Privacy notice
Guests who only read a menu
We collect nothing about a diner who does not ask us to. The public guest menu is designed so it needs no consent banner.
- No cookies on the guest menu
- No persistent identifier. A session nonce is random, memory-only, and regenerated per visit
- Raw IP is never stored. Abuse control may HMAC an address for at most 24 hours
- No precise location
- No third-party scripts and no cross-site tracking
- Language preference may be stored in first-party
localStorageso the menu stays in the language you chose
Aggregate menu analytics (views, scans, language mix) are non-identifying by construction. They do not contain your name, email, or a cookie.
When a guest later gives us data
Service requests and orders are not in this release. If they ship, they will be minimal, purpose-limited, kept for hours not months, and covered by a notice for that venue.
Operators
If you create an owner or staff account we store the email, password hash, and membership you use to sign in. That account data is ours for the SaaS relationship. Menu content and allergen declarations belong to the venue.
Export
Menu export (JSON, CSV, PDF) is available on every plan, including Free. Account erasure is specified for a later release and is not a self-serve control here.