Grapevine Codes™ Privacy Policy
Effective date: August 18, 2026 · Last updated: August 18, 2026
This Privacy Policy explains how Grapevine Codes LLC ("Grapevine," "we," "us," or "our") collects, uses, discloses, retains, and protects personal information.
This Privacy Policy applies to:
- the Grapevine website and web applications;
- Grapevine consumer mobile applications;
- the Grapevine vendor dashboard;
- Grapevine checkout, product-registration, referral, QR-code, and NFC-tag services;
- reward and settlement features;
- guest checkout;
- support and communications; and
- integrations that vendors connect to Grapevine, including supported commerce and fulfillment platforms.
Together, these are the "Services."
This Privacy Policy does not replace the privacy policy of a vendor from whom you purchase a product or the privacy policy of a connected commerce, fulfillment, identity, or payment provider.
1. Who We Are and the Roles We Perform
1.1 Grapevine as a controller
Grapevine determines the purposes and means of processing for information relating to:
- Grapevine consumer accounts;
- guest checkout;
- purchases initiated through Grapevine;
- payment and transaction records;
- product registrations;
- QR-code, NFC-tag, and referral activity;
- reward balances and reward records;
- Grapevine vendor accounts and organization administration;
- customer and vendor support;
- security, fraud prevention, and abuse prevention;
- service administration and aggregated platform analytics; and
- Grapevine's legal, tax, accounting, and regulatory obligations.
In those contexts, Grapevine acts as a controller, business, or similarly responsible organization under applicable privacy law.
1.2 Grapevine as a processor for vendors
When Grapevine handles personal information solely to operate an integration for a vendor — for example, by transmitting an order to the vendor's connected fulfillment system, retrieving the fulfillment status of that order, or responding to a request concerning that vendor's customer relationship — the vendor generally determines the purpose of that processing and Grapevine acts on the vendor's instructions.
A vendor's instruction or deletion request applies only to information processed in connection with that vendor. It does not authorize the vendor to delete a consumer's separate Grapevine account, reward balance, or relationship with another vendor.
1.3 Separate responsibilities
A vendor, payment provider, authentication provider, and connected commerce platform may process information under its own privacy notice and for its own purposes. Grapevine is not responsible for another organization's independent privacy practices.
2. Information We Collect
The information we collect depends on how you use the Services.
2.1 Consumer account and authentication information
When you create or use a Grapevine account, we may collect:
- your name;
- email address;
- username;
- telephone number;
- gender, if you choose to share it — the question is asked during account setup and you may skip it by selecting "Skip / Prefer not to say"; your answer is not visible to other users or vendors. We ask so that future features, such as personalized product recommendations, can take it into account. No current feature uses it, and we will update this Privacy Policy when one does;
- an optional profile image;
- account status and account preferences;
- internal user identifiers;
- authentication and email-verification status;
- organization roles and permissions, where applicable; and
- information needed to secure, deactivate, reactivate, or delete your account.
Authentication is provided through our authentication provider. We do not store your password in readable form.
If you sign in through an external identity provider, such as Google or Apple, we may receive the account identifier, email address, verification status, name, or other information that you authorize that provider to disclose.
2.2 Guest-checkout information
You may be able to complete a purchase without creating a login account.
For guest checkout, we may collect:
- your email address;
- an optional telephone number;
- your fulfillment name;
- your shipping address;
- purchase and order information; and
- a randomly generated internal identifier.
A guest checkout does not create a password or a full user profile. We create a limited guest record so that we can complete the order and, if you later register using the same email address, offer to attach eligible purchase history, registered products, and related records to your account.
2.3 Purchase, order, and payment information
When a purchase is initiated through Grapevine, we may collect or generate:
- purchaser name, email address, and telephone number;
- shipping name and address;
- items purchased, quantity, price, currency, and total;
- internal transaction and order identifiers;
- vendor and product identifiers;
- payment status and payment-method type;
- payment-provider identifiers;
- the last four digits of a payment card, where made available by the payment provider;
- refund, cancellation, chargeback, or failure information;
- order, financial, fulfillment, and shipment status;
- tracking information;
- processor fees, platform fees, reward amounts, and settlement information; and
- timestamps and accounting records.
