Draft: not yet in force. This document still contains placeholder details and has not been finalised. It does not constitute the operative agreement until completed.
Privacy Policy
Last updated: 14 August 2026
This policy explains what data Cellarist collects, why, and the choices you have. [Your legal entity name] is the controller of your personal data. We handle personal data in line with applicable data-protection laws, including Singapore’s Personal Data Protection Act (PDPA) and, where relevant, the EU/UK GDPR.
1. Data we collect
- Account data. Your email address, optional display name, and password. Passwords are hashed and managed by our authentication provider; we never see them in plain text.
- Your content. The wines, cellars, stock movements, locations, menu settings and any images you upload (label photos, menu logos, avatar).
- Billing data. Your plan and subscription status, and a customer identifier from Stripe. Card and payment details are collected and stored by Stripe, not by us.
- Technical data. IP address, device/browser information and request logs, used for security, abuse prevention and debugging.
- Cookies. We use strictly necessary cookies only: to keep you signed in and to remember your active cellar. We do not use advertising or cross-site tracking cookies.
2. How we use your data
- To provide and operate the service (store your inventory, derive stock, publish your menu).
- To process subscriptions and send billing-related communications via Stripe.
- To secure the service (enforcing rate limits, quotas and abuse containment).
- To provide support and respond to your requests.
- To send essential account emails (sign-up confirmation, password reset, important service notices).
- To produce anonymised, aggregated statistics and insights that no longer identify you (see Data retention below).
- To build and improve a shared wine reference catalogue from facts about wines themselves (producer, name, vintage, origin, label imagery), separated from your identity and your business — never from your costs, suppliers, stock levels or prices.
- To meet legal and tax obligations.
3. Legal bases and consent
We process your data to perform our contract with you (providing the service and billing), for our legitimate interests (security, abuse prevention, improving the product), to comply with legal obligations (tax, accounting), and with your consent where required (for example, optional marketing emails, which you can opt out of at any time). Under the PDPA we may also rely on deemed consent or applicable exceptions where the law permits.
Where we rely on your consent, you can withdraw it at any time. Withdrawal does not affect processing already carried out, and we will tell you if withdrawing affects our ability to provide the service.
4. Who we share data with (sub-processors)
We do not sell your personal data. We share it only with providers who process it on our behalf:
- Supabase. Database, authentication and file storage (hosts your account and content).
- Stripe. Payment processing and subscription billing.
- Google. AI label recognition: the image you capture for a label scan is sent to Google to extract wine details.
- Vercel. Hosting and content delivery (serving the application and public menus).
- Our email provider. Delivering transactional emails such as password resets.
We keep this list up to date and will update this policy before adding a sub-processor that materially changes how your personal data is handled. We do not use your data for automated decision-making that produces legal or similarly significant effects about you.
We may also disclose data where required by law, or to protect the rights, safety and security of our users and the service.
5. Public menus
If you choose to publish a wine menu, the information you include in it becomes publicly accessible to anyone with the link. Only the customer-facing fields you configure are exposed; private data (cost, internal notes, locations, by-the-glass cost) is never included in a public menu.
6. Data retention
We keep your data for as long as your account is active. When you delete your account, your personal data and content are permanently removed from our systems, and your billing record with Stripe is closed; residual copies in encrypted backups are purged on the backup rotation cycle (within 35 days). We may retain limited records where required for legal, tax or fraud-prevention purposes, for no longer than those purposes require. We may also retain wine, pricing and supplier information in anonymised or aggregated form that no longer identifies you or your business, and use such anonymised data to improve the service (for example, market and pricing insights).
Where we produce aggregated commercial statistics (for example, the typical price paid for a wine), they are computed only across a minimum number of independent businesses, shown as ranges or statistics rather than individual figures, and are never attributable to you, your business or your suppliers. Anonymisation is applied when the aggregate is produced, not retroactively.
7. Your rights
Depending on where you live, you have rights over your personal data. Cellarist supports the core ones directly from your account:
- Access & portability: export all of your data as a JSON file from your account settings.
- Erasure: delete your account and data at any time from your account settings.
- Rectification: edit your profile and content directly in the app.
- Withdraw consent: where we rely on your consent, you can withdraw it at any time.
- Objection & restriction, and the right to lodge a complaint with a data-protection authority: in Singapore, the Personal Data Protection Commission (PDPC); in the EU/UK, your local supervisory authority.
To exercise any right we don’t cover in-app, email privacy@cellarist.app.
8. Security
Data is isolated per user at the database level (row-level security), transmitted over encrypted connections, and privileged credentials are held only on our servers. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.
If a data breach affecting your personal data occurs and meets the legal notification threshold, we will notify the relevant authorities and affected individuals as required, including the PDPC under Singapore’s PDPA and, where the GDPR applies, the supervisory authority within 72 hours of becoming aware of the breach.
9. International transfers
Our providers may process data in countries other than yours. Where personal data is transferred internationally, it is protected by appropriate safeguards, such as the EU Standard Contractual Clauses or, for providers certified under it, the EU–US Data Privacy Framework.
10. Children
Cellarist is not intended for anyone under 18, and we do not knowingly collect data from children.
11. Changes to this policy
We may update this policy over time. Material changes will be notified through the service or by email. The “last updated” date above always reflects the current version.
12. Contact & Data Protection Officer
For privacy questions or requests, or to reach our Data Protection Officer, contact us at privacy@cellarist.app. We aim to respond within the timeframes required by applicable law (for example, 30 days for access requests under the PDPA).