The short version
Bonafero is a travel concierge. To plan and book your trips we need to know things about you — where you want to go, who you're travelling with, and the details airlines require to issue a ticket. This page explains exactly what we hold, who we hand it to, and how to get it back or have it erased.
Three things we want you to know up front:
- We don't sell your information, and we never will. We don't run advertising, we don't share your data with advertisers, and our website sets no cookies and runs no analytics or tracking of any kind.
- We never store your credit card. Card details go straight from the payment screen to the airline or hotel's booking system. We don't keep the number, and we never keep the security code.
- Your conversations with Sophie go to an AI provider to produce a reply, and nowhere else. They are not used to train AI models.
If anything below is unclear, write to us at privacy@bonafero.com and a person will answer.
1. Who we are
Bonafero ("Bonafero", "we", "us") is a travel concierge service operated from Ontario, Canada, consisting of the Bonafero iOS app, our website at www.bonafero.com, and the service behind them.
We are the organisation accountable for your personal information under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).
Privacy contact: privacy@bonafero.com
2. What we collect
Things you tell us
Your account. Your email address, a password (which we store only as a one-way cryptographic hash — we cannot read it), and your name.
Details airlines and hotels require. Your date of birth, gender as it appears on your travel document, and your phone number. Carriers will not issue a ticket without these. We ask once and remember them so you're never asked again.
Your home city, so Sophie knows where you're flying from.
Your phone number, which we also use to text you a sign-in code (see "Two-step sign-in" below).
Who you're travelling with. For each companion you add: their name, date of birth, gender, and optionally their email and phone. These ride along on bookings made for them.
People who should know your plans. For contacts and emergency contacts you add: their name, relationship to you, phone, and email.
Your preferences. Your travel interests, pace, dining preferences, dietary restrictions, accessibility needs, and notification choices.
Your conversations with Sophie. The full text of what you type or say to our concierge, and her replies, so she can remember what you've told her across sittings. Remembering is the point of the service — you should never have to repeat yourself.
Your trips. Destinations, dates, itineraries, activities, and any booking you add yourself that you made elsewhere.
Things we create or receive about you
Your bookings. Flight and hotel reservations, confirmation and record locator numbers, ticket status, and prices — received from the travel systems we book through.
Flight status. For flights on your itinerary, live departure, arrival, gate, and delay information, so we can tell you when something changes.
Trip alerts. Weather and disruption notices we generate for your upcoming trips.
Technical records of how the concierge behaved on each turn — the information she was given, the tools she used, and any error — which our engineers use to diagnose problems. Card details never reach this system.
Things from your device
Your voice, if you choose to speak to Sophie. When you tap the microphone, your speech is transcribed to text using Apple's speech recognition, which may process the audio on Apple's servers. We receive only the resulting text; we do not record or keep the audio.
A push notification token, if you allow notifications, so we can deliver trip alerts to your device. It identifies the device, not you.
Things we do not collect
- Your location. The app does not track where you are.
- Photos or camera access.
- Your contacts, calendar, or health data.
- Anything for advertising. No ad identifiers, no ad networks, no tracking pixels, no cookies on our website.
- Your credit card number. See section 5.
3. Why we use your information
We use it only for these purposes:
- To plan your trip — searching flights, hotels, and places, and building your itinerary.
- To book and ticket travel — passing the details carriers require to the airline or hotel.
- To remember you — so you're never asked the same question twice, and so an unfinished plan is still there when you come back.
- To keep you informed — flight status, delays, weather, disruptions, and when to leave for the airport.
- To sign you in securely, including texting you a verification code.
- To answer you when you need help, including passing your question to a person if Sophie can't resolve it.
- To keep the service working and safe — diagnosing errors, preventing abuse, and monitoring our costs.
- To meet legal obligations, such as tax, accounting, and lawful requests.
Under PIPEDA, our basis for all of this is your consent — given when you create an account and use the service — together with the limited uses Canadian law permits without consent, such as responding to a lawful demand. Where the EU or UK GDPR applies to you, see section 13.
We do not use your information for advertising, sell it, rent it, or trade it.
4. About the AI
Sophie is artificial intelligence, not a human travel agent. This has real privacy consequences, so we set them out plainly.
