Privacy Policy
Last updated: INSERT DATE WHEN PUBLISHED
1. Who we are
Daily Dram is a personal spirits collection tracker operated by Driven Consulting Solutions, LLC ("Driven Consulting," "we," "us," "our"), a limited liability company organized under the laws of Virginia, USA. Daily Dram is available at distilledadrenaline.com.
If you have questions about this policy or how we handle your data, contact us at:
This policy applies to anyone who uses Daily Dram. By using the service, you agree to the practices described below.
2. The short version
We built Daily Dram to be honest about what it does with your data. The plain summary:
- We collect what's necessary to run the service: your email, the bottles you add, and any photos you upload.
- We use that data to provide the service to you, and for nothing else.
- We do not sell your personal information. We do not show advertising. We do not share your data with third parties for their marketing.
- We use a small number of service providers (Supabase, Vercel, Google Gemini, SerpAPI, Go-UPC, and OAuth providers) to operate the app. They process data on our behalf under their own security commitments.
- You can delete your data at any time.
The rest of this document is the detailed version.
3. What we collect
3.1 Information you provide directly
- Email address. Required to create an account. Collected when you sign in via magic link, Google, or Facebook.
- Display name and profile picture. If you sign in via Google or Facebook, those providers share your public name and avatar with us. You can sign in via email instead and skip this.
- Bottle data. Anything you add about bottles in your collection: name, distillery, region, type, age, ABV, status (sealed/opened/empty), fill level, location, purchase price, current value, purchase date, ratings, tasting notes, custom notes, wishlist target prices, photos.
- Imported data. If you import a CSV file, the bottle data inside it.
- Pour timestamps. When you log a pour from the Daily Dram randomizer, we record the time so the randomizer can rotate intelligently through your collection.
3.2 Information collected automatically
- Authentication data. When you sign in, our auth provider (Supabase) generates a session token stored in your browser's local storage to keep you signed in.
- Standard server logs. Our hosting provider (Vercel) logs basic information for every request — IP address, browser type, request time. These logs are retained briefly for operational and security purposes.
- API usage counts. We track how many price lookups and barcode scans each user performs per day, to enforce per-user usage limits.
3.3 Information we don't collect
To be explicit about things we deliberately don't do:
- We don't use Google Analytics, Facebook Pixel, or any third-party tracking.
- We don't fingerprint your device.
- We don't track you across other websites.
- We don't read or access data outside Daily Dram.
- We don't collect precise location, contacts, calendar, or any other phone-level data.
4. How we use your data
We use your data for one purpose: to provide Daily Dram to you. Specifically:
- To authenticate you and keep you signed in.
- To store your bottle collection and make it available across your devices.
- To look up market prices for bottles when you ask.
- To identify products from barcodes you scan.
- To enforce per-user fair-use limits on third-party API calls.
- To diagnose problems and investigate security issues if they arise.
We do not use your data to train AI models, build advertising profiles, or for any purpose unrelated to providing the service.
5. Who we share data with
We use a small number of service providers ("data processors") to operate Daily Dram. They process data only on our behalf and under contracts that limit how they may use it.
5.1 Supabase (database, authentication, file storage)
Supabase is our primary infrastructure provider. Your account, your bottle data, and your uploaded photos are stored in Supabase's hosted infrastructure. Supabase processes this data on our behalf under its Data Processing Addendum.
5.2 Vercel (hosting)
Vercel hosts the Daily Dram web application. When your browser loads the app, Vercel's servers see your IP address, user agent, and the URLs you request. Vercel processes this data under its Data Processing Agreement.
5.3 Google Gemini AI (price lookup)
When you request a market price for a bottle that isn't in our built-in catalog, we send the bottle's name, distillery, and age (no personal information) to Google's Gemini API. Gemini searches the web and returns retailer prices. Google's use of data is governed by the Gemini API terms.
5.4 SerpAPI (price lookup fallback)
If Gemini doesn't return useful pricing, we may send the same bottle information (name, distillery, age) to SerpAPI, which queries Google Shopping. No personal information is sent.
