Privacy Policy

Effective 24 June 2026 · Last updated 24 June 2026

Binterra is a wine- and beverage-inventory platform for restaurants, hotels, and retailers, operated by Vinifera Systems LLC. This policy explains, in plain terms, what personal information we handle, why, who we share it with, and the choices and rights you have.

01Who we are

Binterra is operated by Vinifera Systems LLC (“Vinifera,” “Binterra,” “we,” “us,” or “our”). This Privacy Policy explains how we handle personal information in connection with our website, web application, and mobile app (together, the “Service”).

If you have questions about this policy or how we handle your information, contact us at privacy@binterra.app.

02Our role: controller & processor

Binterra is a B2B service, so our role depends on whose information is involved:

  • We are a controller for information about our account holders (your staff who log in) and website visitors. This policy governs that information.
  • We are a processor for the content our customers upload — supplier invoices and the data extracted from them, which may include third parties’ personal information (such as a distributor sales rep’s name, email, or phone number). We process that content solely on the customer’s documented instructions — as necessary to provide the Service, comply with law, or protect the security and integrity of the Service. Where we act as a processor, our handling of that content is governed primarily by our agreement and Data Processing Agreement (DPA) with the customer rather than by this policy.

Customers that require a DPA may contact us at privacy@binterra.app.

03Information we collect

a) Account & staff data (we are controller)

The name, email address, role, and organization membership of users invited to the Service, along with the authentication identifiers needed to sign in securely.

b) Customer-uploaded content (we are processor)

Supplier invoices you upload or email in (PDFs and images) and the structured data extracted from them — vendor and producer names, invoice numbers and dates, quantities, and prices — plus any personal or commercial information that appears on the face of those documents. We do not deliberately collect payment-card numbers, government IDs, or special-category data; however, an uploaded invoice image may contain such information incidentally, and where it does, it is retained within the stored source document.

c) Integration data

If you connect a point-of-sale system (for example, Toast), we process your sales and menu data and store the authentication tokens, API credentials, and configuration details needed to maintain the integration in encrypted form.

d) Technical & usage data

Authentication and session cookies and limited first-party operational telemetry (such as app version and network-error events) that we use to diagnose reliability. We also use Microsoft Clarity, a third-party product-analytics service, to understand how our website and web application are used — through aggregated usage metrics, heatmaps, and session replays. See Cookies & analytics for details and your choices. We do not use advertising or cross-context behavioral-tracking technologies.

e) Support & communications data

Information you submit when you contact us for support, including the contents of your messages and any screenshots, attachments, or troubleshooting details you choose to share.

f) Security & log data

Records generated as you use the Service, such as IP address, authentication and session logs, basic browser and device metadata, and security and abuse-prevention logs.

04How we use information

We use the information above to:

  • Provide and operate the Service, and authenticate users and secure accounts.
  • Extract and structure invoice data and power inventory, cost, and reporting features.
  • Send transactional emails such as invitations and reminders, and respond to your support requests.
  • Maintain reliability and security, and understand and improve how people use the Service through product analytics.
  • Detect, prevent, and investigate fraud, abuse, unauthorized access, and security incidents.
  • Meet our legal obligations.

We do not use your information for advertising.

05Legal bases

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service); legitimate interests (securing, maintaining, and improving the Service, operational diagnostics, and product analytics); legal obligation; and consent where required — for example, for optional analytics or similar technologies where applicable.

06AI processing of invoices

To turn uploaded invoices into structured data, we transmit the uploaded document to specialized third-party AI providers — Anthropic (for PDF documents) and OpenAI (for image documents) — which perform the extraction and return structured fields. The full document is sent for this purpose. These providers act as our sub-processors for this step.

Our commitment
Both providers process your documents only to perform the extraction and return results to us. We use these providers under business and commercial terms and data-processing agreements that restrict their use of submitted content, and under those terms submitted content is not used to train their models.

This step structures the information already on your documents; we do not use it to make solely automated decisions that produce legal or similarly significant effects about individuals.

07Sub-processors

We use the following service providers to operate the Service. We maintain this as a current, dated list and update it as it changes.