Where your words go. To answer you, we send your message — along with the relevant context from your trip, your saved preferences, and your recent conversation — to our AI provider, Anthropic (Claude). If Anthropic is unavailable, we fall back to Google (Gemini) so you aren't left without a reply. These providers process this content on our behalf, to generate that reply, under commercial API terms.
We do not train AI models on your information, and we do not permit our providers to train their models on it.
Web searches. When Sophie needs a fact she can't get from our travel systems — whether a museum is open on a Monday, a current price — she may run a web search through our AI provider. The search terms describe the place or fact she's checking. Your name, contact details, and account information are not included.
Your card never reaches the AI. This is a rule built into the system, not a matter of policy: card details are collected on a separate secure screen and sent to a dedicated endpoint that the AI has no access to.
A caution, not a privacy point but worth saying here: AI can be wrong. Please confirm anything critical — passport and visa requirements, health rules, exact times — with the airline, the hotel, or an official source. Our Terms of Use say more about this.
5. Payment cards
When you book through Bonafero, you enter your card on a dedicated secure screen. That screen is separate from the chat, and card details never pass through the AI.
- The card is used once, for that booking, and passed to the travel system that charges it.
- We do not store your card number, and we do not offer saved cards.
- We never store the security code (CVV/CVC). Payment-industry rules forbid it, even encrypted.
- Card details are never written to our logs.
Who actually charges you. For a flight, the merchant of record is normally the airline, charged through the Travelport booking system — not Bonafero. For a hotel, it is normally the property or its booking system. Your statement will usually show their name, not ours.
Bonafero currently charges no fee for the concierge service itself. If that ever changes, we will tell you before it applies to you.
6. Who we share it with
We share personal information only with the organisations below, only for the purpose listed, and only what that purpose needs. None of them may use your information for their own marketing.
To book and plan your travel
- Travelport (the travel distribution system we book through) — receives traveller name, date of birth, gender, a contact phone number, your flight or hotel selection, and card details for the charge, in order to search, reserve, and ticket travel.
- Airlines and hotels, via Travelport — receive the details needed for your reservation. They are the ones actually carrying or hosting you.
- Kayak, only when Travelport is unavailable — receives search criteria (dates, cities, number of travellers) to return flight, hotel, and car results and links.
- TripAdvisor — receives place and restaurant names and cities, to return details, ratings, and photos for places in your itinerary.
To run the service
- Anthropic (Claude) — receives your conversation and the relevant trip and preference context, to generate Sophie's replies and run her web-search lookups.
- Google (Gemini) — receives the same, but only when Anthropic is unavailable, so you still get an answer.
- Twilio — receives your phone number, to send your sign-in verification code. Twilio generates and checks the code; we never see or store it.
- Apple — receives your push notification token to deliver trip alerts, and separately your speech audio if you use voice input, to transcribe it to text.
- FlightAware — receives flight numbers and dates from your itinerary, but not your name, to return live flight status and delay information.
- Amazon Web Services — hosts our servers and database, and therefore holds everything we store.
Services that receive no personal information
Open-Meteo (weather by destination), OpenStreetMap/Nominatim (geocoding a place name), Michelin Guide, Unsplash, and Wikipedia receive only place names or coordinates for a destination — never your identity or contact details.
Uber is a link, not an integration. If you tap "Get an Uber" for an airport transfer, we hand Uber the two addresses in a web link and you continue in Uber's own app under Uber's terms and privacy policy. We send Uber nothing about you, we receive nothing back, and no payment passes through us.
Other circumstances
- When you ask us to. If you ask Sophie to contact someone on your behalf, or to notify a contact about your plans, we will ask you first.
- When the law requires it. A court order, subpoena, or lawful demand from an authority. We disclose only what is required.
- To protect people. Where we reasonably believe disclosure is needed to prevent serious harm, or to investigate fraud or abuse.
- If our business changes hands. In a merger, acquisition, or sale of assets, your information may transfer to the acquirer, who would remain bound by this policy. We would notify you first.
7. Where your information is stored
Your information is stored in the United States, on Amazon Web Services infrastructure in AWS's US regions. Our AI, travel, messaging, and flight-data providers also process information in the United States and, for some travel suppliers, in other countries where they operate.
