GrapeVineGrapeVine
PRIVACY POLICY

The GrapeVine Group LLC
Effective Date: April 26, 2026
Last Updated: April 26, 2026

This Privacy Policy describes how The GrapeVine Group LLC ("GrapeVine," "we," "us," or "our") collects, uses, shares, and protects information about you when you use our restaurant inventory management platform (the "Service") accessible at thegrapevine.shop and any related applications. By using the Service, you consent to the practices described in this Privacy Policy.

If you do not agree with this Privacy Policy, do not use the Service.

1. WHO WE ARE AND HOW TO REACH US

GrapeVine is a software platform that helps bars and restaurants track inventory, ingest invoices via OCR, sync POS sales data, and surface analytics. We are based in the United States.

For privacy questions, requests, or complaints, contact us at:

  Email: privacy@thegrapevine.shop
  Subject line: "Privacy Request"

We commit to acknowledging your request within seven (7) business days and resolving it within thirty (30) days, subject to applicable law.

2. INFORMATION WE COLLECT

We collect three categories of information:

2.1 Account Information You Provide
- Name, email address, phone number, and password (hashed)
- Organization name, business address, and timezone
- Payment method information (processed and stored by Stripe — we never see raw card numbers; see Section 5 on Subprocessors)
- Profile preferences and notification settings
- Team member invitations and role assignments

2.2 Business Data You Submit
- Inventory items, par levels, vendors, and recipes
- Invoices, line items, prices, and quantities (whether typed or extracted from images via OCR)
- Sales reports from your POS provider (Toast, Square, Clover, etc., when you enable that integration)
- Stock check counts, waste logs, and adjustment notes

2.3 Information Collected Automatically
- IP address, browser type, device identifiers, and operating system
- Pages visited, features used, and timestamps of activity
- Crash logs and error stack traces (used to fix bugs; we strip request bodies and authentication tokens before storage)
- Cookies and similar storage technologies (see Section 7)

We do not sell or rent your information. We do not collect biometric data, precise geolocation, racial or ethnic origin, religious beliefs, sexual orientation, or any other sensitive category as defined by GDPR Article 9 or California's CPRA.

3. HOW WE USE YOUR INFORMATION

We use your information to:

(a) provide, operate, and maintain the Service, including running OCR on invoices, syncing POS data, and computing analytics;
(b) authenticate you, secure your account, and prevent fraud;
(c) process payments and manage your subscription;
(d) send transactional emails (account verification, password resets, billing notices, trial expiry reminders);
(e) deliver in-app notifications and, if you opt in, push notifications to your device;
(f) respond to support requests and diagnose product issues;
(g) improve the Service through aggregated, de-identified analytics;
(h) comply with legal obligations, including tax-record retention requirements; and
(i) enforce our Terms and Conditions and protect our rights.

We do NOT use your business data to train artificial intelligence models on a cross-customer basis. AI features operate only on your own organization's data; see Section 4.

4. AI PROCESSING DISCLOSURE

GrapeVine uses third-party AI providers — currently Anthropic (Claude) and OpenAI — to power three features:

4.1 Invoice OCR
When you upload an invoice PDF or image, the rasterized pages are transmitted to Anthropic's Claude API for line-item extraction. Anthropic retains the request only for the time required to compute and return the response and does not use it to train its models on a per-customer basis (per Anthropic's data processing terms in effect as of the date of this policy). The extracted JSON is stored in your GrapeVine account; the original image is also stored.

4.2 Menu OCR
Same flow as invoice OCR. Menu images you submit are sent to Anthropic for cocktail-recipe and item extraction.

4.3 AI Analytics
When you ask a question in the AI Insights panel, your question and a snapshot of your organization's relevant data (inventory, recent invoices, sales, recipes, waste logs, daily snapshots) are sent to Anthropic's Claude API to generate the response. Other organizations' data is never included in any prompt. Cached responses are stored for thirty (30) minutes per organization to reduce duplicate API costs and are then deleted.

We log token usage per organization for billing and quota enforcement. We do not log the literal prompt or response contents in our analytics tables; the question text and response are stored only in the per-organization activity log and ai_response_cache, both of which are subject to your deletion rights (see Section 9).

You can disable AI features for your organization at any time by contacting us at privacy@thegrapevine.shop.

5. WHO WE SHARE YOUR INFORMATION WITH (SUBPROCESSORS)

We engage a small set of vendors to operate the Service. Each is contractually bound to handle your information consistent with this Privacy Policy.

Current subprocessors:

  Vendor          Purpose                                  Data categories
  ─────────────   ──────────────────────────────────────   ──────────────────────────
  Supabase        Database, authentication, storage,       All categories (US region)
                  serverless functions
  Vercel          Application hosting + edge network       All categories (transit)
  Stripe          Payment processing + subscription mgmt   Payment + account info
  Anthropic       Claude AI API (OCR + analytics)          Invoice images, AI prompts
  OpenAI          Image generation (admin pipeline only,   Catalog product names
                  no end-user data)
  SendGrid        Transactional email delivery             Email + notification body
  Cloudflare      Bot detection (Turnstile CAPTCHA)        IP + browser fingerprint
                  on signup
  Apple/Google    Push notification delivery               Anonymous push endpoints

We will publish updates to this list at thegrapevine.shop/privacy whenever we add or remove a subprocessor. Material changes (a new vendor handling a new category of data) will additionally be emailed to active customers at least thirty (30) days before the change takes effect.

We do NOT share information with advertisers, data brokers, or marketing networks.

