Effective October 2, 2026
RMO Public Relations manages WineX and is responsible for the personal information described in this notice. Its address is 50 South Main Street, Providence, Rhode Island 02903. This notice covers the WineX RI festival app and its account, passport and order-request services at winexri.com.
Local Robot LLC builds and publishes the app and provides technical support. Send privacy questions, access, correction or deletion requests to Local Robot at ben@localrobot.com. Local Robot will forward requests to RMO Public Relations as needed.
Information you choose to provide
You can browse the festival guide without an account. The app saves downloaded content, your selected edition, wine selections and preferences on your device. A guest passport stores scanned vendor identities, festival editions and scan times on that device. Guest progress can be lost if local data is removed or the device is lost.
An optional WineX attendee account saves your passport across devices. Dedicated WineX database tables on the same WordPress-hosted service store your email address, attendee identifier, account timestamps, device and website session records, and synchronized vendor stamps. Attendee identities are separate from WordPress staff accounts and do not use WordPress user authentication. Ordinary attendee sign-in uses an eight-digit code sent to your email address; attendees do not create a WineX password. Code records contain your email, a protected hash of the code, expiration and attempt information. Session records contain a credential handle, a protected hash of its secret, session type, device label and timestamps. Signing in merges eligible guest stamps with your account. The app securely stores a revocable device credential. Website account pages use essential session and security cookies.
Designated store reviewers can use the openly labeled Store review access option with a reusable access key for one isolated review account. We store only a protected hash of that key. It does not grant access to other attendee accounts or WordPress staff functions. Review access uses the same passport and account-deletion services, and changing or disabling the key invalidates sessions issued through that option. After the review account is deleted, a later review-key sign-in can create a new empty review account; it does not restore the deleted passport.
If you submit an order request, we receive your first and last name, email, optional phone number, 21+ affirmation, products, vintages, quantities and festival edition. The server records product and vendor details, units and sizes, price estimates, submission time and an order reference. Gravity Forms stores the request and generates its email notification. Contact details and unfinished requests stay on your device across restarts and failures. Submission requires your action; the app does not automatically submit later when connectivity returns.
Currently, order notifications go to the WineX website administrator. A direct notification recipient at The Savory Grape has not been configured. Submitting a request does not complete a purchase, make a payment or guarantee retailer acceptance. The app collects no payment-card details or identity-document images. We will update this notice before changing the order-data handoff.
Camera, maps and notifications
The camera is used only when you open the QR scanner. Barcode recognition runs on your device. WineX does not record or upload camera photographs or video, and does not request microphone or photo-library access. A recognized vendor code becomes passport data. Android uses Google's bundled ML Kit scanner, which sends app/device information, per-installation identifiers, performance, configuration and error metrics to Google for diagnostics and usage analysis. ML Kit does not send the input images or decoded results to Google. See ML Kit privacy information and its Android data disclosure.
Opening the map connects to Mapbox. Mapbox processes network and device information such as IP addresses and service identifiers, map usage and diagnostics. Choosing Show my location or Walking directions requests foreground location permission; if granted, precise or approximate location can be processed by Mapbox, including for location telemetry. Walking directions sends your current coordinates and the selected destination to the Mapbox Directions API to calculate a walking route, estimated duration and steps. Routes stay in app memory and are not saved to your account. WineX does not save your coordinates in passport or order records and does not request background location. The map's information/attribution control provides Mapbox telemetry choices; device settings control location permission. Necessary map-network requests still occur when telemetry is disabled. Map lighting uses New York time without GPS. See Mapbox's privacy policies.
Optional festival updates use Google Firebase Cloud Messaging and, on Apple devices, Apple Push Notification service. These services process installation and push identifiers and technical app/device information for registration, delivery and service operation. Updates use festival-year topics. We do not send your order details or passport account to Firebase, and the website does not maintain a separate device-token database. The app does not include Firebase Analytics, Crashlytics, Firebase Authentication or an advertising SDK. Messaging and other service SDKs still process their own technical data. See Firebase privacy information.
You can decline camera, location and notification permissions and still browse. Notification registration is initially disabled. If you enable updates, your choice is saved; turning them off saves that preference and requests topic unsubscription and token deletion. An interrupted network cleanup is retried when the app reconnects. Device notification settings also control whether updates are displayed.
