Legal
Privacy Policy
VaultSomm is built for privacy-conscious collectors. We do not sell your data, share it with advertisers, or use it to train AI models. Your cellar is yours.
1. Who We Are
VaultSomm ("VaultSomm," "we," "us," or "our") operates the VaultSomm platform at vaultsomm.com and app.vaultsomm.com. We provide wine portfolio tracking, market intelligence, and tax reporting tools for serious wine collectors.
For privacy-related questions, requests, or concerns, contact [email protected]. For general inquiries, contact [email protected].
2. Information We Collect
We collect information you provide directly and information generated through your use of the platform.
- Account information: Email address and password (stored securely via Supabase Auth).
- Profile information: Name, subscription tier, and preferences you set in your profile.
- Cellar data: Wine bottle records you add — including producer, vintage, region, purchase price, current value, storage location, and notes.
- Usage data: Pages visited, features used, and actions taken within the app (e.g., reports generated, searches made).
- Device data: Browser type, operating system, IP address, and approximate location (country/region level only).
- Communications: Any messages you send to our support team.
2.1 Notice at Collection (California residents)
The table below discloses the categories of personal information we have collected in the preceding 12 months, the sources, the purposes, the categories with whom we disclose that information for a business purpose, and how long we retain each category. We do not sell or share any category of personal information as those terms are defined by the CCPA/CPRA.
| Category (CCPA §1798.140) | Sources | Business purpose | Disclosed to | Retention |
|---|---|---|---|---|
| Identifiers (name, email, IP, account ID) | Directly from you; automatically from your device | Account creation, authentication, service delivery, security | Supabase, Cloudflare, Zoho | Account life + 30 days |
| Customer records (billing name, billing address) | Directly from you; from Stripe at checkout | Payment processing, tax records | Stripe | 7 years (tax obligation) |
| Commercial information (subscription tier, purchase history) | Directly from you; from Stripe | Service delivery, invoicing | Stripe, Supabase | 7 years (tax obligation) |
| Internet/network activity (pages visited, feature usage, device data) | Automatically from your device | Service functionality, security, improvement | Cloudflare, Supabase | 90 days |
| Geolocation (approximate — country/region level) | Automatically from IP address | Security, fraud prevention, regional pricing | Cloudflare | 90 days |
| Inference data (aggregate cellar patterns — never linked to identity) | Derived internally from usage | Product improvement | None (internal only) | Aggregate, indefinite |
| Sensitive Personal Information — see §2.2 below | Directly from you; from Stripe | Authentication and payment processing only | Stripe, Supabase | See §2.2 |
2.2 Sensitive Personal Information (CPRA)
Under the California Privacy Rights Act, some information we collect qualifies as "Sensitive Personal Information" (SPI):
- Account credentials: Email address in combination with your password (hashed).
- Payment information: Payment card details entered at checkout. VaultSomm never receives or stores card numbers — they are collected and stored by Stripe. VaultSomm receives only a Stripe customer ID and last-four digits for display.
We use SPI only for the narrow purposes permitted under CPRA §7027(m) — to provide the service you request, verify your identity, prevent fraud, and comply with law. We do not use SPI to infer characteristics about you, and we do not disclose SPI beyond the processors named above.
Right to Limit Use of Sensitive Personal Information. Because we already use SPI only for the permitted purposes above, there is no additional use to limit. If our practices change, we will provide a "Limit the Use of My Sensitive Personal Information" link and honor your choice.
3. How We Use Your Information
We use your information only to provide and improve the VaultSomm service:
- Authenticate your account and secure your data.
- Display your cellar, portfolio, and valuation data.
- Generate PDF reports (Insurance Valuation, Schedule D, Estate Inventory, Form 709).
- Power the AI Sommelier feature — your queries are sent to Perplexity AI's API but are not stored by VaultSomm beyond your session.
- Send transactional emails (account confirmation, password reset). We do not send marketing emails without your explicit consent.
- Analyze aggregate usage patterns to improve features (never linked to individual identities).
- Comply with applicable law.
