Digby App – Privacy
Last updated: 9 June 2026 Effective from: 9 June 2026
This Privacy Policy explains how Digby Fine English (“we”, “us”, “our”) collects, uses, and protects personal data when you use the Digby Sparkle iOS app (“the App”). It supplements — and where it differs, takes precedence over — the privacy policy published on digbyfineenglish.com for App users.
We are the data controller for the personal data we collect through the App.
Contact: Digby Fine English Ltd 55-57 High Street, Arundel, West Sussex, BN18 9AJ Company number: 08020783 ICO registration: ZA683531 Email: privacy@digbyfineenglish.com
1. Summary
In short:
- We collect the minimum data needed to run your membership: email, name, date of birth, payment status, and wine-purchase history.
- We do not track you across other apps or websites, show advertising, or sell your data to anyone.
- Your payment card details are handled by Stripe — we never see or store them.
- Your wine order and reservation history is handled by Commerce7 under our existing wine-club terms.
- You can delete your account at any time from inside the App: Account tab → Delete Account.
The sections below give the detail.
2. What we collect, and why
2.1 Account data
| What | When | Why | Legal basis |
| Email address | At sign-up (email/password, or via Apple/Google sign-in) | Identify your account, send transactional emails (password reset, subscription receipts) | Contract performance |
| First and last name | At sign-up | Personalise the App, link to your Commerce7 customer record | Contract performance |
| Date of birth | At sign-up (age-gate) | Confirm you are 18 or over as required by UK alcohol-sales regulations; trigger your annual birthday-gift reward | Legal obligation; legitimate interest |
| Password (if email sign-in) | At sign-up | Authenticate you on subsequent logins | Contract performance |
| Apple / Google user identifier (if SSO) | At sign-up | Authenticate you on subsequent logins | Contract performance |
We collect the minimum identity data required to operate the membership. If you sign in with Apple and choose to hide your email address, we receive only Apple’s relay address and never see your real one.
2.2 Membership and payment data
| What | When | Why | Legal basis |
| Subscription tier (Access / Silver / Gold / Platinum) | When you subscribe | Determine which benefits you receive | Contract performance |
| Stripe customer ID | First time you subscribe | Link App account to your Stripe billing record | Contract performance |
| Subscription status, plan, renewal date | Updated by Stripe webhooks | Show your subscription state in-App; gate access to paid benefits | Contract performance |
| Payment card details | At checkout, handled solely by Stripe | Process subscription payments | Contract performance |
We never see or store your card number, expiry, or CVC. All card data is handled directly by Stripe Payments Ltd on Stripe’s hosted checkout page. See Stripe’s privacy policy at https://stripe.com/gb/privacy.
2.3 Wine club and order data
| What | When | Why | Legal basis |
| Commerce7 customer ID | First time you interact with a wine-club feature | Link App account to your existing Commerce7 wine-club profile | Contract performance |
| Order history (line items, totals, payment status) | Each time you place an order on Commerce7 | Compute your membership tier (rolling 12-month spend); track first-case milestone reward; show “My Orders” | Contract performance |
| Club membership records | When you join or leave a club | Show “My Clubs”; confirm tier qualification | Contract performance |
| Tasting-room reservations | When you book | Manage your booking via Commerce7 | Contract performance |
Wine-purchase history is held in Commerce7 under the existing wine-club terms; the App reads from it via the Commerce7 API. See Commerce7’s privacy policy at https://commerce7.com/privacy.
2.4 In-app rewards data
| What | When | Why | Legal basis |
| Referral code | When you open the Wallet tab | Identify you when a referee enters your code | Contract performance |
| Referral count | Each time a referee subscribes | Track the 5-referral milestone reward | Contract performance |
| In-app credit balance | When you earn or spend credit | Show your wallet; apply at checkout | Contract performance |
| Credit ledger (every grant and redemption) | Each credit transaction | Audit trail for credit movements | Legitimate interest (accurate accounting) |
| Reward claim records (birthday gift, first-case merch) | When you claim a reward | Prevent duplicate claims; arrange fulfilment | Contract performance |
2.5 Authentication tokens
When you sign in, the App stores a short-lived session token on your device using iOS Keychain (Apple’s secure enclave) or Android Keystore. This token is only accessible to the Digby Sparkle App; it is never sent to anyone other than our authentication backend (Supabase) when you make a request.
