Privacy Policy
Effective 24 June 2026 · Last updated 24 June 2026
Binterra is a wine- and beverage-inventory platform for restaurants, hotels, and retailers, operated by Vinifera Systems LLC. This policy explains, in plain terms, what personal information we handle, why, who we share it with, and the choices and rights you have.
01Who we are
Binterra is operated by Vinifera Systems LLC (“Vinifera,” “Binterra,” “we,” “us,” or “our”). This Privacy Policy explains how we handle personal information in connection with our website, web application, and mobile app (together, the “Service”).
If you have questions about this policy or how we handle your information, contact us at privacy@binterra.app.
02Our role: controller & processor
Binterra is a B2B service, so our role depends on whose information is involved:
- We are a controller for information about our account holders (your staff who log in) and website visitors. This policy governs that information.
- We are a processor for the content our customers upload — supplier invoices and the data extracted from them, which may include third parties’ personal information (such as a distributor sales rep’s name, email, or phone number). We process that content solely on the customer’s documented instructions — as necessary to provide the Service, comply with law, or protect the security and integrity of the Service. Where we act as a processor, our handling of that content is governed primarily by our agreement and Data Processing Agreement (DPA) with the customer rather than by this policy.
Customers that require a DPA may contact us at privacy@binterra.app.
03Information we collect
a) Account & staff data (we are controller)
The name, email address, role, and organization membership of users invited to the Service, along with the authentication identifiers needed to sign in securely.
b) Customer-uploaded content (we are processor)
Supplier invoices you upload or email in (PDFs and images) and the structured data extracted from them — vendor and producer names, invoice numbers and dates, quantities, and prices — plus any personal or commercial information that appears on the face of those documents. We do not deliberately collect payment-card numbers, government IDs, or special-category data; however, an uploaded invoice image may contain such information incidentally, and where it does, it is retained within the stored source document.
c) Integration data
If you connect a point-of-sale system (for example, Toast), we process your sales and menu data and store the authentication tokens, API credentials, and configuration details needed to maintain the integration in encrypted form.
d) Technical & usage data
Authentication and session cookies and limited first-party operational telemetry (such as app version and network-error events) that we use to diagnose reliability. We also use Microsoft Clarity, a third-party product-analytics service, to understand how our website and web application are used — through aggregated usage metrics, heatmaps, and session replays. See Cookies & analytics for details and your choices. We do not use advertising or cross-context behavioral-tracking technologies.
e) Support & communications data
Information you submit when you contact us for support, including the contents of your messages and any screenshots, attachments, or troubleshooting details you choose to share.
f) Security & log data
Records generated as you use the Service, such as IP address, authentication and session logs, basic browser and device metadata, and security and abuse-prevention logs.
04How we use information
We use the information above to:
- Provide and operate the Service, and authenticate users and secure accounts.
- Extract and structure invoice data and power inventory, cost, and reporting features.
- Send transactional emails such as invitations and reminders, and respond to your support requests.
- Maintain reliability and security, and understand and improve how people use the Service through product analytics.
- Detect, prevent, and investigate fraud, abuse, unauthorized access, and security incidents.
- Meet our legal obligations.
We do not use your information for advertising.
05Legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (providing the Service); legitimate interests (securing, maintaining, and improving the Service, operational diagnostics, and product analytics); legal obligation; and consent where required — for example, for optional analytics or similar technologies where applicable.
06AI processing of invoices
To turn uploaded invoices into structured data, we transmit the uploaded document to specialized third-party AI providers — Anthropic (for PDF documents) and OpenAI (for image documents) — which perform the extraction and return structured fields. The full document is sent for this purpose. These providers act as our sub-processors for this step.
This step structures the information already on your documents; we do not use it to make solely automated decisions that produce legal or similarly significant effects about individuals.
07Sub-processors
We use the following service providers to operate the Service. We maintain this as a current, dated list and update it as it changes.
| Sub-processor | Purpose |
|---|---|
| Supabase | Database, authentication, and encrypted file storage |
| Vercel | Application hosting |
| Anthropic | Invoice data extraction (PDF documents) |
| OpenAI | Invoice data extraction (image documents) |
| Microsoft Clarity | Product analytics, heatmaps, and session replay |
| Postmark | Inbound invoice-by-email processing and outbound transactional email |
| Upstash | Rate limiting and abuse protection |
Customer-enabled integrations
Some third-party platforms are not sub-processors but services you choose to connect. If you enable the Toast point-of-sale integration, you authorize us to exchange sales and menu data with Toast to provide that feature; your use of Toast is also governed by Toast’s own terms and privacy practices.
10Data retention & deletion
We retain account data for as long as your account is active. When you delete your account, we aim to delete or anonymize the associated personal account data within 30 days in most cases, except where a longer period is needed for legal, accounting, security, or dispute-resolution purposes. For our own business records, certain financial records (such as billing and tax records) may be retained for up to seven years to meet legal obligations. Product-analytics data collected by Microsoft Clarity is retained by Microsoft for a limited period in line with its retention practices.
Customers control the retention of the content they upload. We retain customer-uploaded content for the duration of the customer relationship and, on termination, delete or return it — including stored invoice documents — in accordance with the customer’s agreement and DPA, in most cases within 30 days of a verified request.
You can delete your account from within the Service; doing so removes your authentication credentials and deletes or anonymizes your personal account data.
Some records, such as security and audit logs, are retained for integrity and legal purposes and may persist after account deletion. Deleted data may also remain in secure backups for a limited period before it is overwritten in the ordinary course.
11International data transfers
The Service is hosted in the United States, and certain sub-processors — including our AI, email, and analytics providers — are located in the United States. Where personal data is transferred across borders, we rely on appropriate transfer mechanisms and safeguards, such as contractual commitments, data processing agreements, and the European Commission’s Standard Contractual Clauses.
12Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know and delete, and the right to opt out of the “sale” or “sharing” of personal information — note that we do not sell or share personal information for those purposes. Where applicable, you may use an authorized agent to submit a request, appeal a decision we make about your request, and exercise your rights without being discriminated against.
For customer-uploaded content, where we act as a processor, please direct requests to the customer (the controller); we will assist them as required by our DPA.
To exercise your rights, contact us at privacy@binterra.app.
13Security
We implement technical and organizational measures designed to protect your information, including:
- Encryption in transit, and encryption of stored integration secrets.
- Private file storage accessed through short-lived, signed links.
- Logical tenant separation designed to keep one organization’s data from being accessible to another.
- Role-based access controls and authentication via a managed provider.
- Rate limiting and abuse protection.
No method of transmission or storage is 100% secure, but we work to protect your information using measures appropriate to its sensitivity.
14Children
The Service is a business tool that is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect children’s data.
15Changes to this policy
We may update this policy from time to time and will revise the “Last updated” date above. We will communicate material changes as required.
16Contact
Vinifera Systems LLC
Privacy questions: privacy@binterra.app