electronic means, with reasonable advance notice before they take effect.
12. Children
The Platform is not directed at, and does not offer its services to, persons under the age of 18. If the Controller becomes aware that personal data of a minor has been provided without an appropriate legal basis, such data will be deleted.
13. Contact
For matters relating to this Privacy Policy and the processing of personal data, please contact the Controller: • e-mail: info@campigotravel.com • correspondence address: ul. Wielicka 42/B3, 30-552 Kraków, Poland • phone: +48 799 041 345 This Privacy Policy is also available in a Polish-language version. In the event of any discrepancy between the Polish version and the English version, the Polish version shall prevail.
This Privacy Policy is also available in Polish. In the event of any discrepancy between the Polish and English versions, the Polish version shall prevail.
