Privacy notice
What data we collect, why we use it and how you can exercise your rights.
Last updated: 5 October 2026
1. Who processes your data
The data controller is Menumi, which operates the Menumi service. For any request about your personal data, write to info@menumi.app.
This notice is provided under Regulation (EU) 2016/679 (GDPR) and covers people who visit the site, contact us or create an account for their venue.
2. If you are a guest of a venue that uses Menumi
When you browse a menu, book a table, place an order or join a venue's loyalty programme, the controller of your data is that venue. Menumi processes it on the venue's behalf, as a data processor, only to run the service.
To exercise your rights over that data, contact the venue directly. If you write to us, we forward your request to the venue concerned.
3. What data we collect
We collect only the data needed to provide the service:
- Account data: name, email, password (stored in encrypted form), preferred language and, if you sign in with Google, your basic Google profile data.
- Venue data: name, address, contact details, menus, images and the other content you enter in the panel.
- Billing data: chosen plan, subscription status and tax details. Card details are handled directly by Stripe and never reach our systems.
- Contact requests: name, email, optional phone number and venue name, and the text of your message.
- Technical data: IP address, browser type and access logs, used for security and troubleshooting.
- Menu statistics: number of views and QR scans, in aggregate form and without identifying who browses the menu.
4. Why we use it and on what basis
- To create and manage your account and provide the service: performance of the contract.
- To manage subscriptions, payments and invoices: performance of the contract and legal obligations.
- To reply to the requests you send us: your consent and the pre-contractual steps you ask for.
- To send you service messages (email verification, password reset, trial expiry, payment notices): performance of the contract.
- To protect the service from abuse and unauthorised access: our legitimate interest.
5. Who we share it with
We do not sell your data or pass it to third parties for marketing. We entrust it to providers that process it on our behalf, only as far as the service requires:
- Cloud infrastructure and file storage (Laravel Cloud, Amazon Web Services).
- Payments and invoicing (Stripe).
- Delivery of service emails (Resend).
- Network, security and incoming mail for the domain (Cloudflare).
- Sign-in with Google, only if you choose to use it (Google).
- Automatic menu import and translation, for example OpenAI and DeepL: they receive menu texts, not your account data.
- Site usage statistics, only with your consent (Google Analytics).
6. Transfers outside the European Union
Some providers are based or have servers outside the European Economic Area. In those cases the transfer takes place with the safeguards required by the GDPR, such as the standard contractual clauses approved by the European Commission or adequacy decisions.
7. How long we keep it
- Account and venue data: for as long as the account is active. After closure it is deleted or anonymised within a reasonable time, unless the law requires otherwise.
- Billing data: for the period required by tax and accounting law, normally ten years.
- Contact requests: for the time needed to reply and in any case no longer than twenty-four months.
- Technical logs: for the time strictly needed for security and troubleshooting.
9. Your rights
At any time you can ask us to:
- access your data and receive a copy;
- correct or update it;
- delete it, where we are not required to keep it;
- restrict its processing or object to it;
- receive it in a format another service can read (portability);
- withdraw a consent you gave us, without affecting processing already carried out.
10. How to exercise them
Write to info@menumi.app. We reply within one month of the request. If you believe the processing does not comply with the law, you can lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
11. Changes to this notice
We may update this notice when the service or the law changes. The date at the top shows the latest revision. For significant changes we notify account holders by email or in the panel.