1. Overview
This Privacy Policy describes how SanaView, LLC (“Vinni,” “we,” “us”) collects, uses, and shares information in connection with the Vinni winery management service (the “Service”). By using the Service you agree to the practices described here and in our Terms of Service.
Vinni is designed for use by licensed commercial wineries. We do not knowingly provide the Service to consumers for personal use and do not direct the Service to children.
2. Information we collect
2.1 Information you provide.
- Account information — your name, email address, winery name, role (admin, winemaker, cellar assistant, viewer), and hashed password. Passwords are never stored in plaintext.
- Billing information — billing contact details collected when you start a subscription. A payment method is required to begin a free trial, so this is collected during sign-up. Payment card details are entered directly into our payment processor (Stripe) and are not stored on our servers; we retain a tokenized customer reference and the card brand, last four digits, and expiration date for display.
- Winery operational data — the batches, vessels, events, inventory items, work orders, production materials, packaging supplies, sanitation logs, batch costs, files, and TTB report drafts you create in the Service.
- Feedback and support messages — any feedback, bug reports, or support requests you submit through the Service.
- Integration credentials — encrypted tokens and configuration for optional third-party integrations you connect (for example Square or Vinoshipper).
- AI chat content — the messages you send to the AI assistant and any context the Service attaches to help the assistant respond.
2.2 Information collected automatically.
- Usage and diagnostic data — server logs, error messages, request IDs, route paths, timestamps, response statuses, and AI token counts. These are used for operations, security, and billing.
- Sign-in records — the date and time of each successful sign-in, and counts of failed sign-in attempts. We use these to secure accounts, to identify accounts that have been invited but never activated, and to understand whether a winery is actively using the Service.
- Product usage analytics — which screens in the application you open, how many times, and roughly how long each screen is open while your browser tab is in the foreground. We use this to decide which parts of the Service to improve.
Screen addresses are reduced to a generic pattern before they are stored — a visit to a specific batch is recorded as/batch/[id], never as the address containing that batch’s identifier. Anything after a?in an address, which can contain search terms and filter values, is discarded before storage. We do not record page content, keystrokes, mouse movement, or screen recordings. - Operational counters — a daily count of how many records your winery creates or changes. This enforces the fair-use limits described in our Terms and alerts us to unusual activity. It is a count only, and does not describe what the records contain.
- Device and connection data — IP address, user agent, referring page, and similar technical metadata collected by our hosting and edge providers.
- Cookies and local storage — used for authentication, session management, and user preferences. See Section 10.
2.3 Information from third parties.
If you enable an integration (such as Square or Vinoshipper), we receive order, inventory, and webhook data from that provider in accordance with the permissions you grant. If you pay via Stripe, we receive billing status and invoice data from Stripe.
2.4 Information we do not collect.
We do not collect special categories of personal data (such as health or biometric data), and we do not use third-party advertising trackers on the Service. We do not record your screen, keystrokes, or mouse movement, and we do not use session-replay tooling.
3. How we use information
We use the information above to:
- Provide, secure, and maintain the Service.
- Authenticate users, prevent abuse, and enforce our Terms.
- Process payments and administer subscriptions, including metered AI overage when you opt in.
- Send transactional email (email verification, password reset, work-order review notifications, billing receipts) via our email provider.
- Generate AI-assisted content, insights, and draft reports when you use our AI features.
- Diagnose and fix bugs, monitor performance, and improve the Service.
- Understand which features are used, how often, and by how many wineries, so we can prioritise improvements and retire parts of the Service that are not useful. This analysis uses the aggregated usage data described in Section 2.2, not the contents of your winery records.
- Respond to your feedback, support requests, and inquiries.
- Comply with legal obligations and respond to lawful requests from authorities.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
4. How we process information in AI features
When you use an AI feature, we send the relevant input — your message, selected winery context, and system instructions — to our AI provider (Anthropic) so it can generate a response. AI inputs and outputs are handled as follows:
- Processing.Anthropic processes the content to generate a response. Under our agreement with Anthropic, your AI inputs and outputs are not used to train Anthropic's foundation models.
- Storage. We store AI chat history on your account so you can reference prior conversations. We also record per-request token counts for billing and abuse prevention.
- Content you should not submit. Do not send any information to the AI features that you would not be comfortable sharing with our AI provider. Avoid submitting sensitive personal information about customers or employees that is not relevant to winery operations.
