CHRAVEL PRIVACY POLICY
Effective Date: October 9, 2026
Last Updated: October 9, 2026
Chravel respects your privacy. This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you use our website, applications, AI-powered travel planning features, booking services, memberships, promotional credits, and related services.
Chravel is operated by Doorstep Labs LLC, a Montana limited liability company, with its business address at 1001 S. Main St., Ste. 500, Kalispell, MT 59901, United States.
In this Policy, “Chravel,” “we,” “us,” and “our” refer to Doorstep Labs LLC. “You” means an individual who visits, uses, or interacts with our Services.
Website: https://chravel.co
Privacy contact: hello@chravel.co
This Policy should be read together with the Chravel Terms of Service and any additional privacy notice provided when you use a particular feature or make a booking.
1. Scope of This Policy
This Policy applies to personal information processed through Chravel's website, applications, account systems, AI travel-planning features, booking and order-management functions, Chravel+ membership, Chravel Credits and wallet features, customer support, and related communications.
It does not independently govern the privacy practices of airlines, hotels, activity operators, payment providers, or other third parties acting under their own privacy policies. Those parties may separately process your information when you interact with their services.
Where Chravel and a third party have distinct legal responsibilities for processing, each party's obligations depend on the applicable law and the specific activity.
2. Personal Information We Collect
The information we collect depends on how you use Chravel, which features you enable, and which travel services you purchase.
2.1 Account and profile information
We may collect:
- Name and account identifier.
- Email address and contact details.
- Authentication and account-security information.
- Profile preferences, saved settings, and communication preferences.
- Membership status and related account information.
- Information you provide when contacting support.
2.2 Travel planning and itinerary information
When you plan or book a trip, we may collect:
- Origin, destination, travel dates, and trip duration.
- Number and ages of travelers where needed for a booking.
- Room requirements, accommodation preferences, and transportation preferences.
- Preferred activities, destinations, travel styles, and budgets.
- Flight, accommodation, transportation, event, and activity selections.
- Booking references, itinerary details, and order history.
- Information needed to fulfill or modify a booking.
Travel plans may reveal information about your movements, relationships, interests, or activities. We use this information as described in this Policy.
2.3 AI conversations and submitted content
If you use Chravel's AI features, we may collect the prompts, questions, messages, preferences, files, and other information you submit, along with the AI-generated responses and associated conversation history.
This may include information used to build an itinerary, compare travel options, answer travel questions, or modify an existing trip.
Please do not submit sensitive information unless it is necessary for your request. If you choose to include information about health, accessibility, dietary restrictions, or other personal circumstances, it may be processed to provide the requested functionality.
2.4 Booking and transaction information
We may collect:
- Booking confirmations, order identifiers, and transaction records.
- Amounts charged, currencies, taxes, fees, and payment status.
- Refund, cancellation, chargeback, and dispute information.
- Membership payments, renewal status, and cancellation records.
- Chravel Credits earned, reserved, redeemed, reversed, or adjusted.
- Records needed to reconcile transactions or prevent fraud.
Payments may be processed by Stripe or another payment provider. We do not intend to collect or store complete payment-card details in Chravel systems where those details are handled directly by the payment provider. The provider may process payment information under its own applicable privacy terms.
2.5 Device, usage, and technical information
When you access Chravel, we and our service providers may collect technical and usage information, such as:
- IP address and approximate location derived from it.
- Browser type, device type, operating system, and language.
- Pages, screens, features, and links you interact with.
- Session identifiers, timestamps, referring pages, and diagnostic events.
- Error reports, performance information, and security logs.
- Cookie identifiers and similar technologies, where used.
Precise location is collected only where a feature requests it and the relevant permissions or legal basis are in place. You can generally manage device-level location permissions through your device settings.
2.6 Communications and support information
If you contact us, we may collect your messages, attachments, contact details, support history, and information necessary to investigate or resolve your request.
We may also retain relevant communications about bookings, cancellations, refunds, memberships, credits, security, and legal matters.
2.7 Information from third parties
We may receive information from Suppliers, booking and inventory providers, payment processors, identity or fraud-prevention services, analytics providers, and other service providers.
