1. Who operates WineUp
WineUp is a trade name operated by Víctor Arzola, an individual sole proprietor (freelance).
Business address: 2740 Saint Paul St., Baltimore, MD 21218, United States.
WineUp is a technology provider only. We do not sell, serve, store, ship or deliver any alcoholic beverage or food product. Alcohol sales, service, licensing, age verification at the point of service and tax collection are the sole responsibility of the subscribing restaurant.
2. Scope
This policy covers the WineUp website, the restaurant dashboard and the guest experience reached by scanning a table QR code. It does not cover a restaurant’s own websites, apps, POS systems or paper records.
3. Information restaurant customers provide
- Account data: name, email address, password (stored only as a bcrypt hash), role, language preference.
- Two-factor data: email one-time codes, or a TOTP secret if the owner enables an authenticator app; trusted-device records.
- Restaurant profile: business name, cuisine, location details entered by the restaurant, logo and design preferences.
- Operational content: menus, dishes, wine lists, prices, pairing content, QR/table configuration and uploaded files (PDF/images) used for extraction.
- Consent records: AI-processing consent and Terms/Privacy acceptance, stored with a timestamp, the document versions accepted, and the IP address and browser user agent captured at that moment as evidence.
4. Restaurant guests who scan a QR code
WineUp does not require restaurant guests who scan a QR code to create an account or provide their name, email address, telephone number, payment information or other directly identifying account information.
Like most online services, limited technical information is processed automatically where necessary to operate, secure, troubleshoot and measure the service:
- IP address and browser/device information present in web requests, handled by our hosting layer in server and security logs.
- Request timestamps and error information used for troubleshooting and abuse prevention (including rate limiting, which uses the IP address in memory and does not store it in the application database).
- A randomly generated guest session identifier stored in your browser, plus the dish and wine interactions of that session (which dish was selected, which recommendation was viewed, whether you told us you asked your server). This is what produces the restaurant’s guest-intent analytics.
We do not store guest names, emails, phone numbers, payment details or precise geolocation. We do not create persistent cross-restaurant guest profiles and we do not use the guest QR experience to build advertising profiles. There is no Meta Pixel, TikTok Pixel, behavioural advertising SDK or cross-site tracking in the guest experience.
We do not describe this information as anonymous. An IP address or a session identifier is pseudonymous technical data, even though we do not know the person’s name.
5. Information collected automatically from accounts
For authenticated accounts we record security metadata: login and 2FA events, the IP address and user agent attached to a trusted-device record or a consent record, session tokens, and background job history. Passwords are never logged.
6. Payment information and Stripe
Subscription payments are processed by Stripe. WineUp never receives or stores complete card numbers or CVC codes. We store Stripe customer and subscription identifiers, the plan, status, billing period, and transaction metadata needed for accounting and support. Stripe processes payment data as its own controller under its privacy policy.
7. AI processing
When a restaurant uploads a menu or wine list, or generates pairing content, that restaurant content is sent to OpenAI for extraction and text generation. We do not send guest technical data or account passwords to the AI provider. AI output is treated as a draft: the restaurant triggers generation, is shown an AI-review notice, and the approval is recorded with a version history that can be rolled back.
8. Why we process information
- To provide the service the restaurant subscribed to.
- To authenticate users and protect accounts against unauthorised access.
- To bill subscriptions and keep accounting and tax records.
- To generate and display pairing recommendations.
- To produce guest-intent analytics for the restaurant.
- To troubleshoot, monitor service health and prevent abuse or fraud.
- To send transactional notices (verification, security, billing, trial and renewal reminders).
- To comply with legal obligations and to establish or defend legal claims.
9. Sharing and subprocessors
We share information only with the vendors needed to run WineUp, listed on the Subprocessors & Security page, and with authorities where legally required. We do not sell personal data, and we do not share guest data for cross-context behavioural advertising.
10. Cookies and storage technologies
WineUp uses only strictly necessary cookies and browser storage. There are no analytics or advertising trackers.
- session_token — authentication cookie for restaurant accounts (7 days).
- wu_td — trusted-device cookie so 2FA is not requested on every login (30 days).
- wu_token — localStorage session token used by the dashboard (cleared on sign-out).
- wu_guest_session — random guest session identifier in browser storage, used for guest-intent analytics.
- wu_age_ack — temporary flag recording the on-screen 21+ acknowledgement for the current session.
- wu_cookie_ack_v1 — remembers that the cookie notice was dismissed.
- wu_demo_from_landing — per-tab flag so the demo QR shows a link back to the marketing site.
If we ever add non-essential analytics or marketing trackers, we will build consent management before activating them where consent is required.
11. Retention and the cancellation lifecycle
This is the single lifecycle used by the code, by the Refund & Cancellation Policy and by the DPA:
- Cancellation: access continues until the end of the paid billing period, unless the account is terminated immediately for a Terms breach.
- When service access ends, a 30-day read-only recovery period starts. Data can be exported and the account can be reactivated; nothing can be edited.
- At the end of the recovery period an automated server-side job hard-deletes the restaurant’s operational records from active production storage: menus, dishes, wine lists, pairings, pairing versions, QR/table configuration, restaurant analytics, uploaded assets, sessions, trusted devices, consent records and the owner account.
- An auditable deletion event is recorded. It contains the account identifier, the reason and timestamps — never the deleted content.
- Residual copies may remain in encrypted disaster-recovery backups until ordinary rotation removes them, within a maximum of 30 days. Backups are not used for ordinary business operations and are not restored solely to recover a deleted account’s data.
Exceptions kept after deletion, limited to what is necessary:
- Billing, invoice and tax records required by law.
- Fraud-prevention records where retention is reasonably necessary (for example, a trial-abuse fingerprint).
- Security-incident records and legal-hold information.
- The minimum records needed to establish or defend legal claims.
Guest-intent events belong to the restaurant’s account and are deleted with it. Aggregated, non-identifying counts already used in historical reporting may remain.
12. Security
Concrete measures are documented on the Subprocessors & Security page. No online service can be guaranteed 100% secure, and we do not claim that.
13. Your privacy choices and requests
Use the Privacy Request page to ask for access, correction, deletion or an export, or to ask a question. Guests do not need an account to contact us. For restaurant-account data we verify identity before disclosing anything. Restaurant owners can also export all their data from the dashboard at any time (Settings → Privacy & data).
We provide these controls as WineUp privacy features and honour the rights that applicable law gives you. We do not claim that every US state privacy statute currently applies to WineUp; the software is built to support these requests regardless.
14. Email preferences
Transactional messages (email verification, password reset, security alerts, billing, trial-ending and renewal notices) are required to operate an account and are not marketing. Optional messages such as the weekly performance summary can be turned off in the dashboard or via the unsubscribe link in the message; unsubscribing never suppresses transactional notices.
15. Children and age
WineUp is not directed to children. Restaurant accounts are for adults acting for a business. The guest experience shows an on-screen 21+ acknowledgement before wine recommendations; it is an acknowledgement, not identity verification, and it does not replace the restaurant’s ID checks. We do not knowingly collect information from children.
16. International users
WineUp is operated from the United States and its infrastructure is primarily US-based. If you access WineUp from outside the United States, your information will be processed in the United States. Where a cross-border transfer mechanism is legally required, we will put one in place before the transfer.
17. Changes
We version this policy. The current version and effective date appear at the top of the page, and previous versions accepted by a restaurant are preserved as acceptance evidence. Material changes are communicated to account owners.
18. Contact
Privacy questions and requests: wineuptech@gmail.com (subject “Privacy Request”) or the Privacy Request page.
