KKxWF

PRIVACY POLICY

Effective Date: 22.08.2026
Last Updated: 22.08.2026
Website: https://kellerkollektiv.com/winefoo
Jurisdiction: Poland (GDPR & international compliance)


1. Introduction & Scope

This Privacy Policy describes how WineFoo ("we," "our," "us," "Company," or "Data Controller") collects, uses, processes, discloses, stores, and protects your personal information when you use our mobile application ("App") on iOS and Android platforms.

This Privacy Policy applies only to WineFoo. It does NOT apply to Google or Apple (who handle authentication), the App Store or Google Play Store (who process payments), or any third-party services or websites linked from the App. We are committed to protecting your privacy in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR), the Polish Act of 10 May 2018 on Personal Data Protection (Ustawa z dnia 10 maja 2018 r. o ochronie danych osobowych), and other international privacy standards.


1.1 Data Protection Officer

WineFoo is not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR, as we do not carry out large-scale systematic monitoring of individuals or large-scale processing of special categories of data. All privacy inquiries should be directed to our designated privacy contact:

Email: kellerkollektiv@gmail.com
Address: KELLER KOLLEKTIV, Teczowa 82d/1, 53-603 Wroclaw, Poland


1.2 Primary Supervisory Authority

As WineFoo is registered and operated in Poland, our primary data protection supervisory authority is:

Urząd Ochrony Danych Osobowych (UODO) — Polish Data Protection Authority
Website: https://uodo.gov.pl
Address: ul. Stawki 2, 00-193 Warsaw, Poland

You have the right to lodge a complaint with UODO at any time, without prejudice to any other legal remedy.


2. What Information We Collect

2.1 Authentication Information

When you sign in using Google or Apple:

- Email address associated with your Google or Apple account
- Display name from your account
- Profile picture URL from your account
- Unique user identifier assigned by Google or Apple
- Authentication method used (Google Sign-In or Apple Sign-In)

We DO NOT collect or store your password, payment information, or Google/Apple account security details.


2.2 Usage & Behavioural Data

We automatically collect information about how you interact with the App:

- Wine pairing selections you make (which food categories you select)
- Wine recommendations displayed to you
- Time and date of your app usage, session duration and frequency
- Number of daily pairing requests you make
- Features you access within the App
- Feedback and reviews you submit
- Your subscription status (free or premium)
- AI interaction count and usage within the current billing period
- Technical events and errors you encounter


2.3 AI Feature Data (Premium Users)

When you use AI-powered features, we process the following:

- AI-Powered Favourite Matchmaking: You capture a photo using your device camera and crop the relevant portion. Only the cropped portion is transmitted. The cropped image and any accompanying text description you provide are sent to OpenAI's API for processing. The cropped image is processed in real time to generate a recommendation and is NOT permanently stored by WineFoo or OpenAI after processing is complete. OpenAI processes data in accordance with their API data usage policy (https://openai.com/policies/api-data-usage-policies).

- OCR-Based Image Analysis: You capture and crop a photo of a restaurant menu or dish description. Only the cropped portion is transmitted to OpenAI's API for OCR text extraction, which is then mapped to our wine recommendation matrix. The cropped image is NOT permanently stored by WineFoo or OpenAI after processing is complete.

Camera access is required for these features and is requested only at the time of use. You may decline camera access without affecting access to core App features.


2.4 Push Notification Data

If you grant explicit permission for push notifications, we collect:

- Your device push notification token
- Notification delivery and engagement data (sent, received, opened)

You can withdraw notification permissions at any time through your device settings. Withdrawal of permission does not affect the lawfulness of notifications sent prior to withdrawal.


2.5 Email Subscription Data

If you choose to subscribe to our email communications, we collect:

- Your email address
- Subscription date and confirmation status (double opt-in)
- Email engagement data (opens, clicks) where technically available

Email subscription is entirely optional and requires your active, confirmed consent via double opt-in. You may unsubscribe at any time. Withdrawal of email consent does not affect the lawfulness of communications sent prior to withdrawal.


