Effective: 2026 camp session (CTRL+H Camp 2026) Operator: Bethel Community, a Colorado nonprofit corporation (CO Secretary of State entity ID 20111631543; formed 2011-11-14; in good standing; community name in Russian: Вефиль). Registered office: 13231 E Mississippi Ave, Aurora, CO 80012. Site: ctrlh.camp (or production domain)
Plain language summary (read this first)
Bethel Community operates a website that lets parents register their children (ages 12–16) for CTRL+H Camp. To register a camper, we collect:
- Information about your child (name, date of birth, gender, health and medical needs)
- Information about you (parent name, phone, email, emergency contact)
- Information about your payment (handled by Square — we never see your card number)
- Technical information (IP address, browser type, timestamps)
We use this information only to register and operate the camp. We do not sell it. We do not advertise to your child. We keep it for as long as we need it for camp operations, insurance, and tax records, and then we delete it.
You can email hello@ctrlplush.com at any time to see, correct, or delete your information.
Краткое резюме на русском
Bethel Community (Вефиль) ведёт веб-сайт, на котором родители могут зарегистрировать своих детей (12–16 лет) на лагерь CTRL+H. Для регистрации мы собираем информацию о ребёнке, родителе, экстренном контакте, оплате (через Square — мы никогда не видим номер карты) и техническую информацию (IP-адрес, время). Мы используем эти данные только для регистрации и проведения лагеря. Мы не продаём их и не используем рекламу, нацеленную на вашего ребёнка. Мы храним их столько, сколько нужно для работы лагеря, страховки и налоговых документов, а затем удаляем. Вы можете написать на hello@ctrlplush.com, чтобы посмотреть, исправить или удалить свою информацию.
1. Who we are
Bethel Community ("Bethel," "Вефиль," "we," "us"), a Colorado nonprofit corporation (CO Secretary of State entity ID 20111631543; formed 2011-11-14), is the operator of CTRL+H Camp and the controller of the personal information collected through this website.
- Mailing address: Bethel Community · Aurora, CO
- Privacy contact: hello@ctrlplush.com
- Privacy phone: 720-753-8418
The website is technically built and maintained by an independent developer under contract with Bethel. The developer is a processor under privacy law; Bethel remains the controller of all data.
2. What information we collect
2.1 Information you provide when registering your child
- Camper's first name, last name
- Camper's date of birth and gender (used for age eligibility and gender-separated cabin assignment)
- Health and medical information: allergies, medications, chronic conditions, dietary restrictions
- Parent or legal guardian's full name, phone number, email address
- Emergency contact's name and phone
- Optional: how you heard about the camp; church referral
2.2 Waiver and consent information
- Typed signature, language attestation, summary-checkbox booleans (Liability+Terms, Privacy), timestamps
- IP address and hashed device fingerprint at signature
- COPPA parental consent timestamp (captured at payment for under-13 campers)
- Photo/media release consent (single bundled affirmation — see waiver Photo and Media Release section)
2.3 Payment information
Payment is processed by Square, Inc. Bethel does not receive or store your card number, CVV, or full bank details. Square sends Bethel only:
- Confirmation that payment succeeded
- The last 4 digits and brand of the card (for receipts)
- The Square charge ID
- Billing email and (optionally) ZIP/postal code
Square's own privacy policy: https://squareup.com/us/en/legal/general/privacy
2.4 Information collected automatically
- IP address (for security, abuse prevention, fraud detection)
- Browser type and operating system (User-Agent string)
- Page-view timestamps
- Referrer URL and UTM parameters (so we know which marketing channel brought you)
We do not use third-party advertising trackers, analytics that profile users, or social-media pixels.
3. How we use your information
We use the information collected only for:
- Registering your child for CTRL+H Camp
- Processing your payment
- Communicating with you about the camp (welcome, confirmation, intake reminder, schedule updates, cancellation)
- Operating the camp safely (medical care, emergency contact, authorized pickup)
- Inviting you to the camp's Telegram chat
- Meeting our legal, insurance, and tax obligations
- Preventing fraud and abuse on the website
- Improving our registration process based on aggregate, non-identifying patterns
We do not:
- Sell your information to anyone
- Share your information with advertisers
- Use your child's information for any purpose other than camp operations
- Send marketing emails to your child
- Make automated decisions that have legal or significant effects on you
4. Children's privacy — COPPA notice
CTRL+H Camp is designed for children ages 12 to 16. We follow the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §6501) and its implementing regulations (16 CFR Part 312) for any camper under 13 at the time of registration.
4.1 What we collect from under-13 campers
Only what a parent enters during registration and intake. Children under 13 do not interact with the website directly. The parent is the user; the child's information is collected from the parent.
