Your data is yours. Export it, whenever you want.

A way out, built in, so you never need one in a hurry

Most camp software quietly holds your data hostage. Leaving means a support ticket, a wait, and a file you can barely use, if you get one at all. The lock-in is the point: it's easier to keep you than to earn you. CampOrganizer starts from the opposite principle: your organization owns its data. We store and process it to provide the service, ownership never transfers to us. So there's an Export Center inside Camp Hub where owners and administrators export the camp's data themselves, participants, staff, submissions, financial records, as machine-readable files, without asking our permission. A clear path in, and a clear path out. But a self-serve export of a camp's data is also exactly what an attacker or a disgruntled account would want. So the same feature that frees your data protects it: an export that includes sensitive data goes into an approval queue, and a second authorized person, never the requester, must approve it before it runs. Data ownership and data safety are the same feature here: you can always get your data out, and no single person can quietly take it.

Self-serve portability, with a second set of hands on anything sensitive

  • A self-serve Export Center Owners and administrators export their camp's data from a dedicated Export Center in Camp Hub, no support ticket, no gatekeeper, no waiting on us.
  • Machine-readable, actually usable Structured files you can load into another system, not a locked PDF, not a screenshot, not a report you'd have to reverse-engineer.
  • Your slice, or the whole camp Pick the export type and filter to exactly the data you need, or take a comprehensive camp-level export for continuity, audit, or migration.
  • Two-person approval on sensitive exports An export carrying sensitive data starts in an approval queue, and a second, different Camp Manager, never the requester, must approve it before it runs. Nobody approves their own request, and the rule is enforced on the server.
  • Short-lived, tracked download links A completed export is delivered through a short-lived, single-use link, and re-issues are counted, a finished file doesn't linger as an open door.
  • A visible queue and history Requested, awaiting approval, running, completed, expired, the Export Center shows the full lifecycle, and you're notified when your file is ready. Who exported what is visible, not hidden.
  • Scoped by role Camp Managers and admins see and manage the whole export queue; lower-privilege staff see only their own requests.
  • No lock-in, by design Your data leaves in a usable, standard form, so moving platforms is your decision to make, not a hostage negotiation.

An exit path is a trust feature from day one

A Plan B you can actually test

An independent copy of your data, requestable any time, so continuity isn't a theory, it's something you've verified works.

Audits and reviews

When the insurer, the auditor, or the board asks, a comprehensive export supports the review, without a support ticket in the critical path.

Migration, when you choose it

If another system fits better, the export is a structured starting point for the move. We don't block your exit by withholding your data.

Account closure without data loss

Ending the service doesn't mean losing what your organization created. Export before closure is a defined path, not a negotiation.

From "I need our data" to a safe, downloadable file

1

Open the Export Center

A Camp Admin or Manager opens the Export Center in Camp Hub, no ticket, no wait.

2

Choose the data and filters

Pick the export type and narrow it to the slice you need, or request the comprehensive export.

3

Sensitive data goes for approval

If the export carries sensitive data, it enters the approval queue instead of running immediately.

4

A second person approves

A different authorized person reviews and approves, or rejects, the request. The requester can never approve their own.

5

The export runs

Once cleared, the platform prepares the export and notifies you when it's ready.

6

Download through a secure link

Collect the file through a short-lived, single-use link that expires, with re-issues tracked.

7

Every export is on the record

The request, the approval, and each download are recorded, data leaving the platform is always accountable.

The right to your data, with the right controls

Camp owners and administrators

Export the camp's data whenever needed, oversee the queue, and act as the approver that releases anything sensitive.

Camp managers

Request exports and approve other people's sensitive requests, releasing sensitive data is always a two-person act.

Coordinators and other staff

Request the exports their role allows and see their own requests, without visibility into the whole camp's export activity.

Compliance and technology teams

Review the export trail and approval history for governance, and use the structured data for migration, archiving, or integration work.

The requester

Can start an export, but can never approve their own sensitive one. That's the whole point of the control.

Export reads the same data, and the same classification, as everything else

From your records

exports draw on the same participants, staff, submissions, and finances the platform already holds, what you take out is what you put in.

