Privacy Policy

Last updated March 10, 2026

1. Introduction

This Privacy Policy explains how tanniq, Inc. ("tanniq," "we," "us") collects, uses, stores, and shares information when you use the tanniq platform, including tanniq Discovery and tanniq Club Membership features (collectively, the "Services").

tanniq is a discovery and membership-management interface layered on top of third-party systems. Much of the membership-related information available through tanniq is retrieved from connected systems such as Commerce7 rather than entered directly by you. We collect only the information we reasonably need to operate Discovery, linked membership features, communications, analytics, security, and winery-facing tools.

2. Information We Collect

2a. Information You Provide Directly

When you create a tanniq account, we collect your first name, last name, and email address. We may also collect your phone number and date of birth at account creation or when you complete your profile. Phone number and date of birth are used for account operation and may be used for verification purposes where applicable.

You may set notification preferences for email and SMS communications at account creation or through your account settings.

If push notifications are offered in the future and you explicitly opt in, we may collect a push notification token or related device identifier at that time. Push notification capabilities are not currently active.

2b. Information Retrieved from Connected Winery Systems

When you link an eligible winery club membership through Commerce7, tanniq may retrieve, display, cache, or store certain membership-related information from Commerce7 in order to operate the Services. This may include:

  • Club membership status and details
  • Order history and order items
  • Upcoming shipments
  • Shipping addresses
  • Payment method display information such as card brand and last four digits (see Section 2c)

This information originates with the applicable winery and its Commerce7 account. It may be delayed, incomplete, or temporarily unavailable due to third-party system behavior. The winery's and Commerce7's records control in the event of a conflict with what tanniq displays.

2c. Payment-Related Information

tanniq does not collect, process, or store payment credentials. tanniq does not have the ability to modify payment methods on file with a winery.

When you link a Commerce7 account, tanniq may retrieve and display limited payment method display information from Commerce7, such as card brand and last four digits, solely for display purposes within the Services. This information originates with the applicable winery's Commerce7 account and is read-only within tanniq.

Wineries — not tanniq — manage, charge, and process payments for wine club shipments and wine purchases.

2d. Usage, Analytics, and Technical Information

We use privacy-focused analytics (Umami Cloud, configured without cookies) to understand how people use the Services. This may include pages viewed and interactions such as clicking directions, winery website links, or booking links.

We may also record event-level interaction data relating to Discovery usage, referral context, QR scans, and similar actions. These events are used for product analytics, attribution, aggregated reporting, security, and service improvement. Where possible, analytics are configured to minimize direct identification of individual users.

Like most web services, we may receive limited technical information such as device type and browser type to support basic aggregation and protect against abuse.

2e. Location-Related Information

Precise location is collected only if you affirmatively grant permission through your browser or device settings. You can revoke location permissions at any time through those settings. You can use Discovery without providing location.

When you perform a location-based search, your location may be retained in search records for a limited period to support analytics, attribution, and service improvement. Location data may also be used to produce aggregated analytics such as geographic usage patterns. Where feasible, we use measures designed to reduce the visibility of individual-level location patterns in aggregated outputs. Location is not used for targeted advertising.

2f. Search Session Data

When you use Discovery's search features, we may log search parameters and a hash-based session fingerprint. Session fingerprints contain no directly identifiable information and are retained for a short period to support analytics and abuse prevention.

2g. Winery and Business Listing Information

tanniq stores and displays business information to power Discovery. This includes winery name, address, hours, website links, amenities, discovery tags, and other business profile content. This content is not personal information about users. It may come from wineries directly, publicly available sources, internal research, or other lawful sources.

2h. Support and Communications

If you contact us, we receive the information you choose to share, such as your email address and the contents of your message. Support communications are retained for as long as reasonably necessary to resolve your request and for related security, legal, and audit purposes.

