This policy explains what personal data Campaign Vision ("we", "us") collects, how we use it, and the choices you have. It covers two things: this website (campaignvision.ai) and the Campaign Vision analytics platform (the "Service").
The short version
- This website has no advertising trackers and no third-party analytics cookies.
- We collect personal data on this site only when you submit a form — and we use it only to respond to you.
- The Service is designed so that it never identifies the people it counts: camera frames are processed in memory and discarded, no video is stored, no facial recognition is performed, and only aggregate metrics are kept.
- We do not sell personal information, and we never have.
1. Data we collect on this website
Forms you submit
When you book a demo, request a quote, or join the newsletter, we collect what you type — typically your name, work email, company, and message. We use it to respond to your inquiry, prepare your quote, or send you the content you signed up for. Form submissions are delivered to us by Formspree (our form-processing provider) and retained for as long as we need them to handle your request and maintain our business records. You can ask us to delete a submission at any time (see Your rights).
Newsletter
If you subscribe, we use your email only to send the newsletter. Every email includes a way to unsubscribe, and unsubscribing removes you from the list.
Preferences stored in your browser
Your light/dark theme choice is stored in your browser's local storage. It never leaves your device and is not a tracking cookie.
Server logs
Like nearly every website, our hosting provider records standard technical logs (IP address, browser type, pages requested) for security and reliability. These are kept briefly and are not used to profile visitors. If we ever add website analytics, we will use a privacy-respecting, cookieless tool and update this policy first.
2. Data processed by the Service
The Service turns camera feeds from live events into aggregate crowd metrics — headcounts, dwell time, zone engagement. Two roles matter here:
- Our clients are the data controllers for their events. They decide where cameras point and what notice attendees receive.
- We are the data processor: we process camera frames on our clients' behalf, under their instructions and a Data Processing Agreement.
How the Service is built to handle that data:
- Camera frames are processed transiently in memory and immediately discarded. No video is recorded or stored.
- No facial recognition is performed and no biometric templates are created or stored.
- No device identifiers (Wi-Fi/Bluetooth MAC addresses or similar) are collected.
- What persists are derived, aggregate metrics: counts, dwell times, zone activity, heatmaps. These numbers do not identify anyone.
- Optional demographic estimates (age band and gender mix), where a client explicitly enables them, are produced only as crowd-level aggregates with small-group suppression — never as per-person records.
- Derived metrics are retained for 90 days by default, then deleted automatically. Clients can contract for different retention.
Because the Service keeps no data that identifies an event attendee, we cannot look up an individual's data — there is nothing to look up. If you attended an event and have questions about how it was measured, the event organizer (our client) is the controller and your first point of contact; we support our clients in answering those requests.
3. Sub-processors
We use a small set of infrastructure providers to run the website and the Service. All processing currently takes place in the United States:
- Vercel — hosting for this website and the app front end
- Render — application backend hosting
- Supabase — database and authentication
- Modal — GPU compute for transient camera-frame processing
- Upstash — in-memory data infrastructure (queues, pub/sub)
- Cloudflare — DNS, security, and file storage (e.g. venue floor plans)
- Anthropic — AI-generated report text, produced from aggregate metrics only
- Formspree — website form processing
Each provider processes data only as needed to provide its service to us. We will update this list when it changes; clients with a DPA are notified of sub-processor changes under its terms.
4. Security
Data moves over encrypted connections (TLS). Camera credentials supplied by clients are encrypted at rest. Access to production systems is restricted and credentialed. Privacy-sensitive capabilities in the Service (such as demographic estimation) are disabled by default and gated so they cannot be switched on accidentally.
5. Your rights
Depending on where you live (including under the GDPR and the CCPA), you may have rights to access, correct, delete, or receive a copy of your personal data, and to object to or restrict certain processing. To exercise any of these, email [email protected] — we respond to every request. We do not sell or share personal information as those terms are defined by the CCPA, and we do not discriminate against anyone for exercising a privacy right.
6. International visitors
We are based in the United States and process data there. If you contact us from outside the US, your form submission will be transferred to and processed in the US.
7. Children
Neither the website nor the Service is directed at children, and we do not knowingly collect personal data from anyone under 16. In the Service, demographic estimates for under-18 age bands are suppressed by design.
8. Changes to this policy
When we change this policy, we update the date at the top of this page. Material changes affecting clients are communicated directly.
9. Contact
Questions, requests, or complaints: [email protected]. Clients who need our Data Processing Agreement can request the current version at the same address.