Privacy Policy

Last updated: April 24, 2026

Who We Are

Vin'Up is operated by Seedworks Studio, a French auto-entrepreneur (sole trader) registered in France. Registered address available upon request. Contact: privacy@getvinup.com. For the purposes of EU data protection law, Seedworks Studio is the data controller.

Data We Collect

When you create an account via Google Sign-In, we receive your Google account email address, display name, and profile picture. When you use the app, we collect the wine collection data you enter (bottle names, vintages, producers, regions, tasting notes, ratings), your in-app activity (bottles added/opened, cellar layout), and technical data (IP address, browser/device type, session identifiers). We do not collect payment card numbers — these are handled directly by Stripe.

Legal Bases for Processing (GDPR Art. 6)

We process your data on the following legal bases: (a) Contract performance — to provide and maintain your account and wine cellar; (b) Legitimate interests — to detect and prevent fraud, fix bugs, and improve the service; (c) Consent — for optional analytics and non-essential cookies (PostHog). You may withdraw consent at any time.

How We Use Your Data

Your data is used to: authenticate your account via Google OAuth; store and display your wine collection; generate AI sommelier suggestions (Premium) by sending anonymised collection context to Mistral AI; process Premium subscription payments via Stripe; send transactional emails (account notifications); monitor app performance and errors via Sentry; analyse aggregate usage patterns via PostHog. We never sell your data.

Third-Party Services

We share limited data with the following processors, all subject to GDPR-compliant data processing agreements: Railway.app (hosting, EU-Netherlands) — stores all app data within the EU; Google LLC (OAuth authentication) — receives only sign-in data; Mistral AI SAS (AI sommelier, France) — receives anonymised wine collection context for Premium users; Stripe, Inc. (payments, US) — processes billing data under EU Standard Contractual Clauses; PostHog, Inc. (analytics, EU-Netherlands) — receives usage events, data stored within the EU; Sentry, Inc. (error monitoring, US) — receives anonymised crash reports under EU Standard Contractual Clauses; transactional email provider (TBD) — receives your email address for account notifications.

Cookies

We use strictly necessary cookies for session management. PostHog sets analytics cookies to understand feature usage. You can disable non-essential cookies in your browser settings or by contacting us. A cookie consent mechanism will be provided in the app.

Data Retention

We retain your account and collection data for as long as your account is active. If you delete your account, all personal data is deleted within 30 days, except where retention is required by law (e.g. billing records for 10 years under French accounting law).

Your Rights (GDPR)

Under GDPR you have the right to: access your data; correct inaccurate data; request deletion (right to be forgotten); restrict or object to processing; data portability (export your collection at any time from the app); and withdraw consent. To exercise these rights, contact privacy@getvinup.com. You also have the right to lodge a complaint with the French data protection authority (CNIL — cnil.fr).

Contact

Data controller: Seedworks Studio — privacy@getvinup.com. We will respond to requests within 30 days.