This policy explains what personal data poured collects when you use our Wine Program-as-a-Service, why we collect it, and the rights you have over it. It covers both the venue staff who run poured and the guests who scan a QR menu. The service is operated by Poured.Tech, based in Târgu Mureș, Romania (“we”, “us”). We act as the data controller for account data and as a processor for the content a venue enters on our platform.
We keep the data we hold to what the service actually needs to run:
Our legal bases are the performance of our contract with you, our legitimate interest in running a secure and reliable service, and, where required, your consent. We do not sell your data or use it for third-party advertising.
We rely on a small set of vetted providers, each acting under a data-processing agreement and only for the purposes above:
Where any provider processes data outside the European Economic Area, that transfer is covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
We use only the cookies needed to keep you signed in and to remember a plan choice during sign-up. We do not use advertising or cross-site tracking cookies. See our Cookie Policy for the full list.
We keep account and venue data for as long as your venue has an active account, and for a short period afterwards so the account can be recovered. When you close your account we delete or anonymise your data unless we are required to retain some of it to meet a legal or accounting obligation. Server logs are kept only for a limited retention window.
Under the GDPR and Romanian data-protection law you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or provide it in a portable form. You can also withdraw any consent you have given. To exercise these rights, email hello@poured.tech. We will respond within the time the law allows. If you believe we have mishandled your data, you have the right to complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
The application is the only client of our database: every read and write goes through server-side actions, the database enforces row-level security, and the public data API is disabled. We use encryption in transit and restrict access to production data to the people who need it. No system is perfectly secure, but we work to protect your data in line with industry practice.
Poured is a tool for hospitality businesses, not for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
We may update this policy as the service evolves; we will change the date above and, for material changes, tell you in the app. Questions about privacy? Write to hello@poured.tech.