Privacy Policy
Effective Date: April 30, 2026
This policy applies to CrushSuite Compliance, CrushSuite Clubs, and CrushSuite Seats.
1. Who We Are
CrushSuite ("CrushSuite," "we," "us," or "our") is a software company that develops and operates a suite of Shopify applications — CrushSuite Compliance, CrushSuite Clubs, and CrushSuite Seats — designed for wineries, cideries, breweries, and other alcohol beverage producers selling direct-to-consumer through Shopify.
This Privacy Policy explains how we collect, use, share, and protect information in connection with our apps and website at https://crushsuite.com. By installing or using any CrushSuite app, you agree to the practices described in this policy.
Questions? Contact us at admin@crushsuite.com.
2. Information We Collect
2.1 Information from Merchants (Shopify Store Owners)
When you install a CrushSuite app, we receive information from Shopify necessary to operate the app. This includes:
- Your Shopify store name, domain, and store ID
- Your account email address and contact information
- Your billing information (processed by Shopify — we do not store payment card data)
- Store configuration data, including product catalogs, inventory, and shipping settings
- Order data, including order IDs, line items, quantities, shipping destinations, and order status
- Customer records from your store (names, shipping addresses, email addresses, purchase history)
- App configuration settings you configure within CrushSuite
2.2 Information from Your Customers (End Users)
When your customers interact with CrushSuite features within your Shopify storefront or checkout, we may process:
- Name, shipping address, and email address (from Shopify checkout)
- Date of birth or age verification responses submitted through our age gate
- State of residence for shipping eligibility determination
- Order details sufficient to apply compliance rules and calculate fees
We process this data on behalf of you, the merchant, as a data processor. Your customers' relationship is with your store. We do not use your customers' data for our own marketing purposes.
2.3 CrushSuite Compliance — Additional Data
For merchants using CrushSuite Compliance, we additionally process:
- VinoShipper account credentials and license data (when VinoShipper integration is enabled)
- State-by-state DTC shipping license status and volume limits
- Compliance fee calculations applied per order
- Age verification records, including method of verification and outcome
- Cumulative shipping volumes per customer per state for volume limit enforcement
2.4 CrushSuite Clubs — Additional Data
For merchants using CrushSuite Clubs, we additionally process:
- Wine club membership records, including tier, join date, and status
- Release schedule data and member allocation preferences
- Recurring billing records, including billing cycle, amounts, and payment status
- Member customization preferences (e.g., build-a-box selections)
- Club cancellation and pause records
2.5 CrushSuite Seats — Additional Data
For merchants using CrushSuite Seats, we additionally process:
- Reservation records, including date, time, party size, and guest name
- Event and ticketing data, including event details, ticket types, and attendee information
- Guest contact information provided at booking
- Walk-in and waitlist records
2.6 Information Collected Automatically
When you use our website or apps, we automatically collect certain technical data:
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Pages visited, time spent, and navigation patterns
- Referring URLs and exit pages
- App performance data and error logs
This technical data is used solely to operate, secure, and improve the Apps and the website. Application logs and error traces are retained for no longer than ninety (90) days. Aggregate analytics data may be retained indefinitely in anonymized or aggregated form. We do not use technical data to build advertising profiles or to identify visitors across sites.
3. How We Use Information
We use the information we collect for the following purposes:
3.1 Operating and Delivering the Apps
- Enforcing state-by-state shipping rules and compliance restrictions at checkout
- Calculating and applying alcohol compliance fees
- Running age verification and address validation
- Syncing data with VinoShipper and other integrated compliance partners
- Managing wine club memberships, billing cycles, and release fulfillment
- Processing tasting room reservations and event ticket sales
- Generating compliance reports required by state regulators
3.2 Account and Billing Management
- Creating and managing your CrushSuite merchant account
- Processing subscription payments via Shopify's billing API
- Sending billing confirmations, renewal notices, and payment failure alerts
3.3 Support and Communications
- Responding to support requests and technical inquiries
- Sending product updates, new feature announcements, and operational notices
- Providing onboarding guidance and setup assistance
3.4 Improvement and Analytics
- Analyzing usage patterns to improve app performance and features
- Identifying and fixing bugs and errors
- Developing new features based on merchant needs and feedback
3.5 Legal Compliance
- Complying with applicable laws, regulations, and legal process
- Enforcing our Terms of Service and other agreements
- Protecting against fraud, abuse, and security threats
3.6 Legal Bases for Processing (GDPR / UK GDPR)
Where applicable data protection law requires, we rely on the following legal bases to process personal data:
- Performance of a contract — to deliver the Apps to merchants under the Terms of Service, including billing, account management, and core feature operation.
- Compliance with legal obligations — to retain compliance records required by state alcohol regulations, tax law, and applicable consumer protection laws.
- Legitimate interests — to secure our systems against fraud and abuse, to detect and fix bugs, to develop new features based on aggregate usage patterns, and to communicate with merchants about operational matters. Where we rely on legitimate interest, we balance our interest against the rights and freedoms of data subjects.
