Effective Date: [Date]
Last Updated: [Date]
1. Introduction
[Your Company Name] ("Company," "we," "us," or "our") operates the BenchpriceDTC platform ("Service"). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
2.1 Personal Information You Provide
When you create an account or use our Service, we may collect:
Account Information:
- Name and contact information (email address, phone number)
- Company name and business information
- Billing address and payment information
- Username and password
Profile Information:
- Job title and role
- Wine industry experience and interests
- Communication preferences
User-Generated Content:
- Wines saved to your personal cellar
- Search queries and filters used
- Feedback, reviews, and communications with us
2.2 Information We Collect Automatically
Usage Data:
- Pages visited and features used
- Time spent on our platform
- Search queries and results viewed
- Click patterns and user interactions
- Device information (browser type, operating system, IP address)
Analytics Data:
- Website traffic and user behavior patterns
- Feature usage statistics
- Performance metrics and error logs
Cookies and Tracking Technologies:
- Essential cookies for platform functionality
- Analytics cookies to understand user behavior
- Preference cookies to remember your settings
2.3 Information from Third Parties
Payment Processors:
- Transaction data and payment verification
- Billing and subscription status information
Data Partners:
- Wine pricing information from public sources
- Market data and industry benchmarks
- Winery and product information for our database
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Service Provision
- Create and manage your account
- Process payments and subscriptions
- Provide wine pricing data and market analytics
- Maintain your personal wine cellar
- Deliver customer support and respond to inquiries
3.2 Service Improvement
- Analyze usage patterns to enhance our platform
- Develop new features and functionality
- Improve data accuracy and coverage
- Optimize user experience and interface design
3.3 Communication
- Send service-related notifications
- Provide account and billing updates
- Share relevant industry insights (with your consent)
- Respond to your questions and feedback
3.4 Business Operations
- Prevent fraud and ensure platform security
- Comply with legal obligations
- Enforce our Terms of Service
- Protect our rights and the rights of other users
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal information based on the following legal grounds:
- Contract Performance: To provide our Service and fulfill our contractual obligations
- Legitimate Interests: To improve our Service, prevent fraud, and operate our business
- Consent: For marketing communications and non-essential cookies (where required)
- Legal Compliance: To comply with applicable laws and regulations
5. How We Share Your Information
5.1 We Do NOT Sell Personal Information
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.2 Service Providers
We may share information with trusted third-party service providers who help us operate our business:
- Payment processors (Stripe, PayPal) for billing and subscription management
- Cloud hosting providers (AWS, Google Cloud) for data storage and platform hosting
- Analytics services (Google Analytics) for usage analysis and platform optimization
- Customer support tools for providing assistance and resolving issues
- Email services for sending transactional and marketing communications
5.3 Business Transfers
If we are involved in a merger, acquisition, or asset sale, your personal information may be transferred as part of that transaction.
5.4 Legal Requirements
We may disclose your information when required by law or to:
- Comply with legal process or government requests
- Protect our rights, property, or safety
- Prevent fraud or illegal activities
- Enforce our Terms of Service
5.5 Aggregated Data
We may share aggregated, non-personally identifiable information about our users and platform usage for business purposes, such as industry reports or marketing materials.
6. Data Security
6.1 Security Measures
We implement appropriate technical and organizational security measures to protect your personal information:
- Encryption: Data is encrypted in transit and at rest
- Access Controls: Restricted access to personal information on a need-to-know basis
- Regular Monitoring: Continuous monitoring for security threats and vulnerabilities
- Secure Infrastructure: Industry-standard hosting and security practices
6.2 Data Breach Response
In the event of a data breach that affects your personal information, we will notify you and relevant authorities as required by applicable law.
6.3 Your Responsibility
You are responsible for maintaining the security of your account credentials and notifying us of any unauthorized access.
7. Data Retention
7.1 Account Data
We retain your personal information for as long as your account is active or as needed to provide our Service.
7.2 Inactive Accounts
If your account becomes inactive, we may retain your information for up to [X years] to allow you to reactivate your account.
7.3 Legal Requirements
We may retain certain information longer when required by law, for litigation purposes, or to protect our legitimate business interests.
7.4 Data Deletion
When we no longer need your personal information, we will securely delete or anonymize it.
8. Your Privacy Rights
8.1 Account Management
You can access and update most of your personal information through your account settings.
8.2 GDPR Rights (EEA Residents)
If you are located in the EEA, you have the following rights:
- Access: Request a copy of the personal information we hold about you
- Rectification: Request correction of inaccurate or incomplete information
- Erasure: Request deletion of your personal information in certain circumstances
- Portability: Request transfer of your data to another service provider
- Restriction: Request limitation of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdraw Consent: Withdraw consent for processing where applicable
8.3 CCPA Rights (California Residents)
California residents have additional rights under the California Consumer Privacy Act:
- Right to Know: What personal information we collect and how it's used
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt out of the sale of personal information (we don't sell information)
- Right to Non-Discrimination: Equal service regardless of privacy choices
8.4 Exercising Your Rights
To exercise any of these rights, please contact us at [privacy@fallbrightsolutions.com]. We will respond to your request within the timeframe required by applicable law.
9. Cookies and Tracking
9.1 Types of Cookies
We use the following types of cookies:
- Essential Cookies: Required for platform functionality and security
- Analytics Cookies: Help us understand how users interact with our Service
- Preference Cookies: Remember your settings and preferences
9.2 Cookie Management
You can control cookies through your browser settings. Note that disabling essential cookies may affect platform functionality.
9.3 Third-Party Analytics
We use Google Analytics to analyze website usage. You can opt out by installing the Google Analytics opt-out browser add-on.
10. International Data Transfers
10.1 Data Processing Locations
Your personal information may be processed in countries other than your own, including the United States.
10.2 Safeguards for International Transfers
When transferring data internationally, we implement appropriate safeguards such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by relevant data protection authorities
- Other legally recognized transfer mechanisms
11. Children's Privacy
Our Service is not intended for individuals under the age of 21. We do not knowingly collect personal information from children under 21. If we discover that we have collected information from a child under 21, we will delete it immediately.
12. Marketing Communications
12.1 Subscription
We may send you marketing communications about our Service, industry insights, and related topics. You can opt out at any time.
12.2 Opt-Out Methods
- Click the "unsubscribe" link in any marketing email
- Update your communication preferences in your account settings
- Contact us at [privacy@fallbrightsolutions.com]
12.3 Transactional Communications
You cannot opt out of essential service communications (account notifications, billing updates, security alerts).
13. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those external sites or services. We encourage you to review their privacy policies.
14. Changes to This Privacy Policy
14.1 Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements.
14.2 Notification of Changes
We will notify you of material changes by:
- Posting an updated policy on our website
- Sending email notification to registered users
- Providing notice through our Service
14.3 Continued Use
Your continued use of our Service after policy changes constitutes acceptance of the updated Privacy Policy.
15. Contact Information
15.1 Privacy Questions
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Privacy Officer
[Your Company Name]
Email: [privacy@fallbrightsolutions.com]
Address: [Your Business Address]
Phone: [Your Phone Number]
15.2 Data Protection Officer (if applicable)
If you are located in the EEA and have concerns about our data processing, you may contact our Data Protection Officer at [dpo@fallbrightsolutions.com].
15.3 Supervisory Authority
EEA residents have the right to lodge a complaint with their local data protection authority if they believe we have not addressed their privacy concerns adequately.
This Privacy Policy is effective as of [Date] and applies to all users of the BenchpriceDTC platform.