Privacy Statement
This statement explains how Greg Bowe trading as MyNextWine processes personal data when a WooCommerce merchant connects and uses the My Next Wine Wine Finder plugin and externally hosted service.
- Legal form: Sole trader registered in Ireland
- Business address: 33 Belarmine View, Dublin 18, Dublin, D18 Nra0, Ireland
- CRO business-name registration number: 761722
- Privacy contact: info@myownsomm.com
1. External service and consent
Installing or activating the plugin alone does not send the store's account or catalogue data to My Next Wine. An authorised WordPress administrator must open WooCommerce โ My Next Wine, review the disclosed data transfer, accept the current Merchant Terms and expressly connect the store. The plugin then uses the My Next Wine service at mynextwine.ie to verify ownership, prepare the catalogue and provide recommendations.
2. Who controls the data
The WooCommerce merchant normally controls shopper and customer personal data and must provide its own privacy notice. My Next Wine acts as the merchant's processor where it handles shopper preference inputs, recommendation requests and attributed order references solely to provide the Wine Finder on the merchant's instructions.
My Next Wine acts as an independent controller for merchant account administration, contract and trial/subscription records, service security, fraud and abuse prevention, legal compliance, support correspondence and its own business records. The Merchant Terms include the processor obligations applying between the merchant and My Next Wine.
3. Information sent after connection
Store and administrator information
- The store URL and name, WordPress/WooCommerce installation identifier and ownership-verification challenge.
- The WordPress administrator email, store address, telephone number, country/state, currency and locale used to identify, create or safely reuse the correct merchant account.
- WordPress, WooCommerce, PHP and plugin versions, connection state and security/audit metadata.
- The Merchant Terms version accepted, acceptance time and associated installation record.
- An installation secret used to sign later requests; it is encrypted locally using WordPress salts and protected on the My Next Wine service.
Catalogue information
- Product and variation identifiers, SKUs, names, descriptions, images, categories, attributes, prices, currency, stock and availability required to map and recommend wines.
- Normalised wine mappings and catalogue-readiness decisions, including items ignored because they are unsuitable or cannot be matched.
Shopper and attributed-order information
- The bottle mix, budget, wine-style preferences and food-pairing text submitted for a recommendation.
- The candidate and selected wines, substitutions, per-wine recommendation explanations and structured
MATCH/SUBSTITUTErequirement tags, result, selected quantities and a short-lived recommendation reference. - For attributed orders only, the WooCommerce order identifier, currency, order total, selected product/variation references and quantities.
The plugin is not designed to send customer names, account details, email addresses, billing/delivery addresses, order notes or payment-card details to My Next Wine. Merchant subscription checkout is hosted by Stripe. Payment-card details are submitted directly to Stripe and are not transmitted through the WordPress plugin or stored by My Next Wine. The merchant must not deliberately include sensitive personal data or customer-identifying information in free-text preference or food-pairing fields.
Analytics and security information
- Optional shop-level events such as impressions, opens, recommendation requests/results, failures, swaps and item-level basket attempts/outcomes. A successful basket addition is the only recommendation-usefulness signal; the widget does not ask shoppers to rate recommendations. These non-essential analytics are disabled by default. Where the WordPress Consent API is available, they are sent only when the merchant enables them and the site reports positive statistics consent. Where that API is unavailable, enabling analytics confirms that the merchant has implemented another lawful consent or privacy basis and any notices required in the shopper's jurisdiction.
- Attributed-order events required for the merchant's Wine Finder reporting, containing the limited order fields described above.
- Requested budgets and recommended/order values used for aggregate merchant reporting.
- Request timestamps, replay identifiers, browser/device metadata, network/security metadata and application logs reasonably needed to operate, diagnose and protect the Service.
Merchant reporting is designed to be aggregated rather than to create shopper profiles. Recommendation and basket operations are necessary to provide the feature requested by the shopper; optional analytics are separately consent-gated. Normal web-server and security logs may nevertheless contain personal data such as IP addresses or user-agent information.
