Legal
Privacy Policy
Last updated: July 20, 2026
Cardoo is operated by Cabos, LLC, a California limited liability company (“Cabos,” “we,” “us,” or “our”). We take your privacy seriously. Because Cardoo connects to your credit card and financial accounts, we handle sensitive information, and we want to be direct about what we do with it.
By using or accessing the Services in any manner, you acknowledge that you accept the practices described below. Your use of the Services remains subject to our Terms of Service, which incorporates this Privacy Policy.
The short version: we access your financial accounts on a read-only basis to show you what your cards owe you. We do not sell your personal data. We do not share your financial data with advertisers, and we do not use it to train generalized AI models.
We may modify this Privacy Policy over time. We will communicate material changes by notice on this website, by email, or by other means. If you use the Services after changes have been posted, that means you agree to those changes.
1. What This Policy Covers
This Privacy Policy governs how we treat Personal Data collected when you access or use the Services. “Personal Data” means any information that identifies or relates to a particular individual, including information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws.
This Privacy Policy does not cover the practices of companies we do not own or control, including your card issuers, banks, loyalty programs, airlines, and hotels. Your relationship with those institutions is governed by their own privacy policies.
2. Categories of Personal Data We Collect
We may collect, and have collected over the past 12 months, the following categories of Personal Data:
Profile or Contact Data
- First and last name
- Email address
- Account credentials
- Shared with: Service Providers
Financial Account Data
- Identity of the financial institutions and card products you link
- Masked account identifiers (such as the last four digits)
- Transaction history, including merchant name, amount, date, and category
- Statement credit activity, balances, and posting dates
- Rewards, points, and miles balances where available
- Shared with: our account-linking provider and hosting providers, acting as Service Providers on our behalf
Payment Data
- Payment card type and last four digits
- Billing address and email
- Subscription and billing history
- Shared with: our payment processor, Stripe, Inc. We do not store full payment card numbers.
Travel and Search Data
- Award search criteria, including origin, destination, dates, cabin, and passenger count
- Award alert configurations, including routes and mileage caps
- Hotel search criteria, including destination and travel dates
- Shared with: Service Providers and award availability data sources
Device/IP Data
- IP address and IP-based approximate location
- Device identifier, operating system, and browser type
- Shared with: Analytics Partners, in aggregated or de-identified form only
Web Analytics
- Page interactions and feature usage within the Services
- Referring webpage or source through which you reached us
- Shared with: Analytics Partners, in aggregated form. Financial Account Data is excluded.
Other Information You Choose to Provide
- Information contained in emails, support requests, surveys, or other communications you send us
- Shared with: Service Providers
3. Financial Account Data
Because Financial Account Data is the most sensitive category we handle, this section describes it specifically.
How we obtain it. We use a third-party account-linking provider, currently Plaid Inc., to establish and maintain connections to your financial institutions. When you link an account, you authenticate directly with your financial institution through the provider’s interface. We do not receive, store, or have access to your online banking username or password. Plaid’s handling of your information is governed by its own privacy policy, available at plaid.com/legal.
Read-only access. Our access to your Linked Accounts is read-only. We cannot and do not initiate payments, transfers, redemptions, or bookings.
What we use it for. We process Financial Account Data solely to deliver the features you have requested: matching statement credits against your transactions, showing what has been used and what remains, alerting you to credits that are about to expire, and surfacing the card benefits and points balances relevant to your searches.
What we will never do with it. We will not:
- Sell or rent your Financial Account Data to anyone
- Share it with advertisers, advertising networks, or data brokers
- Use it to train, fine-tune, or improve any generalized artificial intelligence or machine learning model, whether ours or a third party’s
- Pool it across users for any purpose other than aggregated, de-identified analytics that cannot be linked back to any individual
- Use it for marketing purposes
Disconnecting. You may disconnect any Linked Account at any time in your Account settings. Disconnecting stops further data retrieval immediately. You may also request deletion of previously retrieved Financial Account Data as described in Section 12.
4. Categories of Sources of Personal Data
From You
- When you provide information directly during account creation, when configuring alerts, when completing surveys, or when contacting us
- When you use the Services and information is collected automatically through cookies and similar technologies
From Your Financial Institutions
- Through our account-linking provider, once you have authorized the connection, as described in Section 3
From Third Parties
- Award availability, fare, and hotel data sources, which supply inventory and pricing information but do not receive your Financial Account Data
- Analytics providers that help us understand how visitors interact with our website, using non-financial data only
5. How We Use Personal Data
Note on Financial Account Data — we process Financial Account Data only to deliver the features you have requested inside Cardoo. It is never used for marketing, generalized analytics, advertising, or AI model training.
