Privacy Policy

Version 1.0 — effective July 26, 2026

Summary

Built For More Works builds software that camps, retreats, churches, and mission organizations use to run registration, health records, payments, and email. Most of the personal information in our systems belongs to those organizations and to the families and supporters who deal with them — we hold and protect it on their behalf. We do not sell personal information, we do not run advertising, and we do not use the information in our systems to train artificial-intelligence models.

1. Who this policy covers

This policy applies to the software services operated by Built For More Works (builtformore.works), including Built For Camp (builtforcamp.com) and the other Built For More products that share the same platform, together with the public pages of those sites. We call all of it the Services.

It does not cover the websites, newsletters, or offices of the camps, churches, and organizations that use the Services. Those organizations set their own policies.

2. Our role, and your organization's role

Nearly everything in the Services is entered by, or on behalf of, an organization that has an account with us — a camp, a retreat host, a church, or a mission agency. That organization decides what to collect, who on its staff may see it, and how long to keep it. It is the controller of that information. We are its service provider: we store and process the information to run the Services and to support the organization, and we act on its instructions.

If you are a parent, camper, attendee, donor, or newsletter subscriber, the organization you registered with is the first place to go with a question about your information, a correction, or a deletion request. We help them answer you.

3. Information in the Services

What is actually present depends on which features an organization uses.

  • Account and sign-in. Name, email address, phone number, date of birth, mailing address, and the one-time codes used for passwordless sign-in.
  • Registration. Attendee and camper details such as name, date of birth, grade, gender, lodging or program choice, church or group affiliation, schedule information, and the answers to any custom questions an organization adds to its own forms.
  • Emergency and pick-up contacts. Names, relationships, and phone numbers of the people a family authorizes.
  • Health information. Where a camp uses the health features: allergies, medical conditions, medications and dosing schedules, over-the-counter consent, medication check-in and administration records, incident and first-aid reports, and health-form answers.
  • Consents and signatures. Waivers, liability releases, faith statements, and training acknowledgements, with the date, time, and IP address of the acceptance.
  • Payments. Amounts charged, paid, refunded, and owed; the payment method type; check or reference notes an office enters; discount and sponsorship codes. Card numbers and bank details are entered directly with our payment processor and are never stored in our systems.
  • Contacts, supporters, and gifts. Where an organization uses the newsletter or donor tools: contact name, email address, phone number, mailing address, the classification and notes its staff record, subscription and unsubscribe status, and manually recorded gift amounts, funds, and dates.
  • Messages. The content of email an organization sends through the Services, the addresses it went to, and delivery outcomes. Message bodies are kept for a limited window for troubleshooting; the record that the message was sent is kept longer.
  • Files and images. Logos, newsletter images, and documents uploaded by staff.
  • Technical and audit records. IP address, browser type, dates and times of access, sign-in events, and a log of who viewed or changed sensitive records. Some of these logs are append-only by design: they can be added to but not edited or deleted, which is what makes them worth trusting.

4. How the information is used

  • To provide the Services an organization has asked for: registration, rosters, health records, check-in and check-out, payments, reporting, and email.
  • To send transactional messages — sign-in codes, registration confirmations, receipts, reminders, and account notices.
  • To send newsletters and organization announcements, where the organization sends them and the recipient has not unsubscribed.
  • To keep the Services secure: rate limiting, spam prevention, investigation of fraud and abuse, and audit logging.
  • To support and troubleshoot at an organization's request.
  • To meet legal, accounting, and safety obligations.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it to train artificial-intelligence models.

5. Health information

Health information a family provides for a camper or attendee is treated as sensitive. Access is limited to the staff an organization designates — typically its nurse, medical staff, and administrators — and each view or change is written to an audit log that cannot be edited afterward. Health records are stored in the same protected database as the rest of an organization's data and are not used for any purpose other than caring for the person they describe.

Built For More Works is generally not a HIPAA covered entity, and most camps are not either. Where an organization is subject to HIPAA or a comparable obligation, we will enter into the agreement it needs.

