Skip to main content

Privacy Policy

Last updated: 26 May 2026

1. Data controller

The data controller for personal data is Mon Chez Toit SRL (trade name: Trinqo), VAT number BE0885913767.

GDPR contact point: privacy@trinqo.app. No formal Data Protection Officer (DPO) has been appointed, Trinqo does not meet the designation criteria set out in Article 37 of the GDPR.

2. Data collected

We collect the following data:

  • Account data: email address, display name (optional)
  • Tasting data: name, producer, notes, photos, ratings
  • Payment data: processed exclusively by Stripe (we do not store any card numbers)
  • Technical data: IP address, browser type, pages visited

3. Purposes of processing

Your data is used to:

  • Create and manage your user account
  • Record and display your tastings
  • Manage your subscription and payments
  • Send you transactional emails (payment confirmation, notifications). Trinqo does not send any marketing emails or newsletters without your explicit prior consent
  • Story sharing (9:16): you can share a public tasting as a 9:16 image on social media. The image is generated on demand by our API and served via a CDN (1-year immutable cache). It can only be removed by switching the tasting back to private visibility (the URL then returns a 404)
  • Improve the service

4. Legal basis

The processing of your data is based on the following legal grounds:

  • Performance of the contract (Art. 6.1.b GDPR): account management, tasting records, payment processing, label scanning and virtual sommelier advice based on the tastings you have recorded.
  • Consent (Art. 6.1.a GDPR): account creation and acceptance of the terms and conditions.
  • Legitimate interests (Art. 6.1.f GDPR): product analytics (PostHog), AI cost monitoring, guest scan photos for recognition improvement purposes.
  • Legal obligation (Art. 6.1.c GDPR): retention of billing data for 7 years (Belgian accounting obligation).

5. Sub-processors

Your data is processed by the following sub-processors:

  • Supabase (European Union, Ireland), Database hosting and authentication
  • Vercel (United States), Application hosting
  • Stripe (Ireland), Payment processing
  • Brevo (France), Transactional email delivery
  • Google (United States), Image analysis and OCR via the Gemini API, vector embedding generation for similar wine search (gemini-embedding-001 model)
  • OpenAI (United States), AI image analysis (OCR/label recognition, fallback) via the gpt-5.4-mini API
  • Anthropic (United States), AI image analysis (OCR fallback) via the Claude API
  • Sentry (United States), Application monitoring and error tracking
  • Upstash (United States), Rate limiting and abuse protection
  • PostHog (EU, Frankfurt), Privacy-friendly product analytics (no cookies, memory-only persistence)
  • Open Food Facts (France), Wine data enrichment (EAN barcodes, images, country of origin, alcohol content)
  • Tavily (United States), Web search for RAG description enrichment

6. Transfers outside the EU

Some sub-processors process your data outside the European Union. In accordance with CJEU ruling C-311/18 Schrems II and the Data Privacy Framework (DPF) adequacy decision of 10 July 2023 (European Commission, Art. 45 GDPR), the following safeguards govern these transfers: the primary basis for transfer is the DPF adequacy decision where the sub-processor is certified (verifiable at dataprivacyframework.gov); Standard Contractual Clauses (SCC, Art. 46 GDPR) apply as a subsidiary safeguard. Additional technical measures are in place: TLS 1.3 in transit, encryption at rest, pseudonymisation where technically possible. Full list:

  • Supabase (European Union, Ireland), database hosting, data processed within the EU (GDPR Art. 46 not applicable)
  • Vercel (United States), application hosting, Data Privacy Framework (DPF)
  • Stripe (United States), payment, certified Data Privacy Framework (DPF); SCC as subsidiary safeguard
  • Brevo (France/EU), transactional emails, no transfer outside the EU
  • Google (United States), image analysis/OCR via Gemini and vector embeddings (gemini-embedding-001), Data Privacy Framework (DPF) where applicable; SCC as subsidiary safeguard
  • OpenAI (United States), OCR/image analysis fallback via gpt-5.4-mini, transfer outside the EU covered by Standard Contractual Clauses (SCC, Art. 46 GDPR)
  • Anthropic (United States), AI image analysis/OCR fallback and sommelier description generation via Claude, Data Privacy Framework (DPF) where applicable; SCC as subsidiary safeguard
  • Sentry (United States), monitoring, Standard Contractual Clauses (SCC)
  • Upstash (United States), rate limiting, Standard Contractual Clauses (SCC)
  • PostHog (EU, Frankfurt), product analytics, data processed within the EU (GDPR Art. 46 not applicable)
  • Open Food Facts (France), data enrichment, open source database, no transfer outside EU
  • Tavily (United States), web search for RAG enrichment, Data Privacy Framework (DPF)

A detailed list of sub-processors and applicable safeguards is available upon request at privacy@trinqo.app.