Payment-card information is collected through the payment provider. Grapevine does not receive or store a complete payment-card number or card security code.
2.4 Product registration, referral, scan, and reward information
We may collect or generate:
- products you register;
- QR-code, NFC-tag, referral-link, and code identifiers;
- the vendor and product associated with a code;
- referral relationships;
- the referrer and purchaser associated with a qualifying transaction;
- scan timestamps, channel, product, vendor, and code information;
- a consumer identifier or anonymous scan identifier;
- reward eligibility results;
- reward balances and reward-ledger entries;
- reward amounts earned, spent, reversed, or forfeited;
- the transaction linked to a reward;
- payout or verification status, if a payout feature is offered; and
- records used to identify self-referrals, duplicate activity, or suspected fraud.
Our scan-event records are designed not to contain precise location information. Hosting and security logs may separately contain an IP address.
2.5 Vendor and vendor-team information
When a vendor uses Grapevine, we may collect:
- organization and business name;
- business contact and mailing information;
- organization logo, icon, and other branding;
- vendor owner, administrator, and member information;
- team-member names, email addresses, invitations, and roles;
- product listings, product images, variants, options, pricing, inventory, and reward amounts;
- connected-store domain and integration status;
- fulfillment and payout-account status;
- vendor-specific fee rates;
- support requests and attachments; and
- credentials or tokens needed to operate a connected integration.
2.6 Information from connected commerce and fulfillment platforms
A vendor may authorize Grapevine to connect to a commerce or fulfillment platform.
For Shopify integrations, Grapevine currently uses permissions needed to:
- read product and variant information;
- read orders;
- create orders; and
- read fulfillment information.
Through that integration, Grapevine may receive:
- product names, descriptions, images, options, variants, SKUs, prices, and inventory information;
- store and integration identifiers;
- order identifiers for orders created by Grapevine;
- payment and fulfillment status;
- shipment status and tracking information; and
- related timestamps.
Grapevine does not request permission to browse a Shopify merchant's general customer list. Its order-status requests for Grapevine-created orders are designed not to request customer names, email addresses, telephone numbers, or shipping addresses from Shopify.
Automatic order-update notifications sent by the platform for Grapevine-created orders may echo back customer details that Grapevine itself supplied when it created the order. Grapevine handles that information as part of the original order record.
Information also travels from Grapevine to the connected platform. For example, when a buyer places an order through Grapevine, Grapevine may send the buyer's email address, fulfillment name, telephone number, shipping address, and purchased items to the vendor's connected store so the vendor can fulfill the order.
A future integration may involve different information. We will update this Privacy Policy when a new integration materially changes our processing.
2.7 Communications, support, and issue reports
We collect information you include in:
- contact forms;
- customer-support requests;
- vendor-support requests;
- issue or bug reports;
- screenshots and attachments;
- responses to service communications; and
- other communications with Grapevine.
Because free-text fields may contain personal information, you should avoid including information that is not necessary for us to address your request.
2.8 Device, log, and security information
We and our providers may automatically process:
- IP address;
- browser and device type;
- operating system;
- requested page, route, or endpoint;
- request time and response information;
- session and authentication information;
- cookie or local-storage identifiers;
- push-notification tokens;
- security and fraud signals;
- error and diagnostic information;
- anti-bot challenge information; and
- information about account, checkout, or integration events.
2.9 Address-autocomplete information
When you use address autocomplete, address fragments you enter and a coarse city, state, or postal-code bias may be sent to the address provider to return suggested addresses.