4.2 Verifiable Parental Consent (VPC)
For any camper who is under 13 at the date of registration, we obtain verifiable parental consent using the "monetary transaction" method permitted by 16 CFR §312.5(b)(2)(ii): the parent completes a $260 payment on a credit/debit card in their name through Square, which provides reasonable assurance that the consenting adult is the parent. We capture and store the timestamp of this consent (coppa_consent_at) alongside the COPPA notice text the parent agreed to.
Timing of data collection. A small amount of camper identifying information (first name, last name, date of birth, gender) is collected at the registration step before the Square payment that captures VPC. This is the minimum information required to verify age eligibility and gender-balance availability prior to checkout. Bethel does not use this pre-VPC data for any purpose other than completing the registration funnel; if the parent abandons before payment, the row is deleted within 30 days. Health, medical, and any other sensitive data for under-13 campers is collected only at /intake after VPC is captured at payment.
4.3 Parent's rights under COPPA
If your child is under 13, you have the right to:
- Review the personal information we have collected about your child
- Have us delete that information
- Refuse to permit further collection or use of your child's information (in which case we will cancel the registration and process any refund per the refund policy)
To exercise any of these rights, email hello@ctrlplush.com. We will respond within 30 days, typically sooner.
4.4 No conditional disclosure
We do not condition your child's participation in any activity on disclosing more information than is reasonably necessary for that activity.
5. Colorado Privacy Act (CPA) disclosures
Colorado residents have the following rights under the Colorado Privacy Act (CRS §6-1-1301 et seq.):
- Right to access: confirm we are processing your data, and obtain a copy
- Right to correct: correct inaccurate personal data
- Right to delete: request deletion of personal data we hold
- Right to data portability: receive your data in a portable format
- Right to opt out: of sale or targeted advertising. Because Bethel does not sell personal data and does not engage in targeted advertising or profiling that produces legal or similarly significant effects, no universal opt-out mechanism (such as Global Privacy Control) is required to be honored. Bethel will nevertheless treat any received signal as a confirming preference.
To exercise any of these rights, email hello@ctrlplush.com. We respond within 45 days as required by §6-1-1306(2). You may appeal a denial by replying to our response within 45 days; we respond to appeals within 45 days. If unsatisfied, you may contact the Colorado Attorney General at coag.gov.
We do not engage in "profiling" that produces legal or similarly significant effects.
We process "sensitive data" (health data for minors). We rely on your consent (provided at registration) as the lawful basis. We obtain affirmative consent from the parent or legal guardian before processing sensitive personal data (including health data) of any camper under 13, as required by C.R.S. §6-1-1308(7). You may withdraw consent at any time by emailing us.
Data Protection Assessment
Bethel maintains a Data Protection Assessment for the processing described in this policy, on file with the privacy contact above.
6. GDPR / UK GDPR notice for EU/UK residents
If you are an EU or UK resident registering a child from outside the United States, please note:
- Bethel is established in the United States. Your data will be transferred to and stored in the United States.
- Our legal bases for processing under GDPR Art. 6 are: consent (Art. 6(1)(a)) for general processing, and contractual necessity (Art. 6(1)(b)) for completing your registration. For health data we rely on explicit consent (Art. 9(2)(a)).
- You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Contact hello@ctrlplush.com.
- You have the right to lodge a complaint with your local supervisory authority.
- Bethel has not appointed an EU representative under Art. 27 because the processing is occasional and low-volume. If this changes, this policy will be updated.
If you are unsure whether registering from your country is appropriate, please contact us first.
7. Who we share your information with
We share information only with these categories of third parties, and only as needed:
| Recipient | What | Why |
|---|---|---|
| Square, Inc. | Payment data | To process your payment |
| Supabase (Postgres hosting) | Stored registration data | Database hosting |
| Resend | Email address and template content | To send transactional emails |
| Vercel | Server logs | Website hosting |
| Bethel staff and volunteers | Camp roster, allergy summary, emergency contacts, authorized pickup persons | Camp operations |
| Emergency medical providers | Medical authorization and contact data | If your child needs medical care |
| Bethel's insurance carrier | Registration record and waiver | If an incident occurs |
| Law enforcement / courts | As legally required | Subpoena, court order, mandatory reporting |
Each commercial recipient has signed a contract (Data Processing Addendum or equivalent) requiring them to handle data securely and only as instructed.