3.1 Legal Bases for Processing (GDPR Article 6)
If you are in the EEA, United Kingdom, or Switzerland, we rely on the following legal bases for processing your personal data:
| Processing activity | Legal basis (Article 6) |
|---|---|
| Providing the VaultSomm service, hosting your cellar, generating reports | Contract — Art. 6(1)(b) |
| Processing payment and maintaining billing records | Contract — Art. 6(1)(b); Legal obligation — Art. 6(1)(c) |
| Transactional emails (signup, password reset, receipt) | Contract — Art. 6(1)(b) |
| Marketing emails (only if you opt in) | Consent — Art. 6(1)(a) |
| Security, fraud prevention, service integrity | Legitimate interest — Art. 6(1)(f) |
| Aggregate product analytics (non-identifying) | Legitimate interest — Art. 6(1)(f) |
| Responding to legal process, tax records | Legal obligation — Art. 6(1)(c) |
3.2 Automated Decision-Making (GDPR Article 22)
VaultSomm does not engage in automated decision-making that produces legal or similarly significant effects concerning you. Valuation figures, tax report calculations, and market indices are computed algorithmically for informational purposes only and are not used to make automated decisions about you.
4. Data Storage & Security
Your data is stored in a Supabase-managed PostgreSQL database hosted in the United States. We implement the following safeguards:
- All data in transit is encrypted via TLS 1.2+.
- All data at rest is encrypted using AES-256.
- Authentication uses industry-standard JWT tokens with short expiry windows.
- Row-level security policies ensure users can only access their own data.
- We do not store payment card information — billing is handled by a third-party payment processor.
No security system is impenetrable. In the event of a breach that may affect your data, we will notify you within 72 hours of becoming aware of it, consistent with GDPR Article 33 and applicable US state breach-notification laws.
5. Data Sharing & Third-Party Processors
We do not sell, rent, or share your personal data with third parties for their own marketing or advertising purposes. We share data only with the following service providers (categorized per GDPR Article 13), solely to operate the platform:
Category A — Sub-processors (act on our documented instructions)
- Stripe, Inc. (Payment processing) — Processes subscription payments. Stripe handles all card data; VaultSomm never stores payment card numbers. Stripe Privacy Policy
- Supabase, Inc. (Database & authentication) — Stores your account data, cellar records, and portfolio data in encrypted databases hosted in the United States. Supabase Privacy Policy
- Cloudflare, Inc. (Hosting & CDN) — Serves the VaultSomm website and application. Cloudflare may process request logs including IP addresses. Cloudflare Privacy Policy
- Zoho Corporation (Transactional email) — Sends account-related emails (signup confirmations, password resets). Zoho Privacy Policy
Category B — Third-party processors (independent controllers for portions of processing)
- Perplexity AI, Inc. (AI Sommelier) — When you use the AI Sommelier or Wine Search features, your text prompts (including wine names and questions) are transmitted to Perplexity's API servers in the United States for real-time processing. These queries are not stored by VaultSomm beyond your active session. Perplexity may retain query data per their own policy. We do not transmit your name, email, payment details, or full cellar inventory to Perplexity. Perplexity Privacy Policy
- Mapbox, Inc. (Map tiles) — Provides wine region map tiles on the Market Intelligence page. No personally identifiable user data is transmitted to Mapbox. Mapbox Privacy Policy
Category C — Other disclosures
- Legal requirements: If required by law, court order, or governmental authority.
- Business transfers: In connection with a merger, acquisition, or sale of assets — you will be notified before your data is transferred to a new entity.
International Data Transfers
VaultSomm is based in the United States. If you access the Service from outside the United States, your personal data will be transferred to and processed in the United States, where data protection laws may differ from those in your country. All of our processors (Supabase, Stripe, Cloudflare, Perplexity AI, Zoho) operate primarily in the United States.
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, such transfers are conducted under Standard Contractual Clauses (SCCs) or equivalent safeguards maintained by our processors. To inquire about our transfer mechanisms, email [email protected].
EU Representative
VaultSomm does not currently target or actively offer its services to residents of the European Economic Area, and therefore has not appointed an Article 27 representative. If we begin offering the service to EEA residents in the future, we will appoint a representative and update this policy accordingly.
