Privacy Policy
Privacy.
What we collect, why, who sees it, how long we keep it. Plainly stated.
Last updated 28 July 2026
Who we are
Valmont is operated by Collecta Technologies Limited, a company registered in England and Wales (company number 17022135), with its registered office at 105 Piccadilly, London, W1J 7NJ. In this policy, "we", "us", and "Valmont" refer to that entity.
For any question about your data, write to hello@valmont.app.
What we collect
What you give us directly
- Account details such as email address, name, handle, and date of birth for age checks.
- Taste preferences, saved wines, pours, restaurant activity, reservations, social choices, and anything you ask The Nod.
- Bottle or wine-list images and profile images you choose to upload.
- For nominations, a short private label chosen by the nominator and the resulting status. The label is not a verified identity.
- Anything you choose to send us when you contact us.
What the app, browser, and service provide
- App version, device and operating-system information, locale, approximate network location, page or screen interactions, and performance diagnostics. Website campaign analytics run only after cookie consent.
- Standard request logs (IP address, user-agent, timestamp) kept short-term by our hosting provider for security and abuse prevention. We also derive a one-way hash of your IP address to rate-limit form submissions; it is stored only briefly by our database processor (Supabase).
- Subscription and Valmont Pro entitlement status from Apple and RevenueCat. We do not receive your full card details.
- Precise location only when you grant the app permission, to find nearby restaurants. You can revoke that permission in device settings.
What we do not collect
- No cross-site advertising identifiers.
- Nominations do not read or upload your Contacts or address book, and do not ask for a nominee's phone number or email.
- Opaque nomination tokens, full nomination URLs, private labels, and QR codes are excluded from product analytics, diagnostics, and session replay.
Why we collect it
- Account and product. To create your account, verify age, provide recommendations, save your choices, and deliver the features you request.
- Nominations. To create one-person links, show the nominator an owner-only status label, enforce five successful grants and one redemption per recipient account, and place three months of Pro through RevenueCat.
- Security and support. To rate-limit abuse, reconcile uncertain grants, investigate failures, and answer requests without exposing bearer credentials.
- Measurement. To understand reliability and product use. Website campaign analytics require cookie consent; app analytics are minimised and exclude nomination secrets.
AI processing
Some Valmont features are answered by a third-party AI model rather than by us. Before anything of yours is sent, the app shows you what will be sent and who receives it, and asks you to agree. Nothing reaches the AI processor until you do.
What is sent
- The messages you write to The Nod, and the conversation so far in that chat.
- Your taste profile, meaning the grape, region and style preferences derived from your ratings and pours, so the answer matches your palate.
- Your approximate location, meaning the city we resolve and how far you are from the nearest venue whose wine list we hold, and only while you allow the app location access.
- Photographs of the wine lists and bottles you choose to scan.
Your name, email address, account identifier, and date of birth are not included. Scanned photographs are sent so the wine names and prices printed on them can be read; they are not used to identify people.
Who receives it
OpenAI(openai.com) is the AI processor. Requests are made from Valmont's own servers (Supabase edge functions) rather than from your device, and are covered by OpenAI's API data-processing terms. Anthropic (anthropic.com) is configured in the same service as an alternative model provider for The Nod; if we switch to it, the chat content described above would be processed by Anthropic instead, under its commercial API terms.
What it is used for
Producing wine recommendations, answers, and tasting notes for you, and reading the wine lists you scan. Under OpenAI's API terms, data submitted through the API is not used to train or improve OpenAI's models; OpenAI retains it for up to 30 days for abuse monitoring and then deletes it, unless the law requires otherwise. Anthropic's commercial terms likewise state that inputs and outputs submitted through its API are not used to train its models. Neither processor uses your data for advertising, and neither may use it for any purpose other than providing the service to us and the safety monitoring described above.
Your control
The in-app disclosure appears the first time you reach an AI feature, whether that is the first message you send to The Nod or the first list or bottle you scan, and the request is held until you answer. You can withdraw at any time in the app under Settings → The Nod and your data, which stops any further sending and makes the app ask again the next time. Declining or withdrawing leaves the rest of Valmont working.
