Skip to content

title: Not Every Note About a Guest Is for Every Employee: Confidential, Manager-Only Client Notes description: Some notes about a guest should not be visible to every seasonal front-desk employee. Here is how confidential, manager-only client notes work, how to hide sensitive guest information from staff who do not need it, and how it fits Canadian privacy expectations (PIPEDA). search: exclude: true


Not Every Note About a Guest Is for Every Employee: Confidential, Manager-Only Client Notes

Quick answer: To keep sensitive notes about a guest private from seasonal or front-desk staff, use a confidential notes field that is separate from your everyday guest notes. It should only appear for users you have specifically granted the privilege to, ask them to confirm their password before it opens, and lock itself again after a few minutes of inactivity. In PitchCamp this is called Restricted Client Notes. Staff without the privilege never see the field, and never see any hint that a restricted note exists.


Picture the note. A guest had a serious dispute with your staff two seasons ago. It ended badly, management wants a record of exactly what happened, and that record needs to be there the next time the guest calls to book. So somebody types it into the notes field on the guest's file.

Now picture who reads it. A seventeen-year-old you hired for the summer pulls up the same guest at check-in on the Canada Day weekend, and the first thing on their screen is a paragraph about a conflict they had nothing to do with. Maybe they mention it out loud. Maybe the guest is standing right there.

This is the problem with a single notes field: it treats "firewood delivered to site" and "do not rent to this person again, here is why" as the same kind of information. They are not. One is for everyone who works the desk. The other is for the two or three people who actually run the place.

Most campground and RV park software gives you exactly one notes field, and everyone who can open the guest can read it. This post is about the second field, the confidential one, and why we built it into PitchCamp the way we did.


Key takeaways

  • A restricted client note is a second, confidential notes area on a guest file that only designated staff can open. Your everyday notes field stays exactly as it is, visible to everyone who can open a guest.
  • Two things must both be true to read one: the user holds a specific privilege an administrator granted, and the user confirms their password. Neither alone is enough.
  • Staff without the privilege see no tab, no padlock, and no hint that a restricted note exists. The confidential note is invisible, not just locked.
  • Restricted notes auto-lock when the user clicks Lock, after 15 minutes of inactivity, 30 minutes after the password was confirmed, when they switch away from the browser tab, or when they log out.
  • They appear nowhere else in the system: not in the client grid, search, reservation calendar, point of sale, exports, printed output, or emails. Even for privileged users.
  • We are not aware of another campground management platform that ships a second, password-confirmed notes field that stays invisible to staff without the privilege. Most competitors offer one plain notes field, and some offer general staff roles, but that is a different thing.
  • This is the practical answer to advice every privacy guide gives ("only give staff the access they need") that no software page actually operationalizes at the level of a single note.

What are confidential (restricted) client notes?

A restricted client note is a manager-only notes field on a guest's record that is hidden from any staff member who has not been granted access to it, and that reopens only after the user re-enters their password. It sits alongside the ordinary guest notes field rather than replacing it.

The distinction that matters: ordinary guest notes answer "what does everyone at the desk need to know to serve this guest?" Restricted notes answer "what does management need on record about this guest that a seasonal employee should not be reading?" The two live on the same guest file, but only one of them is universally readable.

If you have ever wanted to write something on a guest's account that you did not want every summer hire to see, that is the exact gap this fills.


The everyday notes field is doing two jobs, and one of them badly

Walk through what usually ends up in a single campground notes field:

  • "Prefers a pull-through site, travels with two dogs."
  • "Paid the balance in cash on arrival, receipt in the drawer."
  • "Complained about the bathhouse, comped one night, was fine after."
  • "Do not rent again. Verbal threats to staff in July 2024. Owner has the details."

The first two belong to everyone. The last one belongs to management. In a single field, they all sit together, readable by whoever opens the guest, including the staff who turn over every spring and the summer student covering the desk while you are out on the property.

There are three specific situations where this goes wrong:

Seasonal turnover. A campground's front desk is often the highest-turnover role on the property. Every person who has ever held a login has read every note. A sensitive record from three seasons ago has been seen by people who no longer work for you and were never meant to see it.

The shared workstation. Plenty of parks run the front desk on one computer that stays logged in all day. Anyone who walks behind the counter (a guest, a delivery driver, a contractor) can read whatever is on the screen. A single notes field means the sensitive stuff is one click away for anyone.

The "do not rent" reason. Flagging a problem guest is one thing. The reason behind the flag (a past dispute, a safety concern, an unpaid balance that got ugly) is exactly the kind of detail that should be on record for management and invisible to the person checking the guest in. A visible flag with an invisible reason is the right shape, and a single notes field cannot do it.


How restricted client notes work in PitchCamp

The design principle is simple: being able to read a confidential note requires both a permission and a password, and it does not stay open.