We are telling you this plainly because it matters: while your information is in another country, it is subject to that country's laws, and may be accessible to that country's courts and law-enforcement or national-security authorities under their legal processes, without notice to you or to us.
We remain accountable for your information wherever it is held, and we require our providers by contract to protect it to a standard comparable to ours.
8. How long we keep it
- Your account and profile — until you ask us to delete it (see section 9).
- Your trips, bookings, and travel preferences — while your account is open, so your history and preferences stay useful to you.
- An unfinished trip plan you abandoned — 24 hours, so you can pick it back up, after which the draft is dropped.
- Conversations with Sophie — while your account is open, because remembering is the service. You can end a chat at any time.
- Engineering diagnostic records — 90 days, then deleted.
- Booking and payment records — as long as tax, accounting, and consumer-protection law require us to keep them, typically seven years, even after you close your account.
- Push notification tokens — until the device is removed or the token is revoked.
When we delete your account, we delete or irreversibly anonymise the above, except records we are legally required to retain.
9. Your choices and your rights
You may:
- See what we hold about you, and get a copy.
- Correct anything wrong — most of it directly in the app, under Profile.
- Delete your account and your information.
- Withdraw your consent and stop using the service, subject to records we must legally keep.
- Turn off notifications — in the app under Profile → Notifications, or in your iPhone's Settings.
- Decline the microphone. Voice is optional; typing works identically.
How to exercise these rights: email privacy@bonafero.com from the address on your account. We will confirm your identity and respond within 30 days, as PIPEDA requires. There is no charge.
If you're unhappy with how we've handled your information, tell us first — we'd like the chance to put it right. If we don't resolve it, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca, 1‑800‑282‑1376). If you're in the EU or UK, you can complain to your local data protection authority.
10. Other people's information
When you add a travel companion, a contact, or an emergency contact, you are giving us someone else's personal information.
Please only add someone whose permission you have, and please tell them that their details are held by Bonafero for the purpose of your travel. They have the same rights over their information as you do over yours — if one of them contacts us at privacy@bonafero.com, we will help them.
You can remove any companion or contact at any time in the app under Profile.
11. How we protect it
- Connections between the app and our servers are encrypted in transit (TLS).
- Your password is stored as a bcrypt hash, never in readable form.
- Two-step sign-in. After your password, we text a code to your verified phone. The code is generated and checked by Twilio; we never see or store it.
- Sign-in sessions expire and must be renewed.
- Card details are never stored and never logged.
- Access to production systems is limited to the people who need it.
- Our systems are built to fail safely: a misconfigured deployment locks down rather than opening up.
No system is perfectly secure. If a breach ever creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner as Canadian law requires.
12. Children
Bonafero is built for adult travellers and is not intended for anyone under 18. We don't knowingly collect information from children. If a child's details appear as a travel companion, they are held as part of an adult's booking and are the responsibility of that adult.
If you believe a child has created an account, write to privacy@bonafero.com and we will remove it.
13. If you are in the EU, the UK, or California
EU / UK. Where the GDPR or UK GDPR applies, our lawful bases are: contract (planning and booking your travel, running your account), legitimate interests (keeping the service secure, diagnosing faults, preventing abuse), consent (voice input, push notifications, marketing if we ever send any), and legal obligation (records we must keep). You additionally have the rights to restrict or object to processing, to data portability, and not to be subject to solely automated decisions with legal effect — Sophie makes no such decisions; nothing is booked or charged without your explicit confirmation. Transfers to the United States rely on standard contractual clauses with our providers.
California. We do not sell or share personal information as the CCPA/CPRA define those terms, and we do not use it for cross-context behavioural advertising. You have the right to know, delete, correct, and to be free from discrimination for exercising those rights. Exercise them at privacy@bonafero.com.
14. Changes to this policy
If we change how we handle your information, we'll update this page and change the date at the top. If a change is significant, we'll tell you in the app or by email before it takes effect — we won't quietly broaden what we do with your information.
15. Contact us
privacy@bonafero.com — privacy questions, access requests, deletion requests.
support@bonafero.com — anything else.
A person reads both.
You may also want to read our Terms of Use.