- Consent — where consent is the appropriate basis (for example, certain optional analytics or marketing communications), we will request it and you may withdraw it at any time.
End customers' personal data is processed on behalf of the merchant under the merchant's own legal basis. We do not establish a direct relationship or processing purpose with end customers.
4. How We Share Information
We do not sell your data or your customers' data. We share information only in the following circumstances:
4.0 Our Role
For the purposes of EU and UK data protection law and the California Consumer Privacy Act, you (the merchant) are the data controller with respect to your customers' personal data, and CrushSuite acts as a data processor processing such data on your behalf and pursuant to your documented instructions, as further described in our Terms of Service.
4.1 Shopify
Our apps operate within the Shopify platform. Shopify processes data in connection with your store in accordance with Shopify's Privacy Policy.
4.2 VinoShipper and Compliance Partners
If you have enabled VinoShipper integration within CrushSuite Compliance, we share order data, customer shipping information, and compliance-relevant details with VinoShipper solely for the purpose of fulfilling compliance obligations. This data sharing is governed by your agreement with VinoShipper.
4.3 Subprocessors
We engage the following categories of third-party service providers ("subprocessors") who assist us in operating CrushSuite. Each is contractually required to handle data only as directed by us and in accordance with this policy and applicable law.
- Cloud hosting and database — Railway (United States), providing primary application hosting, PostgreSQL database, and Redis cache.
- Webhook and messaging infrastructure — Google Cloud Platform (United States/global), providing Pub/Sub delivery for Shopify order webhooks.
- Transactional email — Mailgun, an operating brand of Sinch (United States), providing email delivery for billing notices, support replies, and operational alerts.
- Marketing website hosting and analytics — Vercel (United States), providing crushsuite.com hosting and anonymous, aggregate Vercel Analytics.
- Public asset storage — Amazon Web Services S3 (us-west-2 region, United States), used only for non-personal marketing and product imagery.
- Customer support — Freshdesk, an operating brand of Freshworks (United States/global), providing the support ticketing system at crushsuite.freshdesk.com.
- Compliance partners — VinoShipper (United States) and other compliance partners you have explicitly enabled, processing order and customer data necessary for alcohol shipping compliance.
- Shopify — your platform of record. Shopify processes data in connection with your store under its own terms.
We will provide at least thirty (30) days' advance notice via email or in-app notice before adding a new subprocessor or changing the role of an existing one in a way that materially affects the processing of your data. A current subprocessor list is available at any time on request to admin@crushsuite.com.
4.4 International Data Transfers
CrushSuite is operated from the United States. Data we process — including merchant data and end-customer data — is stored and processed in the United States and other jurisdictions where our subprocessors operate. We protect transferred data with technical safeguards including encryption in transit (TLS), encryption at rest, and column-level encryption of particularly sensitive fields.
4.5 Legal Requirements
We may disclose information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of CrushSuite, our merchants, or the public.
4.6 Business Transfers
If CrushSuite is acquired by or merged with another company, your information may be transferred as part of that transaction. We will notify affected merchants before any such transfer occurs.
5. Data Retention
Active accounts: We retain merchant and customer data for as long as your CrushSuite subscription is active.
Following termination or app uninstallation: We delete or anonymize merchant and customer personal data within 90 days, in line with the Shop Data Erasure obligation in Section 6. The 90-day window allows for operational needs such as final billing reconciliation and recovery from accidental uninstalls.
Compliance retention exception: A narrow set of compliance records — specifically, age verification logs, shipped-volume records used for state volume-limit enforcement, and tax calculation history — may be retained in anonymized or pseudonymized form for up to 7 years where required by applicable state alcohol regulations or tax law. Where retained, these records are stripped of contact information (email, phone, postal address) and reduced to the minimum data needed to defend against a regulatory audit. They are not used for any operational or marketing purpose.
Earlier deletion: You or a data subject may request earlier deletion of personal data by contacting us at admin@crushsuite.com. Requests are processed within 30 days, subject to the compliance retention exception above and other legal retention obligations.
6. Data Subject Requests via Shopify GDPR Webhooks
Shopify operates the front line for data subject requests received through its platform and forwards relevant requests to apps installed on a merchant's store, including CrushSuite. As a data processor for our merchants, we implement the three mandatory Shopify webhook topics:
- customers/data_request — Upon receipt, we provide a report of personal data we hold for the specified customer within 30 days. Requests are routed to the merchant for fulfillment, with our cooperation as the processor.
- customers/redact — Upon receipt, we delete or anonymize personal data associated with the specified customer, subject to the compliance retention exception in Section 5.
- shop/redact — Upon receipt following app uninstallation, we delete all merchant and customer personal data associated with the store within 90 days, subject to the compliance retention exception in Section 5.