6. Cookies & Tracking
VaultSomm uses minimal, essential cookies only. We do not use advertising cookies, cross-site tracking pixels, or third-party analytics that identify individuals. We do not use Google Analytics.
| Cookie | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
| sb-access-token | Strictly necessary | Supabase authentication — keeps you logged in | 1 hour (rotating) | Supabase |
| sb-refresh-token | Strictly necessary | Supabase session refresh — extends your logged-in session | 30 days | Supabase |
| vs_theme | Preferences (localStorage, not a cookie) | Remembers your dark/light theme choice | Until cleared | VaultSomm (first-party) |
| __cf_bm | Strictly necessary | Cloudflare bot management — protects the site from automated abuse | 30 minutes | Cloudflare |
| cf_clearance | Strictly necessary | Cloudflare security challenge validation | 30 minutes to 1 year (configurable) | Cloudflare |
All cookies above are classified as strictly necessary under ePrivacy Directive Article 5(3), meaning no consent banner is required. If we ever add non-essential cookies (analytics or advertising), we will implement a consent banner before deploying them.
7. Your Rights
Depending on your location, you may have the following rights under applicable privacy law. To exercise any right, email [email protected].
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct inaccurate data.
- Deletion: Request that we delete your account and all associated data. You can also delete your account directly from the app settings.
- Portability: Request your cellar data in a machine-readable format (CSV export is available in-app).
- Restriction: Request that we limit how we process your data.
- Objection: Object to processing based on legitimate interests.
- Opt-out of targeted advertising, sale, and profiling: We do not engage in these activities, but you have the right to submit an opt-out request at any time.
- Appeal: If we deny a request, you may appeal our decision (see §7.4).
- Non-discrimination: We will not discriminate against you for exercising your privacy rights, and we do not offer financial incentives in exchange for personal information (see §7.5).
7.1 Response Timelines
| Regulation | Acknowledgment | Substantive response | Extension available |
|---|---|---|---|
| GDPR / UK GDPR | Without undue delay | One calendar month (Art. 12(3)) | +2 months for complex or numerous requests |
| CCPA / CPRA (California) | 10 business days | 45 calendar days | +45 days with notice |
| Right to Limit Use of SPI (California) | Immediate acknowledgment | 15 business days | None |
| VCDPA / CPA / CTDPA / UCPA / TDPSA / other state laws | Without undue delay | 45 calendar days | +45 days with notice |
7.2 Global Privacy Control (GPC)
VaultSomm honors the Global Privacy Control browser signal. When we detect a GPC signal from your browser, we treat it as a valid opt-out of sale, sharing, and targeted advertising for that browser session under the CCPA/CPRA and equivalent US state laws. Because VaultSomm does not sell or share personal information or engage in targeted advertising, the GPC signal does not change what data we collect — but we record its receipt as your opt-out preference.
7.3 Authorized Agents (California and other US states)
You may designate an authorized agent to submit a privacy request on your behalf. To act as an authorized agent, the agent must:
- Provide written permission signed by you (a Power of Attorney under Cal. Probate Code §§4000–4465 is also acceptable), and
- Verify their own identity with us.
We may also require you to verify your own identity directly with us and confirm that you have authorized the agent, unless the agent presents a valid Power of Attorney. Send authorized-agent requests to [email protected].
7.4 Right to Appeal
If we deny your privacy request in whole or in part, you may appeal that decision by replying to our response email with the subject line "Privacy Request Appeal" within 60 days. We will respond to your appeal within:
- Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and similar state laws: 60 calendar days of receipt.
- Other jurisdictions: Without undue delay, and in any event within 60 calendar days.
If your appeal is denied, you may contact the Attorney General of your state (see §7.6) or your data protection supervisory authority (see §7.7).
7.5 Financial Incentives
VaultSomm offers annual pricing at a discount to monthly pricing (Collector: $199/year vs. $228/year monthly; Connoisseur: $799/year vs. $948/year monthly). Under CPRA §1798.125(b), this may be characterized as a "financial incentive." The discount is not conditional on providing additional personal information beyond what is required to operate the account, and you may cancel or switch cadences at any time from within the app. The reasonable and good-faith value of the personal information to VaultSomm is $0 above the subscription price itself; the discount reflects reduced billing and churn costs, not the value of data.
7.6 California "Shine the Light" (§1798.83)
California residents may request a list of the personal information categories we have disclosed to third parties for their direct marketing purposes in the preceding calendar year. VaultSomm has not disclosed any personal information to any third party for third-party direct marketing purposes. If our practices change, we will update this section and honor Shine the Light requests within 30 days of receipt. Send requests to [email protected] with the subject line "Shine the Light Request".