7. Data retention period

  • Profile and tasting data: duration of account, deleted immediately upon account deletion
  • Collections and shares: duration of account, deleted immediately upon account deletion
  • Invitations: deleted 90 days after their creation if not accepted, or 90 days after their acceptance
  • Friendships: duration of account, deleted immediately upon account deletion
  • Submitted wine corrections: duration of account, deleted immediately upon account deletion
  • Support tickets: 2 years after closure of the ticket, then anonymized (data retained in case of litigation or legal audit)
  • Push notifications (subscriptions): deleted 1 year after their creation. You are automatically re-subscribed on your next visit if you have accepted notifications
  • Sessions (table_sessions): 24 hours after session expiration. User-saved sessions are retained as long as the account is active
  • Label photos: duration of account, deleted immediately upon account deletion
  • Payment data: retained by Stripe according to their policy (see stripe.com/privacy)
  • Technical logs (Sentry): 90 days. No personal data is sent (configuration sendDefaultPii: false, no email, no IP address, no user identifier)
  • AI usage logs (ai_usage_logs): 90 days (automatic purge)
  • Billing events (billing_events): retained anonymously for 7 years after account deletion (Belgian accounting obligation, Art. 6.1.c GDPR). After account deletion, your identifier is replaced by NULL (no data can be linked back to you)

8. Your rights

Under the GDPR, you have the following rights:

  • Access: obtain a copy of your personal data
  • Rectification: correct inaccurate data
  • Erasure: request the deletion of your data
  • Portability (Art. 20): you can export your personal data in a structured, machine-readable format from your account settings
  • Objection: object to the processing of your data
  • Restriction: request the restriction of processing

To exercise your rights, contact us at privacy@trinqo.app. We will respond within 30 days.

9. Cookies and analytics

Trinqo uses only strictly necessary cookies for the service to function. No advertising or tracking cookies are used. No consent is required for these cookies in accordance with the ePrivacy Directive.

  • Supabase session cookie: authentication of the logged-in user (session cookie, strictly necessary, expires when the browser is closed)
  • trinqo-locale: remembering the language chosen by the user (functional cookie, strictly necessary, expires after 7 days of inactivity)

The PostHog analytics tool is hosted in the EU (Frankfurt) and configured in native cookieless mode (persistence: 'memory'): no cookies, local storage, or digital fingerprint are created on your device. Your IP address is not transmitted to PostHog (ip: false). Click autocapture is disabled (autocapture: false). No profile is created for anonymous visitors (person_profiles: 'identified_only'). The legal basis is Trinqo's legitimate interest in improving its service (Art. 6.1.f GDPR), in accordance with CNIL analytics exemption, no consent is required. You can opt out of this collection from the Settings page of your account.

10. Security

We implement appropriate technical and organizational measures to protect your data: HTTPS encryption, secure authentication, restricted data access, and database-level security policies.

11. Complaints

If you believe that the processing of your data does not comply with the GDPR, you may file a complaint with the Belgian Data Protection Authority: www.autoriteprotectiondonnees.be

12. Open Food Facts

When you use the barcode scanning feature, Trinqo queries the Open Food Facts service to enrich the product record.

  • Data sent: EAN barcode of the product
  • Data received: product name, brand, category
  • Legal basis: legitimate interest (improving the product record)
  • Open Food Facts terms of use: world.openfoodfacts.org/terms-of-use

13. Data breach (Art. 33 GDPR)

In the event of a personal data breach, Trinqo follows the procedure below:

  • Detection: real-time Sentry alerts
  • Notification to the supervisory authority: within 72 hours of detection, notification to the Belgian Data Protection Authority (www.autoriteprotectiondonnees.be)
  • Communication to data subjects: if the breach is likely to result in a high risk to their rights and freedoms (Art. 34 GDPR)
  • Contact: info@trinqo.app

14. AI label scanning

When you use the label scanning feature, Trinqo sends the label photo to third-party AI services to automatically extract wine information (name, producer, region, vintage, grape varieties).

