Privacy Policy
Restaurant guests never need an account. We do not build advertising profiles and we do not sell personal data. Limited technical data (IP, browser/device, timestamps, temporary session IDs) is processed to run and secure the service.
Subprocessors & Security
The vendors we actually use, plus our technical and organisational measures: HTTPS, bcrypt password hashing, 2FA, per-tenant authorization, rate limits, Stripe-tokenised payments.
AI & Human Review
Pairing copy is AI-assisted. Every generation is triggered by the restaurant, records who approved it and when, keeps a version history and can be rolled back. AI output is never presented as infallible, and we never generate health claims about alcohol.
Data Retention
Cancellation keeps access to the end of the paid period, then a 30-day read-only recovery window, then a hard delete from active storage. Encrypted disaster-recovery backups rotate within 30 days.
Accessibility
WCAG 2.2 Level AA is our engineering target. We publish known limitations and a contact route for accessibility problems. We are not certified.
Alcohol Responsibility
WineUp does not sell, serve or deliver alcohol. The restaurant controls pricing, availability, service and legally required ID checks. Our on-screen 21+ acknowledgement is not identity verification.
What we do NOT claim
- We are not SOC 2, ISO 27001 or PCI DSS certified.
- We do not claim to be “100% secure” or “fully compliant with all privacy laws”.
- We do not claim AI output is error-free.
- We do not guarantee uptime beyond what a written agreement states.
- We do not guarantee increases in wine sales, revenue or average ticket.
- We do not display insurance coverage, because no policy has been verified.
Questions about anything on this page: wineuptech@gmail.com.
