/ Legal

Privacy Policy

Last updated 4 August 2026

This policy explains what personal data poured collects when you use our Wine Program-as-a-Service, why we collect it, and the rights you have over it. It covers both the venue staff who run poured and the guests who scan a QR menu. The service is operated by Poured.Tech, based in Târgu Mureș, Romania (“we”, “us”). We act as the data controller for account data and as a processor for the content a venue enters on our platform.

01

Data we collect

We keep the data we hold to what the service actually needs to run:

  • Account & identity. When you sign up, our authentication provider (Clerk) stores your name, email address, and login credentials. We store your Clerk user ID against your venue membership so we know which venue you belong to and your role.
  • Venue content. The wine lists, food menus, prices, tasting notes, and pairings you enter or upload. This is your business data; we process it to provide the service.
  • Uploaded files. Spreadsheets and PDFs you import are parsed to extract menu data and are not retained beyond what is needed to complete the import you review.
  • Guest activity. When a guest opens a public QR menu we serve the page and may record aggregate, non-identifying usage. Guests do not create accounts and we do not ask them for personal details.
  • Technical data. Standard server logs (IP address, browser type, timestamps) generated when any page is requested, used for security and to keep the service reliable.
02

How we use it

  • To create and secure your account and control who can access each venue.
  • To operate the product — render your menus, calculate margins, and generate floor-ready decisions.
  • To generate AI content (tasting notes, pairings, health-check insights) by sending the relevant menu text to our language-model provider. We do not send guest personal data for this, and our provider does not use your content to train its models.
  • To respond to support requests and to send essential service messages about your account.
  • To detect abuse, debug problems, and meet our legal obligations.

Our legal bases are the performance of our contract with you, our legitimate interest in running a secure and reliable service, and, where required, your consent. We do not sell your data or use it for third-party advertising.

03

Who processes it for us

We rely on a small set of vetted providers, each acting under a data-processing agreement and only for the purposes above:

  • Clerk — authentication and identity (your name, email, and login).
  • Supabase — the managed Postgres database that stores your venue data.
  • Vercel — hosting and delivery of the application.
  • Our language-model provider — generates AI menu content from the menu text we send it.

Where any provider processes data outside the European Economic Area, that transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

04

Cookies

We use only the cookies needed to keep you signed in and to remember a plan choice during sign-up. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list.

05

How long we keep it

We keep account and venue data for as long as your venue has an active account, and for a short period afterwards so the account can be recovered. When you close your account we delete or anonymise your data unless we are required to retain some of it to meet a legal or accounting obligation. Server logs are kept only for a limited retention window.

06

Your rights

Under the GDPR and Romanian data-protection law you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. You can also withdraw any consent you have given. To exercise these rights, email hello@poured.tech. We will respond within the time the law allows. If you believe we have mishandled your data, you have the right to complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

07

Security

The application is the only client of our database: every read and write goes through server-side actions, the database enforces row-level security, and the public data API is disabled. We use encryption in transit and restrict access to production data to the people who need it. No system is perfectly secure, but we work to protect your data in line with industry practice.

08

Children’s privacy

Poured is a tool for hospitality businesses, not for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

09

Changes & contact

We may update this policy as the service evolves; we will change the date above and, for material changes, tell you in the app. Questions about privacy? Write to hello@poured.tech.