Privacy policy

1. This policy

This privacy policy (“Privacy Policy”) explains how Marzipan LTD (“Marzipan”, “we”, “us” “our”) collects, controls, processes and uses information about you when you access the Marzipan Services, and any other websites, software or applications or otherwise services that we make available in conjunction with these Marzipan Services. The “Marzipan Services”, which we also call “Services” include:

  1. our cloud-based e-Commerce and data management software and application programming interface (“API”) for wineries as made available on https://www.marzipan.co (the “Platform Services”); and
  2. the digital wine label (“e-label”) creation, management and hosting service that we make available under the trade name “Labls” on https://www.labls.io (the “Labls Services”).

If you have any questions about this Privacy Policy, or any complaints about Marzipan’s use and handling of your Personal information, you can contact us by email at hello@marzipan.co or write to us at our correspondence address at 7 Bell Yard, London, England, WC2A AJR. Marzipan LTD is a private company limited by shares incorporated and registered in England and Wales with company number 14708758, and serves as the data controller of any information about you that is processed as a result of your use of the Services.

3. Personal data that we may collect

We may collect the following information about you and your customers:

Information you provide to Marzipan

  • Customer Information. We collect information that we receive from you, or from a third party at your direction, about your winery’s business and consumer clients, suppliers, distributors and vendors (“Customer Information”). We collect only the Customer Information that you provide to us, direct us to collect, or access to provide the Services to you. Customer Information may include personal data about different types of individuals, including: consumers, employees, business clients, suppliers and other business partners. Such personal data may include basic contact information, such as name, postal address, email address and phone number, as well as more sensitive personal data, such as purchase history, demographic information and market-research information.

    We operate under the assumption that it is your obligation as a data controller to notify individuals whose personal data may be included in the Customer Information you share with Marzipan about the personal data you collect and the purposes for which you collect it, to obtain their consent to our processing of their personal data, where required, and to ensure that such personal data is reliable for its intended use, accurate, complete and current. We have no direct relationship with the individuals whose personal data is included in the Customer Information we process.

  • Profile information. We collect information that you provide when you register an account (whether as a sole trader who purchases a subscription to the Services in their own name or an authorised user of a winery’s subscription to the Services), such as your name, username, verifiable email address and password.

  • User Content. We collect the content that you create or publish through the Services, such as e-labels and their associated content, Customer Information, graphics, marketing campaigns, purchase data & history, client, supplier and vendor lists, tax data, reviews, logos as well in each case the associated metadata (such as when, where and by whom the content was created) (together “Your Content” or “Content”).

  • Your preferences.We collect information that you submit on the Services relating to your preferences. This includes any information you provide to Marzipan with respect to your preferred data filters, views and models, performance and reporting indices, accounting reference periods, communication and notification preferences and similar.

  • Content and Direct Messages. When you communicate directly with any customers, suppliers, partners or otherwise business partners using any live or relay messaging system (if any) offered within the Services, we may collect the content of the post and the associated metadata (i.e. when it was posted, who it was seen by, what it said). We may do this in order to check that it complies with our Terms of Service. We will also collect any messages you send or receive through any chat functionality when communicating in-app or on our Websites with any Marzipan customer service representative (including any virtual assistants/chatbots).

  • Purchase Information. When you make a purchase a Subscription for the Services, or purchase any add-on products or services connected to the foregoing, we collect information about the purchase such as the Subscription purchased, the purchase time and date and your contact information. Please note that as we purchase payment via a third-party payment processor (such as PayPal), we do not collect or store your payment details such as any credit or debit card numbers, bank account details or preferred payment methods.

  • Information when you contact Marzipan. For administrative purposes, we may need to record information about your interactions with Marzipan, including such as where you telephone us, or communicate with a member of our staff by email. This is necessary so that we may keep a record of any requests or updates you have provided us with.

Information we collect automatically

  • Usage Information. We collect information concerning how you engage with the Services, including without limitation and for illustrative purposes, information about the data analytics models and metrics you have viewed, the e-commerce web elements that you have accessed, the time of day, duration and frequency of your use of the Services, data on search queries made by you within the Services (i.e. such as data you have searched for), the third-party services offered on the Services that you have interacted with, and the features of the Services that you have used. We may also collect information as to the platform or website that you visited prior to accessing the Services, as well as the platform or website that you visit next.

  • Technical Information. Marzipan collects certain browser, device and network connection information when you access the Services. The categories of information we collect vary in accordance with your respective browser, device and network settings.

  • Location Data. We automatically collect information about your approximate location (e.g. country, city, region) based on your device and network information (such as your IP address).

  • Cookies. We assign a unique cookie identifier to each device that accesses the Services. These cookie identifiers allow us to store information relating to your use of the Services, such as your preferred settings on the Services. They also allow access information stored on your device to enable certain features and distinguish your device from others. Please see our cookie policy for more details.

Information we collect from others

  • Payment Providers.We receive information about you from third-party payment service providers (such as PayPal) when you purchase a Subscription. This information consists of your name, email address and your payment confirmation details.

  • Social Media Platforms.When you connect your winery’s social media profile with your account on the Services, we receive information about your social media profile from the relevant social media provider. The categories of information vary depending on the Social Media Platform concerned, but will most often include your name, e-mail address, contact and friend list, profile picture as well as any other information that you have elected to make public on the relevant Social Media Platform.

  • Third Party Services.When you integrate any third-party services or ad-ons with the Services, such as any third-party payment processing gateway (such as PayPal), tax, accounting or shipping software or any third-party API, we may collect certain information from the providers of each of the foregoing relating to your use of each of such services.