  • Data sent: photo of the wine label
  • Data received: extracted information (wine name, producer, region, vintage, grape varieties, alcohol content)
  • Legal basis: performance of the contract (core service feature)
  • Photo retention: the AI provider receives the photo in real time and does NOT retain it after processing. Trinqo, however, retains the photo for a maximum of 7 days for quality purposes (see section 20)
  • AI services used: Google Gemini (primary), OpenAI gpt-5.4-mini (fallback), Anthropic Claude (fallback)
  • Personal data in the photo: the photo may accidentally contain visual elements (background, reflections). Avoid including personally identifiable elements in your label photos

15. AI usage data

Trinqo collects technical data related to the use of artificial intelligence features:

  • Purpose: service improvement and operational cost monitoring
  • Legal basis: legitimate interest (Art. 6.1.f GDPR), optimisation and monitoring of the AI service
  • Data collected: request type, AI model used, number of tokens, processing duration
  • What is NOT collected: conversation content, transmitted photos, personal data
  • Retention period: 90 days, then automatically purged

16. Meta advertising measurement (removed)

Trinqo has discontinued all advertising measurement via the Meta Conversions API (CAPI). No data (IP address, User-Agent, Meta advertising cookie identifiers, conversion events) is transmitted to Meta any longer, and the trinqo_utm attribution cookie is no longer set or read. Trinqo does not use any third-party advertising tracker or measurement.

17. Taste profile shown on your Sommelier page

Until 31 August 2026, Trinqo calculated a taste profile stored in your account (user_taste_profile) and used it to personalise the virtual sommelier's answers. That processing has been discontinued: no profile is calculated to feed a recommendation any more, and the virtual sommelier no longer receives any profile inferred from your behaviour.

  • What remains: your Sommelier Profile page displays seven taste axes (tannins, acidity, sugar, body, oak, minerality, variety) derived from your own tastings. They are recalculated every time the page is displayed, are never stored, and are visible to you alone.
  • No automated decision: this display triggers nothing. It does not affect your price, your access to the service, or any recommendation. It therefore falls outside Art. 22 GDPR, which covers automated decisions producing legal effects or similarly significantly affecting you.
  • Data used: the tasting notes, appellations and comments you recorded yourself. No other source.
  • Profiles calculated before 31 August 2026: they are no longer read or updated. They are still deleted immediately when you delete your account, and you may request access to them, a copy of them, or their erasure from privacy@trinqo.app.
  • Right to object (Art. 21 GDPR): you may ask at any time for this display to stop, by writing to privacy@trinqo.app.

18. Temporary guest scan photos (try-photos-temp bucket)

When an unregistered visitor uses the label scan trial feature (/try flow), the captured photo is temporarily stored in a dedicated storage bucket hosted by Supabase (Ireland, European Union) in order to generate a 9:16 story-format share image (Instagram/Facebook) via our rendering service (Satori).

  • Purpose: enable on-the-fly generation of a 9:16 story image shareable on social media, without requiring account creation
  • Legal basis: legitimate interest (Art. 6.1.f GDPR), offering product trial and viral sharing without forcing the user to create an account
  • Data stored: wine label photo taken by the visitor. No direct identifying data (email, name) is associated with the photo
  • Recipient: Supabase (internal storage) and the browser of the user who requested the generation. No public transmission
  • Hosting: Supabase, EU region, Ireland (no transfer outside the EU)
  • Retention period: maximum 1 hour. Deletion is automatic via a scheduled task (pg_cron) that empties the bucket after expiration
  • Your rights: given the very short duration and the absence of an identifier, the individual exercise of rights is not practically applicable. For requests, contact privacy@trinqo.app

19. Guest AI sommelier chat (askGuestSommelier)

The /try trial flow offers a mini-chat with the virtual sommelier, accessible without account creation. The visitor's questions and the metadata of the scanned wine are sent to the Google Gemini API to produce the response.

  • Purpose: allow the visitor to try the sommelier feature before registration
  • Legal basis: legitimate interest (Art. 6.1.f GDPR), product demonstration without prior collection of account data
  • Data sent to Google Gemini: wine name, producer, appellation, vintage if available, and the visitor's question text. No personal data of the visitor (first name, email, identifier) is sent, the "name" field in the prompt corresponds to the wine name, not the user's name
  • Recipient: Google Ireland Ltd. (Ireland), with possible processing by Google LLC (United States) governed by Standard Contractual Clauses (SCC)
  • Rate-limiting: to prevent abuse, a per-IP limit is applied in ephemeral memory (Upstash, not logged beyond the counting window)
  • Retention: no retention on Trinqo's side of chat questions or answers. On Google Gemini's side, see the Gemini API policy (ai.google.dev/gemini-api/terms)
  • Your rights: to exercise your rights or request further information, contact privacy@trinqo.app

20. Scan photo retention and quality review

Whether the label scan is made with an account or in guest mode (/try flow), the captured photo may be retained for up to 7 days to improve recognition quality, and the record produced by the AI may be reviewed by the Trinqo team during that period.

