Grapevine Codes™ Terms of Service
This is an archived version of the Grapevine Codes™ Terms of Service, kept as a record of what was in force on August 13, 2026.
It is not the current version. Read the current Grapevine Codes™ Terms of Service.
Last updated: August 13, 2026
These terms govern your use of Grapevine, which comprises the website at grapevinecodes.com, the Grapevine mobile apps, the vendor dashboard, and the integrations Grapevine provides for the commerce and fulfillment systems that vendors connect to their Grapevine account (Shopify today; others as Grapevine adds support for them), all operated by Grapevine Codes LLC ("Grapevine", "we"). How we handle personal data is described in our Privacy Policy; vendors should also read the Vendor Data Processing section below.
Acceptance of Terms
By accessing or using Grapevine, you agree to be bound by these terms. If you do not agree to these terms, you may not use our services.
Accounts
You must be at least 13 years old to hold a Grapevine account, and old enough to enter a binding contract to make a purchase or receive a payout. Give accurate information, keep your password confidential, and tell us promptly if you think your account has been compromised. You are responsible for activity under your account. You can close your account at any time from your account settings.
Use of Services
Use Grapevine only for lawful purposes and in line with these terms. Do not misrepresent who you are; interfere with, overload, or probe the service; try to access accounts or data that are not yours; scrape or bulk-extract content; reverse engineer the service except where law permits it; upload malware or unlawful, infringing, or abusive content; or manipulate referrals and rewards, including by self-referral, fake accounts, or fabricated scans or purchases. We may withhold or reverse rewards obtained this way.
Purchases, Referrals and Rewards
Purchases made through Grapevine are contracts between you and the vendor whose product you buy. Grapevine operates the platform, processes the payment through its payment processor, and passes the order to the vendor to fulfill. The vendor is responsible for the product, for shipping it, and for their own return and warranty policy.
Rewards are cash amounts set by the vendor and credited to your Grapevine balance when a qualifying referred purchase completes. A reward may be reversed if the underlying purchase is refunded, charged back, cancelled, or found to be fraudulent. Rewards have no value outside Grapevine, are not transferable, and are not a bank deposit. Payouts are made through our payment processor and may require identity or tax information before they can be released. You are responsible for any tax on rewards you receive.
Vendor Responsibilities
As a vendor you are responsible for: the accuracy of your listings, prices, and reward amounts; having the right to sell what you list; fulfilling orders you receive and honoring your stated shipping, return and warranty terms; complying with the laws that apply to your business, including consumer protection, product safety, tax, and data protection; and keeping your connected fulfillment and payout accounts in good standing. You grant Grapevine a non-exclusive licence to display your brand name, logo, and product content for the purpose of operating and promoting the platform. You may withdraw products at any time; doing so does not cancel orders already placed.
Platform Fees and Settlement
Grapevine retains a platform fee from transactions it processes, and settles the net proceeds to the vendor through our payment processor. The fee applicable to a transaction is the one in effect and disclosed to the vendor when that transaction occurs. Grapevine is free to install and creates no charges in any connected third-party account.
Intellectual Property
Grapevine and its underlying technology, including patent-pending elements, remain our property. You keep ownership of the content you submit and grant us the licence needed to host and display it in the service. You may not use our name or logo without permission.
Vendor Data Processing
This section is the data processing agreement between Grapevine Codes LLC ("Grapevine") and each vendor organization that connects a commerce or fulfillment system to Grapevine. It applies in addition to the rest of these terms and governs personal data handled through that connection.
1. Roles of the parties
Grapevine acts in two distinct capacities, and the distinction determines who may instruct whom:
- Grapevine as processor. When Grapevine transmits data to, or reads data from, a system you control (for example, creating an order in your connected store so you can fulfill it, or reading your product catalog and order status), Grapevine processes that data on your behalf and on your instructions. You are the controller of the customer records held in your own store.
- Grapevine as controller. Grapevine is the controller of the data belonging to its own platform: consumer accounts, the referral graph, rewards balances, and the transactions Grapevine originates and processes. Consumers hold this relationship with Grapevine directly, not with any individual vendor.
A practical consequence: an erasure request you forward to Grapevine is honored for the personal data Grapevine holds in connection with your organization. It does not delete that individual's Grapevine account or their history with other vendors, because your instruction does not extend to data for which Grapevine is the controller. Consumers exercise those rights directly with Grapevine through their account settings.
