← Back
Privacy Policy
Last Updated: October 2026
At Champord, we are committed to protecting your privacy and being transparent about how we handle your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding your information.
1. Information we collect
We collect information you provide directly and data generated through your use of our Services:
Personal Information
- Account data: name, email address, password (encrypted)
- Sign-in providers: if you use Sign in with Apple or Google Sign-In, we receive your name and email address (or Apple's relay email) from that provider — we never receive your password
- Profile information: age range, citizenship, travel preferences
- Payment data: processed by the Apple App Store (iOS), Google Play (Android) or Paddle (purchases on champord.com). We never collect or store your card details — only the receipt and subscription status needed to entitle your account
- Communications: messages you send us
Travel Data
- Trip details: destinations, dates, budget, companions
- Companions, pets and equipment: names and details you save for the people and animals travelling with you
- Preferences: interests, dietary restrictions, accessibility needs
- AI interactions: chat history for trip assistance
- Voice recordings: when you plan a trip by voice, the audio is uploaded to our servers, transcribed, and used only to build that trip. Recordings are deleted within 30 days of transcription; the resulting text is kept with your trip
- Photos: profile pictures and trip cover images you choose to upload
- Calendar data: only if you turn on calendar sync. We write your trip events to the calendar you pick, and read that calendar's existing events solely to avoid creating duplicates. We never read or store the content of your other appointments
Shared Expenses
- Expense records: titles, amounts, currencies, categories, dates, and who paid
- Balances and settlements between you and the people in a project
- People you add to a project by name, and email addresses you enter to invite someone to Champord. We use an invitation email address only to send that invitation
Automatically Collected
- Device information: model, OS version, unique identifiers
- Usage data: features used, interaction patterns
- Push notification token: a device token used to deliver trip and account notifications, only if you grant notification permission
- Crash reports (mobile app only): the error, stack trace, device model and OS version, via Firebase Crashlytics
We do not collect your device's location, and the app never asks for location permission.
App Tracking (iOS): we do not track you across other companies' apps or websites for advertising. We do not use Apple's advertising identifier (IDFA) and therefore show no App Tracking Transparency prompt.
2. How we use your information
We use your information to
Provide Services
- Generate personalized travel itineraries
- Process payments and manage subscriptions
- Provide AI-powered trip assistance
- Manage your account and preferences
Improve Our Services
- Analyze usage patterns to enhance features
- Improve AI-powered recommendations using anonymized usage patterns
- Use anonymized structural patterns from approved trips (such as itinerary pacing, activity categories, and budget allocation) to improve recommendations for other users
- Fix bugs and optimize performance
- Develop new features based on user needs
Legal Bases (GDPR)
- Contract performance: trip generation, account management, payment processing
- Legitimate interest: crash reporting, AI improvement, fraud prevention, service optimization
- Consent: marketing communications
- Legal obligation: tax records, law enforcement requests
Communicate With You
- Send service-related notifications
- Respond to your inquiries and support requests
- Send marketing communications (with your consent)
Legal and Security
- Comply with legal obligations
- Detect and prevent fraud or abuse
- Enforce our Terms and Conditions
3. Data sharing and disclosure
We do not sell your personal information. We may share data with:
Service Providers
- Apple App Store and Google Play: in-app payment processing and receipt validation
- Paddle (paddle.com): payment processing for purchases made on champord.com, acting as merchant of record. Paddle processes your name, email address and payment details under its own privacy policy
- Microsoft Azure: AI processing, including voice transcription, and data storage
- Anthropic and Google (Gemini): AI processing of your chat messages, trip requests and travel preferences to write replies and itineraries
- Google Maps Platform: place details and locations used in your itineraries
- Duffel and LiteAPI: flight and accommodation availability and prices for the trips you plan, using your search details such as destinations and dates
- Resend: delivery of account and trip emails, which requires your email address and the content of those emails
- Google Firebase (Crashlytics, Cloud Messaging): crash reports from the mobile app and push-notification delivery
- CARTO and OpenStreetMap (Nominatim): map images and place look-ups on the champord.com map, which receive your IP address and the places you search for or select
- Contabo: hosting of our servers and databases on EU-based servers
Other People in Your Projects
- When you add someone to an expense project or a trip, the expenses, amounts, balances and your display name are visible to the other members of that project. Only share a project with people you intend to see that information
Third-Party Integrations
- When you connect external services (with your consent)