Depending on the transaction, this may include availability, prices, booking status, traveler details needed for fulfillment, payment confirmation, refund status, or fraud-risk signals.
We may also receive information you ask another person or service to share with Chravel.
3. How We Use Personal Information
We use personal information for the following purposes, subject to applicable law:
3.1 Provide and operate Chravel
We use information to create and manage accounts, remember preferences, generate itineraries, respond to travel requests, display options, manage bookings, and provide customer support.
3.2 Search for and fulfill travel services
We use relevant information to request availability, obtain pricing, submit bookings, communicate with Suppliers, issue confirmations, handle changes, and support cancellations and refunds.
3.3 Provide AI-powered features
We use submitted prompts, trip preferences, relevant account context, and related information to generate responses, recommendations, itineraries, and other requested AI outputs.
We may process relevant information through our AI service providers to deliver those features.
3.4 Process payments and manage financial records
We use transaction information to facilitate authorized payments, administer Chravel+ membership, maintain Chravel Credits, process eligible refunds, reconcile transactions, respond to disputes, and detect suspicious activity.
3.5 Administer Chravel+ and Chravel Credits
We use relevant information to determine membership eligibility, apply benefits, record renewals and cancellations, calculate or apply promotional credits, maintain wallet records, and investigate errors or abuse.
3.6 Secure and improve the Services
We use technical and usage information to troubleshoot problems, maintain reliability, understand how features are used, improve the user experience, prevent abuse, and protect our systems.
Where analytics or similar technologies require consent, we will obtain and respect that consent as required by law.
3.7 Communicate with you
We may send transactional messages about account security, bookings, payment status, itinerary changes, membership administration, credits, and customer support.
Where permitted, we may also send product updates, promotional communications, and marketing messages. You can unsubscribe from marketing emails using the provided method. Necessary transactional communications may still be sent.
3.8 Meet legal obligations and protect rights
We may process information to comply with law, respond to lawful requests, maintain required records, enforce agreements, investigate fraud, resolve disputes, protect users, and establish or defend legal claims.
3.9 Other purposes disclosed to you
We may use information for another purpose when we disclose that purpose at the time of collection or otherwise obtain any consent required by law.
4. Legal Bases for Processing
Where laws such as the European Union General Data Protection Regulation (GDPR) or United Kingdom data-protection law apply, we rely on one or more legal bases depending on the specific purpose.
These may include:
- Contract: Processing necessary to provide a requested service, manage an account, or perform a booking-related agreement.
- Legitimate interests: Processing necessary for purposes such as securing our systems, preventing fraud, improving services, and handling business operations, where those interests are not overridden by your rights.
- Legal obligation: Processing necessary to comply with applicable laws and regulatory requirements.
- Consent: Processing based on your consent, including where consent is required for certain cookies, marketing, or sensitive information.
- Vital interests or public interest: Where applicable law permits and the circumstances justify that basis.
The relevant legal basis depends on the specific activity and jurisdiction. Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.
Where a request involves sensitive personal information, we will rely on an appropriate legal condition where one is required.
5. AI Processing and AI Providers
Chravel uses AI technology to provide conversational travel planning, recommendations, itinerary generation, and related features.
Our current AI features use Google Gemini through the Lovable AI Gateway. We may change or add AI providers in the future, subject to applicable law and any notices or consents required for the change.
When an AI feature is used, information submitted to that feature may be transmitted to the relevant provider to generate a response. The information processed may include prompts, travel preferences, itinerary details, and relevant conversation context.
We seek to limit AI processing to information reasonably necessary for the requested feature. However, the precise information transmitted depends on the feature and how you use it.
AI providers may process information under their applicable service agreements, security practices, and privacy terms. Their processing and retention arrangements may differ by service and configuration.
We do not make a blanket promise that information submitted to an AI provider is never retained or used for model improvement. We will configure and use provider services in accordance with our applicable agreements and will disclose material processing practices where required.
5.1 AI accuracy and review
AI-generated recommendations may be inaccurate, incomplete, or outdated. Review material travel, pricing, and booking details before making a purchase.
An AI-generated itinerary or conversation is not, by itself, a confirmed reservation or authorization to charge a payment method. Purchases are subject to the applicable booking and authorization process.
