← Back
Privacy Policy
Last Updated: September 2026
At Champord, we are committed to protecting your privacy and being transparent about how we handle your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your information.
1. Information We Collect
We collect information you provide directly and data generated through your use of our Services:
Personal Information
- Account data: name, email address, password (encrypted)
- Sign-in providers: if you use Sign in with Apple or Google Sign-In, we receive your name and email address (or Apple's relay email) from that provider — we never receive your password
- Profile information: age range, citizenship, travel preferences
- Payment data: processed by the Apple App Store (iOS), Google Play (Android) or Paddle (purchases on champord.com). We never collect or store your card details — only the receipt and subscription status needed to entitle your account
- Communications: messages you send us
Travel Data
- Trip details: destinations, dates, budget, companions
- Companions, pets and equipment: names and details you save for the people and animals travelling with you
- Preferences: interests, dietary restrictions, accessibility needs
- AI interactions: chat history for trip assistance
- Voice recordings: when you plan a trip by voice, the audio is uploaded to our servers, transcribed, and used only to build that trip. Recordings are deleted within 30 days of transcription; the resulting text is kept with your trip
- Photos: profile pictures and trip cover images you choose to upload
- Calendar data: only if you turn on calendar sync. We write your trip events to the calendar you pick, and read that calendar's existing events solely to avoid creating duplicates. We never read or store the content of your other appointments
Shared Expenses
- Expense records: titles, amounts, currencies, categories, dates, and who paid
- Balances and settlements between you and the people in a project
- People you add to a project by name, and email addresses you enter to invite someone to Champord. We use an invitation email address only to send that invitation
Automatically Collected
- Device information: model, OS version, unique identifiers
- Usage data: features used, interaction patterns
- Push notification token: a device token used to deliver trip and account notifications, only if you grant notification permission
- Analytics and crash reports: app performance and stability data via Firebase Analytics and Firebase Crashlytics
We do not collect your device's location, and the app never asks for location permission.
App Tracking (iOS): we do not track you across other companies' apps or websites for advertising. We do not use Apple's advertising identifier (IDFA) and therefore show no App Tracking Transparency prompt.
2. How We Use Your Information
Provide Services
- Generate personalized travel itineraries
- Process payments and manage subscriptions
- Provide AI-powered trip assistance
- Manage your account and preferences
Improve Our Services
- Analyze usage patterns to enhance features
- Train and improve our AI models (using anonymized data)
- Fix bugs and optimize performance
- Develop new features based on user needs
Communicate With You
- Send service-related notifications
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
Legal and Security
- Comply with legal obligations
- Detect and prevent fraud or abuse
- Enforce our Terms and Conditions
3. Data Sharing and Disclosure
We do not sell your personal information. We may share data with
Service Providers
- Apple App Store and Google Play: in-app payment processing and receipt validation
- Paddle (paddle.com): payment processing for purchases made on champord.com, acting as merchant of record. Paddle processes your name, email address and payment details under its own privacy policy
- Microsoft Azure: AI processing, including voice transcription, and data storage
- Google Firebase (Analytics, Crashlytics, Cloud Messaging): usage analytics, crash reports and push-notification delivery
- Cloud infrastructure: data hosting on EU-based servers
Other People in Your Projects
- When you add someone to an expense project or a trip, the expenses, amounts, balances and your display name are visible to the other members of that project. Only share a project with people you intend to see that information
Third-Party Integrations
- When you connect external services (with your consent)
- Travel service providers (only necessary booking information)
Legal Requirements
- When required by law or legal process
- To protect our rights or safety
- In response to valid government requests
Business Transfers
- In connection with mergers, acquisitions, or asset sales
- With appropriate confidentiality protections
4. Data Retention
We retain your information for as long as necessary to
- Maintain your active account
- Provide requested services
- Comply with legal obligations
- Resolve disputes and enforce agreements
Retention Periods
- Active account data: until account deletion
- Trip history: 3 years after trip completion
- Voice recordings: deleted within 30 days of transcription
- Expense and settlement records: until the project is deleted, or 3 years after its last activity
- Payment records: 7 years (legal requirement)
- Analytics data: 26 months (anonymized)
After account deletion
- Personal data is deleted within 30 days
- Expense records shared with other people may remain visible to them, with your name replaced by a removed-member placeholder, because they form part of those people's own records
- Anonymized data may be retained for analytics
- Backup copies are purged within 90 days
5. Your Privacy Rights
Under GDPR, CCPA, and other privacy laws, you have rights including:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Request deletion of your data ("right to be forgotten")
- Portability: Receive your data in a portable format
- Restriction: Limit how we process your data
- Objection: Object to certain processing activities
- Withdraw Consent: Revoke previously given consent
To Exercise These Rights
- Use in-app settings for most requests
- Email privacy@champord.com for complex requests
- We respond within 30 days (GDPR requirement)
Note: Some requests may be limited by legal obligations or legitimate interests.
6. Data Security
We implement industry-standard security measures:
Technical Safeguards
- TLS 1.3 encryption for data in transit
- AES-256 encryption for data at rest
- Secure password hashing (bcrypt)
- Regular security audits and penetration testing
Organizational Measures
- Access controls and authentication
- Employee security training
- Incident response procedures
- Data minimization practices
While we strive to protect your data, no system is completely secure. We encourage you to use strong passwords and protect your account credentials.
7. International Data Transfers
Your data may be processed in countries outside your residence. We ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs)
- Data Processing Agreements with all vendors
- EU–U.S. Data Privacy Framework (where applicable to U.S.-based sub-processors)
- Adequacy decisions by data protection authorities
We primarily store data in EU data centers to ensure GDPR compliance.
8. Children's Privacy
Our Services are not directed to children under 16. We do not knowingly collect personal information from children.
If you believe a child has provided us with personal information, please contact us immediately at privacy@champord.com. We will promptly delete such information.
Parents or guardians who wish to review or delete their child's data may contact us with proof of identity.
9. Cookies and Tracking
Our website and mobile app use:
Essential Technologies
- Local storage for app preferences
- Session tokens for authentication
- Analytics SDKs for performance monitoring
You Can Control Tracking Through
- Browser cookie settings
- Device privacy settings
- In-app privacy preferences
- OS-level app tracking controls
We respect "Do Not Track" signals and similar mechanisms where technically feasible.
10. AI and Automated Processing
Our AI-powered features process your data to:
- Generate personalized travel recommendations
- Provide conversational trip assistance
- Improve suggestion accuracy over time
AI Processing Transparency
- AI decisions are based on your stated preferences
- You can request human review of AI-generated content
- We don't use AI for automated legal decisions
- AI models are trained on anonymized, aggregated data
You have the right to opt out of AI-based personalization while still using basic app features.
11. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be:
- Posted on this page with the new effective date
- Notified via email for material changes
- Communicated through in-app notifications
Continued use after changes indicates acceptance. We encourage you to review this policy regularly.
12. Contact Us
For privacy-related questions or to exercise your rights:
For EU residents: You may also contact your local data protection authority if you have concerns about our data practices.
We aim to resolve all privacy concerns within 30 days.