🛡️ CampCrew

Security Policy & Data Protection Architecture

Last Updated: August 31, 2026

At CampCrew, safeguarding family memories, private campsite logs, and personal data is central to our engineering architecture. This document outlines the technical security controls, access models, and operational measures protecting your data across our mobile applications, web platforms, and cloud infrastructure.

1. Security Architecture Principles

🔒 Zero Password Exposure

We do not manage or store passwords. User authentication is delegated entirely to Google OAuth 2.0 and Firebase Auth tokens.

👥 Crew-Scoped Isolation

Database and object access controls enforce strict tenant boundaries so data is never readable outside authorized family groups.

🌐 Enforced TLS 1.3 Transport

All client-to-server and cloud-to-cloud traffic is encrypted with modern TLS 1.3/HTTPS and strict security headers.

💳 Zero Card Data On Servers

All financial and payment transactions are handled directly by PCI-DSS Level 1 certified gateways (Stripe & Google Play).

2. Authentication, Access Control & Registration Passes

CampCrew relies exclusively on Google Sign-In via Firebase Authentication:

3. Granular Database Security (Cloud Firestore)

Cloud Firestore data access is governed by comprehensive, emulator-tested Security Rules that operate at the query level:

4. Media Storage & Object Protection (Cloudflare R2)

CampCrew stores campsite photos, banner images, and park maps in encrypted Cloudflare R2 object storage with multi-layered defenses:

5. Payment & Billing Security

6. Data Minimization & Right to Erasure

7. Vulnerability Disclosure & Bug Reporting

We welcome security researchers and community members to report potential vulnerabilities. If you discover a security flaw, please contact our dedicated security team:

Security Contact: security@campcrew.camp

Please include a detailed description of the vulnerability, reproduction steps, and proof of concept. We commit to acknowledging reports within 48 hours and will not pursue legal action against researchers acting in good faith.