5.2 Sensitive information
Avoid including passport numbers, payment-card details, government identification numbers, medical records, or other sensitive information in an AI prompt unless it is necessary and the feature is designed to handle it.
If you submit accessibility or other sensitive travel requirements, we may process that information to help provide the requested service, subject to applicable law.
6. How We Share Personal Information
We may disclose personal information to the following categories of recipients when necessary for the purposes described in this Policy.
6.1 Service providers and processors
Our technology and service providers may process information on our behalf, including:
- Google Gemini and Lovable AI Gateway: AI-powered features and responses.
- Supabase: Database, authentication, and related application infrastructure.
- Lovable and its hosting infrastructure: Website and application delivery.
- Stripe: Payment processing and related payment operations.
- PostHog: Product analytics and usage measurement, depending on our configuration.
- Travel technology providers and Suppliers: Availability, search, booking, fulfillment, and travel-service operations.
We may also use providers for communications, email delivery, customer support, fraud prevention, security, and related business functions.
The exact information shared with a provider depends on the feature, transaction, provider configuration, and information necessary to perform the service.
We require appropriate contractual, confidentiality, security, and data-protection safeguards where applicable.
6.2 Travel Suppliers
When you request or purchase a travel service, we may share the information needed to search for, reserve, issue, modify, or fulfill that service with the relevant Supplier, booking provider, or intermediary.
For example, a flight booking may require passenger details and contact information, while an accommodation booking may require guest names and stay dates.
The relevant Supplier may process the information under its own privacy policy and legal responsibilities.
6.3 Payment providers
We share transaction and payment-related information with Stripe or another applicable payment provider to process authorized payments, refunds, verification, and related financial operations.
Payment providers may also process information to comply with law, prevent fraud, and secure their systems.
6.4 Legal, safety, and fraud-prevention disclosures
We may disclose information when reasonably necessary to:
- Comply with applicable law, court orders, or lawful requests.
- Protect the rights, safety, and security of users, Chravel, or others.
- Investigate fraud, unauthorized transactions, or abuse.
- Enforce our agreements.
- Establish, exercise, or defend legal claims.
We evaluate requests as appropriate and disclose only information we reasonably determine is necessary and legally permitted.
6.5 Business transfers
If Chravel or its relevant assets are involved in a merger, acquisition, restructuring, financing, or sale, personal information may be transferred as part of that transaction, subject to appropriate safeguards and applicable law.
6.6 With your direction or consent
We may share information with other recipients when you ask us to do so, authorize the sharing, or where applicable law otherwise permits it.
7. International Data Transfers
Chravel is operated from the United States and may use service providers or Suppliers located in other countries. As a result, personal information may be processed in countries other than the country where you live.
Those countries may have different data-protection laws.
Where required, we will implement an appropriate transfer mechanism or safeguard, such as an applicable adequacy decision, standard contractual clauses, or another lawful mechanism.
You may contact hello@chravel.co to request further information about applicable international transfer safeguards, subject to lawful restrictions.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, subject to legal requirements, contractual obligations, security needs, and the establishment or defense of legal claims.
Retention periods depend on the type of information and the circumstances.
- Account and profile information: Retained while the account is active and for any additional period reasonably necessary for account administration, security, legal compliance, and disputes.
- Booking and transaction records: Retained for the periods needed to administer bookings, reconcile transactions, handle refunds and disputes, and meet applicable tax, accounting, travel, and consumer-law requirements.
- AI conversations and itineraries: Retained as needed to provide conversation history, saved trips, requested features, support, and security, subject to the relevant product settings and provider arrangements.
- Analytics and usage information: Retained according to our analytics configuration, provider settings, consent choices where applicable, and legal requirements.
- Customer-support communications: Retained as needed to respond to requests, document resolutions, manage complaints, and handle disputes.
- Security and authentication logs: Retained for an appropriate period to protect the Services, investigate suspicious activity, and meet legal requirements.
- Membership, credits, and consent records: Retained as needed to administer benefits, reconcile transactions, prevent abuse, demonstrate consent or authorization, and comply with legal obligations.
