Privacy Policy
Last updated: March 2026 · Applies to: Decanta web app, mobile app, and browser extension
Decanta is a wine technology platform. We are committed to handling your personal data with transparency and care. This policy explains what we collect, why we collect it, and how you control it.
1. Who We Are
Decanta ("we", "us", "our") is operated by Allwis Pty Ltd (ABN 14 689 039 343), an Australian company. Our platform includes the Decanta web and mobile application, and the Decanta — Wine Companion browser extension available for Chrome and Firefox.
For privacy enquiries, contact us at: [email protected]
2. What We Collect
Account & Identity
- Email address and display name (on registration)
- Profile details you choose to provide (avatar, location, language, currency preference)
- Authentication tokens (via Supabase; Google OAuth where used)
Wine & Cellar Data
- Wines you add to your cellar or wishlist, including quantities, vintages, and prices
- Ratings and reviews you submit
- Dietary and allergy preferences you set
Browser Extension — Page Data
- When you trigger a wine scan or import, the extension reads visible product information (wine names, prices, structured data) from the current page
- This page content is processed locally and/or sent to the Decanta database solely to match and display wine information to you
- We do not persistently store the contents of pages you visit
Usage & Technical Data
- Extension preferences: overlay position, popup window size and location (stored locally in your browser via
chrome.storage.local)
- Subscription tier and billing status
- Standard server logs (IP address, browser type, timestamps) retained for security and diagnostics
We do not collect: browsing history, page content outside of user-triggered wine scans, financial account details, or any data from pages unrelated to wine retail.
3. How We Use Your Data
- Providing the service — authenticating your account, syncing your cellar and wishlist, delivering wine scores and recommendations
- AI enrichment — when you opt in during bulk import, wine names and metadata are passed to an AI model to clean and enrich entries. No personal data is included in these requests
- Personalisation — tailoring recommendations, vintage ratings, and pairing suggestions based on your preferences and cellar
- Security & integrity — detecting abuse, managing subscription entitlements, and maintaining platform reliability
- Communications — transactional emails (account, billing). We do not send marketing emails without your explicit consent
4. Data Sharing
We do not sell your personal data. We share data only in the following circumstances:
- Supabase — our backend infrastructure provider (authentication, database, storage). Data is processed under their data processing agreement
- AI providers — anonymised wine metadata only (no personal data) is sent to AI models for enrichment, under strict data processing terms
- Legal obligation — where required by law, court order, or to protect the safety of users or the public
All third-party providers are bound by confidentiality obligations and may not use your data for their own purposes.
5. Browser Extension — Permissions
The Decanta browser extension requests the following permissions:
- activeTab — to read the current page when you trigger a wine scan or import. Only active on your request; not used passively
- scripting — to inject the wine detection overlay and UI into the active tab on demand
- contextMenus — to add "Look up in Decanta" and "Scan page for wines" to your right-click menu
- storage — to remember your overlay position, popup size, and session token locally in your browser
- identity — to enable secure Google OAuth sign-in via Chrome's identity flow
- Host permissions — to detect wines and inject the overlay on wine retailer websites. The extension does not read or transmit data from non-wine pages
6. Data Retention
- Account and cellar data is retained for as long as your account is active
- On account deletion, your personal data is removed within 30 days
- Local browser storage (extension preferences) can be cleared at any time by removing the extension
- Server logs are retained for up to 90 days for security purposes
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your account and associated data
- Export your cellar data in a portable format
- Withdraw consent for optional data uses at any time
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Security
We implement industry-standard security measures including encrypted connections (TLS), row-level security in our database, and token-based authentication. Passwords are never stored in plain text. We conduct regular reviews of our security practices.
No system is completely immune to risk. If you believe your account has been compromised, contact us immediately at [email protected].
9. Children
Decanta is intended for users aged 18 and over. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us and we will remove it promptly.
10. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will notify you via the app or by email. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of Decanta after changes take effect constitutes acceptance of the updated policy.