Privacy Policy
Effective Date: March 2, 2026
Welcome to Pourly Done (“we,” “our,” or “us”). This Privacy Policy explains how we collect, use, and
protect your personal information when you use the Pourly Done mobile application (the “App”), available
on iOS (App Store) and Android (Google Play).
We are committed to protecting your privacy and being transparent about the data we handle. Please read
this policy carefully. By using the App, you agree to the practices described below.
1. Information We Collect
Account Information
When you create an account, we collect your name and email address
through Google Sign-In or Apple Sign-In (OAuth). We do not store your password — authentication
is handled entirely by Google or Apple through our authentication provider, Supabase.
User-Generated Content
When you use the App, you may choose to create and store:
- Tasting notes and ratings
- Product reviews
- Venue check-ins
- Home bar inventory records
- Custom product lists and categories
This content is stored in our cloud database (hosted by Supabase) and is associated with your account.
Product Photos
You may take or upload photos of bottles and products. These images are stored in our cloud storage
(hosted by Supabase) and are associated with your account.
Device & Usage Information
We collect standard device and usage information provided by the Apple App Store and Google Play Store
(such as device type, operating system version, and crash reports). We do not currently use any
third-party analytics SDKs within the App itself.
2. How We Use Your Information
We use the information we collect to:
- Provide the App’s features — authenticate your account, store your tasting notes, reviews, inventory, and other user-generated content
- Display nearby venues — use your location to show relevant places on the map
- Enable product lookup — use your camera to scan barcodes and identify products
- Improve the App — understand how the App is used and fix bugs
- Communicate with you — respond to support requests or send service-related notices
What we do NOT do: We do not sell your personal data to third parties. We do not
use advertising SDKs or show ads. We do not track you across other apps or websites. We do not use
fingerprinting or cross-device tracking.
3. Third-Party Services
The App uses the following third-party services to function:
-
Supabase — Provides authentication, cloud database, and file storage. Your
account data, user-generated content, and product photos are stored on Supabase’s cloud
infrastructure. Supabase Privacy Policy -
Google Sign-In — Used for account authentication on all platforms. Google
receives your authentication request and provides us with your name and email.
Google Privacy Policy -
Apple Sign-In — Used for account authentication, primarily on iOS. Apple
provides us with your name and email (or a private relay email, if you choose to hide your email).
Apple Privacy Policy -
Mapbox — Provides map display for venue discovery. Your approximate location
is sent to Mapbox to render the map. Mapbox may collect usage data as described in their privacy
policy. Mapbox Privacy Policy
We only share data with these services to the extent necessary to provide the App’s functionality. We
do not share your data with any other third parties.
4. Data Storage & Security
Your data is stored on Supabase’s cloud infrastructure, which uses industry-standard security measures
including encryption in transit (TLS) and encryption at rest. Access to the database is protected by
row-level security policies that ensure you can only access your own data.
While we take reasonable measures to protect your information, no method of electronic transmission or
storage is 100% secure. We cannot guarantee absolute security, but we are committed to maintaining
appropriate safeguards.
5. Camera & Location Permissions
Camera
The App requests camera access for two purposes: barcode scanning (to look up products
by their UPC code) and product photography (to capture images of bottles for your
personal collection). Camera access is optional — you can use the App without granting this
permission, though barcode scanning and photo features will be unavailable.
Location
The App requests location access to display nearby venues on a map. Your location is used in real time
to center the map and show relevant places. Your location data is not stored on our
servers. It is sent to Mapbox solely to render the map view. Location access is optional —
you can use the App without granting this permission, though the venue map will not be able to show
your nearby area.
6. Children’s Privacy
The App is intended for users who are 18 years of age or older. The App relates to
alcoholic beverages, and we do not knowingly collect personal information from anyone under the age of
18. If we learn that we have collected personal information from a child under 18, we will take steps
to delete that information promptly. If you believe a child under 18 has provided us with personal
data, please contact us at the email address below.
7. Data Retention & Deletion
We retain your account data and user-generated content for as long as your account is active. If you
wish to delete your account and all associated data, you may request deletion by contacting us at
support@pourlydone.com.
Upon receiving a valid deletion request, we will:
- Remove your consumer profile and account data
- Delete your tasting notes, reviews, check-ins, and inventory records
- Delete your uploaded product photos from cloud storage
- Remove your authentication credentials from our system
Deletion is typically completed within 30 days of your request. Some data may be retained in encrypted
backups for a limited period before being purged through normal backup rotation.
8. Your Rights (EU/EEA Users — GDPR)
If you are located in the European Union or European Economic Area, you have the following rights under
the General Data Protection Regulation (GDPR):
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure — You can request that we delete your personal data.
- Right to restrict processing — You can ask us to limit how we use your data.
- Right to data portability — You can request your data in a structured, machine-readable format.
- Right to object — You can object to the processing of your personal data.
- Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time.
Our legal basis for processing your personal data is your consent (provided when you
create an account and use the App) and our legitimate interest in providing and improving
the App’s services. To exercise any of these rights, please contact us at the email address below.
9. Your Rights (California Users — CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the
following rights:
- Right to know — You can request information about what personal data we collect, use, and disclose.
- Right to delete — You can request deletion of your personal data.
- Right to opt out of sale — We do not sell your personal data, so this right does not apply. However, you may still make this request and we will confirm that no sale has occurred.
- Right to non-discrimination — We will not discriminate against you for exercising any of your CCPA rights.
To exercise any of these rights, please contact us at the email address below. We will respond to
verifiable requests within 45 days.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the
“Effective Date” at the top of this page. If we make material changes, we will notify you through the
App or by other appropriate means. We encourage you to review this policy periodically to stay
informed about how we protect your data.
11. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data rights, or need to
report a privacy concern, please contact us:
Pourly Done, LLC
Email: support@pourlydone.com