3. How We Use Personal Information
We use personal information to:
- create, authenticate, secure, and administer accounts;
- operate guest checkout;
- display products and product information;
- process purchases and confirm payment;
- create and route orders for fulfillment;
- provide delivery and fulfillment status;
- register products and generate referral identifiers;
- attribute qualifying referrals;
- calculate, credit, spend, reverse, or forfeit rewards;
- settle vendor proceeds and reconcile processor fees;
- provide vendor dashboards, product management, and analytics;
- provide transactional email, push notifications, and service announcements;
- respond to support and issue reports;
- prevent self-referrals, fabricated scans, account abuse, fraud, and security incidents;
- maintain accounting, tax, audit, dispute, and settlement records;
- enforce our Terms of Service and vendor agreements;
- comply with law and valid legal process;
- protect the rights, safety, and property of Grapevine, users, vendors, and others; and
- produce aggregated or pseudonymous statistics concerning use of the Services.
We may use automated rules to determine reward eligibility, identify self-referrals, detect suspected fraud, change account status, route settlements, or protect the Services. You may contact us to request review of a decision where applicable law provides that right.
4. Legal Bases for Processing
Where the GDPR, UK GDPR, or another law requiring a legal basis applies, Grapevine relies on one or more of the following:
- Contract: to create and administer an account, complete a checkout, process a transaction, provide referrals and rewards, operate a vendor account, or perform another service you request.
- Legitimate interests: to secure and improve the Services, prevent fraud, attribute referrals, provide support, administer the business, maintain pseudonymous analytics, and protect legal rights.
- Consent: where we request consent for optional marketing, push notifications, non-essential technologies, or another activity for which consent is required.
- Legal obligation: to maintain tax, accounting, payment, sanctions, security, or legally required records and to respond to lawful process.
- Documented vendor instructions: when Grapevine processes information solely on behalf of a vendor.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that occurred before the withdrawal.
5. How We Disclose Information
We disclose information only as reasonably necessary for the purposes described in this Privacy Policy.
5.1 Vendors
When you purchase a vendor's product, the vendor receives information needed to:
- accept and fulfill the order;
- deliver the product;
- provide order support;
- administer returns or warranties;
- address a recall, dispute, or legal obligation; and
- perform other activities disclosed at checkout.
Once information is held in a vendor's own systems, that vendor's privacy practices apply.
5.2 Service providers and connected platforms
We currently use the following types of providers:
- Supabase: database hosting, authentication, object storage, and related infrastructure.
- Vercel: website, application, and API hosting and delivery.
- Stripe: payment processing, connected vendor accounts, transfers, and related payment services.
- Google Firebase Cloud Messaging: mobile push-notification delivery.
- Resend: transactional email delivery.
- Google Maps Places: shipping-address autocomplete.
- Cloudflare Turnstile: bot protection on selected public forms.
- Shopify: product, order, and fulfillment exchange for vendors who connect a Shopify store.
These providers receive only the information reasonably needed for their function. A provider may process information under its own privacy notice and legal obligations in addition to processing it for Grapevine.
5.3 Legal, safety, and corporate disclosures
We may disclose information:
- where required by law, subpoena, court order, or valid governmental request;
- to investigate fraud, abuse, security incidents, or violations of our agreements;
- to protect rights, property, safety, or the integrity of the Services;
- to professional advisers, auditors, insurers, and legal counsel subject to appropriate confidentiality obligations;
- in connection with financing, a merger, acquisition, reorganization, sale of assets, or similar transaction; or
- with your direction or consent.
6. No Sale, Targeted Advertising, or AI Training
Grapevine does not:
- sell or rent personal information;
- share personal information for cross-context behavioral advertising;
- operate third-party advertising trackers;
- use merchant, customer, or platform personal information to train, fine-tune, or evaluate machine-learning or artificial-intelligence models; or
- disclose merchant or customer information to an external model provider for those purposes.
Grapevine may use aggregated statistics and pseudonymous operational information to administer and improve the Services, provided that this use is not for targeted advertising or AI-model training.
The Grapevine referral program provides compensation for qualifying referral activity. It is not offered in exchange for permission to sell or share personal information.
7. Cookies, Local Storage, and Similar Technologies
The Services use technologies needed to:
- keep you signed in;
- protect account sessions;
- remember service and environment preferences;
- support checkout and referral attribution;
- detect fraud and abuse;
- display account notices; and
- operate requested features.
These technologies may include cookies, authentication tokens, local storage, session storage, and referral identifiers.