2.6 Subscription & Account Status

- Whether you are a free or premium user
- Your subscription start date and renewal dates
- Your subscription status (active, cancelled, expired, pending)
- AI interaction counter balance within the current billing period
- Device identifiers associated with your subscription

We DO NOT collect or store your credit card number, payment method details, billing address, or full payment history.


2.7 Technical & Device Information

- Device type and manufacturer
- Operating system and version
- App version and build number
- Device advertising ID (IDFA for iOS, Google Advertising ID for Android) — note: this is a pseudonymous identifier, not a directly identifying one
- General geographic location based on IP address (country/region only — NOT precise GPS location)
- IP address
- Crash reports and error logs
- App performance metrics and diagnostics

We DO NOT collect: precise GPS location data; your contact list or call history; photos or media files stored on your device (camera images are captured in-app and processed immediately — they are not saved to your device gallery or stored by WineFoo); microphone access; health data or biometric information.


2.8 Google Analytics & Firebase Analytics

Through Google Analytics (via Firebase), we collect user engagement metrics, feature usage statistics, user flow and navigation patterns, device and OS information, custom events, crash reports, performance data, and user acquisition source. This data is pseudonymised before analysis — individual user identities are not visible in analytics reports. Note: Firebase Analytics uses device advertising IDs, which makes this data pseudonymised (not fully anonymised) under GDPR. You can opt out through your device privacy settings.


3. How We Use Your Information

3.1 Core Service Delivery

- Provide wine pairing recommendations based on your selections
- Process AI-powered matching and OCR image analysis via OpenAI's API (Premium)
- Manage your subscription status and AI interaction counter
- Enforce the 24-hour free user limit
- Send push notifications (with your explicit permission)
- Send email communications (only after confirmed double opt-in)
- Display partner and promotional banner content
- Authenticate you securely


3.2 Service Improvement & Optimisation

- Analyse pseudonymised usage patterns to improve recommendation accuracy
- Identify and fix bugs and technical issues
- Optimise app performance
- Understand which features users find most valuable
- Train and improve our recommendation algorithms using pseudonymised, aggregated data only — we do not use your identifiable personal images to train AI models


3.3 We DO NOT Use Your Data For:

- Marketing emails or promotional communications without your active confirmed consent
- Selling or sharing with third parties for their marketing
- Behavioural advertising based on your wine selections
- Profiling or predictive modelling about your personal preferences
- Training AI models on your identifiable personal images


4. Legal Basis for Processing (GDPR)

For European Union and United Kingdom residents, our legal basis for processing your data is as follows. Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) confirming that our interests are not overridden by your rights and freedoms. You may request details of any LIA by contacting us at kellerkollektiv@gmail.com.

- Authentication data → Article 6(1)(b) Contract: Necessary to provide app access and manage your account
- Usage & behavioural data → Article 6(1)(f) Legitimate Interest: Improve app performance and user experience (LIA conducted)
- AI/OCR image processing → Article 6(1)(b) Contract + Article 6(1)(a) Consent: Deliver Premium AI features you explicitly activate; images processed under your direct instruction
- Push notification data → Article 6(1)(a) Consent: Notifications sent only with your explicit device-level permission
- Email subscription data → Article 6(1)(a) Consent: Communications sent only after confirmed double opt-in
- Subscription & billing data → Article 6(1)(b) Contract: Manage your subscription and enforce service tier limits
- Analytics data (Firebase) → Article 6(1)(f) Legitimate Interest: Improve recommendations and app optimisation; data is pseudonymised (LIA conducted)
- Technical & device data → Article 6(1)(f) Legitimate Interest: Security, fraud prevention, system maintenance (LIA conducted)
- Partner/banner content delivery → Article 6(1)(f) Legitimate Interest: Support app operations and partner relationships using aggregated non-identifiable data only (LIA conducted)
- Legal compliance → Article 6(1)(c) Legal Obligation: Comply with applicable laws and regulations

Right to object: Where we rely on legitimate interests (Article 6(1)(f)), you have the right to object to that processing at any time. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.


