Grapevine Codes™ Privacy Policy
This is an archived version of the Grapevine Codes™ Privacy Policy, kept as a record of what was in force on August 13, 2026.
It is not the current version. Read the current Grapevine Codes™ Privacy Policy.
Last updated: August 13, 2026
This policy explains what personal data Grapevine Codes LLC ("Grapevine", "we") collects, why we collect it, how long we keep it, and what you can ask us to do with it. It covers the Grapevine website at grapevinecodes.com, the Grapevine consumer mobile app, the vendor dashboard, and the integrations Grapevine provides for the commerce and fulfillment systems that vendors connect to their Grapevine account. Shopify is the platform Grapevine supports today; where a statement below applies only to a particular platform, it says so.
We are based in the United States. If you are a vendor and need the contractual data-processing terms rather than this notice, see the Vendor Data Processing section of our Terms of Service.
1. The two roles we play
Which part of this policy applies to you depends on how your data reached us.
- Grapevine as the controller. For consumers who create a Grapevine account, scan or register products, refer friends, earn rewards, and buy through Grapevine, we decide how that data is used and we are responsible for it. Purchases made through Grapevine happen on our own platform and are processed by our own payment processor.
- Grapevine as a processor.When we act on a vendor's behalf, for example by creating an order in the store or fulfillment system that vendor has connected so they can ship it, we handle that data on their instructions, and their privacy policy governs what they do with it.
2. Information we collect
2.1 Directly from consumers
- Account details: name, email address, username, password (stored hashed by our authentication provider), and optionally phone number, gender, and a profile photo.
- Purchase and delivery details: shipping address, contact phone and email, order contents, and the last four digits and brand of the payment card. We never receive or store a full card number; card details go directly to our payment processor.
- Referral and rewards activity: which products you register, the codes you share, which purchases resulted from your shares, and your rewards balance and payout history.
- Anything you send us: support requests, contact-form messages, issue reports, and survey responses.
2.2 Directly from vendors
- Business details: organization name, business contact information, logo and imagery, business hours, and the details required to open a connected payout account with our payment processor.
- Account details for each team member you invite, and their role in your organization.
- Product listings you create or enroll, including prices and the cash reward you set.
2.3 From a vendor's connected commerce or fulfillment system
Vendors connect the system they already use to run their store, so Grapevine can keep listings accurate and hand completed orders over for fulfillment. Today that system is Shopify, and the rest of this section describes that connection specifically. When a vendor connects a Shopify store, Grapevine is granted four permissions: read products, read orders, write orders, and read fulfillments. Using those, we read:
- Product and variant data (titles, descriptions, images, options, prices, SKUs and inventory levels), so enrolled listings stay accurate.
- Order status for orders Grapevine itself created, such as the order number, payment and fulfillment status, and shipment tracking details, so buyers can follow their delivery.
We do not read a vendor's customer records. Grapevine holds no permission to browse customers, and the order queries it makes request no customer name, email, address or phone field.
Data also travels the other way. When someone buys through Grapevine, we sendthat order into the vendor's Shopify store so it can be fulfilled, including the buyer's email address and the shipping name, address and phone number. That information originates from the Grapevine checkout, not from Shopify. Once the order exists in the vendor's store, the vendor's own privacy policy governs it.
2.4 Collected automatically
- Standard server logs: IP address, browser or device type, pages and endpoints requested, and timestamps.
- Scan events: when a Grapevine QR code or NFC tag is scanned, we record the scan and the referral link it carries, so the right person is credited.
- Push notification tokens, if you allow notifications in the mobile app.
We do not use third-party advertising or behavioural-analytics trackers, and we do not sell personal data. The mobile app requests camera access only to scan QR codes; images are processed on your device and not uploaded.
3. Why we use it
- To operate the platform: create and secure accounts, show products, take payment, and attribute referrals and rewards correctly.
- To fulfill orders: pass the order and shipping details to the vendor's fulfillment system and report status back to the buyer.
- To pay people: settle vendor proceeds and consumer reward payouts through our payment processor.
- To communicate: order and shipping updates, reward notifications, service announcements, and replies to your messages.
- To keep the service safe: prevent fraud and abuse, and investigate security incidents.