Providing, Customizing, and Improving the Services
- Creating and managing your Account
- Processing subscriptions, transactions, and billing
- Matching statement credits to transactions and calculating remaining credit value
- Sending the weekly expiring-credits digest and award alerts
- Running award and hotel searches you request
- Providing support and responding to your requests
- Improving the Services through testing, research, and product development using aggregated or de-identified data
- Conducting fraud prevention, security monitoring, and debugging
Marketing the Services
- Marketing and promoting the Services, excluding any use of Financial Account Data
Corresponding With You
- Responding to your correspondence
- Sending service, security, and billing notices
- Sending product communications in accordance with your preferences
Meeting Legal Requirements and Enforcing Legal Terms
- Fulfilling obligations under applicable law, regulation, court order, or legal process, including preventing and investigating security incidents
- Protecting the rights, property, or safety of you, us, or another party
- Enforcing our agreements with you and resolving disputes
We will not collect additional categories of Personal Data, or use the Personal Data we have collected for materially different, unrelated, or incompatible purposes, without providing you notice.
6. How We Disclose Your Personal Data
We do not sell your Personal Data. We disclose it only as described below.
Service Providers
These parties help us provide the Services or perform business functions on our behalf, under contractual obligations to protect your data and to use it only for the purposes we specify:
- Account linking: Plaid Inc., to establish and maintain connections to your financial institutions
- Payment processing: Stripe, Inc., which collects and processes payment card information for subscriptions. See Stripe’s terms and privacy policy for information on its use and storage of that data.
- Hosting and infrastructure: cloud hosting, database, and content delivery providers
- Email delivery: providers that deliver your digests, alerts, and transactional email
- Support tooling: customer support and communication vendors
- Security: security monitoring and fraud prevention vendors
Analytics Partners
These parties provide analytics on website traffic and product usage using aggregated or de-identified information only. No Financial Account Data is shared with them. We currently use Vercel Analytics for privacy-preserving website analytics.
Award and Travel Data Sources
When you run an award or hotel search, we transmit the search parameters you provide, such as route and dates, to the data sources that return availability and pricing. We do not transmit your Financial Account Data, your identity, or your transaction history to these sources.
Legal Obligations
We may share Personal Data with third parties as described in the “Meeting Legal Requirements and Enforcing Legal Terms” section above, but only to the extent legally required. Any third party that receives Financial Account Data under this subsection is bound to use it solely for the legal purpose for which it was disclosed.
Business Transfers
Personal Data may be transferred to a third party in connection with a merger, acquisition, bankruptcy, or other transaction in which that party assumes control of all or part of our business. Should this occur, we will make reasonable efforts to notify you before your information becomes subject to materially different privacy terms, and we will require the successor entity to honor the commitments regarding Financial Account Data set out in Section 3.
7. Data That Is Not Personal Data
We may create aggregated, de-identified, or anonymized data from Personal Data by removing information that identifies you. We may use such data to analyze and improve the Services, to understand product usage in aggregate, and for internal reporting.
Aggregated data derived from Financial Account Data is used only for our internal operations. It is not sold, not shared with advertisers, and not used to train generalized AI or machine learning models. We do not attempt to re-identify de-identified data.
8. Tracking Tools and Opt-Out
The Services use cookies and similar technologies — including pixel tags, web beacons, and JavaScript (collectively, “Cookies”) — to recognize your browser, track visits and usage, analyze trends, and improve the Services. We do not combine Financial Account Data with cookie-based analytics, and we do not share it with advertising networks or third-party tracking services.
Essential Cookies are required to provide features you have requested, such as keeping you signed in to secure areas of the Services. Disabling these may make certain features unavailable.
Functional Cookies record your choices and settings, such as your theme preference, and recognize you as a returning user.
Performance and Analytical Cookies help us understand how visitors use the Services by collecting information about visitor numbers, pages viewed, and time spent. Financial Account Data is excluded from these analytics.
You can decide whether to accept Cookies through your browser settings. Most browsers let you disable Cookies, delete existing Cookies, or be prompted before a new Cookie is set. Some functionality may not work if you disable Cookies. For more information, visit allaboutcookies.org.