6. HOW LONG WE KEEP YOUR INFORMATION (RETENTION)

Different categories of data are retained for different periods:

  Category                                  Retention period
  ───────────────────────────────────────   ──────────────────────────────────────
  Account profile + organization records    Active subscription + 30 days
  Inventory + recipes + vendors             Active subscription + 30 days
  Invoices + line items                     Seven (7) years (US tax-record
                                            retention requirement; you may
                                            request earlier deletion subject
                                            to applicable law — see Section 9)
  POS sales reports                         Active subscription + 30 days
  Stock adjustments + waste logs            Active subscription + 30 days
  Activity log (audit trail)                Two (2) years
  Token usage records                       Thirteen (13) months
  AI response cache                         Thirty (30) minutes (auto-deleted)
  Crash logs                                Ninety (90) days
  Push subscriptions                        Until you disable push or sign out
  Cookie consent record                     365 days from last dismissal

After the retention period elapses, data is permanently deleted from our active systems. Backup snapshots may retain residual copies for up to thirty (30) additional days before they are overwritten on rotation.

If you cancel your subscription, your data is preserved for thirty (30) days in a "grace period" so you can resubscribe without loss, then permanently deleted (subject to the seven-year invoice retention noted above for tax-record purposes).

7. COOKIES AND SIMILAR TECHNOLOGIES

We use first-party cookies and browser localStorage for:

(a) Authentication — keeping you signed in across pages
(b) Preferences — remembering things like which timezone you've configured
(c) Cookie consent record itself
(d) Subscription cache — to avoid a paywall flash on page load
(e) Offline mutation queue — so stock-check counts taken on dodgy wifi survive a tab close

We do not use third-party advertising or analytics cookies. The cookie banner ("Necessary only" vs "Accept all") is presently identical in effect because we have no non-necessary cookies; we provide the choice for legal clarity and so that future analytics, if any, are gated behind explicit consent.

You can clear all GrapeVine cookies and localStorage from your browser settings at any time. Doing so will sign you out and reset preferences but does not affect data stored in your GrapeVine account on our servers.

8. CHILDREN

GrapeVine is intended for use by businesses and their adult employees. We do not knowingly collect personal information from anyone under sixteen (16) years of age. If we learn that we have collected personal information from a minor, we will delete it.

9. YOUR PRIVACY RIGHTS

Depending on your jurisdiction, you may have the following rights:

9.1 Access — You can request a copy of the personal information we hold about you.
9.2 Correction — You can correct inaccurate personal information from within the Service or by emailing us.
9.3 Deletion — You can request deletion of your personal information, subject to legal retention requirements (notably the seven-year invoice retention noted in Section 6).
9.4 Portability — You can export your business data (inventory, invoices, recipes, sales) at any time via Settings → Export Data, in CSV/JSON format.
9.5 Restriction / Objection — You can ask us to restrict or stop certain processing of your information.
9.6 Withdraw Consent — Where processing relies on consent (e.g., AI features), you can withdraw at any time.
9.7 Lodge a Complaint — EU/EEA residents may complain to their local Data Protection Authority. California residents have rights under the CCPA/CPRA, including the right to know, delete, and opt out of "sales" (we do not sell personal information).

To exercise any right, email privacy@thegrapevine.shop. We may need to verify your identity before fulfilling the request. We will not discriminate against you for exercising your rights.

10. SECURITY

We protect your information with:

- Transport encryption (HTTPS/TLS 1.2+) on every page and API request
- Encryption at rest in our database (AES-256 via Supabase)
- Row-level security (RLS) policies on every database table to enforce per-organization isolation
- Server-side enforcement of admin and organization access (no trust placed on client-supplied IDs)
- Time-bounded JWT tokens for authentication
- Hashed pilot keys, hashed passwords (bcrypt), encrypted POS OAuth tokens
- Server-side rate limiting and login lockout to defeat brute force
- Audit logs of administrative trial / billing / data-export actions
- Daily database snapshots with 30-day retention

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and, where required, the relevant authorities, in accordance with Section 11.

11. BREACH NOTIFICATION

In the event of a confirmed personal data breach affecting you, we will:

(a) Investigate the scope and impact within seventy-two (72) hours of confirmation;
(b) Notify the relevant supervisory authorities within seventy-two (72) hours where required (GDPR Art. 33, applicable US state laws);
(c) Notify you by email at the address on file within seventy-two (72) hours of confirming the breach materially affects your information, including:
    - The nature of the breach
    - The categories and approximate volume of records affected
    - The likely consequences
    - The measures we have taken or propose to take
    - Contact information for further questions
(d) Publish a summary at thegrapevine.shop/security-bulletin if the breach affects more than 500 customers in aggregate;
(e) Cooperate with law enforcement and regulators as appropriate.

We maintain a documented incident-response runbook and conduct tabletop exercises annually.

12. INTERNATIONAL TRANSFERS

GrapeVine and its primary subprocessors operate in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection laws than your country of residence. Where required by law, we rely on appropriate transfer mechanisms (Standard Contractual Clauses, adequacy decisions, or your explicit consent).

13. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. Material changes will be:

- Reflected in the "Last Updated" date at the top
- Versioned in our codebase
- Communicated to active customers by email at least thirty (30) days before they take effect, where the changes meaningfully affect your rights or our use of your information

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes acceptance of the changes.

14. JURISDICTION

This Privacy Policy is governed by the laws of the State of Delaware, without regard to conflict-of-law principles. The exclusive forum for any dispute arising from this Privacy Policy is the state and federal courts located in Delaware, except where applicable law requires otherwise.

15. CONTACT

Privacy questions or requests:
  privacy@thegrapevine.shop

General support:
  support@thegrapevine.shop

Mailing address:
  The GrapeVine Group LLC
  [Mailing address — pending]

──────────────────────────────────────────────────────────────────

This Privacy Policy is provided in good faith and reflects our practices as of the Last Updated date. It is not a substitute for legal advice. If you have a specific concern about your data, please contact us before relying on this document for legal purposes.