2.6 What we do not collect
We do not collect or process any of the following:
- Your location (the App does not request location permission).
- Your photos, contacts, calendar, microphone, or camera.
- Device advertising identifier (IDFA / Google Advertising ID).
- Behavioural analytics events (no Mixpanel, Amplitude, Segment, or similar).
- Crash reports from third-party services (no Sentry, Bugsnag, etc.).
- Web tracking pixels, cookies for analytics or advertising, or fingerprinting data.
The App contains no third-party SDK for advertising, analytics, attribution, or cross-app tracking.
3. Who we share data with
We share personal data only with the following organisations, and only as needed to operate the App:
| Service | Purpose | Location | Safeguards |
| Supabase Inc. | Hosts our user database, authentication, and serverless backend functions | EU (Ireland / Frankfurt) | UK and EU data protection compliance; published security overview at https://supabase.com/security |
| Stripe Payments UK Ltd / Stripe Payments Europe Ltd | Processes subscription payments and the in-app wallet redemption coupons | UK / Ireland with US support; transfers under UK IDTA and EU SCCs | PCI DSS Level 1 certified; see https://stripe.com/gb/privacy |
| Commerce7 Inc. | Hosts wine-club customer records, order history, and tasting-room reservations | Canada (UK adequacy decision applies) | https://commerce7.com/privacy |
| Apple Inc. | “Sign in with Apple” authentication (if you use it) | US; transfers under UK IDTA / EU SCCs | https://www.apple.com/legal/privacy/ |
| Google LLC | “Sign in with Google” authentication (if you use it) | US; transfers under UK IDTA / EU SCCs | https://policies.google.com/privacy |
We do not share personal data with anyone for advertising, profiling, or sale. We do not use processors in countries without an adequacy decision unless protected by the UK International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses (SCCs).
We may disclose personal data if required by UK law (e.g. court order, HMRC inquiry, police request supported by appropriate legal process). We do not respond to informal requests.
4. International transfers
Most of your data stays in the UK or EU. Two routes leave that perimeter:
- Stripe processes payments through its US infrastructure for some functions (e.g. fraud screening). Stripe is certified under the UK IDTA and EU SCCs, and is PCI DSS Level 1.
- Commerce7 stores wine-club records on Canadian servers. The UK has determined that Canada provides adequate protection for personal data under the UK adequacy decision (Commercial Organizations) — no additional safeguard is required.
- Apple / Google SSO (if you use either) involves data flowing to those companies’ US infrastructure under UK IDTA / EU SCCs.
5. How long we keep data
| Data | Retention |
| Account identity (email, name, DOB) | Until you delete your account, or 7 years after last activity, whichever comes first |
| Subscription history (Stripe-linked) | Until you delete your account; thereafter Stripe retains payment records for 7 years under UK financial-services rules |
| Wine order history (Commerce7) | Held by Commerce7 under our wine-club terms — typically 7 years for tax compliance (HMRC) |
| In-app credit ledger | Until you delete your account |
| Authentication tokens on device | Until you sign out, delete the App, or the token expires (typically 1 hour for the access token, 30 days for the refresh token) |
| Reward claim records (birthday gift, first-case merch) | Until you delete your account |
When you delete your account from inside the App, we permanently remove your row from our Supabase user table and database cascades clean up your profile, membership, referrals, credits, ledger, and reward-claim records. We currently retain your Commerce7 customer record so that prior wine-club orders, deliveries, and any post-sale support history remains accessible to our cellar team. You can request full Commerce7 deletion separately by emailing privacy@digbyfineenglish.com.