4. How and why information is used
- Verify that the connecting administrator controls the claimed WooCommerce store.
- Create or safely reuse the merchant's My Next Wine organisation and catalogue connection.
- Import, map and reconcile the merchant's available wines.
- Generate, explain, validate and return requested recommendations and substitutions.
- Attribute Wine Finder basket activity and resulting orders without taking payment for or selling the wine.
- Provide aggregate merchant reporting and administer the trial or subscription.
- Provide support, investigate faults, prevent abuse, enforce the Merchant Terms and comply with law.
5. AI-assisted recommendations
Recommendation generation may use an artificial-intelligence service provider. The information sent may include the current preference and food-pairing answers and a shortlist of relevant catalogue wines, but should not include the shopper's direct identity or payment information. AI output is subjected to application rules and backend validation before it is returned. The Wine Finder does not make decisions producing legal or similarly significant effects about a shopper.
6. Legal bases
Where the GDPR applies, My Next Wine relies on:
- Contract: to connect, provide and administer the Service requested by the merchant.
- Legitimate interests: to secure, troubleshoot and improve the Service, prevent fraud and maintain proportionate business records.
- Legal obligation: for tax, accounting, regulatory, privacy-request and lawful-disclosure duties.
- Merchant instructions: where My Next Wine acts as processor.
7. Recipients and subprocessors
Information may be processed by contracted hosting, database, content-delivery, monitoring, logging, communications, support, billing and AI service providers. Stripe acts as an independent provider for merchant subscription checkout, payment processing, invoices and Customer Portal. WooCommerce, WordPress, the merchant's web host and any installed payment or fulfilment providers process information independently within the merchant's store. My Next Wine does not sell merchant or shopper personal data, does not acquire the merchant's customer relationship or customer list, and does not use Wine Finder preference inputs for direct-to-consumer wine marketing.
Current subprocessor information is published at mynextwine.ie/subprocessors. Where information is transferred outside the EEA or UK, an applicable adequacy decision, standard contractual clauses or another lawful mechanism is used where required.
8. Retention, revocation and deletion
- Uninstall removes local plugin settings and credentials and sends a best-effort signed revocation where the store can still reach the Service.
- The merchant can also contact My Next Wine to revoke the server-side installation and request deletion/export.
- Recommendation inputs and technical logs are retained only for reasonable operational, support, security and dispute periods and are not intended to form a persistent consumer wine profile.
- Aggregated merchant analytics may be retained for reporting and performance history.
- Contract acceptance, billing, tax and accounting records may be retained for applicable statutory and legal-claims periods.
- Catalogue and installation data is deleted or anonymised after termination when no longer required, subject to legal retention and backup cycles.
9. Security
Measures include ownership verification, encrypted installation secrets, timestamped HMAC-signed plugin requests, replay protection, rate limiting, access controls and final WooCommerce validation of product identity, quantity, price and stock before basket insertion. No system is completely secure; merchants must keep WordPress, WooCommerce, PHP, themes, extensions and administrator accounts secure and supported.
10. Cookies and local storage
The plugin may use strictly necessary WooCommerce/WordPress session mechanisms and browser storage to maintain security and the current recommendation flow. It is not intended to set independent advertising cookies. The merchant is responsible for its own cookie banner, consent configuration and privacy disclosures where local law requires them.
11. Rights and complaints
Depending on applicable law, an individual may request access, correction, deletion, restriction or portability, or object to certain processing. For data controlled by the merchant, the individual should normally contact that merchant first; My Next Wine will assist the merchant where it acts as processor. Requests concerning My Next Wine's controller records can be sent to the privacy contact above.
Individuals may complain to the Irish Data Protection Commission or another competent supervisory authority, including an authority in the country where they live or work or where the alleged infringement occurred.
12. Changes
This statement may be updated to reflect changes to the plugin, Service, subprocessors or law. Material changes will be notified through the plugin or another reasonable channel and may require renewed acceptance of the Merchant Terms.