5. Data Storage & Security

5.1 Where Your Data Is Stored

Your data is stored using Google Cloud Platform (Firebase Firestore) in the us-central region (nam5 — United States). Backup systems are managed by Google Cloud's redundancy and disaster recovery systems. By using the App, you consent to this international data transfer as described in Section 11.


5.2 Security Measures

We implement: encryption in transit (HTTPS/TLS); encryption at rest (Google-managed encryption keys); role-based access controls with audit logs; Google Cloud Platform security standards (ISO 27001, SOC 2); regular security updates and vulnerability assessments. No security system is 100% secure. We cannot guarantee absolute protection against sophisticated attacks.


5.3 Data Retention Schedule

- Account/Authentication Data: While active + 1 year after deletion (legal compliance, audit trail)
- Subscription Status: While active + 1 year after cancellation (billing records)
- Usage Analytics: Up to 2 years (service improvement)
- AI/OCR Cropped Images: Processed in real time — NOT retained after processing by WineFoo or OpenAI
- Push Notification Tokens: While permission is active; deleted upon withdrawal of permission
- Email Subscription Data: Until you unsubscribe + 1 year for compliance records
- Crash Reports & Error Logs: 30–90 days (technical troubleshooting)
- Backup Data: Google Cloud standard retention (disaster recovery)


6. Data Sharing & Third Parties

6.1 We DO NOT Sell Your Data

WineFoo does not sell, rent, trade, lease, or otherwise monetise your personal information to third parties for any purpose, including marketing. This is an absolute commitment.


6.2 Data Shared with Service Providers

We share limited personal data with the following third-party data processors, each bound by data processing agreements:

- Google Cloud Platform (Firebase) — Data storage, backup, and infrastructure. Data shared: authentication data, usage data, subscription status, analytics. Privacy policy: https://policies.google.com/privacy

- Google Analytics (Firebase Analytics) — Usage analytics and app performance monitoring. Data shared: pseudonymised usage patterns, feature engagement, custom events. Data is pseudonymised before reporting. Privacy policy: https://policies.google.com/privacy

- OpenAI, L.L.C. (San Francisco, CA, USA) — Processing of cropped camera images and OCR text for Premium AI features. Data shared: cropped images (in real time only) and text descriptions you provide. OpenAI processes data under their API data usage policy, which prohibits use of API inputs to train models (https://openai.com/policies/api-data-usage-policies). Cropped images are NOT retained after processing. OpenAI's privacy policy: https://openai.com/privacy

- Apple App Store (iOS) — Subscription management and app distribution. Privacy policy: https://www.apple.com/privacy/

- Google Play Store (Android) — Subscription management and app distribution. Privacy policy: https://policies.google.com/privacy

- Email Service Provider — Delivery of confirmed email communications to subscribers. Data shared: email address, subscription confirmation status, preferences.


6.3 Partner & Affiliate Content

WineFoo may share limited, aggregated, non-identifiable data with commercial partners for the purpose of measuring the performance of promotional banners and partner link campaigns. We do not share your personal identity, email address, wine selections, or any directly identifying information with partners.


6.4 Legal Obligations & Disclosure

We may disclose your information when legally required by subpoenas, court orders, or government authority requests; to protect our legal rights; to prevent fraud or illegal activity; or in connection with mergers, acquisitions, or business transfers. In such cases, we will provide notice where legally possible and limit disclosure to information strictly required.


7. Your Privacy Rights

7.1 Universal Rights (All Users)

You have the right to: know what personal data we collect; access and receive a copy of your data; correct inaccurate information; request deletion of your data (subject to exceptions — see Section 7.2); receive your data in a portable format; object to certain processing; restrict how we use your data; withdraw consent at any time without affecting the lawfulness of prior processing; and lodge a complaint with a supervisory authority.


