Important notice for users: This Privacy Policy applies to the Wine Buddy website and mobile app. It describes in particular how we handle data from camera scans, optional voice/microphone use, account creation, personalised recommendations, external retailer links, and services such as Firebase.
The controller within the meaning of the General Data Protection Regulation (GDPR) is the person named above.
Wine Buddy is an app and website for wine discovery, product identification, personalisation, and referral to external retailer offers. Wine Buddy does not sell alcoholic beverages itself. When you click on a retailer's offer, any resulting purchase contract is made exclusively with that retailer.
Age and retailer notice: Wine Buddy is intended for adults aged 18+. Purchase, age verification, payment, delivery, withdrawal rights, and customer service for orders are handled exclusively by the linked retailer.
Depending on how you use the service, we may process in particular the following categories of data:
We process personal data only where this is legally permitted. The main legal bases are in particular:
Our website is currently hosted via Netlify. When you access the website, technical access data such as IP address, browser type, operating system, referrer, hostname, date, and time of the request may be processed. This processing is used for technical delivery, stability, security, and error analysis. The legal basis is Art. 6(1)(f) GDPR.
We use technically necessary local storage, in particular to remember your language preference (wine-buddy-lang). This helps us display the website in your selected language. You can delete local storage through your browser settings.
The website may load fonts via Google Fonts or Google servers. In that case, technical connection data may be transmitted to Google. If fonts are self-hosted in the future, this external transfer for font delivery will no longer apply.
Non-essential cookies, SDKs, or similar technologies, in particular for analytics, marketing, affiliate tracking, A/B testing, or push/communication services, are only used where valid consent exists or a legal exemption applies. You may withdraw consent at any time with effect for the future.
When you use the camera or your photo library in the app, we process the images you select or capture in order to identify wine bottles, labels, or associated product information, and to display relevant results, recommendations, or retailer suggestions.
Camera or photo library access only occurs when you actively use this feature and grant the relevant device permission. The legal basis is Art. 6(1)(b) GDPR; where device or platform logic requires consent, additionally Art. 6(1)(a) GDPR.
Where Wine Buddy offers voice search, voice input, or voice-controlled interaction and you actively start this feature, the app may access the microphone to receive your voice input and convert it into a search or chat request.
Microphone access does not run continuously in the background – it is only active during the feature you have initiated. The legal basis is Art. 6(1)(b) GDPR; where required, additionally your consent under Art. 6(1)(a) GDPR.
When you create an account or sign in, we use services for authentication and account security, in particular Firebase Authentication. Data processed may include in particular your email address, technical authentication information, login timestamps, pseudonymous identifiers, and security-related metadata.
Processing serves to provide your account, handle sign-in, ensure account security, and prevent misuse and fraud. The legal basis is Art. 6(1)(b) GDPR and additionally Art. 6(1)(f) GDPR.
To provide app features, we may use Cloud Firestore and Firebase Storage / Cloud Storage for Firebase. Data stored and processed may include in particular profile data, preferences, favourites, scan and search history, chat content, and uploaded images and – where used by you – audio files.
Processing serves to provide app features, synchronise content across devices, manage user profiles, and display or restore saved content. The legal basis is Art. 6(1)(b) GDPR.
To improve the stability, usability, and performance of the app, we may use Firebase Analytics and Firebase Crashlytics.
Where analytics or similar measurement require consent under applicable law, we obtain this in advance. Otherwise, we rely on Art. 6(1)(f) GDPR for product quality, IT security, and error analysis.
When you use chat, search, recommendation, or identification features in Wine Buddy, your inputs, images, voice inputs, and associated technical metadata may be transmitted to backend services or AI/automation services we use, to the extent necessary to provide the feature you have requested.
This includes in particular processing your request, generating responses, identifying a wine, creating personalised recommendations, and conducting security and abuse checks. The legal basis is Art. 6(1)(b) GDPR and additionally Art. 6(1)(f) GDPR.
Wine Buddy uses the Google Gemini API on a paid tier. Google does not use data transmitted via the paid API tier to train or improve its AI models. For details, see Google's Privacy Policy.
Please do not enter unnecessary sensitive personal data in free-text fields.
For full details on how AI is used in Wine Buddy, see our AI Transparency Notice.
Wine Buddy may use your stated preferences for taste, style, price range, occasions, pairings, favourites, saved wines, scan results, and past interactions to show you more relevant content and recommendations. This also includes feedback signals such as thumbs-up / thumbs-down ratings on AI chat responses in the app, which may be used as preference indicators and fed into your Taste DNA profile.
The legal basis is Art. 6(1)(b) GDPR where you use this feature, and additionally Art. 6(1)(f) GDPR for improving our service.
When you click on an external retailer's offer, we may technically log the redirect and tag it with affiliate identifiers so that visits or referred transactions can be attributed to Wine Buddy.
Data processed may include in particular click data, referrer information, timestamps, browser/device information, and identifiers in links. Once you open an external retailer's website, the privacy information of that retailer governs further data processing.
Wine Buddy uses the affiliate network AWIN (AWIN AG, Eichhornstraße 3, 10785 Berlin, Germany) to technically track and settle referred transactions. AWIN may use its own technologies and process its own data. For details, see AWIN's Privacy Policy.
Your data may – to the extent necessary to provide the service – be transmitted to the following recipients or categories of recipients:
Where service providers act as processors on our behalf, this is done on the basis of a data processing agreement pursuant to Art. 28 GDPR.
When using certain service providers, personal data may be processed in countries outside the EU/EEA, in particular in the United States. Where no adequacy decision applies or is relevant, we base transfers on appropriate safeguards such as standard contractual clauses or other legally permitted mechanisms.
We retain personal data only for as long as necessary for the relevant purposes, as long as statutory retention obligations exist, or where legitimate interests require limited retention. If actual service configurations differ, we update these details when the relevant service changes.
Where Wine Buddy offers account creation, you may also request deletion of your account and the associated personal data at any time.
You can submit a deletion request either within the app (where such a feature is provided) or outside the app by email to support@buddy.wine with the subject line "Delete my Wine Buddy account". For details, see our Account Deletion page.
For a valid deletion request, we delete or anonymise the personal data associated with the account generally within 30 days after successful identity verification, to the extent we do not need to retain it for legal, security, fraud prevention, or billing reasons.
Where personal data is processed by service providers on our behalf, we also take steps, within legal and technical limits, to delete or anonymise the relevant data there. Any remaining data is retained only for the required purposes and then deleted.
Subject to the applicable legal requirements, you have in particular the following rights:
To exercise your rights, a simple message to support@buddy.wine is sufficient.
You may also lodge a complaint with a competent data protection supervisory authority. For private-sector controllers in Bavaria, this is generally the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Wine Buddy is intended for adults of the minimum legal age for alcohol-related content and products in the applicable jurisdiction. We do not intend to collect personal data from children where this is not permitted for our service.
We update this Privacy Policy whenever the actual processing activities, services used, or legal framework changes. The version published on this page is always current.
Ilker Demirel
Maximilianstr. 30
85399 Hallbergmoos
Germany