When information is no longer needed, we will delete it, anonymize it, or otherwise securely dispose of it, subject to lawful retention requirements and necessary preservation for legal claims or investigations.
Deleting an account may not immediately remove information that must be retained for legal, financial, security, or transaction-related purposes. Where information must be retained, we will limit its use to the relevant purposes.
We maintain or will establish an internal retention schedule specifying operational retention periods and will configure our systems and service providers accordingly.
9. Cookies, Analytics, and Similar Technologies
Chravel and its service providers may use cookies, local storage, pixels, SDKs, and similar technologies to operate the Services, remember preferences, maintain sessions, protect accounts, understand usage, and improve performance.
9.1 Essential technologies
Some technologies are necessary for authentication, security, account sessions, checkout, or other requested functionality. Disabling these technologies may prevent parts of the Services from working correctly.
9.2 Analytics
We use PostHog for product analytics, subject to the features and configuration enabled in our deployment.
Depending on configuration, analytics technologies may collect information about page views, feature usage, navigation, errors, and interactions.
We will configure analytics and any optional tracking technologies to comply with applicable consent and privacy requirements.
9.3 Managing your choices
Where required by law, we will provide a mechanism to accept, reject, or manage non-essential cookies and similar technologies. You may also be able to control certain technologies through your browser or device settings.
Browser-level controls may not affect all technologies used by applications or devices.
If Chravel offers a cookie-preference interface, use that interface to manage your choices. We will honor applicable opt-out signals where required by law.
10. Marketing and Communications
We may send service-related communications necessary to administer your account, bookings, payments, memberships, credits, and support requests.
We may send marketing communications where permitted by law and, where required, after obtaining your consent.
You can unsubscribe from marketing emails through the unsubscribe link or method included in the message. You may also contact hello@chravel.co.
Unsubscribing from marketing does not necessarily stop transactional or legally required messages.
11. Your Privacy Rights
Depending on your location and the applicable law, you may have rights concerning your personal information, including the right to:
- Request access to personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion of personal information.
- Request a copy of certain information in a portable format.
- Object to certain processing or request restriction of processing.
- Withdraw consent where processing relies on consent.
- Opt out of certain targeted advertising, sale, or sharing of personal information, where applicable.
- Appeal certain privacy-rights decisions where the law provides that right.
- Lodge a complaint with a relevant data-protection authority.
These rights are not absolute and may be subject to legal exceptions, including obligations to retain transaction records, prevent fraud, protect other people's rights, or establish and defend legal claims.
11.1 How to submit a request
To exercise a privacy right, email hello@chravel.co with the subject line “Privacy Request.”
Please describe the right you wish to exercise and provide enough information for us to understand and process your request. We may need to verify your identity or authority before acting.
We will respond within the period required by applicable law. If we cannot fulfill a request, we will explain the reason where required and inform you of any available appeal process.
You may authorize an agent to submit a request where applicable law permits, subject to verification and authorization requirements.
We will not unlawfully discriminate against you for exercising a privacy right.
12. Additional Information for European and UK Users
Where the GDPR, UK GDPR, or related laws apply, you may have additional rights and protections.
These may include the right to access, correct, erase, restrict, or port certain personal information; object to processing based on legitimate interests; withdraw consent; and lodge a complaint with your local supervisory authority.
You may also have protections concerning certain solely automated decisions that produce legal or similarly significant effects.
Chravel uses AI to support travel planning and recommendations. AI-generated suggestions should not be treated as a guarantee of booking availability or as a substitute for reviewing a transaction before purchase.
Where applicable law requires additional safeguards, information, or human review for a particular automated decision, we will comply with those requirements.
For processing based on legitimate interests, you may object on grounds relating to your particular situation, subject to applicable law.
Where relevant, you may contact your local data-protection authority. We encourage you to contact us first so we can attempt to address your concern, but doing so is not a condition of exercising your legal rights.
13. Additional Information for California and Other U.S. State Residents
Depending on the state where you reside and whether the relevant law applies to Chravel, you may have rights to know about, access, correct, or delete personal information, obtain a portable copy, and opt out of certain processing.