4. How we use Personal Data

We use Customer Information and your personal data to:

  • Provide, maintain, administer and enhance the Services. Our primary purpose in collecting your information is so as to provide the Services and is various features to you, such as by enabling you to create e-labels, set up, manage and administer your e-commerce store, interface the Marzipan API with your online storefronts, purchase and redeem Subscriptions, access data analytics and insights, and receive customer and technical support. We also use the information we collect from you in order to maintain and enhance the Services, including by identifying and addressing technical bugs, and by monitoring interactions and usage across devices.

  • Provide paid features. We collect your information so as to enable you to purchase Subscriptions and otherwise paid features.

  • To administer your account, contracts, enquiries or complaints. We use you information to register, configure and administer your user account on the Services to fulfil any contracts we have with you (including in respect of your licence to access Marzipan under our Terms of Service), and to handle and process your customer support requests and any complaints that you make or are subject to.

  • Enforce our Terms. We may use your information in order to enforce our Terms of Service and any other terms and conditions we make available from time to time, as well as to monitor your compliance with applicable laws and the appropriateness of your interactions with other users.

  • Comply with our legal obligations. We collect your information to comply with our legal obligations in various jurisdictions, as well as necessary to perform tasks in the public interest, or to protect the vital interests of our users and third-parties.

5. How we share your personal data

We may disclose personal information to:

  • Third Party Service Providers. We share personal data with third party service providers for the purpose of enabling them to provide their services, including (without limitation) IT service providers, data storage, hosting and server providers, ad networks, analytics, error loggers, debt collectors, maintenance or problem-solving providers, marketing or advertising providers, professional advisors and payment systems operators.

  • Our Staff and Group entities: including our employees, contractors and/or related entities.

  • Credit reporting agencies, courts, tribunals and regulatory authorities: in the event you fail to pay for goods or services we have provided to you.

  • Courts, tribunals, regulatory authorities and law enforcement officers: as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise or defend our legal rights.

  • Third parties: including agents or sub-contractors who assist us in providing information, products, services or direct marketing to you.

  • our Successors and Assigns. If Marzipan engages in a merger, acquisition, bankruptcy, dissolution, reorganisation, sale of some or all of Marzipan’s assets or shares, financing, public offering of securities, acquisition of all or a portion of our business, a similar transaction or proceeding or steps in contemplation of such activities, some or all of yout personal data may be shared or transferred, subject to standard confidentiality arrangements.

7. Data retention

Except as otherwise permitted or required by applicable law or regulation, we will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, as required to satisfy any contractual, legal or reporting obligations, where we have a legitimate business interest to do so, or as necessary to resolve disputes (including the exercise or defence of legal claims). Except where a longer retention period is allowed under applicable laws, we delete or permanently de-identify Customer Information and personal data within 30 days of the end of your Subscription.

To determine the appropriate retention period for personal information, we consider our statutory obligations, the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes we process your personal information for, and whether we can achieve those purposes through other means

8. International transfers of personal information

Marzipan is based in the United Kingdom and all the personal information we collect on the Services are stored in servers located in the UK.

That said, our Services integrate with and are supported in part by the products and services of third-party services providers, many of whom are located outside of the UK and European Economic Area (“EEA”) in jurisdictions that do not provide an adequate level of data protection as defined by data protection laws in the UK and EEA.

We only transfers to third parties located in such third countries using a valid data transfer mechanism, such as the EU Standard Contractual Clauses (SCCs) (as well as the corresponding UK Addendum, as appropriate), on the basis of permissible statutory derogations, or with reference to any other valid data transfer mechanism issued or approved by the UK or EEA authorities. Certain third countries have been officially recognized by the EEA and UK authorities as providing an adequate level of protection, and no further safeguards are necessary.

The SCCs are a contractual terms template that have been pre-approved by the European Commission and serve as a legal transfer mechanism. Marzipan uses these SCCs and supplemental measures in accordance with European Commission and European Data Protection Board guidance. These updated SCCs, as well as the corresponding UK Addendum, are an integral part of the Marzipan Data Processing Agreements (DPAs) that Marzipan executes with its customers, sub-processors and partners when applicable.

9. Your rights and controlling your personal information

  • Choice and consent: by providing personal information to us, you consent to us collecting, holding, using and disclosing your personal information in accordance with this privacy policy. If you are under 16 years of age, you must have, and warrant to the extent permitted by law to us, that you have your parent or legal guardian’s permission to access and use the website and they (your parents or guardian) have consented to you providing us with your personal information. You do not have to provide personal information to us, however, if you do not, it may affect your use of this website or the products and/or services offered on or through it.

  • Information from third parties: if we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person’s consent to provide the personal information to us.

  • Restrict: you may choose to restrict the collection or use of your personal information. If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by contacting us. If you ask us to restrict or limit how we process your personal information, we will let you know how the restriction affects your use of our website or products and services. Please note that we may be unable to offer you a service.

  • Access and data portability: you may request details of the personal information that we hold about you. You may request a copy of the personal information we hold about you. Where possible, we will provide this information in CSV format or other easily readable machine format. You may request that we erase the personal information we hold about you at any time. You may also request that we transfer this personal information to another third party.

  • Correction: if you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details below. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading or out of date.

  • Notification of data breaches: we will comply with laws applicable to us in respect of any data breach.

  • Complaints: if you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.

  • Unsubscribe: to unsubscribe from our e-mail database or opt-out of communications (including marketing communications), please contact us using the details below or opt-out using the opt-out facilities provided in the communication.

10. Cookies

We only use essential cookies to ensure our website and app functions properly. We do not use tracking cookies. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on preferences you have specified. Please refer to our cookie policy for more information.

11. Limits of our policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

12. Changes to this policy

At our discretion, we may change our privacy policy to reflect current acceptable practices. We will take reasonable steps to let users know about changes via our website. Your continued use of this site after any changes to this policy will be regarded as acceptance of our practices around privacy and personal information.