7.2 GDPR Rights (EU/UK/Swiss Residents)

If you are located in the European Union, United Kingdom, or Switzerland, you have specific rights under GDPR including:

- Right to Access (Article 15): Request all personal data we hold about you. Response within 30 days (extendable to 60 days for complex requests).
- Right to Rectification (Article 16): Correct inaccurate or incomplete personal data.
- Right to Erasure / "Right to Be Forgotten" (Article 17): Request deletion of your personal data. Response within 30 days. Exceptions include: data required for legal compliance or legal obligation; data necessary for the establishment, exercise, or defence of legal claims; data where processing is required by law.
- Right to Restrict Processing (Article 18): Request that we limit processing of your data while a dispute is resolved.
- Right to Data Portability (Article 20): Receive your data in a portable, machine-readable format (JSON, CSV, etc.) where technically feasible.
- Right to Object (Article 21): Object to processing based on legitimate interests or direct marketing. We will cease processing unless we have compelling legitimate grounds.
- Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- Right not to be subject to solely automated decision-making (Article 22): WineFoo does not make decisions about you based purely on automated processing that produce legal or similarly significant effects.
- Right to Lodge a Complaint (Article 77): You may lodge a complaint with your national Data Protection Authority at any time.

Primary Supervisory Authority (Poland):
UODO — Urząd Ochrony Danych Osobowych | https://uodo.gov.pl | ul. Stawki 2, 00-193 Warsaw, Poland

Other Supervisory Authorities:
EU (EDPB): https://edpb.ec.europa.eu/
UK (ICO): https://ico.org.uk/
Switzerland (FDPIC): https://www.edoeb.admin.ch/


7.3 CCPA/CPRA Rights (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

- Right to Know (§1798.100): Know what personal information we collect, the purpose of collection, sources, and with whom we share it.
- Right to Delete (§1798.105): Request deletion of personal information we collected. Exceptions include: data required for legal compliance, service provision, and fraud prevention. Response within 45 days.
- Right to Correct (§1798.120): Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing (§1798.120): We do not sell your personal information or share it for cross-context behavioural advertising. Accordingly, a "Do Not Sell or Share My Personal Information" link is not required. California residents may nonetheless submit opt-out requests to kellerkollektiv@gmail.com and we will confirm our non-sale status in writing.
- Right to Limit Use of Sensitive Personal Information (§1798.121): We do not collect sensitive personal information as defined under CPRA (health data, precise location, biometrics, etc.).
- Right to Non-Discrimination (§1798.125): We will not discriminate against you for exercising your rights — no denial of service, price increases, or reduced benefits.

Response timeframe: 45 days (extendable by a further 45 days for complex requests).
Contact: kellerkollektiv@gmail.com


7.4 How to Exercise Your Rights

To exercise any privacy right, contact us at:

Email: kellerkollektiv@gmail.com
Website: https://kellerkollektiv.com/winefoo
Mail: KELLER KOLLEKTIV, Teczowa 82d/1, 53-603 Wroclaw, Poland

Please include your name, email address associated with your account, the specific right you are exercising, and a description of your request. We will verify your identity before responding. All requests are free of charge.


8. Camera & Image Data — Special Notice

WineFoo's AI-powered features (AI Matchmaking and OCR Image Analysis) require camera access. Please note:

- You initiate every image capture manually — the App never accesses your camera without your explicit action
- You crop the image before it is processed — only the cropped portion is transmitted
- Cropped images are transmitted securely to OpenAI's API over HTTPS/TLS
- Cropped images are processed in real time and are NOT stored by WineFoo or OpenAI after the recommendation is generated
- Images are NOT saved to your device gallery by the App
- Images are NOT used to train AI models — OpenAI's API policy prohibits use of API inputs for model training

You can revoke camera permission at any time through your device settings. Revoking camera access only disables AI Matchmaking and OCR features; all other App features remain fully available.


