Privacy Policy
This policy explains what personal data winemap collects, why, who gets it, how long we keep it, and what rights you have. We keep it as plain as the law allows.
The short version
- We collect what we need to run the app: your account, the pins you log (including where), your photos, and your friends and comments.
- We don't sell your data, we don't show ads, and we don't use analytics or tracking cookies.
- You choose who sees each pin: public, friends or private. Two optional settings let your profile count private or friends-only pins in the "Total Wines" number (the number only, never the pins).
- You can delete your account yourself, and you can ask us for a copy of your data or to correct it.
- The app is for people who are old enough to drink alcohol legally where they live.
1. Who is responsible
The controller is Bent Verberckmoes, a private individual in Belgium, who runs winemap as a non-commercial project. Contact for everything about your data: support@winemap.vpswb.store. Because we are a private hobby project we have not appointed a data protection officer.
2. What we collect, why, and on what legal basis
| Data | What we use it for | Legal basis (GDPR) |
|---|---|---|
| Account: username, email address, password (stored only as a one-way hash), Google account name and email if you sign in with Google, the version of these terms you accepted and when you confirmed you are old enough to drink legally where you live, and the email addresses your account has used before (visible only to the operator, to help with support requests about your account). | Create and secure your account, verify your email, reset your password, show your username, keep proof that you accepted the terms. | Contract (Art. 6(1)(b)); legal obligation and legitimate interest for the proof of acceptance (Art. 6(1)(c), (f)). |
| Guest data: the name you chose, your pins, and a random guest code in a cookie. | Let you log wines without an account and keep them if you make an account later. | Contract (Art. 6(1)(b)). |
| Pins: the wine name, ABV, rating, notes, colour, whether you finished it, the location you drop the pin at, time, visibility, and any photo or video you add. | The core of the app: show your pins to you and to the people you choose, on the map, in your profile and in statistics. | Contract (Art. 6(1)(b)). See "Sensitive information" below. |
| Social data: friend requests and friends, comments, likes, nominations, notifications, badges, achievements. | Run the social features. | Contract (Art. 6(1)(b)). |
| Leaderboards: your username, badge and number of public pins. | Show the friends and global leaderboards. You can opt out of the global one in Settings. | Legitimate interest (Art. 6(1)(f)); you can object and opt out. |
| Support messages: your name, email, the message and our replies. Also wine suggestions you send. | Answer you and review wine suggestions. | Contract and legitimate interest (Art. 6(1)(b), (f)). |
| Security and sign-in records: session and "stay signed in" tokens (stored as hashes), a random device identifier of your browser, and, if you are banned, the ban, the reason and the devices it covers. | Keep you signed in, protect accounts, prevent abuse, and make bans effective. We do not use the device identifier to track you across other websites, and we do not use it for advertising. | Legitimate interest in security and preventing abuse (Art. 6(1)(f)); legal obligation under the Digital Services Act (Art. 6(1)(c)). |
| Settings on your device: theme, a joke display effect, camera choice and similar. | Remember your choices. | Consent (Art. 6(1)(a)); you can say no in the cookie banner. |
Sensitive information
How much you drink can say something about your health or lifestyle. We take that seriously. By logging a wine you choose to give us that information, which is your explicit consent where the law treats it as sensitive (Art. 9(2)(a)). You decide who can see it, you can delete a pin or your whole account at any time, and withdrawing your consent this way does not affect what we did before.
3. Your location
- The "locate me" button and centering the map use your device's location on your device only. Your browser asks you first, and you can refuse.
- We store a location only when you drop a pin: the coordinates of that pin. A public pin shows that location to everyone.
- Photos are re-saved without their hidden metadata (such as GPS position, camera and time) when you upload them. Videos are stored as uploaded, so a video may still contain such metadata.
4. Who sees your data
Other users
Public pins, your username, badges, public pin count and profile are visible to everyone. Friends-only pins are visible to your friends. Private pins are visible only to you.