- Travel service providers (only necessary booking information)
Legal Requirements
- When required by law or legal process
- To protect our rights or safety
- In response to valid government requests
Business Transfers
- In connection with mergers, acquisitions, or asset sales
- With appropriate confidentiality protections
4. Data retention
We retain your information for as long as necessary to:
- Maintain your active account
- Provide requested services
- Comply with legal obligations
- Resolve disputes and enforce agreements
Retention Periods
- Active account data: until account deletion
- Trip history: 3 years after trip completion
- Voice recordings: deleted within 30 days of transcription
- Expense and settlement records: until the project is deleted, or 3 years after its last activity
- Payment records: 7 years (legal requirement)
- Crash reports: 90 days
After account deletion
- Personal data is deleted within 30 days
- Expense records shared with other people may remain visible to them, with your name replaced by a removed-member placeholder, because they form part of those people's own records
- Anonymized, aggregated data that can no longer identify you may be kept to improve the Services
- Backup copies are purged within 90 days
5. Your privacy rights
Under GDPR, CCPA, and other privacy laws, you have rights including:
Access: Request a copy of your personal data Correction: Update inaccurate information Deletion: Request deletion of your data ("right to be forgotten") Portability: Receive your data in a portable format Restriction: Limit how we process your data Objection: Object to certain processing activities Withdraw Consent: Revoke previously given consent
To exercise these rights
- Use in-app settings for most requests
- Email privacy@champord.com for complex requests
- We respond within 30 days (GDPR requirement)
Note: Some requests may be limited by legal obligations or legitimate interests.
6. Data security
We implement industry-standard security measures
Technical Safeguards
- TLS 1.3 encryption for data in transit
- AES-256 encryption for data at rest
- Secure password hashing (bcrypt)
- Regular security audits and penetration testing
Organizational Measures
- Access controls and authentication
- Employee security training
- Incident response procedures
- Data minimization practices
While we strive to protect your data, no system is completely secure. We encourage you to use strong passwords and protect your account credentials.
7. International data transfers
Your data may be processed in countries outside your residence. We ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs)
- Data Processing Agreements with all vendors
- EU–U.S. Data Privacy Framework (where applicable to U.S.-based sub-processors)
- Adequacy decisions by data protection authorities
We primarily store data in EU data centers (Sweden) to ensure GDPR compliance.
8. Children's privacy
Our Services are not directed to children under 16. We do not knowingly collect personal information from children.
If you believe a child has provided us with personal information, please contact us immediately at privacy@champord.com. We will promptly delete such information.
Parents or guardians who wish to review or delete their child's data may contact us with proof of identity.
9. Cookies and tracking
We do not use advertising, analytics or tracking cookies. The website keeps only what it needs to work in your browser's local and session storage: your sign-in, language, subscription status and unfinished trip. The mobile app keeps your sign-in and settings in its own storage and sends crash reports through Firebase Crashlytics.
Sign-in with Google or Apple, Paddle checkout and the map providers load only when you use them and may set their own cookies. Our Cookie Policy on champord.com lists everything we store and how to remove it.
10. AI and automated processing
Our AI-powered features process your data to:
- Generate personalized travel recommendations
- Provide conversational trip assistance
- Improve suggestion accuracy over time
AI Processing Transparency
- AI decisions are based on your stated preferences and publicly available travel information
- You can request human review of AI-generated content
- We don't use AI for automated legal or financial decisions
- We use third-party AI services (Azure OpenAI, Anthropic and Google Gemini) to process trip requests and chat messages; your data is sent to these services under strict data processing agreements
- Anonymized structural patterns from trips that users approve (such as pacing, activity mix, and budget tier) are stored and used to improve recommendations for other users; no personally identifying information is included in these patterns
You have the right to opt out of AI-based personalization while still using basic app features.
11. Changes to this policy
We may update this Privacy Policy periodically. Changes will be:
- Posted in the app with the new effective date
- Notified via email for material changes
- Communicated through in-app notifications
Continued use after changes indicates acceptance. We encourage you to review this policy regularly.
12. Contact us
For privacy-related questions or to exercise your rights:
Data Protection Officer
Email: privacy@champord.com
Champord Travel Technologies Yerevan, Republic of Armenia Email: support@champord.com
For EU/EEA residents
You have the right to lodge a complaint with your local data protection authority if you have concerns about our data practices.
We aim to resolve all privacy concerns within 30 days.