6. Children

Accounts in the Services are created by adults. Children do not sign themselves up, and the Services are not directed to children as consumers. Information about a child is provided by a parent or guardian, or by the organization the family registered with, so that the child can attend a camp, retreat, or program. We use it only for that purpose and to provide the Services to the organization. A parent or guardian may review, correct, or ask for deletion of a child's information by contacting the organization, or us at the address below.

7. Payments

Card payments are processed by Stripe, on the organization's own connected Stripe account. Card details are collected by Stripe in its hosted checkout and are never transmitted to or stored by us; we receive a confirmation, the amount, and a reference number. Stripe handles payment data under its own privacy policy.

8. Email you receive

Transactional email — sign-in codes, confirmations, receipts, and notices about a registration — is part of the service and is sent when you use it.

Newsletters and announcements carry a one-click unsubscribe link in every message. Unsubscribing from an individual sender stops that sender; there is also an option to stop all messages from the organization. Unsubscribe requests take effect immediately and are kept on file so the address is not mailed again.

9. Cookies

The Services use the cookies they need to work: a sign-in cookie that keeps you logged in, and a security token that protects forms against cross-site request forgery. We do not use advertising cookies, and the application embeds no third-party analytics or advertising trackers. Some public forms use Google reCAPTCHA to block automated abuse; where it appears, Google receives information about that interaction under its own privacy policy.

10. Who we share information with

We share information with the organization whose records they are, and with the service providers that make the Services run:

  • Microsoft Azure — hosting, databases, and file storage, in the United States.
  • Stripe — payment processing.
  • Postmark, and other email delivery providers an organization selects — sending email on the organization's behalf.
  • SignWell — electronic signature, only for organizations that turn it on with their own account.
  • Google reCAPTCHA — automated-abuse prevention on public forms where it is enabled.

These providers may use the information only to perform their service for us. We also disclose information where the law requires it, to protect someone's safety, to establish or defend legal claims, or in connection with a merger or sale of the business — in which case the information stays subject to a policy at least as protective as this one.

11. Security

Traffic is encrypted in transit, and data is encrypted at rest by our hosting provider. Sign-in is passwordless: a one-time code is emailed to a verified address, so there is no password to reuse or leak. Access to an organization's data is limited by role, and each organization's records are separated from every other organization's at the data layer. Sensitive audit trails — consent records, health-record access, and payment history — are append-only. Third-party keys an organization entrusts to us are encrypted before they are stored.

No system is perfectly secure. If a breach affects personal information, we will notify the affected organizations promptly and cooperate with the notices the law requires.

12. How long information is kept

We keep an organization's information for as long as it uses the Services, and afterward for the period it asks for or the law requires. Within that:

  • Registration and attendance records are retained across seasons, so families and offices can see their history.
  • Financial records are retained for accounting and tax purposes.
  • Health records are retained for the period the organization sets, and are reduced to what is still needed once a season is closed.
  • Email message bodies in the send log are removed after a short retention window; the record of the send remains.
  • Append-only audit logs are retained for the life of the account.

When an organization leaves, we return or delete its data on request, except for records we are required to keep.

13. Your choices and rights

You can review and update most of your own information by signing in. Depending on where you live, you may also have the right to request a copy of your personal information, to correct it, to delete it, or to object to certain uses, and to be free from discrimination for exercising those rights. We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of on that front.

Because organizations control the records they enter, please start with the organization you registered with. If you would rather come to us, write to privacy@builtformore.works and we will route the request and help fulfill it. We may need to verify your identity before acting.

14. Where information is stored

The Services are hosted in the United States. If you use them from another country, your information is transferred to and stored in the United States.

15. Changes to this policy

When this policy changes we publish a new version with a new effective date. Earlier versions stay available on this page, so the history of what we said, and from when, remains visible. We also tell the organizations that use the Services about material changes.

16. Contact

Built For More Works
privacy@builtformore.works