How information is used and shared
We use information to provide the festival guide, save and synchronize passports, process requests you submit, provide account and support messages, deliver optional updates and protect the service against misuse. Authorized WineX administrators can access account, passport and order records needed for these purposes. WP Engine hosting and the website's email delivery services process information needed to operate the site and send messages. Mapbox, Firebase, Google ML Kit and Apple process the information described above under their applicable terms and privacy policies; their roles and retention practices are not all the same.
Website and email systems process technical records such as IP addresses, browser/app details and access or error logs. The app sends a random installation identifier with API requests. Abuse controls store salted hashes of installation, IP or email signals. Gravity Forms additionally records request IP address, user agent and source URL. Order-delivery and notification histories help prevent duplicates and investigate failures. If you contact us or send feedback, we receive the information you choose to include, such as screenshots, device details and a description of the issue.
The app has no advertising SDK or social feed and does not use account or order information for advertising profiling. Opening event links, directions or a store listing takes you to another service, where its own privacy practices apply. Service providers may process information outside your state or country; this notice does not promise that every provider stores data only in Rhode Island or the United States.
Device storage and security
Connections to WineX account and API services use HTTPS. Device credentials use operating-system secure storage. On iPhone and iPad, contact and pending-order drafts use private files with Complete Data Protection and backup-exclusion settings; session credentials remain in Keychain with synchronization disabled. Other saved data, including guest passport progress and wine selections, may be included in iOS device backups. Android app backup is disabled and backup/device-transfer exclusions are configured. Operating-system restore behavior can vary; a device backup is not a substitute for saving your passport to an optional account.
Local account data is separated from guest data and other accounts. Signing out removes the device credential, but unfinished account-specific selections or contact drafts can remain separately on that device so you can return to them. Successful submission clears the corresponding local request drafts. These protections reduce risk, but no storage or transmission system is guaranteed to be completely secure.
Retention and your choices
WineX attendee accounts and historical stamps remain until you delete the account or ask us to remove them. Attendee accounts, submitted order records, delivery records and notification histories do not have an automatic fixed-period purge. Sign-in codes expire after 10 minutes and can be used once, with at most five verification attempts. Used codes and codes that reach the attempt limit are deleted. Expired code and session records are eligible for scheduled daily cleanup; execution depends on the hosting scheduler. Website sessions expire after 30 days and device sessions after one year unless revoked earlier. Short-lived abuse-control records are cleaned up separately. Support feedback and diagnostic copies held by Local Robot are reviewed manually for deletion. We review deletion requests manually where the app does not provide a deletion control.
For accounts moved from the earlier account system, linked legacy identity and passport records remain for migration recovery until account deletion. Their old password, reset links and sessions no longer grant access. Ordinary attendee sign-in requires a fresh email code; the designated review account also has the limited review-access option described above.
- Use Clear saved details on the order contact screen to remove that account/guest edition's contact draft and uncheck the age affirmation while keeping the product selection. Resolve any uncertain submission first so its original retry information is preserved.
- Use Delete my account in the app, or the website account-deletion page, and verify again with a fresh email code before confirming deletion. The designated review account can instead reenter its review access key before confirming deletion. This removes your WineX attendee account, its device and website sessions, pending sign-in codes, and its saved server passport, including any linked passport records from the earlier account system. Successful deletion from the app also clears that account's local passport and order drafts on that device. Deleting through the website does not remotely erase files already stored on your devices.
- Deleting a WineX attendee account does not delete or change a separate WordPress staff account. RMO Public Relations manages staff access to the website. Staff can use the privacy contact above to discuss that access.
- Account deletion does not automatically remove separate submitted order records or their email copies. Email ben@localrobot.com with an order reference, if available, to request access, correction or deletion. We will verify that the request concerns your information and remove data unless a specific record must be retained under applicable law. We will explain any such exception.
- Server backups and provider logs can retain copies after information is removed from the live service. Their expiry depends on the host/provider arrangements. Contact us for the applicable handling of your request; removal from the live app does not immediately remove every backup copy.
Do not send sign-in codes, review access keys, device credentials or identity-document images with a privacy request. You can also email us about other privacy rights that apply where you live. We will assess requests under the applicable law.
Age and future changes
WineX is an adult festival experience. Alcohol order requests require an explicit affirmation that you are at least 21. This is not document-based age verification and does not replace the retailer's required age/ID checks for a sale or handoff. If you believe an underage person has provided information inappropriately, contact us.
We will update this page and its effective date when our data practices change, including before introducing a different merchant handoff. For questions about this notice or your information, contact RMO Public Relations through the technical contact, Local Robot LLC, at ben@localrobot.com, or write to RMO Public Relations at the address above.