Applicable laws may also provide rights to opt out of the sale of personal information, targeted advertising, or certain profiling. These terms have specific legal meanings and do not necessarily apply to every disclosure or analytics activity.
Chravel's practices are described in this Policy. Relevant categories of information may include identifiers, account and transaction information, commercial information, internet or electronic activity, approximate location, travel preferences, and information you submit in communications or AI prompts.
We collect these categories from you, your use of the Services, and relevant Suppliers or service providers. We use them for the purposes described in Sections 2 and 3 and disclose them to the categories of recipients described in Section 6.
We do not state in this Policy that every form of third-party disclosure is or is not a legally defined “sale” or “sharing.” The classification depends on the actual processing and applicable law. We will provide the required opt-out mechanism and honor applicable opt-out rights where required.
To submit a request, email hello@chravel.co with the subject line “U.S. State Privacy Request.” We may verify your identity and will respond within the applicable statutory period.
If applicable law provides an appeal right and we deny your request, we will provide information about how to appeal.
14. Children and Minors
Chravel is not intended for children under 13, and we do not knowingly seek to collect personal information directly from children under 13 without an appropriate legal basis and any required parental consent.
If you believe a child under 13 has submitted personal information directly to Chravel, contact hello@chravel.co. We will investigate and take appropriate steps in accordance with applicable law.
Travel bookings may involve minors traveling with parents, guardians, or other authorized adults. If an adult submits a minor's information for a booking, the adult is responsible for ensuring they have the authority to provide that information and that the disclosure is lawful.
We may need to process limited information about minors to fulfill a requested travel service or comply with legal requirements.
15. Security
We use reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.
These measures may include access controls, authentication safeguards, encryption where appropriate, security monitoring, provider safeguards, and procedures for handling incidents.
No system or transmission method can be guaranteed to be completely secure. We cannot promise absolute security, but we will handle security incidents in accordance with applicable law and our obligations.
If a personal-data breach occurs, we will investigate and provide any notifications required by applicable law.
16. Account Deletion
You may request deletion of your Chravel account through available account controls or by emailing hello@chravel.co.
We may ask you to verify your identity before processing the request.
After receiving a valid request, we will delete or anonymize personal information that we are not legally required or otherwise lawfully permitted to retain. Some information may remain for a limited period in backups or records maintained for legal compliance, transaction reconciliation, fraud prevention, security, or disputes.
Account deletion may affect access to saved itineraries, conversation history, membership features, and other account-based functionality.
Deleting an account does not automatically cancel a separate booking, membership, or payment obligation. Use the relevant cancellation process and review applicable booking or membership terms.
17. Third-Party Websites and Services
Chravel may contain links to Supplier websites, payment services, and other third-party platforms.
Those third parties may collect information directly from you and process it under their own privacy policies. We do not control their independent practices.
Before providing personal information directly to a third party, review its privacy notice and terms.
18. Changes to This Privacy Policy
We may update this Policy to reflect changes in our Services, providers, processing practices, legal obligations, or business operations.
We will post the revised Policy and update the “Last Updated” date. If a change materially affects your rights or requires additional notice or consent, we will take the steps required by applicable law.
Where legally required, we will obtain consent before conducting materially different processing that relies on consent.
We encourage you to review this Policy periodically.
19. Contact and Privacy Requests
For privacy questions, access or deletion requests, complaints, or questions about our data practices, contact:
Doorstep Labs LLC — Chravel
1001 S. Main St., Ste. 500
Kalispell, MT 59901
United States
Email: hello@chravel.co
Website: https://chravel.co
If applicable law requires Chravel to appoint a data-protection officer, local representative, or other designated privacy contact for a particular jurisdiction, the relevant contact information will be provided in the applicable supplemental notice or through the required channel.
20. Jurisdiction-Specific Privacy Information
Chravel provides services internationally, subject to applicable laws and service availability.
Additional privacy disclosures, rights, contact details, representative information, or regulatory information may apply depending on your location and the processing involved.
Where required by applicable law, Chravel will provide the relevant supplemental notice, identify the appropriate privacy contact or representative, and explain how to exercise applicable rights.
For privacy requests, contact hello@chravel.co.