9. Push Notifications — Special Notice

Push notifications are sent only if you grant explicit permission via your device's system prompt. We send a maximum of 1–2 push notifications per week. You can revoke notification permission at any time through your device settings without affecting access to core App features. Withdrawal of permission does not affect the lawfulness of notifications sent prior to withdrawal.


10. Children's Privacy

Our App is NOT intended for children or individuals under 18 years of age. The App contains alcohol-related content. We do not knowingly collect information from children under 18. An in-app age declaration is required upon first launch before any content is accessible. If we discover we have collected information from a minor, we will delete such information immediately and notify the parent or guardian where possible. If you believe we have collected information from your minor child, contact us immediately at kellerkollektiv@gmail.com.


11. International Data Transfers

Your data may be transferred to, stored in, and processed in countries outside your country of residence, including the United States (Google Cloud Platform / Firebase and OpenAI).

For EU/UK/Swiss residents, all international transfers comply with GDPR Chapter 5 requirements. Specifically:

- Google Cloud Platform (Firebase): Transfers are covered by Standard Contractual Clauses (SCCs) under Google's data processing terms, with supplementary measures consistent with the Schrems II requirements.
- OpenAI: Transfers are covered by Standard Contractual Clauses (SCCs) under OpenAI's data processing addendum. OpenAI is also certified under applicable EU-US data transfer frameworks.

By using the App and accepting this Privacy Policy, you consent to international data transfers as described. If you do not consent to international transfers, you should not use the App.


12. Data Breach Notification

In the event of a confirmed personal data breach, we will:

- Notify the UODO (and any other relevant supervisory authority) within 72 hours of becoming aware of the breach, as required by GDPR Article 33
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34

Notification to you will include: the nature of the breach; categories and approximate number of records concerned; likely consequences; measures taken or proposed; and our contact details. We will cooperate fully with UODO and other authorities in any investigation.


13. Cookies & Tracking Technology

The WineFoo App does NOT use traditional HTTP cookies. Instead, we use Firebase Analytics for usage tracking and device advertising IDs (IDFA for iOS, Google Advertising ID for Android). These identifiers are pseudonymous — they do not directly identify you by name but can be used to distinguish devices.

Opt-out options:

- iOS: Settings → Privacy & Security → Tracking → disable for WineFoo; or Settings → Privacy → Advertising → Limit Ad Tracking
- Android: Settings → Google → Manage your Google Account → Data & Privacy → Ad personalisation → opt out


14. Third-Party Links & Services

The App may contain partner and affiliate links to third-party websites or services (wine retailers, related products, etc.). WineFoo is not responsible for third-party privacy practices. Third-party services are governed by their own privacy policies. Your use of third-party services is at your own risk. We encourage you to review their policies before providing information.


15. Changes to This Privacy Policy

WineFoo reserves the right to modify this Privacy Policy at any time. Changes will be posted in the App and the "Last Updated" date will be updated. For material changes, we will provide prominent notice (email to subscribers, in-app banner) at least 30 days before they take effect.

Important: Where a change affects processing that relies on your consent as its legal basis, we will seek fresh, active consent before the change takes effect. Continued use of the App alone will not constitute consent to privacy policy changes that affect consent-based processing.


16. Contact Information

For privacy questions, data requests, or concerns:

Email: kellerkollektiv@gmail.com
Website: https://kellerkollektiv.com/winefoo
Mailing Address: KELLER KOLLEKTIV, Teczowa 82d/1, 53-603 Wroclaw, Poland
Response Timeframe: We will respond to all privacy inquiries within 30 days.

Additional Resources:
Terms of Service: https://kellerkollektiv.com/winefoo-terms
Privacy Policy: https://kellerkollektiv.com/winefoo-privacy


By using WineFoo, you acknowledge you have read, understood, and agree to this Privacy Policy.

Don't know if or how any of this can help your busines, product, service stand out?

KELLERKOLLEKTIV_Design_Portfolio_HandsLight

Wr✹claw, Poland
⮩ Worldwide

Email: hello@kellerkollektiv.com

All rights reserved © 2025

Back to top Arrow
error: Content is protected !!