5.5 Go-UPC (barcode lookup)
When you scan a barcode that isn't in our built-in catalog, we send the UPC code to Go-UPC to identify the product. No personal information is sent.
5.6 Google and Meta (OAuth sign-in)
If you choose to sign in via Google or Facebook, those providers handle the authentication flow and share your email, name, and profile picture with us. Their handling of authentication data is governed by Google's privacy policy and Meta's privacy policy.
5.7 What we do NOT do
- We do not sell your personal information to anyone.
- We do not share your data with advertisers or marketing partners.
- We do not share your bottle data, photos, or usage with any third party not listed above.
6. How long we keep your data
- Account, bottles, photos, alerts: retained until you delete them or delete your account.
- Authentication tokens: Supabase rotates these on a regular cycle; old tokens become invalid automatically.
- Server logs (Vercel): retained briefly per Vercel's defaults (typically days to weeks).
- API usage counters: reset daily.
- Cached pricing and barcode lookups: held for 7-30 days to reduce costs and improve performance. These caches are keyed by bottle/UPC, not by user identity, and are shared across all users.
7. Your rights and choices
You have the right to:
- Access the data we hold about you. Most of it is visible directly in the app; for anything else, contact us.
- Correct inaccurate information. You can edit any bottle, your name, or your photos directly in the app.
- Delete specific bottles, photos, or alerts at any time within the app.
- Delete your entire account. This feature is being added; until then, email [email protected] with the subject "Delete my account" from the email address you signed up with, and we will delete your account and associated data within 30 days.
- Export your data. CSV export of your collection is available within the app. For other data, contact us.
- Withdraw consent at any time by signing out and requesting account deletion.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Security
We protect your data with reasonable technical and organizational measures:
- All connections to Daily Dram and our APIs use HTTPS encryption.
- Authentication is passwordless (magic link or OAuth), so we never store your password.
- Database access is enforced at the row level — each user's data is only readable by that user, even by our own application code, except where we (the operator) need direct access to investigate problems.
- Sensitive credentials (API keys for third-party services) are stored as encrypted environment variables on the server, never sent to your device.
No security system is perfect. If we ever discover a breach affecting your data, we will notify affected users without unreasonable delay.
9. Age requirements
Daily Dram is intended for users 21 years of age or older, the legal drinking age in the United States. We do not knowingly collect information from anyone under 21. If you are under 21, do not use Daily Dram. If you believe a minor has provided us with personal information, contact us at [email protected] and we will delete it.
10. International users
Daily Dram is operated from the United States. Our service providers (Supabase, Vercel, Google, SerpAPI, Go-UPC, Meta) operate globally and may store or process your data on servers located outside your country of residence, including in the United States.
If you are located in the European Union, the United Kingdom, or another jurisdiction with data protection laws like the GDPR:
- Driven Consulting Solutions, LLC is the data controller for your information.
- Our legal basis for processing is your consent (when you sign up) and our legitimate interest in providing the service.
- You have the rights described in Section 7 above, plus additional rights under GDPR, including the right to lodge a complaint with your local data protection authority.
- International transfers are protected by Standard Contractual Clauses with our processors where applicable.
11. California privacy rights
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you specific rights:
- Right to know what personal information we collect, use, and share — fully described in this policy.
- Right to delete personal information we have collected about you (Section 7).
- Right to opt out of sale — not applicable, because we do not sell personal information.
- Right to non-discrimination — we will not deny service, change pricing, or otherwise discriminate against you for exercising your privacy rights.
To exercise these rights, contact [email protected].
12. Changes to this policy
We may update this policy from time to time. If we make material changes (for example, adding a new data processor or a new category of data), we will notify users by email and post the updated policy at this URL with a revised "Last updated" date.
If you continue to use Daily Dram after a material change, you accept the updated policy. If you don't accept it, you may delete your account.
13. Contact us
For any questions about this policy or your data:
We aim to respond to all privacy inquiries within 30 days.