Skip to content
·
WineUp
Legal

Subprocessors & Security

The vendors WineUp actually uses in production and the technical and organisational measures we operate.

Last updated · September 13, 2026

This page is referenced by the Privacy Policy and by the Data Processing Addendum. We list only vendors that the application actually calls.

1. Production subprocessors

ProviderPurposeData categoryLocationInformation
Emergent Labs (application hosting)Kubernetes hosting, HTTPS edge, secrets, monitoringAll application traffic, system and security logsUnited States / EUProvider privacy
MongoDB AtlasPrimary application database and encrypted backupsRestaurant accounts, menus, wines, pairings, guest-intent eventsUnited StatesProvider privacy
Stripe, Inc.Subscription billing, checkout, customer billing portalBilling contact, subscription metadata, payment tokens (card data never reaches WineUp)United StatesProvider privacy
OpenAI, L.L.C.Menu/wine extraction and pairing copy generationRestaurant menu and wine-list content submitted by the restaurantUnited StatesProvider privacy
Resend, Inc.Transactional email delivery (verification, billing, security)Recipient email address, email contentUnited StatesProvider privacy
Google LLC (Google Sign-In)Optional OAuth sign-in for restaurant accountsAccount email address, public profile name/picture, OAuth tokensUnited StatesProvider privacy

If we add or replace a subprocessor we update this page. Subscribing restaurants may request advance notice of changes by writing to us.

2. Technical and organisational measures

  • HTTPS only in production; security HTTP headers at the edge.
  • Passwords stored with strong hashing (bcrypt); never in plaintext and never logged.
  • Two-factor authentication by email or TOTP app, with revocable trusted devices.
  • JWT sessions with expiry; session revocation available.
  • Server-side per-tenant authorization (restaurant_id) on every protected route.
  • Account lockout after 3 failed attempts, with an email alert and a 30-minute auto-unlock.
  • Rate limits on authentication, 2FA, password reset and privacy requests.
  • Typed input validation; parameterised queries to prevent injection.
  • CORS restricted to known origins; credentials never combined with a wildcard.
  • Secrets kept out of source control, in server environment variables.
  • Card data never stored — payments are tokenised by Stripe.
  • Sensitive onboarding secrets encrypted at rest (Fernet/AES).
  • Logging of sensitive administrative actions and deletion events.
  • Stripe webhook signature verification and idempotent processing.

No system is 100% secure and we do not claim otherwise. WineUp is not SOC 2, ISO 27001 or PCI DSS certified.

3. Backups and retention

Disaster-recovery backups are encrypted and rotate within a maximum of 30 days. They are not used for ordinary business operations and are not restored to recover a deleted account's data. After cancellation there is a 30-day read-only recovery period; after that, operational records are permanently deleted from active storage. Detail in the Privacy Policy.

4. Security incidents

We maintain an internal incident-response plan (detection, containment, assessment, notification, recovery and post-incident review). If an incident affects a subscribing restaurant's data we will inform them without undue delay with the information available. Report a security problem to wineuptech@gmail.com with the subject “Security”.

Have a question? Email wineuptech@gmail.com