Legal

Privacy policy

How we handle information in the Tectalic Wine Club app for Shopify, for merchants and for the members of their wine clubs.

Introduction

Tectalic (ABN 71 113 915 601) is an Australian business committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our Shopify app, Tectalic Wine Club Subscriptions (the “App”). The App provides subscription wine club facilities for Shopify-based wine merchants. By using the App, you consent to the practices described in this Privacy Policy. We comply with applicable data protection laws, including Australia's Privacy Act 1988 (Cth), the European Union's General Data Protection Regulation (EU GDPR), the United Kingdom's General Data Protection Regulation (UK GDPR), and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). If you do not agree with this policy, please do not use the App. This policy applies to Merchants (as defined below) who install and use the App, and to the processing of Merchant Subscriber data that we handle on behalf of Merchants. Merchant Subscribers should refer to the relevant Merchant's privacy policy for details on how their information is handled.

This policy covers the App. Information you give us through this website — for example when you book a demo, make an enquiry or join our mailing list — is handled under the Tectalic privacy policy, which covers visitors to our websites.

Definitions

For clarity, we use the following terms in this Privacy Policy:

Information we collect

We collect information to provide and improve our Services. The types of information we collect depend on your role (e.g., as a Merchant or through Merchant Subscriber data processed on behalf of Merchants).

Merchant data

Merchant Subscriber data

Merchant and Merchant Subscriber data

Information we do not collect

We do not collect, store, or process payment data for credit card transactions. Such information is transmitted, stored, and processed directly by Shopify or other payment processors you select.

How we use your information

We use the information we collect for the following purposes, in compliance with Data Protection Laws:

We distinguish between Personal Information and Non-Personal Information. Non-Personal Information may be derived from Personal Information but is anonymized so it cannot identify individuals. Under GDPR and UK GDPR, our legal basis for processing include contract performance (for service delivery), legitimate interests (for analytics and marketing), and legal compliance. For CCPA purposes, we use information for business purposes like auditing, security, and service provision.

Email communications

We send transactional emails using a third-party email delivery service. This includes emails to Merchants (such as account notifications and service updates) and emails to Merchant Subscribers on behalf of Merchants (such as subscription confirmations, order notifications, and delivery updates). We maintain logs of emails sent, including recipient, subject, and delivery status, for service reliability and troubleshooting purposes. Our email service provider processes delivery confirmations, bounces, and spam complaints, which we use to maintain email deliverability and comply with anti-spam requirements.

Sharing your information

We may disclose information to trusted parties as necessary for our operations, always in line with Data Protection Laws:

We do not sell Personal Information as defined under CCPA. Recipients are bound by confidentiality and data protection obligations.

Cookies and tracking technologies

We use cookies, web beacons, and similar technologies on our Online Platforms for the following purposes:

You can manage these through your browser settings or our opt-out tools. Essential cookies cannot be opted out of without affecting App functionality. Under CCPA, GDPR, and UK GDPR, you have rights to opt out of certain tracking.

Security

We implement commercially reasonable administrative, technical, and physical measures to protect your information from unauthorized access, loss, or alteration. This includes encryption, access controls, and encrypted backups maintained in secure cloud storage for disaster recovery. However, no system is completely secure, and we cannot guarantee absolute security.

International data transfers

Data is primarily processed and stored in the United States. For transfers from the EU, UK, or Australia, we use adequate safeguards such as Standard Contractual Clauses or equivalent mechanisms to ensure compliance with Data Protection Laws.

Data retention

We retain Merchant Data and Merchant Subscriber Data for as long as your account is active and as necessary to provide the Services. Upon uninstallation of the App, we initiate data removal processes in accordance with Shopify's data protection requirements, including a brief grace period to allow for reinstallation. Certain operational data such as logs may be retained for a limited period for security and troubleshooting purposes. Certain data may be retained for a longer period where required by law (e.g., for tax, audit, or legal compliance purposes). After this period, data is securely deleted or anonymized. We retain Non-Personal Information indefinitely, where it does not identify individuals or is aggregated, and is not subject to retention requirements under applicable Data Protection Laws. Such data is retained for ongoing purposes, including analytics, research, product improvement, and other legitimate business operations.

Your rights

Merchant rights

As a Merchant, you have rights under Data Protection Laws, including:

To exercise these, contact us at [email protected]. We respond within required timelines (e.g., 30 days under CCPA, one month under GDPR).

Merchant Subscriber rights

Merchant Subscribers' rights are managed by the relevant Merchant. We process Merchant Subscriber Data as a service provider (or “processor” under GDPR) on behalf of the Merchant, who is responsible for handling requests. If we receive a request directly, we will forward it to the Merchant.

Merchant responsibilities

Merchants are responsible for complying with all Data Protection Laws regarding Merchant Subscriber Data. This includes obtaining necessary consents, providing privacy notices, and facilitating rights requests (e.g., access or deletion). Merchants must assist us in responding to any regulatory inquiries related to their Subscribers.

Exclusions

This policy does not apply to third-party websites or services linked from our App; review their policies separately. It also excludes information you publicly share, which may be visible to others.

Changes to this privacy policy

We may update this policy to reflect changes in our practices or laws. We will notify you via email or the App for significant changes. Continued use after updates constitutes acceptance.

Complaints and contact us

If you have questions, concerns, or complaints about this Privacy Policy or our practices, contact our Data Protection Officer at [email protected]. For complaints under Data Protection Laws, contacts include:

We aim to resolve complaints promptly and fairly.