Security and trust
Last updated: 28 August 2026
The short version
CampSuite® is built and run in Carlisle by WorkBee Limited, a UK company. Your guests’ data is held in the UK and the EEA. Their card details go straight to Stripe and never touch our systems. The money lands in your own Stripe account, in your name, not in ours.
Below is the detail behind each of those, and the agreements that hold us to them. Anything this page does not answer, ask and we will answer it: hello@campsuite.net or 01228 581035.
Who you are dealing with
| Legal entity | WorkBee Limited, trading as CampSuite |
| Company number | 13120552, registered in England and Wales |
| Registered office | 2 Eden Bank, Etterby, Carlisle, CA3 9QS |
| VAT number | GB367653755 |
| Support | UK-based. 01228 581035 and hello@campsuite.net |
CampSuite is not a reseller of somebody else's platform and is not a brand on top of an overseas product. It is written and supported by the company named above, in Carlisle.
Payments
- Card processing is Stripe's. Card details go from your guest's browser straight to Stripe. They never reach CampSuite, so there is no card data on our systems to lose. Stripe is certified to PCI DSS Level 1, the highest level the card schemes define.
- The Stripe account is yours. CampSuite connects to your own Stripe account rather than taking your money into ours. Your takings are never pooled with another park's and never sit in a CampSuite balance.
- What CampSuite keeps is the transaction reference, the amount and whether it succeeded, enough to show the booking as paid, and nothing that could be used to take a payment.
- You set the payout schedule. Stripe pays out on the schedule held against your own account, which you change in your Stripe dashboard whenever you like. That is why this page quotes no payout date: the timing is yours to set.
Data protection
- For your guests' data, you are the controller and CampSuite is your processor. Our obligations to you are written down in the data processing agreement, which applies to every account without you having to ask for it.
- Every third party that can process personal data for us is named, with what it does and where, on the subprocessor list.
- Personal data is stored in the United Kingdom and the European Economic Area.
- You can export your data whenever you want, and it is deleted within 30 days of your account closing, other than what the law requires us to keep.
- We do not sell your data, share it with advertisers, or use your guest data to market to your guests.
Full detail: privacy policy · cookie policy.
How the service is protected
- Encrypted in transit and at rest. Everything is served over HTTPS, and stored data is encrypted on disk.
- Separated by site. One park cannot see another park's bookings, guests or takings.
- Access is authenticated and limited. Your staff get their own logins. On our side, access to customer data is restricted to the people who need it to run the service or answer a support request, and everyone with it is under a duty of confidence.
- Backed up. Your site's data is backed up, so a mistake at your end or a failure at ours is recoverable rather than final.
- Hosted in the UK. This website runs on Microsoft Azure App Service in a UK region.
Certifications, and what we offer instead
CampSuite does not hold ISO 27001 or SOC 2. It does not need PCI DSS certification of its own, because card data is handled entirely by Stripe and never reaches our systems.
What we put in their place is specifics. A data processing agreement that applies to your account automatically, with the terms written out rather than promised. A named list of every third party that can touch personal data, what it does and which country it does it in. And a direct answer from the person who wrote the software to whatever question your insurer, your club or your own adviser puts to us. Ask, and you will get one.
Reporting a security problem
If you think you have found a vulnerability in CampSuite, please email security@campsuite.net with enough detail for us to reproduce it. We will acknowledge you, keep you informed, and we will not take action against anybody who reports something in good faith and does not access or change other people's data while doing it.
If personal data we hold for you is involved in a breach, we tell you without undue delay and in time for you to meet your own obligation to report it, as set out in clause 11 of the DPA.