That Lands
Privacy Policy
Last updated: July 25, 2026
What we collect
That Lands collects account identifiers provided through Sign in with Apple or Google sign-in on the web, taste quiz responses, saved wines, wine ratings, feedback reasons, wine scan requests, scan results, Wine Memory records, first-party product analytics, and operational diagnostics needed to run and improve the app.
Wine label or menu photos submitted for scanning are sent to That Lands services hosted by Vercel and Render and to OpenAI for wine extraction. For signed-in iOS users, the app also stores a private account-scoped copy of each scanned wine photo in Supabase Storage so scan history can restore after reinstalling the app or signing in on another device. Guest display photos remain on the device unless they are later attached to an account through a disclosed account flow.
How we use data
We use collected data for account management, app functionality, wine recommendations, product personalization, first-party analytics, diagnostics, and internal quality review. That Lands does not use this data for third-party advertising or tracking across other companies' apps and websites.
Service providers
That Lands uses Supabase for authentication and database storage, Apple for Sign in with Apple, Google for web sign-in, Vercel for web and proxy hosting, Render for backend processing, and OpenAI for image-based wine extraction.
Retention
Scan explanation traces expire after 30 days. Raw scan metadata is retained for up to 90 days for catalogue quality assurance and review. Product analytics events are retained for up to 13 months for release-funnel analysis. Signed-in iOS scan photos remain in private Supabase Storage until you explicitly delete your account and are cached locally until you delete your account, remove the app, or the app data is otherwise cleared.
Account deletion
You can delete your account from the iOS Profile screen. Account deletion removes your account-linked Cellar, ratings, feedback prompt events, Wine Memories, quiz and profile rows, raw scan metadata, scan explanation traces, backed-up scan photos, analytics identity links, account-linked analytics events, and local scan photos on that device. Backed-up photos are removed through the Storage API before server data cleanup and deletion of the Supabase Auth user.
Contact
For privacy questions, data requests, or deletion help, email support@thatlands.com.