2i. Business Contact and Dashboard Information

If a winery representative or other business user requests dashboard access or contacts us about Organization Services, we may collect business contact information such as name, work email, organization name, and role or title. We also maintain access logs and security logs related to dashboard use for security and troubleshooting purposes.

This information is separate from consumer member data.

3. How We Use Information

We use the information we collect to:

  • Operate, maintain, and improve the Services
  • Authenticate accounts and maintain account security
  • Retrieve, display, and cache linked membership information from Commerce7 on your behalf
  • Process and transmit member-initiated actions such as address updates and cancellation requests to Commerce7
  • Send transactional and service-related communications including login links, security alerts, and account or membership notices
  • Send marketing communications where you have opted in and as permitted by applicable law, subject to your preferences
  • Show nearby winery recommendations and compute distances when you provide location
  • Support product analytics, aggregated reporting, attribution, and service improvement
  • Provide and administer Organization Services and related support
  • Prevent abuse, maintain security, and enforce our Terms of Service
  • Comply with legal obligations

4. Aggregated and De-Identified Data

tanniq may aggregate or de-identify information so that it no longer reasonably identifies an individual user. tanniq may use such aggregated or de-identified data for analytics, service improvement, debugging, security, and business reporting, including winery dashboard reporting on QR scans, referral events, and Discovery interactions. To the extent information has been de-identified so that it no longer reasonably identifies an individual, tanniq will maintain and use it in de-identified form as permitted by applicable law.

5. How We Share Information

tanniq does not sell or rent personal information. tanniq does not use personal information for cross-context behavioral advertising or targeted advertising.

We share information in the following circumstances:

5a. Service Providers

We share information with third-party service providers that help us operate the Services. These providers process information on our behalf, subject to contractual and legal restrictions on their use of that information. Current key providers include:

  • Firebase (Google) — authentication, database storage, and infrastructure. User identity and stored account data are processed through Firebase.
  • Vercel — hosting and deployment infrastructure.
  • Umami Cloud — privacy-focused, cookieless analytics.
  • Postmark — transactional email delivery. Email address, name, and relevant account or membership details are shared to deliver service communications.

5b. Connected Third-Party Systems

When you link a Commerce7 account, tanniq interacts with Commerce7 on your behalf to retrieve membership data and transmit user-initiated updates. This interaction is authorized by you at the time of linking. Commerce7's own terms and privacy practices govern how Commerce7 handles your data.

When you use location-based features, location data may be transmitted to mapping API endpoints (Google Maps/Places) to return results. We do not intentionally transmit your core tanniq account profile details as part of those lookups. Google's own terms and privacy practices govern how Google handles data associated with API requests.

When you sign in using Google Sign-In or Apple Sign-In, we receive your email address and name from those providers. Those providers' terms and privacy policies govern their own data handling.

5c. Legal and Compliance Disclosures

We may share information if required by law, regulation, legal process, or governmental request, or to protect the safety, security, or rights of tanniq, our users, or others.

5d. Corporate Transactions

We may share or transfer information in connection with a merger, acquisition, sale of assets, or other corporate transaction. We will provide notice of any such transfer and any material changes to how your information is handled.

6. Communications

By creating an account, you consent to receive transactional and service-related communications, including login links, security alerts, account notices, and membership-related operational messages. These communications are necessary to operate the Services and may be sent even if you have opted out of marketing communications.

Where tanniq offers marketing communications and you have opted in, you may opt out at any time through your account settings or by following the unsubscribe instructions in any such message.

tanniq is not responsible for delays or failures in communications caused by email providers, SMS carriers, spam filtering, device settings, or other third-party delivery factors.

7. Cookies and Tracking

Umami Cloud analytics are configured without cookies for privacy-focused measurement. tanniq does not use cookies or tracking technologies for targeted advertising or cross-site behavioral profiling.

Like most web services, we may receive limited technical information such as browser type and device type to support aggregated analytics and protect against abuse.