2. Scope and purpose of processing
Subject matter: operating the integration between Grapevine and your commerce or fulfillment system. Duration: for as long as the integration is connected, plus the retention periods described below. Categories of data subject: your customers and the consumers who purchase your products through Grapevine. Categories of personal data: name, email address, postal address, phone number, order and fulfillment details. Grapevine does not receive or store full payment card numbers.
Grapevine processes this data only to provide the service: importing orders for fulfillment, keeping catalog and inventory data current, and reporting order and shipping status. Grapevine does not sell personal data, does not share it with third parties other than the sub-processors listed below, and does not use merchant or customer data to train machine learning or artificial intelligence models.
3. Security measures
Data is encrypted in transit (TLS) and at rest (AES-256). Access credentials for your connected systems are additionally encrypted at the application layer with a key held outside the database. Database queries are issued only by server-side application code; the consumer and vendor applications hold no database credentials, and the narrow real-time subscriptions they do open are constrained by row-level security policies. Access to production systems is limited to personnel who require it.
4. Sub-processors
Grapevine uses a limited set of infrastructure providers: Supabase (database, authentication, file storage), Vercel (application hosting), Stripe (payment processing and vendor payouts), Google Firebase Cloud Messaging (mobile push notifications), and Resend (transactional email). Grapevine remains responsible for its sub-processors' performance and will give notice of material changes to this list.
5. Retention and deletion
Retention periods are set per data class and enforced by scheduled jobs. Access credentials for a disconnected system are deleted on disconnection, with a reconciliation sweep as a fallback. Order and transaction records are retained as financial records, with personal data redacted rather than the records deleted, so that accounting and tax obligations can still be met. On termination, Grapevine deletes or redacts the personal data it processes on your behalf, except where retention is required by law.
6. Assistance with data subject requests
Grapevine assists you in responding to requests from data subjects to access, correct, or erase their personal data. Where your commerce platform provides a channel for these requests, Grapevine acts on them automatically: a data request produces an export you can download from your dashboard, and an erasure request is carried out within the timeframe the platform requires, scoped as described in section 1.
7. Personal data breaches
Grapevine will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and will provide the information you reasonably need to meet your own notification obligations. Where a breach involves data obtained through a commerce platform's API, Grapevine will also notify that platform within any period its terms require. For Shopify, that period is 24 hours from becoming aware.
8. International transfers
Grapevine and its sub-processors operate in the United States. Where personal data is transferred from the European Economic Area, the United Kingdom, or Switzerland, that transfer relies on the European Commission's Standard Contractual Clauses and any additional safeguards required by applicable law.
9. Information and audit
On reasonable written request, and no more than once a year unless required by a supervisory authority, Grapevine will provide the information necessary to demonstrate compliance with this section.
Suspension and Termination
You may stop using Grapevine and close your account at any time. We may suspend or terminate access if you breach these terms, if we are required to by law, or to protect the platform and its users from fraud or harm. Where it is reasonable to do so we will give notice first. On termination, obligations that by their nature should survive, such as fees already incurred, the data processing section, limitations of liability, and dispute terms, continue to apply.
Disclaimers
Grapevine is provided "as is" and "as available", without warranties of any kind to the fullest extent the law allows, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the service will be uninterrupted or error-free. We are not a party to the sale contract between a consumer and a vendor, and we do not warrant the products vendors list. Nothing here excludes liability that cannot lawfully be excluded, including, where they apply, your statutory consumer rights.
Limitation of Liability
To the fullest extent permitted by law, Grapevine is not liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, data, or goodwill. Our total liability arising out of or relating to these terms or the service is limited to the greater of the amounts you paid to, or were owed by, Grapevine in the twelve months before the event giving rise to the claim, or one hundred US dollars.
Governing Law
These terms are governed by the laws of the State of Maryland, United States, without regard to its conflict-of-laws rules, and the state and federal courts located in Maryland have exclusive jurisdiction over any dispute, except that either party may seek injunctive relief in any court of competent jurisdiction, and except where the mandatory law of your country of residence gives you the right to bring proceedings elsewhere.
Changes to These Terms
We may update these terms. If a change is material we will update the date at the top of this page and, where it significantly affects you, give notice in the app or by email. Continuing to use Grapevine after a change takes effect means you accept the updated terms. If you do not accept them, stop using the service and close your account.
Contact
Grapevine Codes LLC. For questions about these terms, including the Vendor Data Processing section, send us a message through our contact form. Every submission goes to our team inbox, and we respond to all of them.
Version 2026-08-13. Use your browser's print or "Save as PDF" option to keep a copy; the page is styled to print as a clean document.