- Accuracy. AI outputs may be inaccurate. See our Terms of Service for the full advisory disclaimer.
6. Sub-processors
We use the following third-party services to operate Vinni. We have contracts with each of them that obligate them to protect information consistent with applicable law.
- Vercel, Inc. — application hosting, edge network, and blob file storage.
- Neon, Inc. (or equivalent Postgres provider) — managed PostgreSQL database hosting.
- Anthropic, PBC — large language model processing for AI features.
- Stripe, Inc. — payment processing, subscription management, and invoicing.
- Resend, Inc. — transactional email delivery.
- Functional Software, Inc. (Sentry)— application error monitoring and performance tracing. When an error occurs, we send Sentry the technical details of that error along with the signed-in user’s account ID and email address and the winery ID and role, so we can identify who was affected and reproduce the problem. Error reports can incidentally include values involved in the failure. We do not enable Sentry session recording.
- Cloudflare, Inc. — bot and abuse protection on our public sign-up and sign-in forms, where enabled. Cloudflare receives your IP address and browser characteristics in order to distinguish human visitors from automated ones.
- Square, Inc. — optional POS integration if you connect your Square account.
- Vinoshipper, Inc. — optional direct-to-consumer shipping integration if you connect your Vinoshipper account.
We may update this list from time to time. Material changes will be reflected in the “Last updated” date above. Contact us at hello@itsvinni.ai for the current list at any time.
7. Data retention
We retain account and winery operational data for as long as your subscription is active, and for a commercially reasonable period afterward to accommodate reactivation, backups, dispute resolution, and legal-hold obligations. Typical retention windows:
- Account data: for the life of the account plus up to 90 days after cancellation.
- Backups: rotated on a schedule of up to 30 days.
- Billing records and tax documentation: retained for the period required by applicable tax and accounting law (typically seven years).
- Server and audit logs: typically 30–90 days, or longer if needed for security investigation.
- AI chat history: retained until you delete it or your account is terminated.
- Product usage analytics: up to 12 months, then deleted automatically. A year lets us compare one vintage cycle against the next; nothing we do with this data needs longer.
- Operational counters: 90 days, then deleted automatically.
- Error reports held by Sentry: retained according to Sentry’s retention period for our plan, typically 90 days.
You can request export or deletion of your data at any time (see Section 8). Some records we are legally required to retain (for example, billing and tax records) may survive a deletion request to the extent the law requires.
8. Your rights and choices
Depending on your location, you may have the right to access, correct, export, or delete personal information we hold about you; to object to or restrict certain processing; and to withdraw consent where we rely on it. To exercise these rights, contact us at hello@itsvinni.ai. We will verify your identity before responding.
You can also:
- Export your data from your account settings in common formats (for example, CSV for TTB reports and inventory).
- Delete your account from your account settings or by emailing us. Deletion removes Customer Data subject to the retention periods in Section 7.
- Manage billing-related communications through Stripe, who sends payment receipts on our behalf.
If you believe we have not addressed your concern, you may have the right to complain to a data-protection authority in your jurisdiction.
9. Security
We take industry-standard measures to protect information, including:
- HTTPS/TLS encryption in transit for all traffic to and from the Service.
- Bcrypt password hashing; plaintext passwords are never stored.
- Email-verification tokens and password-reset tokens stored as one-way hashes.
- Stripe webhook signature verification and Square/Vinoshipper signature verification on inbound webhooks.
- Multi-tenant isolation at the application and database layer; every mutation is scoped to the acting winery.
- Rate limiting and audit logging of sensitive events.
No system is perfectly secure. You are responsible for choosing a strong password, keeping your account credentials confidential, and notifying us promptly if you suspect an unauthorized access.
11. Children
The Service is not directed to, and is not intended for, children. You must be at least the legal drinking age in your jurisdiction (21 in the United States) to use the Service. If you believe a child has provided us with personal information, contact us and we will delete it.
12. International transfers
We and our sub-processors operate primarily in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries that may have different data protection laws than yours. Where required, we rely on transfer-safeguarding mechanisms such as the Standard Contractual Clauses (SCCs) published by the European Commission.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our sub-processors, or applicable law. If we make material changes, we will notify you by email or through the Service in advance. The “Last updated” date at the top of this page always reflects the current version.
14. Contact
For privacy questions, data-subject requests, or to report a concern, contact us at hello@itsvinni.ai.
This Privacy Policy is provided for reference and should be reviewed by qualified counsel before use in production.