Privacy Policy
Last updated: October 3, 2026
This Privacy Policy explains how Menusaic collects, uses, and protects information when you use our website (menusaic.com), our restaurant management dashboard (admin.menusaic.com), and the public digital menus we host on behalf of our restaurant customers (together, the "Service").
We built Menusaic for restaurants first, which means we try to collect as little personal data as the Service actually needs. This policy applies whether you're visiting from the EU, the UK, the US, or anywhere else, and calls out region-specific rights where they apply.
1. Who operates Menusaic
Menusaic is an online-only service. It's currently a free, early-stage project with no registered physical company behind it, no office, and no paying customers yet. Once Menusaic takes on paid customers, it will be operated through a registered business entity, and this section will be updated with that entity's name, country of registration, and address.
Until then, Menusaic's operator acts as the data controller for the Menusaic website and dashboard. For the public menu pages, we act as a data processor on behalf of the restaurant that created the menu; the restaurant is the controller for any data collected from its own guests (for example, optional feedback submissions).
Questions, requests, or complaints about this policy can be sent to support@menusaic.com.
2. What we collect
From restaurant owners and managers (dashboard accounts)
- Account details: name, email address, and password. Passwords are stored encrypted, never in plain text, and we cannot read them.
- Restaurant information: business name, logo, contact details, address, and the menu content you create (categories, dishes, descriptions, prices, photos).
- Support communications: anything you send us by email or through the dashboard.
We don't collect any billing or payment information today, because the Service is free and we don't process payments. If we introduce paid plans in the future, billing details will be handled directly by a third-party payment processor, and this policy will be updated to name them before that happens; we will not store full card numbers ourselves.
From visitors to our marketing website
- Contact form submissions: name, email address, and message content, used only to respond to your enquiry.
- Standard technical data collected by any website: IP address, browser type, and pages visited, used for security and keeping the site running. Some of this is also visible to Cloudflare, which we use in front of our infrastructure (see Section 5).
From diners viewing a public menu
Scanning a QR code and browsing a menu does not require an account and does not collect personal data by default. We're planning an optional guest feedback feature that a restaurant can turn on, where a diner could leave a rating and comment, and optionally a name or email address if they choose to provide one, and if the restaurant chooses to ask for it. We haven't finalized exactly what that feature collects yet; this policy will be updated with specifics before it launches. Any such data would be stored on behalf of, and controlled by, the restaurant that enabled the feature, not by us.
3. Cookies and similar technologies
The dashboard uses a strictly necessary session cookie or token to keep you logged in. We do not currently use analytics or advertising cookies on the marketing website. If that changes, we will add a cookie banner that lets you accept or decline non-essential cookies before they're set, as required under EU/UK law.
Our website loads fonts directly from Google Fonts' servers, which means your browser sends its IP address to Google when a page loads. We don't control what Google does with that request beyond serving the font file.
4. Why we process your data (legal basis)
Depending on what you use the Service for, we rely on one or more of the following legal bases under the EU/UK GDPR:
- Performance of a contract: creating your account, running your dashboard, hosting your menu.
- Legitimate interests: keeping the Service secure, preventing abuse, and improving how it works, balanced against your rights.
- Consent: optional marketing emails or any non-essential cookies, which you can withdraw at any time.
5. Who we share data with
We don't sell personal data. We currently use these third-party services to run Menusaic:
- Cloudflare, for content delivery, DNS, and security (e.g. protection against malicious traffic) in front of our infrastructure. Cloudflare may process or cache traffic data as part of that service, generally across its global network.
- AI tools, which we may use to help generate or refine written content (for example, draft text for the site or support responses). We don't feed restaurant customer account data or diner data into these tools as a matter of course.
Beyond that, we don't share personal data with other third parties, except where required by law, a valid legal request, or to protect the rights and safety of Menusaic, our users, or the public.
6. Where your data is hosted
Unlike most SaaS products, Menusaic's data is currently hosted on infrastructure we operate ourselves, at a private location, rather than in a commercial data center. We do this because the Service is free and pre-revenue. This means:
- We don't currently offer the redundancy, uptime, or disaster-recovery guarantees a commercial cloud provider would.
- Traffic to our infrastructure passes through Cloudflare, which has servers in many countries, so some processing of connection data happens outside your own country as a normal part of how Cloudflare's network works.
- We intend to migrate to professional cloud hosting once the Service generates revenue, at which point this section will be updated with the new hosting provider and location.
See Section 9 and our Terms and Conditions for what this means for service availability, which matters more than the usual "international transfers" language while we're at this stage.
7. How long we keep your data
- Account and restaurant data: kept for as long as your account is active, and for a reasonable period after closure in case you want to reactivate, after which it is deleted or anonymized.
- Contact form messages: kept only as long as needed to handle your enquiry and keep a reasonable record of it.
8. Your rights
If you're in the EU, the UK, or a jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your data ("right to be forgotten").
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, where we rely on consent.
- Lodge a complaint with your local data protection authority.
If you're elsewhere, including in US states with their own privacy laws, we extend the same core rights to access, correct, and delete your data. Contact support@menusaic.com to exercise any of these rights, and we'll respond as promptly as we reasonably can.
9. Service availability and data loss
Because Menusaic currently runs on self-hosted infrastructure at a private location and is operated by one person, it does not have the uptime guarantees, monitoring, or backup infrastructure of a funded company. The Service can go offline unexpectedly, including for extended periods, due to power outages, internet outages, hardware failure, or other issues outside our control. We take reasonable steps to back up data, but we cannot guarantee against data loss.
If your restaurant's menu is important to your business, keep your own copy of your menu content (dish names, prices, descriptions, photos) somewhere else, so you aren't solely dependent on Menusaic. See our Terms and Conditions for how this affects liability.
10. Children's privacy
Menusaic is a business tool intended for restaurant owners, managers, and their adult staff. It is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
We take reasonable, good-faith steps to protect your data, including encrypted connections (HTTPS), encrypted password storage, and limiting who can access customer data. As a single-person, self-hosted, free project, our security practices are necessarily less extensive than a funded company with a dedicated security team. No system is completely secure, and we can't guarantee absolute protection.
12. Changes to this policy
We may update this Privacy Policy as the Service evolves, including as we add features, incorporate a company, move to professional hosting, or introduce paid plans. If we make a material change, we'll update the "last updated" date above and, where reasonably practical, let you know directly.
13. Contact us
Email: support@menusaic.com