8. Data Retention

We retain different categories of information for different periods:

  • Search impressions (including location) — limited period, currently up to 90 days
  • Search session fingerprints — short period, currently up to 24 hours
  • Commerce7 webhook logs — limited period, currently up to 30 days
  • Commerce7 link tokens — limited period, currently up to 30 days
  • Account records — retained while your account is active; anonymized upon account deletion as described in Section 10
  • Payment display information — retained while account is active; anonymized upon account deletion as described in Section 10
  • Support communications — retained for as long as reasonably necessary for resolution and related legal, audit, and security purposes
  • Dashboard access and security logs — retained for as long as reasonably necessary for security and troubleshooting purposes
  • Analytics and referral event data — retained for a limited period as reasonably necessary for analytics, security, debugging, and service improvement; after which data may be aggregated, de-identified, or deleted

We do not retain information longer than reasonably necessary for the purposes described in this Policy.

9. Data Security

We implement reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction. These include authentication and access controls, rate-limiting and abuse-prevention measures, and protections around how payment display information retrieved from Commerce7 is stored and handled.

tanniq does not collect or store payment credentials. Payment processing is handled entirely by wineries and their systems.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your Rights and Choices

You may contact us at any time to:

  • Access information we hold about your tanniq account
  • Request correction of inaccurate information
  • Request deletion of your account and associated data, subject to applicable exceptions
  • Update your communication preferences

To exercise any of these rights, contact us at support@tanniq.co. We may need to verify your identity before acting on certain requests. Some information may be retained where permitted or required by law, as described in Section 8.

Account Deletion

You may request deletion of your tanniq account at any time through account settings or by contacting support@tanniq.co. Deleting your tanniq account does not automatically cancel any winery memberships, orders, shipments, subscriptions, or winery relationships. After deleting your tanniq account, you may still need to manage active winery memberships directly with each winery.

When you delete your tanniq account, tanniq will anonymize your personal information, including any membership-related information retrieved from linked Commerce7 accounts, so that it no longer identifies you. tanniq may retain anonymized records after deletion for security, fraud prevention, legal compliance, dispute resolution, audit, and enforcement purposes, but no personally identifiable information will be retained in connection with a deleted account.

11. California Privacy Rights

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Right to Know / Access. You have the right to request information about the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom we share it.

Right to Delete. You have the right to request deletion of personal information we have collected about you, subject to certain exceptions permitted by law.

Right to Correct. You have the right to request correction of inaccurate personal information we maintain about you.

Right to Opt Out of Sale or Sharing. tanniq does not sell personal information. tanniq does not share personal information for cross-context behavioral advertising. You therefore have no need to opt out of sale or sharing as currently practiced by tanniq, but you may contact us if you have questions.

Right to Non-Discrimination. We will not discriminate against you for exercising your California privacy rights.

Sensitive Personal Information. To the extent tanniq collects sensitive personal information as defined under the CPRA — such as account login credentials managed through authentication providers or precise geolocation data — it is collected and used only as necessary to provide the Services and is not used for inferring characteristics or for purposes beyond operating the Services.

To submit a California privacy rights request, contact us at support@tanniq.co. We may need to verify your identity before fulfilling your request. We will respond within the timeframes required by applicable law.

12. Age Restriction

The Services are intended only for individuals age 21 or older. tanniq does not knowingly allow individuals under 21 to create accounts or use age-restricted features of the Services. If tanniq learns that it has collected personal information from someone under 21, it may take steps to delete or disable the account as appropriate.

13. International Users

The Services are currently intended for use in the United States. If you access the Services from outside the United States, you understand that your information may be processed and stored in the United States.

14. Changes to This Policy

tanniq may update this Privacy Policy from time to time. The updated version will be posted with a revised "Last updated" date. If material changes are made, tanniq may provide additional notice through the Services, by email, or by other reasonable means. Where required by law, additional consent will be obtained before material changes take effect.

15. Contact Us

Questions or concerns about this Privacy Policy? Contact us at support@tanniq.co.