Privacy Policy
Last updated [DATE]
This policy explains how [LEGAL ENTITY NAME](“Tino”) handles personal data in connection with the Tino inventory and costing service (the “Service”) and this website. Tino is a business-to-business tool; most data in the Service is winery business data rather than personal data.
Roles
For personal data that our customers put into the Service about their own staff, growers, and vendors, the customer is the controller and Tino is a processoracting on the customer’s instructions. For account registration, billing, support, and this website, Tino is the controller.
What we collect
Data you provide directly
- Account & contact: name, work email, and role of the people who sign in; the winery / organization name.
- Reference contacts entered by customers: names, phone numbers, emails, and websites for vineyards and vendors, entered as reference data.
- Business records: lots, transactions, costs, reports, and similar operational data (generally not personal data).
- Billing: billing contact and plan details. Card details, if collected, are handled by our payment processor and are not stored by Tino. [CONFIRM / NAME PROCESSOR]
- Support communications: the content of messages you send us.
Data collected automatically
- Authentication & session: a session cookie set at sign-in so you stay logged in. See the Cookie Policy.
- Server logs: standard request logs (timestamp, IP address, request path, error details) kept for security and reliability for a limited period.
- Local preferences: your browser stores UI preferences (light/dark theme, table column layout) in local storage on your device. This never reaches our servers.
We do not use analytics, advertising, tracking pixels, or third-party marketing tools in the Service. Web fonts are self-hosted, so loading a page does not call a third-party font provider.
How we use personal data
- to provide, secure, support, and improve the Service;
- to authenticate users and enforce roles and permissions;
- to bill for paid plans and manage subscriptions;
- to communicate about the Service, including security and service notices;
- to comply with law and to establish, exercise, or defend legal claims.
Where required, our legal bases are: performance of a contract; our legitimate interests in running and securing the Service; consent (where we ask for it); and compliance with legal obligations.
Sharing
We do not sell personal data. We share it only with:
- Subprocessors that host and run the Service on our behalf, under written data-protection terms — currently our cloud hosting and database provider [e.g. Supabase / hosting region] and [PAYMENT PROCESSOR]. A current list is available on request. [MAINTAIN SUBPROCESSOR LIST]
- Professional advisors (legal, accounting) under confidentiality, when needed.
- Authorities when legally required, or to protect rights, safety, or the integrity of the Service.
- A successor in a merger, acquisition, or sale of assets, subject to this policy.
International transfers
Data may be processed in [COUNTRY/REGION]. Where personal data moves across borders, we rely on an appropriate transfer mechanism (for example, Standard Contractual Clauses). [CONFIRM]
Retention
We keep account and billing data for as long as your account is active and as needed for legal, tax, and accounting purposes afterward. Customer Data is retained per your subscription; after termination we make it available for export for [NUMBER] days and then delete or anonymize it, subject to backups that age out on a rolling [NUMBER]-day cycle. Server logs are kept for [NUMBER] days.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. If your data was entered into the Service by a customer (your employer or a winery you work with), contact that customer first; we will assist them as their processor. Otherwise, contact us at [PRIVACY EMAIL]. You may also complain to your local data-protection authority.
Security
We use encryption in transit, access controls, least-privilege practices, and provider-managed backups. No system is perfectly secure; report concerns to [SECURITY EMAIL].
Children
The Service is for businesses and is not directed to children. We do not knowingly collect data from children.
Changes
We may update this policy. Material changes will be announced by email or in the Service before they take effect.
Contact
[LEGAL ENTITY NAME], [MAILING ADDRESS]. Privacy questions: [PRIVACY EMAIL]. [Name a Data Protection Officer / EU or UK representative if required.]