Grapevine does not currently use third-party advertising or behavioral-analytics cookies. If we introduce non-essential analytics or advertising technologies, we will update this Privacy Policy and obtain consent or provide opt-out controls where required.
Disabling essential cookies or storage may prevent account, checkout, or security features from working.
8. Data Retention
We retain information according to its purpose, sensitivity, legal requirements, and the technical design of the Services.
| Category | General retention approach |
|---|---|
| Consumer account and profile | Retained while the account exists. Deactivation is reversible and does not erase the account. Permanent deletion removes the authentication identity and removes or replaces direct profile identifiers. |
| Saved addresses, push tokens, and in-app notifications | Generally retained during the account relationship and deleted when the account is permanently deleted. |
| Unclaimed guest-checkout record | Retained for as long as the guest-purchase claim feature remains available, which may be indefinite, unless the guest requests deletion or law requires a shorter period. |
| Claimed guest record | After eligible records are transferred to a full account, the guest record is ordinarily deleted after a 24-hour safety period, provided it no longer owns transaction records. |
| Orders, transactions, settlement records, and reward ledger | Financial facts may be retained for an extended period or indefinitely for accounting, tax, reconciliation, fraud, chargeback, dispute, and audit purposes. Direct identity fields are removed or replaced when deletion or redaction applies. |
| Shipping information on an open order | May be retained after a deletion or redaction request until the order is delivered, completed, cancelled, refunded, or otherwise reaches a terminal status. It is then scheduled for removal. |
| Scan and referral-event facts | May be retained long term for product analytics, attribution, and abuse prevention. After account deletion, associated account information is removed or replaced so the event is retained in pseudonymous form. |
| Connected-platform credentials | Retained while the connection is active. Credentials are deleted when the platform is disconnected, with a fallback process intended to remove missed credentials within seven days. |
| Product and catalog records | May be deactivated rather than deleted so historical orders and line-item records remain understandable. |
| Support, issue, invitation, security, and audit records | Retained for as long as reasonably needed for support, security, abuse prevention, disputes, audit, and legal obligations. Certain records may be retained for an extended period or indefinitely. |
| Data-request export files | Deleted 30 days after they are generated. Signed download links expire after one hour. |
| Application and infrastructure logs | Retained according to the applicable hosting, database, authentication, and infrastructure provider's settings and plan. |
| Images and attachments | When the associated database reference is removed, unreferenced files are deleted through routine storage-cleanup processes. |
We may retain information longer where required by law, subject to a legal hold, needed for an unresolved dispute, or reasonably necessary to prevent fraud or abuse.
When possible, we limit retained records by deleting, redacting, tombstoning, aggregating, or pseudonymizing direct identifiers.
9. Account Deactivation and Deletion
9.1 Deactivation
Account deactivation is reversible.
While an account is deactivated:
- the account data remains in Grapevine;
- public or referral identity may be hidden or shown generically;
- the reward balance is frozen;
- the user cannot use the account until reactivation; and
- new referral rewards that would otherwise be credited may be forfeited under the Terms of Service.
Logging in may reactivate a deactivated account.
9.2 Permanent deletion
Account deletion is intended to be permanent.
When deletion is completed:
- the authentication identity is removed;
- ordinary profile identifiers are removed or replaced;
- saved addresses, push-notification tokens, and notifications are deleted;
- personal fields on completed orders and transactions are removed or replaced;
- financial, settlement, reward, security, and audit facts may remain without ordinary identity fields;
- shipping information for an order still in progress may remain until fulfillment is complete and is then scheduled for removal;
- a remaining reward balance is treated as described in the Terms of Service; and
- a new registration using the same email address may create a new internal account rather than restore the deleted account.
Deleting an account does not cancel an existing order.
A person who is the sole owner of a vendor organization may be required to transfer ownership or close the organization before deleting the account.
9.3 Vendor-scoped deletion or redaction
A request made by or through one vendor applies to personal information connected with that vendor.