Two gates, not one

How access to a restricted client note is controlled A restricted client note opens only after two gates are passed. Gate one: an administrator grants the Restricted Client Note privilege to a specific user; it is off for everyone by default. Gate two: the privileged user confirms their password. Only then is the note readable, and it auto-locks after inactivity, after a maximum session length, on tab switch, or on logout. Staff without the privilege see the ordinary client file with no tab, no padlock, and no hint a restricted note exists. GATE 1: PRIVILEGE GATE 2: PASSWORD RESULT ADMIN GRANTS Restricted Client Note privilege Off for everyone by default USER CONFIRMS Re-enter password to open the Restricted Notes tab Note is readable Only inside the Restricted Notes tab Auto-locks when any one of these happens Locks again, note cleared from screen, password required to reopen: • You click the Lock button above the note • 15 minutes of inactivity in restricted notes • 30 minutes since you confirmed your password • You switch away from or close the browser tab • You log out • 5 wrong passwords: locked 15 minutes on that session
A restricted client note opens only after two gates, and does not stay open.

Gate one is the privilege. An administrator grants the Restricted Client Note privilege to a specific user under Admin, User Accounts, Feature Privileges. This privilege is off for everyone when the feature is first installed, including administrators. Nobody can read a restricted note until you deliberately grant it. That is the opposite of how most feature permissions behave (usually switched on for existing staff during an upgrade), and it is deliberate: a confidential feature should start closed.

Gate two is the password. Even with the privilege, opening the restricted notes tab asks the user to re-enter their password, unless they confirmed it very recently. This is the piece that protects the shared front desk. The session can be logged in all day, but a passer-by still cannot read a restricted note without knowing the password of the person signed in.

It does not stay open

Once a user confirms their password, restricted notes stay open for a short working window so they are not re-prompted for every guest. Then they lock again when any of these happen:

  • They click the Lock button above the note.
  • They stop using restricted notes for 15 minutes.
  • 30 minutes pass since the password was confirmed, even if they have been working the whole time.
  • They switch away from the browser tab or close the window.
  • They log out.

Once locked, the note is cleared from the screen and the password is required again. Five wrong passwords in a row locks restricted notes for 15 minutes on that session, correct password or not.

It is invisible, not just locked

This is the part that makes it genuinely confidential rather than merely gated. A staff member without the privilege sees the guest file exactly as they always have. There is no extra tab, no locked panel, and nothing indicating that a restricted note exists at all. They cannot even tell there is something they are not allowed to see.

And restricted notes are readable only inside the Restricted Notes tab. They never appear in the client grid or its search, the reservation grid or calendar, the reservation editor, the point of sale window, exports, printed output, or emails. That holds for privileged users too. The confidential note simply is not part of the ordinary guest record those screens read.

You can read the full setup in the Restricted Client Notes documentation.


Regular guest notes vs. restricted client notes

Everyday guest notes Restricted client notes
Who can read them Anyone who can open the guest Only users granted the privilege
Extra step to open None Confirm password, unless confirmed very recently
Visible to staff without access Yes No, not even a hint the note exists
Stays open Always, while the guest is open Auto-locks on inactivity, time limit, tab switch, or logout
Appears in grids, search, POS, exports, emails Yes, where notes normally show Never, only inside the Restricted Notes tab
What it is for Operational details everyone needs Sensitive management-only records

The point of the two fields is not to hide information from your team in general. It is to make sure the right note reaches the right people. Firewood preferences go to everyone. The reason a guest is flagged goes to the two people who need it.


What to put in a restricted note (and what not to)

Restricted notes are for internal operational records you do not want every staff member reading. Good examples:

  • The detailed reason behind a "do not rent" or "manager approval required" flag.
  • A record of a past incident or dispute, and how it was resolved, that management wants on file for the next booking.
  • A sensitive account arrangement that only the owner and manager should handle.
  • Context about a guest situation that is accurate and operational, but not something a seasonal employee needs at check-in.

Keep the content factual and operational. A note that records what happened and what was decided is a useful management record. Opinion, speculation, or anything you would not want to stand behind belongs nowhere on a guest file.

And a hard line: restricted notes are not a vault for regulated personal data. Do not use them to store payment card numbers, passwords, medical records, government identification numbers, or other regulated information. Confidential-from-staff is not the same as compliant-for-regulated-data, and the two should never be confused. Payment data belongs in your PCI-compliant payment processing, not in a notes field.


The Canadian privacy angle nobody talks about

Every guide to campground data handling gives the same advice: give staff only the access they need. Canada's privacy framework says the same thing in law. Under PIPEDA's safeguards principle, you are responsible for protecting the personal information you hold, and access should be limited to those who need it for a legitimate purpose. We wrote about the broader picture in how to collect guest data at your campground and use it legally in Canada.