Service providers that handle data for us
| Who | What | Where |
|---|---|---|
| Contabo GmbH (Germany) | Hosts the server, the database and uploaded files. | Server in Lauterbourg, France (EU) |
| Sign-in with Google, if you use it. We also receive notifications about new support messages in a Google mailbox. | EU / USA | |
| Slack | New support messages and new wine suggestions are posted to a private channel that only we can read, so we can review and answer them. These posts contain the username, email address and message text. | USA |
| Anthropic | When we use AI help to polish a reply to a support message, the first 800 characters of your message and our draft reply are sent to Anthropic's Claude model. Nothing else (no pins, photos or profile data). A person always reads and sends the reply. We make no decisions about you with AI. | USA |
| CARTO (basemaps.cartocdn.com) | Provides the map pictures. Your browser contacts CARTO to load map tiles, so CARTO sees your IP address and which part of the map you view. | EU / USA |
| jsDelivr (cdn.jsdelivr.net) | Delivers the label-scanner code and text-recognition data the first time you use label scanning. Your browser contacts jsDelivr, which sees your IP address. The scan itself happens on your device, and the photo is not uploaded for scanning. | Global CDN |
| Our server sends mail (verification codes, replies) directly to your email provider. | Your provider |
We have no other recipients, and we do not sell, rent or trade your data. We may disclose data if the law or a court requires it, or to protect people from harm.
Transfers outside the EU
Some providers above (Google, Slack, Anthropic, CARTO) may process data in the USA. They rely on safeguards such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. You can ask us for details.
5. Cookies and similar technology
We use only the few cookies and storage items the app needs, plus your settings if you allow them. We have no advertising, analytics or tracking cookies. The full list is in the Cookie Policy.
6. Security records, devices and bans
When you are signed in, your browser receives a random identifier (a "device id"). We link it to your account. If we ban an account for breaking the rules, we may also block the devices linked to it, so that the person cannot simply make a new account in the same browser. This is not perfect protection: someone who clears all site data or uses another browser can get around it. We do not use fingerprinting. We do not store your IP address for this. A person decides on every ban, and you are told the reason and can appeal (see the Terms, section 8).
7. How long we keep data
| Data | How long |
|---|---|
| Account, pins, photos, videos, friends, comments, likes | Until you delete them or your account. When you delete your account they are removed straight away from the live service. |
| Guest pins and data | Until you delete them, make an account, or ask us to delete them. |
| Backups | Kept for up to 60 days, then overwritten or deleted. Deleted data can therefore remain in a backup for that time, and is not used for anything else. |
| Sessions and "stay signed in" tokens | Up to 12 months after your last visit, or until you log out, change your password, or are banned. |
| Device identifiers | Up to 24 months after the device was last used, or for as long as a ban that covers it lasts. |
| Previous email addresses of an account | Until you delete your account. Ask us to remove them earlier by contacting support. |
| Support messages | For 24 months after we close the ticket, then deleted. Earlier if you ask. Posts in our private Slack channel are deleted on request. |
| Ban records | While the ban lasts, and for 12 months after it is lifted, as a record of the decision. |
| Proof that you accepted the terms | As long as you have an account. |
8. Your rights
Under the GDPR you have the right to:
- access your data and get a copy;
- correct data that is wrong (you can change most of it yourself in the app);
- erase your data (use "Delete account" in Settings, or write to us);
- restrict or object to how we use it, including the use based on our legitimate interest, such as the leaderboard;
- data portability: receive the data you gave us in a common format;
- withdraw consent at any time, for example by changing the cookie settings (this does not undo what happened before);
- not be subject to a decision based only on automated processing. We make no such decisions.
To use a right, email support@winemap.vpswb.store from the address on your account. We may need to check that it is you. We answer within one month.
Complaints: you can complain to the Belgian data protection authority, the Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels, www.gegevensbeschermingsautoriteit.be, contact@apd-gba.be, or to the authority in the country where you live. We would like the chance to help you first.
9. Age
winemap is only for people who are old enough to drink alcohol legally where they live. That age differs per country, and we do not set our own limit. We do not knowingly collect data from anyone below it. If we learn that we have, we delete it.
10. Security
- Passwords are stored only as bcrypt hashes. Sign-in and reset codes are time-limited and can only be tried a few times.
- The connection is encrypted (HTTPS). Session and sign-in cookies are marked HTTP-only. Uploaded files get random names.
- Tokens that keep you signed in are stored only as hashes.
- No system is perfectly secure. If a breach puts your rights at risk, we tell you and the authority as the law requires.
11. Logs
Our web server does not keep access logs of who visits. Our hosting provider and the networks in between may handle IP addresses technically, as part of delivering the connection.
12. Changes
When we change this policy in an important way, we say so in the app and, where required, ask you to accept the new version. The date at the top shows the latest version.