We do not share your information with:
- Advertisers
- Data brokers
- Social-media platforms beyond the photo participation described in the waiver's Photo and Media Release section (which authorises Bethel's own posting to its closed family Telegram group, its public socials, and future-camp marketing as a condition of registration)
- Affiliated churches or ministries (without your consent)
8. How long we keep your information
| Data | Retention period | Why |
|---|---|---|
| Camper health data, medications, insurance — in the live operational database | 90 days after camp end (October 16, 2026), then deleted from the live database | No longer needed for operations |
| Waiver / intake PDF snapshot (which contains health, signature, clauses, IP, UA hash, photo-consent record) | Indefinitely while Bethel operates, OR a minimum of: until the camper named on this PDF reaches age 25 + 2 years, whichever is later | Colorado tort statute of limitations is tolled during minority (CRS §13-81-103); a 12-year-old can sue until at least age 20, and child sexual abuse claims under CRS §13-20-1201 may accrue without a fixed SOL. Spoliation risk if deleted earlier. Access restricted to Bethel's senior pastor and insurance carrier. |
| Payment record | 7 years | IRS requirements for nonprofit financial records |
| Email logs | 2 years | Deliverability debugging |
| Webhook events | 2 years | Idempotency + audit |
| Camp photos (authorised at waiver signing) | Indefinitely on Bethel-controlled channels (closed Telegram group, public socials, marketing assets) unless the parent submits a written withdrawal request to hello@ctrlplush.com, after which Bethel removes them from its own channels within 30 days where reasonably possible | Photos are part of normal camp operations; the parent's withdrawal right is preserved (see waiver Photo and Media Release section) |
| Aggregate, non-identifying statistics | Indefinite | Year-over-year planning |
Important honesty about health data: When the live database row is purged at 90 days, your child's health information is removed from operational systems. However, the waiver/intake PDF snapshot generated at signing — which is the legal evidence record — necessarily contains a frozen copy of the medical disclosures and elections you made at the time of signature. That PDF is preserved per the retention rule above and accessible only to Bethel's senior pastor and insurance carrier in the event of a claim.
After the retention period, data is permanently deleted from the production database and backups within 60 days.
9. Security
We protect your information using:
- HTTPS (TLS 1.2+) on every page and API call
- Encryption at rest in Supabase
- Service-role database access only from our server (your browser never reads/writes the database directly)
- Square Checkout (PCI-DSS Level 1) for payment — no card data on our servers
- Rate limiting and CSRF protection on all data-changing endpoints
- Webhook signature verification for payment events
- Stripping personal information from server error logs
- Multi-factor authentication on Bethel's administrative accounts (Vercel, Supabase, Square, Resend)
- Annual access review
No system is perfectly secure. If we discover a breach affecting your information, we will notify you and the Colorado Attorney General as required by Colorado law (CRS §6-1-716).
10. Cookies and tracking
This site uses one cookie, named cth_rid. It contains a random identifier (UUID) that lets us tie your registration steps together. It is:
- HTTP-only (JavaScript cannot read it)
- Secure (only sent over HTTPS)
- SameSite=Lax (limits cross-site usage)
- Expires after 24 hours
We do not use:
- Google Analytics or other analytics cookies
- Advertising cookies
- Social-media share-button cookies
- Third-party tracking pixels
You can delete this cookie at any time through your browser settings. If you delete it mid-registration, use the "resume" link in your welcome email to continue, or contact us to recover your registration.
11. Your choices
- Decline to register: the site is voluntary. If you don't agree to this policy, do not register.
- Withdraw consent: email us to delete your data and cancel the registration. Refunds apply per the refund policy.
- Opt out of optional emails: transactional emails (registration confirmation, intake reminder, schedule changes, cancellation notices) are required to operate your camper's registration. We do not send marketing emails to camp-registered parents.
- Photo participation: photos and video are taken of all campers as part of normal camp operations; by signing the waiver you authorise Bethel to use them in the closed Telegram group for registered families, on Bethel's public social-media channels, and in future camp marketing. This is a condition of registration — see the waiver's Photo and Media Release section. Photo participation during camp cannot be opted out of mid-camp. After camp, you may submit a written withdrawal request for future use by emailing hello@ctrlplush.com; Bethel will acknowledge within 7 business days and remove photos of your child from its own channels within 30 days where reasonably possible.
12. Changes to this policy
If we materially change this policy, we will:
- Post the new policy at this URL
- Update the "Effective" date at the top
- Preserve the prior version at
docs/policies/privacy-policy-vN.md - Email registered parents about the change with at least 30 days' notice if the change affects how their data is used
- Re-obtain consent if the change would expand the uses of data beyond what was originally consented to
13. Contact
For any privacy question, request, or concern:
- Email: hello@ctrlplush.com
- Phone: 720-753-8418
- Mail: Bethel Community · Aurora, CO
We aim to respond within 5 business days for general questions and within the statutory deadlines for formal rights requests (30 days for COPPA, 45 days for CPA, 1 month for GDPR per Art. 12(3), extendable by 2 further months for complex requests).