  • What: wine label photo taken during a scan, with or without an account, and the record produced by the AI from that photo
  • Why: improving recognition quality (OCR, wine database, estimated prices). Photos help identify and correct failed or incorrect identifications
  • Retention period: maximum 7 days, automatic deletion thereafter. Exceptional case: up to 30 days for documented quality analysis
  • Legal basis: legitimate interest (Art. 6.1.f GDPR), improving the accuracy of an identification service, in line with the data minimisation principle (Art. 5.1.c GDPR)
  • Associated data: the record as it was returned to you, that is the wine name, producer, vintage, appellation, region, colour, grape varieties, alcohol content, food pairings, drinking window, price range, confidence score and sommelier description. Plus the GeoIP city (never the full IP address) and, for a scan made with an account, the associated email address
  • Access: Trinqo team only, via time limited signed URLs. Private bucket, no public access. Every time an administrator opens a record it is logged, with the date and the scan concerned
  • No model training: photos are not used to train or fine-tune an AI model without your explicit consent
  • Your rights: you may request deletion of your photo by contacting privacy@trinqo.app. Please include the approximate date and time of the scan

21. PostHog capture of signup attempts

When the signup form is submitted, an anonymous identifier and non-personal properties are sent to PostHog (product analytics tool) before the account is created server-side. This capture is intentionally triggered before the server call so that lost signups can be detected and re-engaged in the event of a technical incident (silent server failure, error not surfaced to the user).

  • What: anonymous identifier derived from a SHA-256 hash (first 16 chars) of the email address (non-reversible), boolean properties has_email and marketing_opt_in
  • What is NOT sent: the email address in plain text, the password, first name, last name, or any directly identifying data
  • Why: detection of lost signups during technical incidents (silent server failure) and targeted re-engagement in the event of a confirmed incident
  • Retention: 7 years (PostHog default), deletable on request at privacy@trinqo.app
  • Legal basis: legitimate interest (Art. 6.1.f GDPR), improving service reliability and reducing user loss due to technical failures
  • Associated data: email hash (16 hex chars, non-reversible), marketing_opt_in (boolean), has_email (boolean), timestamp
  • Your rights: you may request deletion of this record at privacy@trinqo.app, specifying the approximate date of your signup attempt

22. Use of artificial intelligence (AI Act 2024/1689)

Trinqo uses artificial intelligence models to deliver its service. In accordance with EU Regulation 2024/1689 (AI Act):

  • AI systems used: Google Gemini Vision (primary label recognition and OCR), Anthropic Claude (sommelier description generation, recommendations and OCR fallback). Trinqo is qualified as a deployer of a limited-risk AI system, subject to transparency obligations (Art. 50 AI Act).
  • Transparency (Art. 13 and 50 AI Act): sommelier descriptions generated by AI are identified as such in the interface (information icon below each description, welcome modal on the first scan). You are informed before each interaction with a detectable AI system.
  • Manual correction: you may at any time manually correct or supplement AI-generated information (wine name, producer, vintage, grape varieties, tasting notes).
  • Provider instructions (Art. 26 AI Act): Trinqo retains and complies with the usage instructions provided by model providers (Anthropic, Google) and does not use these models outside their applicable terms of use.
  • No automated decision-making with legal effect: no automated decision within the meaning of Art. 22 GDPR producing legal effects or similarly significantly affecting you is made solely on the basis of AI systems, without the possibility of human intervention.

23. Alcohol consumption data - precautionary measures

Tasting data collected by Trinqo (notes, comments, frequency, grape varieties, regions) is collected for the purposes of organising and personalising the wine service, and not for health purposes. However, in accordance with EDPB Guidelines 03/2020 on the processing of health data, such data may, in certain contexts, allow inferences to be drawn about a person's state of health. Trinqo applies the following precautionary measures:

  • No health inference: no addiction detection algorithm, no problematic consumption score, no analysis for public health purposes or medical profiling.
  • No sharing for health profiling: tasting data is never shared with insurers, employers, health bodies or commercial third parties for health-related profiling purposes.
  • Effective deletion: all tasting data is deleted within 30 days of an account deletion request (or immediately for deletions via the dashboard).
  • Anonymous aggregation: statistical data derived from tasting activity is aggregated and anonymised before any internal analytical use.
  • Legal notice (Loi Evin): in accordance with French law L.3323-2, all public communications by Trinqo include the legal notice: excessive alcohol consumption is harmful to health. Drink responsibly.

24. Data protection impact assessment (DPIA, Art. 35 GDPR)

A data protection impact assessment (DPIA) has been carried out in accordance with Art. 35 GDPR, in view of the high-risk processing activities identified in this policy (AI label scanning, transfers to sub-processors outside the EU). This DPIA is kept up to date and is available upon reasoned request at privacy@trinqo.app.

← Back to home