Powerful analytics that don't surveil your visitors.
Campaign Vision is anonymous by design. You get real performance data from a live event without facial recognition, without storing video, and without building a profile of anyone in the room.
What the system does — and doesn't do.
What it does
- Detect and count people in the camera view
- Distinguish visitors by body shape and clothing, for the event only
- Measure dwell time, zones, density, and movement between zones
- Optionally estimate the crowd's aggregate age/gender mix — off by default, enabled per event
- Store derived metrics — counts, dwell, zones, heatmaps
- Automatically delete metrics after the retention window (90 days by default)
What it never does
- Run facial recognition or identify anyone by face
- Store video or camera frames
- Keep biometric templates or personal profiles
- Collect device identifiers like MAC addresses
- Attach names, accounts, or identities to anyone
What the system sees — in motion.
From camera frame to a number — and nothing kept in between.
Frame in
A camera frame is read from your existing camera feed and passed to the model in memory.
People detected
Computer vision locates and counts people in the frame — the analytics happen on the image, not on identities.
Metrics derived
Counts, dwell, zone events, and density are calculated and saved as plain numbers.
Frame discarded
The frame is dropped. What persists is the derived metric — never footage of your visitors.
Privacy that's enforced in software, not promised in a PDF.
Anyone can write a privacy policy. These protections are defaults built into the product itself — because the safest data is data the system never keeps.
Facial recognition: off, and locked
Face-based processing ships disabled — and production systems fail closed, refusing to run it without a deliberate, documented override. Nothing in Campaign Vision's analytics identifies anyone by face.
Small groups stay invisible
Heatmaps automatically suppress cells with fewer than three people, so a lone visitor can never be singled out of the data — even by you.
Individual paths aren't stored
Per-person movement trajectories are discarded by default. Journey insights — including cross-camera journeys — are aggregates: how many visitors flowed from one zone to another, never a stored path or profile for any individual.
Deletion is the default
Derived metrics are purged automatically after the retention window — 90 days by default. Forgetting is built into the system, not a support ticket.
“Wouldn't a sensor without a camera be safer?”
It's the right question to ask — here's the honest comparison.
WiFi / Bluetooth trackers
Avoid cameras by tracking phones instead — which means logging device identifiers (MAC addresses), personal data under GDPR. That isn't anonymity; it's a different identifier. And modern phones randomize those identifiers by default, eroding the counts.
Radar & depth sensors
Genuinely anonymous — because they measure almost nothing. A presence count, but no engagement quality, no dwell at a specific display, no attention signal. Proprietary hardware you rent, ship, and install, either way.
Campaign Vision's answer
Process camera frames transiently, keep only numbers. There's no stored footage to breach, leak, or subpoena — and no device identifiers either — while still measuring what actually matters at a live event.
Made to pass a privacy review.
Anonymous by design
No facial recognition and no biometric identity, so processing is designed to stay anonymous — the foundation of a GDPR/CCPA anonymous-processing posture.
Data minimization
Only derived metrics are retained. Less personal data collected means less to secure, govern, and explain to a regulator.
On-site option
Need data to never leave the venue? Ask us about on-premise deployment for security-sensitive activations.
Onboarding guidance
We share practical guidance on venue signage and visitor notice so your deployment fits how you operate.
This page describes how the platform is designed to handle data; it is not legal advice, and your obligations depend on your deployment and local regulations. For where processing physically happens — cloud, on-site relay, or edge/on-premise — see deployment options. For binding terms, see your Data Processing Agreement and our Privacy Policy.
Privacy & data questions
Is this facial recognition?
No. Campaign Vision does not use facial recognition and does not identify anyone by face. Visitors are distinguished by body shape and clothing for the duration of an event only, then those signals are gone. Face-based processing is disabled in the product by default, and production systems refuse to run it without an explicit, documented override.
Do you store video of our visitors?
No. Camera frames are processed in memory and discarded. What's stored are derived metrics — counts, dwell, zones, heatmaps — not footage.
Do you estimate age and gender?
Optionally, and only when you explicitly enable it for an event. The output is an aggregate estimate — an age-band and gender mix for the crowd as a whole. It analyzes appearance in the frame, but no one is identified, no face template is created or stored, nothing is kept per person, and small groups and under-18 estimates are suppressed automatically. This is analysis, not facial recognition — and like every estimated metric, it's labeled as an estimate in the product. For events in jurisdictions with specific biometric statutes (e.g. Illinois), we'll flag the extra review this feature needs before enabling it.
Isn't a sensor with no camera safer than a camera?
Sensor vendors avoid imagery in one of two ways: by tracking phones (which logs device identifiers — personal data under GDPR, not anonymity) or by measuring so little that engagement can't be assessed at all. Campaign Vision takes a third path: camera frames are processed transiently and discarded, and only aggregate numbers are ever kept. Nothing identifying exists to be breached.
Does this make us GDPR/CCPA compliant?
It's designed to support an anonymous-processing posture under GDPR/CCPA, which is a strong starting point. Your overall compliance still depends on your deployment, jurisdiction, and notice/consent practices — we'll help with signage guidance, but this isn't legal advice.
Where is our data hosted and how long is it kept?
Derived metrics are retained for 90 days by default, then deleted automatically; longer retention can be configured for teams that need season-over-season comparisons. Processing and storage run on cloud infrastructure in the United States — the current sub-processor list is published in our Privacy Policy. On-premise deployment is also available for teams that need data to stay on site — ask us.
Can we get a DPA?
Yes — we sign Data Processing Agreements with clients who need one, and we're used to procurement and legal review. Ask during your demo call or email us, and we'll share the current DPA and sub-processor documentation for your review.
Bring your privacy questions.
Book a demo and we'll walk your team through exactly how data is handled — and share the documentation your legal and procurement reviewers need.