Privacy

Privacy at Cordelle

Effective August 28, 2026

The short version

  • Your tour company puts your trip and your details into Cordelle. We hold them to run the app for your trip, and for nothing else.
  • The app stores your whole trip on your phone, so it works with no signal.
  • Location sharing is off until you turn it on, runs for a session you choose, and switches itself off. There is no background tracking.
  • Location pings are erased after 30 days. Push tokens are erased 30 days after your trip ends.
  • No ads, no selling data, no tracking you across other apps or websites. There is no analytics library in the app at all.
  • Questions, corrections or deletion: ask your tour company, or write to [email protected].

How Cordelle works, and whose data this is

Cordelle is a companion app that tour companies license and run for their own trips. If you are a traveler or a guide, you were invited by a tour company: they built the trip, entered the roster, and sent you a join code. The details in the app are the ones you gave them when you booked.

That shapes everything below. Your tour company decides what goes into Cordelle and can correct or remove it from their dashboard at any time. Cordelle stores and moves that data on the tour company's behalf so the app works — we don't use it for anything of our own.

What your tour company puts in

  • About each traveler: name, email address, phone number, traveling party, dietary notes, mobility notes, and an emergency contact's name and phone number — whatever of these the traveler gave the tour company when booking. Guides see these care notes so they can look after the group; on a guide's phone that screen sits behind a PIN.
  • The trip itself: the itinerary, hotels (addresses, phone numbers, Wi‑Fi codes), flights, packing list, and country basics. This is trip information, shared with everyone on the departure.
  • Guides: the guide's name and phone number, shown to the group as the person to call.
  • Tour company staff: office staff sign in with an email address and a password. Passwords are stored only as salted hashes — we cannot read them. Subscription billing runs through Stripe, and card numbers go straight to Stripe; they never touch our servers. Travelers never pay Cordelle anything.

What the app keeps on your phone

Before departure the app downloads your whole trip as one bundle and reads every screen from that copy — that is what makes it work with no signal. Your phone also holds your join session, the message inbox, and a small outbound queue (read acknowledgements, any location pings you chose to send, sync confirmations) that is delivered the next time you are online. Every screen shows when it last synced, so you always know how fresh it is.

  • Some things never leave your phone. Packing-list checkmarks stay on the device — nobody else sees them. A guide's headcounts are kept on the guide's phone only.
  • Leaving a trip erases the app's data. "Leave trip" clears the bundle, the inbox, the queue and the session from the device.

Location sharing

Location sharing exists so a guide can find the two people who wandered off — not to follow anyone around. It works like this, and only like this:

  • Off by default, for every traveler, on every trip.
  • You start it, and it ends itself. Sharing runs for a short, timed session — the app today offers one hour, and a session can never exceed four hours — and expires on its own. You can stop it early at any time; a "stop sharing" tapped with no signal is queued and honored the moment you reconnect.
  • Foreground only. The app sends your position only while you are actively sharing, and it never asks your phone for background location permission. Continuous background tracking isn't a setting we hid — it's a thing we didn't build.
  • SOS is the one exception. An SOS, or a deliberate "send my location once", sends a single position even with sharing off. The tap itself is the consent, and it covers that one position only.
  • What the guide sees is a last known position with its time — never a live track. Anyone not sharing simply shows as not sharing.
  • Every ping is erased after 30 days. A daily sweep on our servers deletes location pings once they are more than 30 days old, counted from when the server received them.

Push notifications

If you allow notifications, the app registers your device's push token so a guide's message can reach you promptly. A push is only the doorbell — the message itself lives in the app's inbox, so nothing important exists only as a notification. The token is removed when you leave the trip, and swept automatically once your departure ended more than 30 days ago.

What we don't do

  • No advertising. There are no ads anywhere in Cordelle.
  • No selling or renting data. To anyone, for any purpose, ever.
  • No tracking across apps or websites. Cordelle contains no advertising or cross-app tracking identifiers.
  • No analytics or tracker SDKs. Not in the traveler app, not in the dashboard, not on this website.
  • No marketing to travelers. The only email a traveler ever gets from Cordelle is the join code their tour company asked us to send.
  • Not for children. Cordelle isn't directed at children; you can only join a trip with a code from a tour company.

The companies that help us run it

Cordelle runs on a small set of well-known services. Each one holds only what its job needs, and none of them may use the data for their own purposes.

ServiceWhat it does for Cordelle
StripeSubscription billing for tour companies. Card details go directly to Stripe; travelers never pay us at all.
ResendSends our email — traveler join codes, staff invites, password resets.
NeonThe database: managed Postgres, running on Amazon Web Services infrastructure.
Fly.ioHosts the Cordelle API.
CloudflareServes this website and the operator dashboard, and routes mail sent to [email protected].
ExpoDelivers push notifications, handing them to Apple and Google for your device.

How long things are kept

  • Location pings: deleted by a daily sweep once more than 30 days old.
  • Push tokens: removed when you leave a trip, and deleted automatically once the departure ended more than 30 days ago.
  • Sign-in sessions: traveler and guide sessions last 180 days so the app never demands anything mid-trip; staff sessions last 30 days. Expired sessions are deleted daily.
  • Trip and roster data: kept for as long as the tour company keeps it. When an operator deletes a departure, its travelers, join codes, sessions, messages, location pings, push tokens and published bundles are deleted with it.

Keeping it safe

Everything travels over HTTPS. Passwords are stored only as salted hashes. Sign-in tokens are opaque and revocable — a tour company can rotate a guide's access with one click, and every session for that code ends immediately. On a guide's phone, the screens holding the group's care notes sit behind a PIN that is never stored, only a salted hash of it.

Corrections and deletion

Your tour company is the right first call: they entered your details, and their dashboard lets them correct or delete any traveler's information, or an entire departure, at any time. If you'd rather ask us directly — or you're not sure who to ask — write to [email protected] and we'll take care of it with them.

This website

cordelle.io sets no cookies and runs no analytics. If you send the interest form, we use what you typed to reply to you and for nothing else — no list, no newsletter. Join-code pages (the cordelle.io/j/… links in traveler invites) are marked so they are neither cached by proxies nor indexed by search engines. The site's typefaces load from Google Fonts, so your browser requests those font files from Google's servers. The operator dashboard keeps its sign-in token in your browser's own storage — that is all.

Changes to this policy

If this policy changes, the new version appears here with a new effective date, and we tell tour companies about any change that matters. We won't quietly weaken it.

Contact

[email protected] — a person reads it, usually within a business day.