Privacy
Last updated 8 September 2026
Who we are
Sobremesa Wine Pte. Ltd., UEN 202633623Z, a company registered in Singapore. We import Spanish wine and run a members’ club. We are the organisation responsible for the personal data described here, and we handle it under Singapore’s Personal Data Protection Act 2012.
What we collect, and why
We collect the least we can get away with. There is no advertising network here, no analytics tracker, and nothing is sold or shared for marketing.
| What | Why |
|---|---|
| Your name, and the name the table calls you | To know who is sitting down, and what to put on your card |
| Email address | To sign you in — we use a link rather than a password, so we never hold one — and to send you the monthly letter |
| Date of birth | We sell alcohol. The law requires us to be satisfied you are 18 or older, and to be able to show it |
| A record each time you confirm your age at checkout, with the time you did it | Required by the conditions of our liquor licence |
| What you have bought, and the bottles resting in your cellar | To fulfil the order and tell you what you own |
| Your points and how they moved | To work out your standing and what you may claim |
| Sessions you attend, and the name and email of any guest you bring | To seat the room, and to send your guest their invitation. We collect a guest’s details from you; please only give them if your guest is content for you to |
| Delivery address and a phone number, when you ask for bottles to be delivered | To get them to you, and so the vault can confirm the time with you directly |
| A notification token for your phone, if you install the app and allow notifications | To tell you when an allocation opens or a letter arrives. It identifies the device, not you, and turning notifications off removes it |
We never see your card details. Payment is handled by Stripe on their own pages; card numbers do not reach our servers. We keep only their reference for the payment, so we can match it to your order.
Cookies
One kind only: the cookie that keeps you signed in. It is necessary for the site to work and it is not used to follow you anywhere. We do not use analytics, advertising or third-party tracking cookies, which is why you have not been asked to dismiss a banner.
If you install the app — to your home screen, or from an app store — your sign-in and a copy of your card and cellar are stored on your own device so they open without a signal. Signing out erases that copy.
Your cellar shows Singapore’s temperature beside the vault’s. In the app that reading is fetched by your phone from a public weather service, which therefore sees your device’s network address; we send it nothing about you, and it is asked only for the weather over Singapore.
Who else touches it
Only the companies that make the club work, and only with what they need:
- Supabase — stores the database and manages sign-in. Hosted in Singapore.
- Vercel — runs the website itself.
- Stripe — takes payment. They receive your email and the amount; we receive no card details.
- Resend — sends our email.
- Expo — delivers notifications to the app. They receive the device token and the message, and nothing else about you.
- Singapore Wine Vault — stores and dispatches your bottles. When you call for a delivery they receive, on that run’s sheet, your name, phone number, delivery address, the time of day you asked for, any note you left for the driver, and the serial numbers of the bottles to bring.
Some of these operate servers outside Singapore. Where data is transferred abroad we rely on their contractual undertakings to protect it to a standard comparable to the PDPA.
How long we keep it
Records of what you bought, and of each age confirmation, are kept for five years, because tax and licensing rules require it. Everything else is kept while you have a seat at the table, and removed within a reasonable period after you leave.
Two exceptions, both deliberate. The Founding Ledger records the fifteen founders’ chosen names and seat numbers permanently; it is written once and never edited, and that permanence is the point. Our administrative audit trail keeps a record of actions taken by administrators.
What you can ask for
Under the PDPA you may ask us to:
- tell you what personal data we hold about you, and how we have used it;
- correct anything that is wrong;
- take you off the letter — write to us and we will, at any time;
- close your account and delete what we are not required to keep.
Write to us at the address below and we will answer within 30 days. If we cannot do what you have asked — usually because a record must be kept for licensing or tax — we will say so plainly and explain why.
If something goes wrong
If personal data is exposed in a way likely to cause you significant harm, we will tell you and notify the Personal Data Protection Commission as the law requires.
Lei Ding, Sobremesa Wine Pte. Ltd.
lei@sobremesa.wine
Unhappy with our answer? You may complain to the Personal Data Protection Commission of Singapore at pdpc.gov.sg.