Legal basis (UK and EU GDPR)
- Providing your account, subscription, recommendations, and accepted nomination, performance of our contract with you (Art. 6(1)(b)).
- Keeping the service secure, preventing duplicate grants, supporting users, and improving reliability, our legitimate interests (Art. 6(1)(f)), balanced against your rights.
- Optional device permissions, sending your data to the AI processor, and website campaign analytics, your consent (Art. 6(1)(a)), withdrawable at any time.
Who sees it
We share your data with the following processors only, each under a written data-processing agreement:
- Clerk (clerk.com), account authentication and identity.
- Supabase (supabase.com), database hosting where account, taste, social, and nomination records are stored (EU region), and serverless functions run.
- RevenueCat (revenuecat.com) and Apple, subscription processing, receipt validation, and promotional Pro entitlement status.
- PostHog (posthog.com), minimised product analytics and masked session replay; Sentry (sentry.io), crash and performance diagnostics.
- Klaviyo (klaviyo.com), transactional and lifecycle messages.
- Expo (expo.dev), app builds, updates, and push notification delivery.
- Google, location search and website analytics; website analytics run only with consent.
- OpenAI (openai.com), the AI processor behind The Nod and the scan features, with Anthropic (anthropic.com) configured as an alternative model provider for The Nod. See AI processing for exactly what is sent, on what basis, and how to withdraw.
- Vercel Inc. (vercel.com), hosting, CDN, and analytics.
- Meta Platforms, Inc. (Meta Pixel), campaign attribution, only with your consent.
We do not sell personal data. We do not share it with data brokers or any advertising network beyond the campaign attribution listed above.
Where your data goes
Our processors may process your data in the United States. Transfers from the UK and the EEA are protected by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, as applicable, together with any supplementary measures required by the UK ICO's guidance.
How long we keep it
- Account and product data, while your account is active, then deleted or anonymised within 30 days of a valid deletion request except for the narrow records below.
- Nomination labels and live links, while the nominator's account and status history exist. Links close after 30 days; deleting the nominator account invalidates every owned unused link and removes the private label.
- Confirmed nomination grants, a minimal pseudonymous programme/account digest and grant/terms timestamps for the life of the programme plus 24 months, solely to enforce the one-account allowance, handle disputes, and prevent abuse. It contains no nominator, private label, bearer, contact detail, or raw Clerk ID.
- Uncertain provider grants, the RevenueCat app user ID only while reconciliation is necessary. It is removed on a terminal outcome and no later than 90 days after the intended grant expiry; unresolved cases then require manual support using the pseudonymous audit record.
- AI requests, held by the AI processor for up to 30 days for abuse monitoring and then deleted. The timestamp recording that you agreed is kept on your profile while your account is active, and is removed when you withdraw or delete the account.
- Server logs, 30 days.
- Website analytics, up to 26 months. App analytics and diagnostic retention follows the configured PostHog and Sentry project periods and is reviewed regularly.
Your rights
Under UK and EU GDPR, you can, at any time:
- Access a copy of the personal data we hold about you.
- Rectify anything that is inaccurate.
- Erase your data (subject to the narrow exceptions the law permits).
- Restrict processing in certain circumstances.
- Portability, receive your data in a commonly used, machine-readable format.
- Object to processing based on our legitimate interests.
- Withdraw consent at any time, for anything given by consent (including switching analytics off via the cookie banner).
To exercise any of these, write to hello@valmont.app. We will respond within 30 days.
If you believe we have mishandled your data, you can complain to the UK Information Commissioner's Office or your local supervisory authority in the EEA.
Children
Valmont is not directed at anyone under 18 and we do not knowingly collect data from children. If you are under 18, do not submit information to the service.
Security
All traffic is encrypted in transit with TLS. We limit processor selection to vendors with SOC 2 Type II or equivalent assurance. No security is absolute, in the event of a confirmed personal data breach, we will notify affected users and the UK ICO within 72 hours, as the law requires.
Changes
We update this policy when the service or the law changes. The "Last updated" date at the top reflects the current version. Material changes will be notified by email to waitlist members.