Sub-processorPurpose
SupabaseDatabase, authentication, and encrypted file storage
VercelApplication hosting
AnthropicInvoice data extraction (PDF documents)
OpenAIInvoice data extraction (image documents)
Microsoft ClarityProduct analytics, heatmaps, and session replay
PostmarkInbound invoice-by-email processing and outbound transactional email
UpstashRate limiting and abuse protection

Customer-enabled integrations

Some third-party platforms are not sub-processors but services you choose to connect. If you enable the Toast point-of-sale integration, you authorize us to exchange sales and menu data with Toast to provide that feature; your use of Toast is also governed by Toast’s own terms and privacy practices.

08How we share information

We share personal information only as needed to run Binterra, and only with:

  • The service providers and sub-processors listed above, to operate the Service.
  • Customer-enabled integrations you choose to connect, to provide the features you turn on.
  • Professional advisers, auditors, and insurers, where reasonably necessary.
  • Law enforcement, regulators, or others where required by law or to protect the Service and our users.
  • A successor entity in connection with a merger, acquisition, financing, or sale of assets, with appropriate safeguards.

We do not sell your personal information, and we do not share it with advertisers, data brokers, or for cross-context behavioral advertising.

09Cookies & analytics

Strictly necessary cookies. We use authentication and session cookies, and a functional cookie used by administrators when supporting a specific organization account. These are required for the Service to work.

Analytics. We use Microsoft Clarity to understand how our website and web application are used and to improve them. Clarity may use cookies and similar technologies to capture aggregated usage metrics, heatmaps, and session replays. We configure Clarity’s privacy controls, including masking of form inputs and sensitive content where appropriate, to limit the capture of information you type. Where required by law, we will seek consent before using optional analytics technologies.

We do not use advertising or cross-site tracking cookies.

You can control or clear cookies through your browser settings, and you can opt out of Microsoft’s analytics where such controls are offered. Blocking strictly necessary cookies may prevent parts of the Service from working.

10Data retention & deletion

We retain account data for as long as your account is active. When you delete your account, we aim to delete or anonymize the associated personal account data within 30 days in most cases, except where a longer period is needed for legal, accounting, security, or dispute-resolution purposes. For our own business records, certain financial records (such as billing and tax records) may be retained for up to seven years to meet legal obligations. Product-analytics data collected by Microsoft Clarity is retained by Microsoft for a limited period in line with its retention practices.

Customers control the retention of the content they upload. We retain customer-uploaded content for the duration of the customer relationship and, on termination, delete or return it — including stored invoice documents — in accordance with the customer’s agreement and DPA, in most cases within 30 days of a verified request.

You can delete your account from within the Service; doing so removes your authentication credentials and deletes or anonymizes your personal account data.

Some records, such as security and audit logs, are retained for integrity and legal purposes and may persist after account deletion. Deleted data may also remain in secure backups for a limited period before it is overwritten in the ordinary course.

11International data transfers

The Service is hosted in the United States, and certain sub-processors — including our AI, email, and analytics providers — are located in the United States. Where personal data is transferred across borders, we rely on appropriate transfer mechanisms and safeguards, such as contractual commitments, data processing agreements, and the European Commission’s Standard Contractual Clauses.

12Your rights

Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know and delete, and the right to opt out of the “sale” or “sharing” of personal information — note that we do not sell or share personal information for those purposes. Where applicable, you may use an authorized agent to submit a request, appeal a decision we make about your request, and exercise your rights without being discriminated against.

For customer-uploaded content, where we act as a processor, please direct requests to the customer (the controller); we will assist them as required by our DPA.

To exercise your rights, contact us at privacy@binterra.app.

13Security

We implement technical and organizational measures designed to protect your information, including:

  • Encryption in transit, and encryption of stored integration secrets.
  • Private file storage accessed through short-lived, signed links.
  • Logical tenant separation designed to keep one organization’s data from being accessible to another.
  • Role-based access controls and authentication via a managed provider.
  • Rate limiting and abuse protection.

No method of transmission or storage is 100% secure, but we work to protect your information using measures appropriate to its sensitivity.

14Children

The Service is a business tool that is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect children’s data.

15Changes to this policy

We may update this policy from time to time and will revise the “Last updated” date above. We will communicate material changes as required.

16Contact

Vinifera Systems LLC

Privacy questions: privacy@binterra.app