Vinkretsen

Privacy policy

Last updated: 2025-05-13

This privacy policy describes how Vinkretsen processes personal data when you use our website, application and services.

Vinkretsen is a digital platform for wine tastings, wine community, importer profiles, a digital cellar, tasting notes, bookings, community tastings and private tastings.

Vinkretsen does not sell alcohol.

1. Who is responsible for your personal data?

Vinkretsen is the data controller for the processing of personal data that takes place within the Vinkretsen platform, unless otherwise stated.

This means Vinkretsen is responsible for how your personal data is processed in connection with, for example, accounts, bookings, tastings, the digital cellar, tasting notes, notifications, payments and platform features.

Wine importers and other external parties may in some cases be independently responsible for personal data they process outside Vinkretsen — for example in their own newsletters, customer registers or external systems.

2. What personal data do we process?

We process different types of personal data depending on how you use Vinkretsen.

Account data

  • name;
  • email address;
  • password or authentication information;
  • profile picture if you add one;
  • user role;
  • account status;
  • date of registration and last activity.

Profile and community data

  • public display name;
  • optional profile bio;
  • followed importers;
  • followed users;
  • tasting groups;
  • comments;
  • reports and moderation history.

Booking and tasting data

  • booked tastings;
  • participant status;
  • ticket or tasting-pass type;
  • payment status;
  • check-in status for in-person events;
  • participation in online tastings;
  • LiveKit / room-related access information;
  • reminder and calendar information.

Digital cellar

  • saved wines;
  • producer;
  • vintage;
  • region;
  • number of bottles;
  • your own notes;
  • drinking window;
  • images you upload;
  • links to tastings or wine lists.

Your cellar is private by default.

Tasting notes and ratings

  • tasting notes;
  • scores;
  • drinking window;
  • "would buy again";
  • images attached to tasting notes;
  • note visibility: private, shared, group-shared or public.

Tasting notes are private by default.

Payment and order data

For paid tastings we process the data needed to handle the booking, payment status, receipt and any refund.

Payments are handled by an external payment provider. Vinkretsen does not store full card details.

Communication and notifications

  • email notifications;
  • booking confirmations;
  • tasting reminders;
  • in-app notifications;
  • push notification settings if you enable them;
  • consents and notification preferences.

Technical information

  • IP address;
  • browser;
  • device type;
  • session information;
  • logs;
  • cookies;
  • debugging data;
  • security events;
  • approximate usage statistics.

Analytics and aggregated statistics

We may process data on how features are used, for example:

  • wine views;
  • clicks to product pages at Systembolaget;
  • additions to cellar;
  • created tasting notes;
  • tasting participation;
  • responses to feedback / NPS.

Importers only see aggregated statistics — never your private notes, private cellar or private personal data.

3. Why do we process personal data?

We process personal data in order to:

  • create and manage your account;
  • let you book and join tastings;
  • handle private and community tastings;
  • give you access to LiveKit tasting rooms;
  • save your digital cellar;
  • save tasting notes and scores;
  • show relevant tastings, importers and wines;
  • send booking confirmations and reminders;
  • handle payments, receipts and refunds;
  • enable importer profiles and wine portfolios;
  • show aggregated statistics to importers;
  • improve the platform;
  • prevent abuse and protect security;
  • comply with legal obligations;
  • handle support, reports and moderation.

4. Legal basis

We process personal data on the following legal bases.

Contract

When you create an account, book a tasting, use your cellar or join a tasting we process data in order to provide the service.

Consent

We may ask for consent for certain types of cookies, analytics, marketing emails or push notifications.

You can withdraw consent at any time where processing is based on consent.

Legitimate interest

We may process certain data for security, debugging, product improvement, aggregated statistics, abuse prevention and relevant in-platform communication.

Legal obligation

We may need to process certain data to comply with legal requirements — for example accounting requirements or handling of legal claims.

5. How do we share personal data?

We do not sell your personal data.

We share personal data only when needed to provide Vinkretsen, to comply with legal requirements or to protect the platform.

Recipients may be:

  • payment provider;
  • email provider;
  • hosting and database services;
  • video technology provider;
  • analytics and error reporting tools;
  • support and security tools;
  • authorities where required by law.

Importers do not get access to your private notes, private cellar, private tastings or personal payment data.

Importers can see aggregated statistics about their own tastings, wines and profiles — for example number of bookings, participants, wine clicks, cellar additions, average ratings and feedback.

6. Systembolaget links

Vinkretsen may show neutral links to public product pages at Systembolaget — for example "View at Systembolaget".

Vinkretsen does not sell alcohol, does not handle orders and has no shopping cart for alcoholic beverages.

Any purchase, order and pickup happens separately at Systembolaget or another legal external channel.

7. Cookies and similar technologies

We use cookies and similar technologies to:

  • make the website work;
  • handle login and security;
  • save settings;
  • analyse usage if you accept analytics cookies;
  • improve the service.

Necessary cookies are used for the service to function. Analytics and marketing cookies are used only if you consent where such consent is required.

You can change cookie settings via the website's cookie settings.

8. How long is the data kept?

We keep personal data for as long as needed for the purposes set out in this policy.

Examples:

  • account data is kept as long as the account exists;
  • booking and payment data is kept according to legal and accounting rules;
  • private cellar data and tasting notes are kept until you delete them or delete your account;
  • logs are kept for a limited time for security and debugging;
  • consents are kept as long as needed to demonstrate that consent was given or withdrawn.

When data is no longer needed it is deleted or anonymised.

9. Your rights

You have the right to:

  • information about how your data is processed;
  • request access to your personal data;
  • request rectification of inaccurate data;
  • request deletion in certain cases;
  • request restriction of processing;
  • object to certain processing;
  • obtain certain data in a structured format;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Some rights may be limited — for example if we need to keep data to comply with legal requirements.

10. Account deletion

You can request deletion of your account via account settings if the feature is available, or by contacting Vinkretsen.

When an account is deleted some data may need to be kept for a limited time or anonymised — for example payment history, accounting records, security logs or content that needs to be preserved for community context.

Private cellars, private tasting notes and private tastings are deleted or anonymised according to our deletion process.

11. Security

We use technical and organisational security measures to protect personal data.

This includes, among other things:

  • access management;
  • role-based access;
  • Row Level Security in the database where applicable;
  • server-side handling of secrets and tokens;
  • encrypted communication;
  • logging of important admin actions;
  • limited access to sensitive data;
  • protection against unauthorised access.

12. International transfers

Some providers may process personal data outside the EU/EEA. In such cases appropriate safeguards must be used — for example standard contractual clauses or another lawful transfer mechanism.

13. Changes to this policy

We may update this privacy policy. For significant changes we inform you in an appropriate way — for example via the website or email.

The latest version is always available on Vinkretsen.