Last updated: August 11, 2026
This policy explains what personal data The Cellar Ledger ("we", "us") collects, why, and what you can do about it. "You" means anyone with an account, and "your organization" means your business's workspace on the platform.
Account data — handled by Clerk, our authentication provider, on our behalf: your name, email address, and (if you sign in with Google) the fact that you used that provider. We don't see or store your password ourselves; Clerk does.
Business data you enter — batches, recipes, ingredient purchases, suppliers, sales, and anything else you type into the app. This is scoped to your organization and never visible to any other tenant on the platform.
We don't collect anything beyond this. No third-party advertising trackers, no analytics scripts, no behavioral profiling.
To run the Service: authenticate you, show you your own organization's data, compute the costs/traceability/reports the app is for, and keep a backup in case something goes wrong. That's it — we don't use your data for advertising, and we don't sell it to anyone, ever.
| Who | What for | Where |
|---|---|---|
| Clerk | Sign-in, account identity | Clerk's own infrastructure |
| Neon | Database (Postgres) | EU (Frankfurt, eu-central-1) |
| Fly.io | Application hosting | EU (Frankfurt, fra) |
These are the only three parties with any technical access to the infrastructure your data runs on ("sub-processors"). None of them are permitted to use your data for their own purposes.
We use the session cookie Clerk sets to keep you signed in. That's the only cookie this app sets — no advertising or cross-site tracking cookies.
For as long as your account is active. Deleted records (batches, recipe steps, transactions) go to a Trash you can restore from before they're permanently removed. Whole-account deletion is described below.
If you're in the EU/UK or California, you may have additional statutory rights under GDPR or CCPA — such as access, correction, deletion, and portability. Contact us at jad.bouchebl@gmail.com to exercise any of them and we'll help.
Every business's data is isolated by organization at the database level — no tenant can query another's records. Destructive actions (deleting a batch, a recipe, a transaction) are soft-deleted with a restore path, not immediately erased. The database is backed up regularly.
The Service is a business tool for beverage producers and isn't directed at children. We don't knowingly collect data from anyone under 16.
Your data is hosted in the EU (see the table above) regardless of where you or your business are located.
If we change how we handle your data in a way that matters, we'll update the date at the top of this page and, for anything significant, let you know directly.
Questions about this policy, or to exercise any of the rights above: jad.bouchebl@gmail.com.