6. Your rights
Under UK GDPR you have the following rights. To exercise any of them, email privacy@digbyfineenglish.com or use the in-App controls noted.
| Right | What it means | How to exercise |
| Access | A copy of the personal data we hold about you | Email privacy@digbyfineenglish.com — we respond within 30 days |
| Rectification | Correct inaccurate data | Update name / DOB in the App’s Profile screen, or email |
| Erasure (“right to be forgotten”) | Delete your account and associated data | In-App: Account tab → Delete Account. Cascades clean Supabase data; email us to also remove Commerce7 history |
| Restriction | Pause our processing of your data in specific cases | Email privacy@digbyfineenglish.com |
| Portability | A machine-readable export of data you provided | Email privacy@digbyfineenglish.com |
| Object | Object to processing based on legitimate interest | Email privacy@digbyfineenglish.com |
| Complain | Lodge a complaint with the UK Information Commissioner | https://ico.org.uk/make-a-complaint/ |
We are required to verify your identity before responding to a rights request — typically by asking you to confirm the request from the email address on your account.
7. Security
We protect your data using the following technical and organisational measures:
- All network traffic to our backend uses TLS 1.2 or higher with HSTS enforced.
- Passwords are stored as bcrypt hashes by Supabase Auth — we never see or store them in plaintext.
- Session tokens on your device are held in iOS Keychain / Android Keystore, accessible only to the Digby Sparkle App.
- Database access is restricted by Supabase Row Level Security policies — each user can only read or write their own data.
- Backend webhooks (Stripe, Commerce7) are verified with cryptographic signatures or HTTP Basic Auth secrets before processing.
- Service-role credentials are stored only on the server side (Supabase Edge Function secrets) — never in the iOS bundle.
No system is perfectly secure. If you believe your account has been compromised, change your password and email privacy@digbyfineenglish.com immediately.
8. Children
The App is for adults aged 18 and over. We collect your date of birth at sign-up to confirm this. If we discover an account belongs to someone under 18, we will delete the account and any associated data without notice.
9. Cookies and similar technologies
The App is a native iOS app and does not use cookies for its own functionality. When you tap a “Subscribe” or “Manage Subscription” button, the App opens Stripe’s hosted checkout page inside an in-App browser — Stripe sets its own cookies on that page under its own privacy policy. The cookies are scoped to the in-App browser session and are cleared when you close it.
10. Sign in with Apple and Google
If you choose to sign in with Apple or Google, the following applies:
- We receive your name and email address (or Apple’s relay address if you choose to hide your email).
- We do not receive your Apple/Google account password or any other data from your Apple/Google account.
- Signing out of the App does not sign you out of Apple/Google.
- If you revoke our access in your Apple ID settings (https://appleid.apple.com → “Apps Using Apple ID”) or your Google account settings (https://myaccount.google.com/permissions), the next time you try to sign in we will treat that as a new sign-in.
11. Apple’s “App Privacy” label
Apple’s App Store shows a “Privacy” section on every App’s page summarising the data it collects. The summary for Digby Sparkle is:
| Data category | Linked to you | Used to track you | Examples |
| Contact info | Yes | No | Email address, name |
| Health & Fitness | — | — | Not collected |
| Financial info | Yes | No | Subscription status (not card details — handled by Stripe) |
| Location | — | — | Not collected |
| Sensitive info | Yes | No | Date of birth (for age verification) |
| Contacts | — | — | Not collected |
| User Content | — | — | Not collected |
| Browsing history | — | — | Not collected |
| Search history | — | — | Not collected |
| Identifiers | Yes | No | Account ID, Apple/Google user ID if SSO used |
| Purchases | Yes | No | Subscription tier and renewal status |
| Usage Data | — | — | Not collected |
| Diagnostics | — | — | Not collected |
“Used to track you” means using your data for advertising or sharing it with data brokers. We do neither.
12. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent change. Material changes (e.g. adding a new data processor, changing legal basis for processing) will be flagged inside the App and announced via email at least 30 days before they take effect.
13. Contacting us
For any question about this policy or to exercise your rights:
Email: privacy@digbyfineenglish.com Post: Data Protection, Digby Fine English Ltd, 55-57 High Street, Arundel, West Sussex, BN18 9AJ
If you are not satisfied with our response you can complain to the UK Information Commissioner:
ICO Helpline: 0303 123 1113 Online: https://ico.org.uk/make-a-complaint/
Latest news