9. Data Security
We seek to protect Personal Data from unauthorized access, use, and disclosure using appropriate physical, technical, organizational, and administrative security measures based on the type of data and how it is processed. For Financial Account Data specifically, we apply encryption in transit (TLS 1.2 or higher) and at rest (AES-256), and we restrict access to trained personnel on a least-privilege basis.
You can help protect your data by choosing a strong, unique password, limiting access to your devices and browser, and signing out after using your Account. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Retention
We retain Personal Data as long as necessary to provide the Services or to fulfill the business purposes described in this policy. When setting retention periods, we consider the source of the data, why it was collected, and how sensitive it is. We may retain data longer where necessary to comply with legal obligations, resolve disputes, or collect fees.
- Profile and credentials: retained for as long as you maintain an Account
- Financial Account Data: retained while the corresponding account remains linked. When you disconnect an account or close your Account, we delete or de-identify the associated Financial Account Data within ninety (90) days, except where we are required to retain records for legal or accounting purposes.
- Payment and billing records: retained as required for tax, accounting, and audit obligations
- Device and log data: retained as needed to secure and operate the Services
11. Personal Data of Children
We do not knowingly collect or solicit Personal Data from children under 16 years of age, and children under 16 may not register for the Services. If we learn that we have collected Personal Data from a child under 16, we will delete that information as quickly as possible. If you believe a child under 16 has provided us Personal Data, please contact hello@cardoo.ai.
12. State Privacy Rights
California (CCPA / CPRA)
We do not “sell” or “share” Personal Data, as those terms are defined under the California Consumer Privacy Act as amended by the California Privacy Rights Act. California residents have the right to know what Personal Data we collect, to request deletion, to request correction, and to be free from discrimination for exercising these rights. California residents may submit requests by emailing hello@cardoo.ai.
Financial Account Data may constitute sensitive personal information under California law. We use it only to provide the Services you have requested, which is a permitted purpose that does not require an opt-out right, and we do not use or disclose it for any other purpose.
Nevada
Nevada residents may opt out of any future “sale” of personal data as defined under Nevada law by emailing hello@cardoo.ai with the subject line “Nevada Do Not Sell Request.”
Other U.S. States
Residents of states with comprehensive privacy laws, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and Montana, may have rights to access, correct, delete, and obtain a portable copy of their Personal Data, and to appeal a denied request. Submit requests to hello@cardoo.ai.
Exercising Your Rights
To exercise any right described above, email hello@cardoo.ai. Your request must include enough information for us to verify your identity and your relationship with us. In some circumstances we may not be able to fully comply — for example, if we cannot verify your identity, if the request is frivolous, or if fulfilling it would jeopardize the rights of others — but we will notify you of any such decision and our reasons.
13. European Union, United Kingdom, and Swiss Data Subject Rights
The Services are hosted and operated in the United States. If you do not reside in the United States, please be aware that laws in the United States may differ from those where you reside. By using the Services, you acknowledge that your information is processed in the United States.
If and to the extent we offer the Services to residents of the European Economic Area, United Kingdom, or Switzerland, data subjects have rights under the EU and UK General Data Protection Regulation, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to withdraw consent and to lodge a complaint with a supervisory authority.
Lawful Bases for Processing
- Contractual necessity: Profile and Contact Data, Financial Account Data, Payment Data, and Travel and Search Data are processed because they are required to provide the Services under our Terms of Service. Without them, we cannot deliver some or all of the Services.
- Legitimate interests: Device/IP Data and Web Analytics are processed to secure, operate, and improve the Services and to market them. Financial Account Data is not processed on a legitimate-interests basis.
- Consent: where we rely on consent, we will indicate this expressly at the point of collection, and you may withdraw it at any time.
- Legal obligation: where processing is necessary to comply with applicable law.
Where required, transfers of Personal Data out of the EEA, UK, or Switzerland rely on Standard Contractual Clauses or another valid transfer mechanism. To exercise any of these rights, email hello@cardoo.ai with the subject line “GDPR Request: [nature of request].”
14. Contact Information
If you have questions or comments about this Privacy Policy, the ways we collect and use Personal Data, or your rights, please contact us:
Cabos, LLC
808 Sonia Way
Mountain View, California 94040
Email: hello@cardoo.ai