If you are a data subject seeking to exercise rights with respect to a specific store, please contact that store's merchant first, as the merchant is the controller. You may also contact us directly at admin@crushsuite.com; we will route the request appropriately and respond within 30 days.
7. Your Privacy Rights
7.1 Merchants (GDPR / EEA)
If you are located in the European Economic Area, you have the right to access, correct, delete, or restrict processing of your personal data. You also have the right to data portability and the right to object to processing based on legitimate interests. To exercise these rights, contact us at admin@crushsuite.com.
7.2 California Residents (CCPA / CPRA)
If you are a California resident, you have the right under the California Consumer Privacy Act and California Privacy Rights Act to know what personal information we collect about you, the sources from which we collect it, the business purposes for which we use it, and the categories of third parties with whom we share it. Section 2 of this policy describes the categories of personal information we process; Section 3 describes the purposes; and Section 4 describes the sharing arrangements.
You also have the right to delete personal information we hold about you, to correct inaccurate personal information, to limit the use of sensitive personal information, and to opt out of any sale or sharing of personal information. CrushSuite does not sell personal information and does not share personal information for cross-context behavioral advertising.
To submit a CCPA request, contact us at admin@crushsuite.com. We will verify your request and respond within forty-five (45) days, with a possible 45-day extension where reasonably necessary.
7.3 All Users
Regardless of location, you may contact us at any time to request access to, correction of, or deletion of personal data we hold about you, subject to applicable legal requirements.
8. Security
We implement technical and organizational measures designed to protect data against unauthorized access, loss, or destruction. These include:
- Encryption in transit using TLS 1.2 or higher for all connections to and from CrushSuite services.
- Encryption at rest for application databases and backups.
- Column-level encryption for particularly sensitive fields, including customer date-of-birth records used for age verification.
- Role-based access control with least-privilege defaults; production access is limited to engineering personnel with a documented operational need.
- Audit logging of administrative access and webhook processing.
- Regular dependency and vulnerability scanning of our application code and runtime images.
- Secrets management with rotation policies for third-party API credentials.
No system is completely secure. In the event of a confirmed data breach affecting your data, we will notify you without undue delay and in any event no later than seventy-two (72) hours after we become aware of the breach. Notice will include, to the extent known: the nature of the breach, categories and approximate number of affected records, likely consequences, and the measures we have taken or propose to take in response.
To report a suspected security issue affecting CrushSuite, contact us at admin@crushsuite.com with the subject line "Security Report."
9. Cookies and Tracking
The crushsuite.com marketing website uses a small number of cookies and similar technologies for purposes limited to:
- Strictly necessary — maintaining session state and CSRF protection.
- Performance and analytics — Vercel Analytics, which collects anonymous, aggregate usage data without persistent identifiers and does not track visitors across third-party sites.
The CrushSuite Apps themselves operate within Shopify's iframe and rely on Shopify session authentication; they do not set independent tracking cookies on your end customers.
Visitors located in the European Economic Area or the United Kingdom may decline non-essential cookies via the consent control on our website. Where consent is the legal basis for a cookie, the cookie is not set until consent is given. Strictly necessary cookies do not require consent under the EU ePrivacy Directive.
We honor browser-level "Do Not Track" and "Global Privacy Control" (GPC) signals for non-essential analytics where technically supported by the underlying provider.
You can disable cookies through your browser settings, though doing so may affect website functionality.
10. Minors and Age Verification Data
CrushSuite is a B2B service designed for use by businesses, not directly by individuals. We do not market the Apps to minors and do not knowingly collect personal information from minors for our own purposes.
Age verification through CrushSuite Compliance is a different matter: by design, the age-gate processes date-of-birth data submitted by your end customers — including, on occasion, individuals under the legal drinking age — for the sole purpose of determining whether a transaction may lawfully proceed. We process this data on your behalf as part of your statutory obligation to verify customer age before shipping alcohol. Where a customer is determined to be under the legal drinking age, the transaction is denied; we retain only the minimum record needed to evidence the denial for compliance audit purposes, in anonymized or pseudonymized form where feasible.
We do not use age verification data for any marketing, analytics, or profiling purpose.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy at https://crushsuite.com/privacy and update the Effective Date. For material changes that adversely affect data subject rights, we will provide at least thirty (30) days' advance notice by email or through a notice in the CrushSuite app. Your continued use of CrushSuite after the effective date constitutes acceptance of the updated policy.
The current version of this policy is always available at https://crushsuite.com/privacy.
12. Privacy Contact
Questions, concerns, or requests regarding this Privacy Policy or our data practices should be directed to our privacy team:
CrushSuite Privacy Team
Email: admin@crushsuite.com
Subject line: "Privacy Request" for data subject requests.
Website: https://crushsuite.com
Note: This Privacy Policy was last updated on April 30, 2026. CrushSuite reserves the right to modify this policy in accordance with Section 11. Merchants are encouraged to consult their own qualified legal counsel regarding their specific data protection obligations.