7.7 Do Not Sell or Share My Personal Information (CCPA/CPRA)
VaultSomm does not sell, share, or disclose your personal information to third parties for cross-context behavioral advertising or any commercial purpose beyond operating the platform. Because we do not sell or share your data in the CCPA/CPRA sense, there is nothing to opt out of — but you have the right to confirm this and to request deletion of your data at any time.
California residents may submit a request by emailing [email protected] with the subject line "CCPA Request".
7.8 Right to Lodge a Complaint (GDPR / UK GDPR)
If you are in the EEA or UK and believe we have not handled your data lawfully, you may lodge a complaint with your local supervisory authority. Find your EU authority at edpb.europa.eu. UK residents may contact the Information Commissioner's Office (ICO). We encourage you to contact us first so we can resolve your concern directly.
8. Additional US State Privacy Rights
In addition to the CCPA/CPRA rights described in §7, residents of the following US states have substantially similar rights under their state privacy laws — including the rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising, opt out of the sale of personal data, opt out of profiling that produces legal or similarly significant effects, and appeal a denial. VaultSomm honors these rights for all users regardless of state, and complies with each of the following:
- Virginia — Virginia Consumer Data Protection Act (VCDPA), effective Jan 1, 2023
- Colorado — Colorado Privacy Act (CPA), effective July 1, 2023
- Connecticut — Connecticut Data Privacy Act (CTDPA), effective July 1, 2023
- Utah — Utah Consumer Privacy Act (UCPA), effective Dec 31, 2023
- Texas — Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024
- Oregon — Oregon Consumer Privacy Act (OCPA), effective July 1, 2024
- Montana — Montana Consumer Data Privacy Act, effective Oct 1, 2024
- Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee — state privacy laws effective throughout 2025
- Minnesota, Maryland, Rhode Island, Kentucky, Indiana — state privacy laws effective 2025–2026
Substantive rights vary slightly by state (for example, only some laws include a right to correct or a universal opt-out mechanism obligation). Where a state law grants a right that this policy does not otherwise describe, that state right still applies. To exercise state-specific rights, email [email protected] and include your state of residence in the subject line.
9. Data Retention
We retain different categories of data for different periods based on the purpose of collection:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account & profile data | Duration of account + 30 days after deletion | Contract performance — Art. 6(1)(b) |
| Cellar & bottle records | Duration of account + 30 days after deletion | Contract performance — Art. 6(1)(b) |
| Payment & billing records | 7 years from transaction date | Legal obligation (tax / financial records) — Art. 6(1)(c) |
| AI Sommelier queries | 90 days (conversation history visible in-app) | Service functionality — Art. 6(1)(b) |
| Usage & server logs | 90 days | Security & service improvement — Art. 6(1)(f) |
| Support communications | 3 years | Legitimate interest (dispute resolution) — Art. 6(1)(f) |
Upon account deletion, all personal data not subject to a legal retention obligation will be permanently deleted within 30 days.
10. Children's Privacy (COPPA)
VaultSomm is not directed to individuals under the age of 18, and is intended solely for adults who collect and invest in fine wine. We do not knowingly collect personal data from children under the age of 13 in compliance with the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has created an account, please contact us at [email protected] and we will delete the account and all associated data promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, notify you via email or an in-app banner at least 14 days before the change takes effect.
Version History
July 9, 2026 — Compliance expansion. Added California Notice at Collection table, Sensitive Personal Information (SPI) disclosure and Right to Limit, Global Privacy Control (GPC) statement, Authorized Agent process, Right to Appeal, Shine the Light §1798.83 notice, GDPR Article 6 legal-bases table, GDPR Article 22 automated decision-making statement, EU representative statement, additional US state privacy laws (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, Montana, and 2025–2026 laws), itemized cookie table, and corrected response-timeline table (GDPR "one calendar month"; CCPA 10 business days + 45 calendar days). Restructured processor list into GDPR Article 13 categories. Financial-incentives disclosure added for annual pricing.
April 17, 2026 — Initial publication.
12. Contact Us
For privacy-related questions, requests, or concerns:
- Privacy contact: [email protected]
- General inquiries: [email protected]
- Website: vaultsomm.com