← Back

The Cellar Ledger

Privacy Policy

Last updated: August 11, 2026

This is beta software. We handle your data carefully — this policy describes exactly how — but The Cellar Ledger is still under active development. Keep your own exports of anything important (Settings → Data & Recovery).

This policy explains what personal data The Cellar Ledger ("we", "us") collects, why, and what you can do about it. "You" means anyone with an account, and "your organization" means your business's workspace on the platform.

1. What we collect

Account data — handled by Clerk, our authentication provider, on our behalf: your name, email address, and (if you sign in with Google) the fact that you used that provider. We don't see or store your password ourselves; Clerk does.

Business data you enter — batches, recipes, ingredient purchases, suppliers, sales, and anything else you type into the app. This is scoped to your organization and never visible to any other tenant on the platform.

We don't collect anything beyond this. No third-party advertising trackers, no analytics scripts, no behavioral profiling.

2. How we use it

To run the Service: authenticate you, show you your own organization's data, compute the costs/traceability/reports the app is for, and keep a backup in case something goes wrong. That's it — we don't use your data for advertising, and we don't sell it to anyone, ever.

3. Where your data lives

WhoWhat forWhere
ClerkSign-in, account identityClerk's own infrastructure
NeonDatabase (Postgres)EU (Frankfurt, eu-central-1)
Fly.ioApplication hostingEU (Frankfurt, fra)

These are the only three parties with any technical access to the infrastructure your data runs on ("sub-processors"). None of them are permitted to use your data for their own purposes.

4. Cookies

We use the session cookie Clerk sets to keep you signed in. That's the only cookie this app sets — no advertising or cross-site tracking cookies.

5. How long we keep it

For as long as your account is active. Deleted records (batches, recipe steps, transactions) go to a Trash you can restore from before they're permanently removed. Whole-account deletion is described below.

6. Your rights

If you're in the EU/UK or California, you may have additional statutory rights under GDPR or CCPA — such as access, correction, deletion, and portability. Contact us at jad.bouchebl@gmail.com to exercise any of them and we'll help.

7. Security

Every business's data is isolated by organization at the database level — no tenant can query another's records. Destructive actions (deleting a batch, a recipe, a transaction) are soft-deleted with a restore path, not immediately erased. The database is backed up regularly.

8. Children's privacy

The Service is a business tool for beverage producers and isn't directed at children. We don't knowingly collect data from anyone under 16.

9. International transfers

Your data is hosted in the EU (see the table above) regardless of where you or your business are located.

10. Changes to this policy

If we change how we handle your data in a way that matters, we'll update the date at the top of this page and, for anything significant, let you know directly.

11. Contact

Questions about this policy, or to exercise any of the rights above: jad.bouchebl@gmail.com.