The gap has always been between that advice and the software. "Limit access to sensitive guest information" is easy to say and hard to do when your reservation system has one notes field that everyone reads. Restricted client notes are the concrete mechanism: the sensitive record exists, it is on the guest file where management can find it, and it is not exposed to the seasonal front-desk staff who have no need to see it. That is least-privilege applied to a single note, which is about as granular as least-privilege gets.

For a Canadian operator, this is also a reasonable answer to the harder version of the question: if a guest ever asked who at your park could see a note about them, "the two managers I granted access to, after they re-enter their password" is a much better answer than "everyone who has ever worked the desk."


Where PitchCamp stands against other campground software

Here is what the landscape actually looks like, based on how competing platforms describe their own products:

  • One plain notes field. Most campground and RV park software gives you a single notes area on the guest or reservation record, visible to anyone with access. There is no confidential tier.
  • General staff roles. Some platforms add role-based permissions that can hide whole sections of the software (reports, settings, financials) from certain staff. That is useful, but it is a different thing from a second notes field on the same guest record that a privileged user unlocks with their password and that locks itself again when they step away.
  • Restricted client notes. A confidential field on the guest file, gated by both a per-user privilege and a password, invisible to everyone else, that auto-locks.

We are not aware of another campground management platform that offers the third option: a second, password-confirmed notes area that stays invisible to staff without the privilege. General permissions are common. A confidential, re-authenticated, self-locking note on the guest record is not.


FAQ

Can front-desk or seasonal staff see confidential guest notes?

No. A restricted client note is only readable by a user who has been granted the Restricted Client Note privilege and who has confirmed their password. Staff without the privilege see the guest file exactly as before, with no tab, no padlock, and no indication that a restricted note exists.

How do I hide a guest note from seasonal staff?

Put it in the restricted notes field instead of the everyday notes field, and grant the Restricted Client Note privilege only to the managers who should see it. The everyday notes field stays visible to everyone, and the restricted note stays invisible to anyone without the privilege.

What is a "do not rent" note, and where should it go?

A "do not rent" note flags a guest you do not want to book again. The flag itself can be operational, but the reason behind it (a past dispute, a safety concern) is sensitive and belongs in a restricted client note, where management can see it and a seasonal employee checking the guest in cannot.

Why does it ask for my password if I already logged in?

Because campground front desks are often shared and stay logged in all day. Requiring a password to open restricted notes means that even on an open session, a passer-by cannot read a confidential note without knowing the password of the person signed in. It also means the note locks itself again after a short window rather than staying open.

Is a restricted note more secure than just using staff permissions?

It is more specific. General staff permissions control which parts of the software a user can open. A restricted client note controls a single field on the guest record, requires a password on top of the permission, hides itself entirely from users without access, and locks after inactivity. It is least-privilege at the level of one note rather than one screen.

Does this help with Canadian privacy law?

It supports the practical side of it. PIPEDA's safeguards principle expects you to limit access to personal information to those who need it. Keeping sensitive guest records in a manager-only, password-gated field is a direct way to do that. It is not legal advice, and it is not a place to store regulated data like ID or payment card numbers, but it is a reasonable access control for sensitive operational notes. See our guide to guest data and Canadian privacy law.

Can I store credit card numbers or ID in a restricted note since it is private?

No. Private-from-staff is not the same as compliant-for-regulated-data. Restricted notes are for internal operational notes only. Payment card data must go through PCI-compliant payment processing, and government ID and medical information should not be stored in a notes field at all.

What happens to a restricted note if I remove someone's access?

Their access ends on their next action. Any restricted note already open on their screen locks. They do not need to log out first. This makes it straightforward to remove access the moment a staff member changes role or leaves the management team.


The right note to the right people

A campground runs on information, and most of it should flow freely to everyone at the desk. Site preferences, payment status, the note about the dog on lot 14: that is what a shared notes field is for, and it should stay exactly as it is.

But some information is different. The reason a guest is flagged, the record of an incident, the account arrangement only the owner should touch: those are management records that happen to live on a guest file, and they should not be sitting one click away from every summer hire and everyone who walks behind the counter. Restricted client notes keep them where management can find them and everyone else cannot, without a second system, a spreadsheet, or a locked filing cabinet in the back office.

If you have ever hesitated before typing something onto a guest's account because you were not sure who would read it, that hesitation is the feature this solves. Learn more in the Restricted Client Notes documentation, or start a free PitchCamp account and try it on your own data.

Book a free demo at pitchcampmanagement.com to see restricted client notes and staff access controls in action. 🍁

Related reading: - How to Collect Guest Data at Your Campground (And Use It Legally in Canada) - Dealing with Difficult Situations as a Campground Owner - The Front Desk Is Overrated: Why Campground Self Check-In Is the Upgrade Your Park Needs

Tags: confidential guest notes · restricted client notes campground · private notes campground software · hide guest notes from staff · manager-only notes · do not rent list campground · staff permissions campground software · PIPEDA campground · PitchCamp · campground management software Canada