The house
Privacy Policy
Last updated: 10 July 2026
This policy explains what personal data FineWyne collects when you browse, buy, and bid — and what we do with it. We collect only what the service needs, and we do not sell or share your data for advertising.
1. Who is responsible
The data controller is [legal entity name — to be confirmed], trading as FineWyne, [registered address — to be confirmed]. For anything in this policy, contact no-reply@localhost.
2. What we collect
- Account details — your name, email address, and date of birth (we sell alcohol, so we must check you are 18 or over).
- Order & delivery details — the delivery address and contact details you give at checkout, and your order history.
- Bidding history — the bids you place, lots you watch, and any winning-bid invoices.
- Communications — the service emails and notifications we have sent you, and any correspondence you send us.
- Payment — payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we keep only a payment reference.
- Sign-in — your password is held by our authentication provider (AWS Cognito), not by us. We never see it.
3. How we use it
- To fulfil your orders and run the auctions you take part in (performance of our contract with you).
- To verify your age and keep records the law requires of us (legal obligation).
- To secure the service — for example rate-limiting sign-in attempts and preventing fraud (legitimate interest).
- To send you service messages: order confirmations, outbid notices, payment reminders, and account notices. These are part of running your account, not marketing. We do not currently send marketing email.
4. Who processes it for us
| Provider | What they do for us |
|---|---|
| AWS Cognito | Account sign-in and credential storage |
| Stripe | Card payments and refunds |
| Amazon SES | Delivering the emails we send you |
| Amazon S3 / CloudFront | Serving product imagery |
| Render | Hosting the application and database |
| Sentry | Error monitoring, so we can fix faults |
Each provider acts under contract as our processor (or, in Stripe's case, as an independent controller for payment processing). We do not sell personal data, and we do not share it with advertisers.
5. Where it is processed
Our infrastructure runs outside the European Union (including Australia, Singapore, and the United States). Where personal data leaves the EU, the transfer is protected by [transfer safeguards, e.g. Standard Contractual Clauses — to be confirmed].
6. Cookies
We use strictly necessary cookies only: your session, a security (CSRF) token, and a cookie recording that you confirmed you are of legal drinking age. We set no advertising, analytics, or tracking cookies.
7. How long we keep it
Order and invoice records are kept for as long as tax and commercial law requires. Account data is kept while your account is open; retention periods after closure are [retention schedule — to be confirmed].
8. Your rights
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, by emailing no-reply@localhost.
- You can close your account yourself at any time from your account settings.
- You can object to, or ask us to restrict, processing based on legitimate interest.
- If you are unhappy with how we handle your data, you have the right to complain to your local data protection authority.