Privacy policy
What we collect, and what we do with it
Caskwork holds a distillery's production records on the distillery's behalf. This policy covers those records, the account details of the people who use the app, and the little that is collected automatically. The short version: we hold what you give us to do the job, we share it with nobody except the providers that run the service, we never sell it, and it stays yours.
Also read: Terms of service How we handle your data
Who we are
Caskwork LLC, a Minnesota limited liability company (“Caskwork”, “we”). We make compliance and production software for craft distilleries. You can reach us at hello@caskwork.com.
What this policy covers
This policy applies to the marketing site at caskwork.com and to the Caskwork app. “You” is a distillery with a Caskwork account, a person using one of its seats, or a visitor to the site. It should be read together with our terms of service and with How we handle your data, which describes the storage, isolation and retention of your records in specific, checked detail. Where this policy summarises something, that page states it exactly.
What we collect
What your distillery enters
The substance of Caskwork is the record your distillery keeps in it: production events, gauge readings, your distillery profile, the customers and suppliers you name on transfers and removals, the documents you upload, and the reports derived from all of that. We process these on your distillery's behalf and on its instructions. Some of this information is about people — the names of the people who log entries, and the names and addresses of the counterparties you deal with — and your distillery is responsible for being entitled to enter it.
Account information
For each person with a seat: name, email address, role, and the status of the seat. For each invitation: the address invited, the role offered, who sent it, and whether the email was delivered. Passwords are not held by Caskwork at all: sign-in is handled by Amazon Cognito, which holds your email address and your credential, and our database stores only the identifier Cognito assigns you.
Collected automatically
- Request logs. For each request to the app: a request id, which distillery and seat it was made under, the path, and the outcome. No request bodies. Kept for two weeks.
- The audit trail. Sign-ins, sign-outs and failed sign-ins (with the address and the reason), alongside every change made outside the ledger, with who and when. Kept with your records.
- Sign-in risk signals. Cognito's threat protection evaluates each sign-in attempt for compromised credentials and unfamiliar devices or locations, using the IP address and device characteristics of the attempt, and blocks the risky ones. We do not otherwise track devices or locations.
- Edge protection. A firewall in front of the site and the app evaluates the IP address of each request for rate limiting and keeps a brief sample of request metadata for its own operation. We keep no visitor logs for the marketing site.
Cookies and browser storage
The app sets two cookies, both used only to keep you signed in and both unreadable by scripts: a session cookie good for an hour and a refresh cookie good for thirty days. Signing out clears both. The app also keeps two things in your browser's own storage, on your device only: a note that you are signed in, and an unsaved draft of an entry you were in the middle of logging, so a reload does not lose it. The marketing site sets no cookies. Neither the site nor the app carries analytics, advertising, tracking pixels or any third-party script.
Invitations and account notices are sent through Amazon SES from a caskwork.com address. Anything you write to hello@caskwork.com is received and kept in Google Workspace.
How we use it
- To provide the service. Storing your ledger, deriving vessel state and reports from it, preparing your TTB filings, and showing each person what their seat allows.
- To support you. When you ask us for help, to look at what you have asked us to look at.
- To keep it safe. Sign-in protection, the audit trail, backups, and the detection of tampering.
- To make Caskwork better. We learn from how distilleries use it — which entries get logged, what a filing turned out to need, where records tend to be incomplete — and use that, across distilleries and in aggregate, to improve defaults, guidance and the checks the app runs, including by building models that suggest what to record. This never identifies a distillery, a person or a counterparty, and never puts one distillery's figures in front of another.
- To tell you about your account. Invitations, and notice of changes to these pages or to the service. We send no marketing email to people with seats.
- To meet legal obligations. Where the law requires it.
That is the whole list. We never sell your information, never use it for advertising, never build profiles of the people who use it, and never build a product for anyone else from it. What we learn is used to make Caskwork better for the distilleries that use it, and for nothing else.
Who we share it with
- The providers that run the service. Amazon Web Services hosts everything; Google Workspace carries our email. They process your data only to provide their services to us. The full list, with what each does and where, is the subprocessors table in How we handle your data. We will update that table before adding a provider, and tell every distillery with an open account.
- When the law requires it. If we receive a subpoena, court order or similar demand for your records, we will tell the owners of your distillery before responding unless we are legally prohibited from doing so, and we will disclose only what the demand requires.
- If Caskwork changes hands. If the business is sold or merged, your records go with it under these same commitments, and we will tell you before it happens.
Nobody else, for any other reason. In particular, no other distillery can see your records: each distillery is a hard boundary in the database, enforced twice and failing closed, as described here.
Whose data it is
The records in a distillery's account belong to that distillery. Its owners decide who has a seat and what each seat may do, and they instruct us about the account — including export and closure. If you use a seat at a distillery, requests about your access go to an owner there; if you are named in a distillery's records — as an employee who logs entries, or as a customer or supplier — the distillery is the party that holds that information, and questions about it go to them. We act on the owner's instructions and will help either of you where we can.
How long we keep it
Your records are kept for as long as your account is open. Request logs expire after two weeks. Backups and audit checkpoints are kept for fixed windows that cannot be shortened by anyone, including us — up to 400 days for a database snapshot and ten years for a checkpoint — which means copies of deleted records persist in locked, encrypted backups until those expire on their own. The full retention table, item by item, with who can delete what and when, is in How we handle your data, and the reason those two windows are locked is stated plainly there.
How we protect it
Encryption in transit and at rest, a firewall at the edge, sign-in threat protection, least-privilege roles that cannot destroy a document or an audit checkpoint, and a database boundary between distilleries that fails closed. The specifics are in How we handle your data. If we learn of a breach that affects your records, we will tell the owners of the affected distilleries without undue delay, say what we know, and say what we are doing about it.
Your choices and rights
- See it. Everything in your account is visible in the app to the seats that are granted it.
- Take it out. Reports, filled forms and uploaded documents can be downloaded from the app today; a complete export is done for you on request, at no charge. See Getting your records out.
- Correct it. Your distillery profile and account details can be changed in the app. A ledger entry is never edited: a correction is a new entry that sits beside the original, and both are kept. That is your audit trail, and it is the reason the record is worth anything to an auditor.
- Delete it. An owner can close the account. What is deleted, in what order, and what persists in locked backups afterwards, is in Leaving Caskwork.
- Stop hearing from us. We send only account email — invitations and notices about the service — to people with seats. Marketing email goes only to people who have written to us asking about Caskwork, and a reply saying “stop” is enough.
If a privacy law where you live gives you rights over information about you — to access it, correct it, delete it, or take it elsewhere — write to us and we will honour them. Where we hold the information on behalf of a distillery, we may need to refer your request to that distillery's owner, and we will tell you if we do.
Children
Caskwork is for licensed distilleries and the adults who work at them. It is not directed at anyone under 18, and we do not knowingly collect information from anyone under 18. If you believe we have, write to us and we will remove it.
Where it is processed
In the United States, in one Amazon Web Services account operated by Caskwork, with backup copies in a second US region. If you use Caskwork from outside the United States, your information is transferred to and processed there.
Changes to this policy
When we change this policy we will update the date at the top. A change that materially affects how your records are handled will be sent by email to the owners of every distillery with an open account before it takes effect.
Contact
Questions, requests and complaints about privacy go to hello@caskwork.com, or by post to Caskwork LLC, Minnesota. You will hear back from the founder.
Also read: Terms of service How we handle your data