- To meet legal obligations: tax, accounting, and responding to lawful requests.
Where the GDPR or UK GDPR applies, we rely on: performance of a contract (running your account, completing your purchase); legitimate interests (fraud prevention, securing and improving the service, referral attribution); consent (push notifications and optional marketing, which you can withdraw at any time); and legal obligation (financial record-keeping).
We do not use personal data, including any merchant or customer data obtained through the Shopify API, to train machine learning or artificial intelligence models.
4. Who we share it with
We do not sell personal data and we do not share it for advertising. We share it only with service providers who process it on our behalf, under contract:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting and delivery.
- Stripe — payment processing, vendor payouts, and consumer reward payouts.
- Google Firebase Cloud Messaging — mobile push notifications.
- Google Maps Places — address autocomplete while you type an address.
- Cloudflare Turnstile — bot protection on public forms.
- Resend — transactional email.
- Shopify — for vendors who connect a Shopify store, for the order and catalog exchange described in section 2.3. Other commerce and fulfillment platforms will be added to this list as Grapevine supports them.
We also share data with a vendor when you buy their product: they receive what they need to fulfill and support your order. And we may disclose data where the law requires it, or to protect our rights, users, or the safety of others. If Grapevine is ever involved in a merger or acquisition, personal data may transfer as part of that transaction; we will give notice before it becomes subject to a different policy.
5. How long we keep it
Retention is set per type of data and enforced by scheduled jobs, not by hand:
| Data | How long |
|---|---|
| Account data | For as long as your account is open. On deletion we anonymize the account and remove your saved addresses, notifications and device tokens. |
| Order and transaction records | Retained as financial records for as long as tax and accounting law requires. Personal details within them are redacted on request rather than the record being destroyed. |
| Shipping address on an order | Cleared on an erasure request, except while the order is still being fulfilled, since removing it then would prevent delivery. It is cleared automatically once the order completes. |
| Vendor store access credentials | Deleted when the store is disconnected, and swept within 7 days if a disconnection notice is ever missed. |
| Data-request export files | Deleted 30 days after they are generated. Download links expire after one hour. |
| Guest checkout records | Deleted within 24 hours of being merged into a full account. |
| Server logs | Kept for the retention period of our hosting and database providers. |
6. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, object to or restrict how we use it, receive it in a portable format, and withdraw consent. If you are in California, you also have the right to know what we collect and to opt out of "sharing". We do not sell or share personal data as those terms are defined there. We will not discriminate against you for exercising any of these rights.
You can delete your account yourself from your account settings, on the website or in the Grapevine app. For anything else, send us a message through our contact form. Every submission reaches our team and we answer all of them. We will respond within the time the applicable law allows, which is 30 days in most cases. We may need to verify your identity first, and we may keep records we are legally required to keep.
If you bought from a vendor and want that vendor's copy of your data erased, you can ask either us or the vendor. A request made through a vendor reaches the data we hold in connection with that vendor; it does not close your Grapevine account, which you control directly.
If you are in the EEA or UK, you also have the right to complain to your local data protection authority.
7. Where your data is processed
Grapevine is established in the United States and is not established in Europe. Our service providers process data in the United States, so data collected from the EEA, the UK, or Switzerland is transferred there. Those transfers rely on the European Commission's Standard Contractual Clauses and any additional safeguards applicable law requires.
8. How we protect it
Data is encrypted in transit and at rest. Vendor store credentials are encrypted a second time at the application layer with a key held outside the database. Database queries are issued only by server-side code; our apps hold no database credentials. Access to production systems is limited to people who need it. No system is perfectly secure, but if a breach affects your personal data we will notify you and the relevant authorities as the law requires.
9. Children
Grapevine is not intended for children under 13, and we do not knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change significantly affects you, give notice in the app or by email.
11. Contact us
Grapevine Codes LLC. The way to reach us is our contact form. Every submission goes to our team inbox, and we respond to all of them. Use it for any question about this policy, to exercise the rights described in section 6, or, if you are a vendor, for anything about the data we process on your behalf. You do not need a Grapevine account to send us a message.
Version 2026-08-13. Use your browser's print or "Save as PDF" option to keep a copy; the page is styled to print as a clean document.