From the classification model

whether an export needs approval is decided from the platform's field classifications, not guessed.

Beside the Report Builder

reports answer operational questions inside the platform; export moves the data itself, in bulk, out.

Into the audit trail

requests, approvals, and downloads are recorded alongside the rest of the platform's security events.

Getting your data out must never be a way to steal it

  • No single person can release sensitive data Two people, always: the requester and a separate approver. The requester can never approve their own request, and the rule is enforced on the server, not just hidden in the interface, a compromised or malicious single account cannot quietly export a camp.
  • Gated by classification, not blanket-open Whether the two-person gate applies is decided from the data's classification, routine exports stay easy, and the ones carrying sensitive data get the extra hands.
  • Files that don't linger Completed exports are delivered through short-lived, single-use links with re-issues tracked. A download is a moment, not a permanently open door.
  • Every export is accountable The request, who approved it, and each download are recorded, any data leaving the platform traces to a person and a decision.
  • After download, the copy is yours, and your responsibility Once an authorized user downloads the export, your organization controls that copy and is responsible for storing, sharing, and deleting it according to its own security and privacy obligations. Portability transfers the data, and the duty of care with it.
  • Certified security management Data is encrypted in transit and at rest, and CampOrganizer's information security management system is certified according to ISO/IEC 27001:2022 by an independent certification body, covering both standard and white-label deployments. The certificate and certified scope are published on the Trust page.

Own your data, without making it easy to steal

No hostage situation

Your data leaves in a usable form whenever you want it, so choosing to stay is about the product, not about being unable to leave.

A Plan B you control, and can verify

Owners and admins get the camp's data themselves. Continuity doesn't depend on our support queue or our goodwill, and you can prove it any Tuesday.

Portability that isn't a back door

The two-person control means the feature that frees your data also stops a single account from walking off with it.

Accountable, not silent

Every export is approved and logged, data movement is a visible, traceable event, not an invisible copy.

Trust runs both ways

We'd rather retain your trust than restrict your exit. A vendor confident enough to hand you your data on demand is a vendor that earns your stay instead of trapping it.

Frequently asked questions about camp data export

Can I export all of my camp's data?
Owners and administrators export the camp's data, participants, staff, form submissions, and financial records, as machine-readable files from the Export Center in Camp Hub. The comprehensive export covers the supported record types; exact contents follow the data available, enabled features, and retention rules.
Do I have to ask support to get my data?
No. Export is self-serve for owners and administrators, no ticket to file, no gatekeeper to wait on.
What format do exports come in?
Structured, machine-readable files you can load into another system, not a locked document or a screenshot.
Can I move to another platform?
Yes, that's one of the export's stated purposes. Your data leaves in a usable, standard form; the receiving platform or migration partner handles mapping it into their own structure, as with any migration.
What stops someone from stealing our data through export?
An export carrying sensitive data can't be released by one person: a second authorized approver, never the requester, must confirm it, enforced on the server. Download links are short-lived and single-use, and every request, approval, and download is logged.
Who approves a sensitive export?
A second authorized person, different from whoever requested it, a camp manager or the owner. Nobody approves their own request, and an unexpected request can be rejected before anything is generated.
Do download links expire?
Yes. Completed exports are delivered through short-lived, single-use links, and re-issues are tracked.
Who can run exports?
Owners and administrators manage the full export queue; lower-privilege staff can request the exports their role allows and see only their own.
Can CampOrganizer stop us from exporting because we plan to leave?
No. We don't use your data as a retention mechanism. Export remains subject to identity, authorization, and security controls, not to a requirement that you stay.
Should we export before closing our account?
Yes, complete and securely retain your exports before closure and before the applicable retention period ends. Each export is a point-in-time copy: data changed later appears in a newer export, not retroactively in an old archive.

See how easy it is to get your data out, and how hard it is to steal

In a 30-minute demo, we'll show how owners and admins export their camp's data themselves, while the two-person approval keeps a self-serve export from ever becoming a leak.

© 2026 CampOrganizer. All rights reserved.