It may remove identity information from that vendor's orders, transactions, exports, and related reward records. It does not automatically delete:
- the consumer's Grapevine account;
- the consumer's saved addresses;
- the consumer's platform-wide reward balance;
- the consumer's relationship with another vendor; or
- information for which Grapevine acts independently as controller.
10. Your Privacy Rights
Depending on where you live, you may have the right to:
- request confirmation that we process your information;
- access personal information;
- correct inaccurate information;
- delete personal information;
- obtain a portable, machine-readable copy;
- object to or restrict certain processing;
- withdraw consent;
- opt out of targeted advertising, sale, or sharing;
- limit certain uses of sensitive information;
- appeal a denial of a privacy request; and
- complain to a privacy or data-protection authority.
Grapevine does not sell personal information or share it for cross-context behavioral advertising.
10.1 How to submit a request
You may use available account settings to update or delete certain information.
For another request, contact: Email: privacy@grapevinecodes.com · Mail: Grapevine Codes LLC, Attn: Privacy, 850 Lindy Ln, Huntingtown, MD 20639
We may need to verify your identity before completing a request. Verification information will be used only to process the request.
An authorized agent may submit a request where permitted by law. We may require proof of the agent's authority and may separately verify the consumer's identity.
We will respond within the period required by applicable law. We may extend the response period where the law permits and will provide notice of an extension.
If we deny a request, we will explain the reason where required. You may appeal by contacting privacy@grapevinecodes.com with "Privacy Appeal" in the subject line.
We will not discriminate against you for exercising an applicable privacy right.
10.2 Vendor-controlled information
Where Grapevine holds information solely on behalf of a vendor, we may refer the request to that vendor or coordinate with the vendor. A request concerning a vendor's copy of an order does not automatically delete the requester's separate Grapevine account.
10.3 Marketing and notifications
You may unsubscribe from marketing emails using the link in the message or by contacting us. You may disable push notifications through your device settings.
We may still send non-promotional communications needed for purchases, security, account administration, legal notices, or support.
10.4 EEA and UK complaints
If the GDPR or UK GDPR applies, you may lodge a complaint with the data-protection authority in the country where you live, work, or believe a violation occurred.
11. International Processing
Grapevine is based in the United States, and the Services are currently offered and directed only to users in the United States. The Services are not directed to persons in the European Economic Area or the United Kingdom.
We and our providers may process information in the United States and other countries where they operate.
Those countries may have privacy laws different from the laws where you live. Where applicable law requires a transfer safeguard, we use an available legal mechanism such as an adequacy decision, contractual data-transfer clauses, a UK transfer mechanism, or another recognized safeguard.
You may contact privacy@grapevinecodes.com for information about a safeguard applicable to your information.
12. Security
Grapevine uses administrative, technical, and organizational measures designed to protect information, including measures relating to:
- encryption in transit and at rest;
- application-layer encryption of connected-platform access credentials, with the encryption key held outside the database;
- account authentication;
- server-side authorization;
- organization-based access controls;
- restricted access to production systems;
- webhook-signature verification;
- credential and secret management;
- fraud and abuse prevention; and
- incident response.
No system or transmission method is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur.
If a security incident affects personal information, we will investigate, contain, and provide notices as required by applicable law and relevant contractual obligations.
13. Children
The Services are not intended for anyone under 18 years old, and creating an account requires attesting that you are at least 18.
We do not knowingly permit a person under 18 to create an account, participate in the reward program, or operate a vendor account, and we do not knowingly collect personal information from anyone under 18.
If you believe a minor has provided personal information, contact privacy@grapevinecodes.com and we will delete it.
14. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in the Services, data practices, providers, or law.
We will update the "Last Updated" date. Where a change is material, we may provide additional notice through the Services, by email, or through another reasonable method.
Material changes will apply prospectively unless law permits or requires otherwise.
15. Contact Us
Grapevine Codes LLC · Attn: Privacy · 850 Lindy Ln, Huntingtown, MD 20639 · privacy@grapevinecodes.com · support@grapevinecodes.com
Review our Refund and Returns Policy here.
Version 2026-08-18. Use your browser's print or "Save as PDF" option to keep a copy; the page is styled to print as a clean document.
Previous versions: