← My Next Wine

Privacy Statement

Version 2026-08-18-UK2 · Last updated 18 August 2026

This statement explains how Greg Bowe trading as MyNextWine processes personal data when a WooCommerce merchant connects and uses the My Next Wine Wine Finder plugin and externally hosted service.

1. External service and consent

Installing or activating the plugin alone does not send the store's account or catalogue data to My Next Wine. An authorised WordPress administrator must open WooCommerce → My Next Wine, review the disclosed data transfer, accept the current Merchant Terms and expressly connect the store. The plugin then uses the My Next Wine service at mynextwine.com to verify ownership, prepare the catalogue and provide recommendations.

2. Who controls the data

The WooCommerce merchant normally controls shopper and customer personal data and must provide its own privacy notice. My Next Wine acts as the merchant's processor where it handles shopper preference inputs, recommendation requests and attributed order references solely to provide the Wine Finder on the merchant's instructions.

My Next Wine acts as an independent controller for merchant account administration, contract and trial/subscription records, service security, fraud and abuse prevention, legal compliance, support correspondence and its own business records. The Merchant Terms include the processor obligations applying between the merchant and My Next Wine.

3. Information sent after connection

Store and administrator information

Catalogue information

Shopper and attributed-order information

The plugin is not designed to send shopper names, account details, email addresses, billing/delivery addresses, order notes or payment-card details to My Next Wine. Merchant subscription checkout is hosted by Stripe. Payment-card details are submitted directly to Stripe and are not transmitted through the WordPress plugin or stored by My Next Wine. For the merchant subscription, My Next Wine retains the legal/business name, billing email, billing country and address, and any tax identifier returned by Stripe as billing, contract, tax and fraud-prevention evidence. The merchant must not deliberately include sensitive personal data or customer-identifying information in free-text preference or food-pairing fields.

Analytics and security information

Merchant reporting is designed to be aggregated rather than to create shopper profiles. Recommendation and basket operations are necessary to provide the feature requested by the shopper; optional analytics are separately consent-gated. Normal web-server and security logs may nevertheless contain personal data such as IP addresses or user-agent information.

4. How and why information is used

5. AI-assisted recommendations

Recommendation generation may use an artificial-intelligence service provider. The information sent may include the current preference and food-pairing answers and a shortlist of relevant catalogue wines, but should not include the shopper's direct identity or payment information. AI output is subjected to application rules and backend validation before it is returned. The Wine Finder does not make decisions producing legal or similarly significant effects about a shopper.

6. Legal bases

Where the GDPR applies, My Next Wine relies on:

7. Recipients and subprocessors

Information may be processed by contracted hosting, database, content-delivery, monitoring, logging, communications, support, billing and AI service providers. Stripe acts as an independent provider for merchant subscription checkout, payment processing, invoices and Customer Portal. WooCommerce, WordPress, the merchant's web host and any installed payment or fulfilment providers process information independently within the merchant's store. My Next Wine does not sell merchant or shopper personal data, does not acquire the merchant's customer relationship or customer list, and does not use Wine Finder preference inputs for direct-to-consumer wine marketing.

Current subprocessor information is published at mynextwine.com/subprocessors. Where a restricted transfer requires safeguards, My Next Wine uses an applicable adequacy decision, the EU Standard Contractual Clauses and, for UK transfers where appropriate, the UK International Data Transfer Addendum, or another lawful mechanism. A required safeguard must be in place before the transfer.

8. Retention, revocation and deletion

9. Security

Measures include ownership verification, encrypted installation secrets, timestamped HMAC-signed plugin requests, replay protection, rate limiting, access controls and final WooCommerce validation of product identity, quantity, price and stock before basket insertion. No system is completely secure; merchants must keep WordPress, WooCommerce, PHP, themes, extensions and administrator accounts secure and supported.

10. Cookies and local storage

The plugin may use strictly necessary WooCommerce/WordPress session mechanisms and browser storage to maintain security and the current recommendation flow. It is not intended to set independent advertising cookies. The merchant is responsible for its own cookie banner, consent configuration and privacy disclosures where local law requires them.

11. Rights and complaints

Depending on applicable law, an individual may request access, correction, deletion, restriction or portability, or object to certain processing. For data controlled by the merchant, the individual should normally contact that merchant first; My Next Wine will assist the merchant where it acts as processor. Requests concerning My Next Wine's controller records can be sent to the privacy contact above. To make a data-protection complaint, use the subject “Data protection complaint” and describe what happened and the outcome sought. Complaints can also be made by post to the business address or, if a UK representative is listed above, through that representative.

We will help people make a complaint, acknowledge it within 30 days, investigate and keep them informed, and communicate the outcome without undue delay. Individuals may also complain directly to the Irish Data Protection Commission or another competent supervisory authority, including the UK Information Commissioner's Office (ICO) where UK data-protection law applies, or an authority in the country where they live or work or where the alleged infringement occurred.

12. Changes

This statement may be updated to reflect changes to the plugin, Service, subprocessors or law. Material changes will be notified through the plugin or another reasonable channel and may require renewed acceptance of the Merchant Terms.