Privacy policy

How MenuSnap handles personal data

This policy explains what data is processed, why it is needed, who receives it and how people can exercise their rights when using MenuSnap services.

1. Scope and roles

This policy covers menusnap.com, the merchant dashboard, MenuSnap POS, KDS, customer display, QR ordering and related support services.

MenuSnap is the controller for merchant-account administration, platform security, billing and direct support data. For guest order, delivery, loyalty and restaurant-customer data, the restaurant normally determines the purpose and means of processing and MenuSnap acts as its service provider or processor. MenuSnap may separately act as controller where necessary for platform security, fraud prevention and legal compliance.

2. Data we process

The exact data depends on the features used by a restaurant or guest. It can include:

  • Merchant and staff data: name, email, password hash, roles, permissions, restaurant details and account status.
  • Restaurant content: menus, prices, tax settings, images, translations, printer and device configuration.
  • Guest and order data: table or QR session, selected items, language, notes, contact details, delivery address, loyalty profile and marketing choices.
  • Transaction data: totals, taxes, payment status, refunds and payment-provider references. MenuSnap does not store full card numbers or card security codes.
  • Technical and security data: IP address, user agent, device and session identifiers, app version, request identifiers, audit events, error logs and approximate location inferred from an IP address where enabled for security.
  • Support data: messages, diagnostic details and files that a user chooses to provide.
  • Optional AI input and output: menu text, images or translation content submitted when a merchant chooses an AI-assisted feature.

3. Purposes and legal bases

We process data only where there is a valid purpose and legal basis. These include:

  • Performing a contract: providing accounts, ordering, POS, kitchen, display, printing, billing and support services.
  • Legal obligations: accounting, tax, fiscal-document, payment and regulatory records where applicable.
  • Legitimate interests: securing accounts, preventing fraud and abuse, diagnosing incidents, maintaining service reliability and improving support.
  • Consent: optional marketing communications and other processing where consent is specifically requested. Consent can be withdrawn at any time without affecting earlier lawful processing.

4. Service providers and data sharing

We do not sell personal data. We disclose it only as needed to provide the service, follow instructions from the relevant restaurant, comply with law or protect the service and its users.

Providers can include cloud hosting, database, storage and content-delivery services; email delivery; Stripe or another payment provider selected by the restaurant; Google services for sign-in, maps or business integrations when enabled; and OpenAI for optional AI-assisted functions. Each provider receives only the data needed for its function and is subject to contractual or legal safeguards.

A restaurant and its authorized staff can access data belonging to that restaurant. Tenant controls are used to separate one restaurant or merchant from another.

5. International transfers

Some providers may process data outside Spain or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard. The actual location can depend on the feature and provider configured for the restaurant.

6. Retention and deletion

We keep data only for as long as needed for the purposes described above. Account and configuration data is generally retained while the service is active and for a limited period afterwards. Orders, fiscal records, payments and refunds may need to be retained for the periods required by tax, commercial or accounting law.

Security logs, expired authentication records, support cases, backups and deleted media are removed or anonymized according to operational retention schedules unless a legal hold or unresolved dispute requires longer retention. Backup copies disappear as the backup cycle rotates.

7. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability or object to processing. You may withdraw consent where processing relies on consent and may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.

For restaurant order, delivery or loyalty data, contact the restaurant first because it is normally the controller. You may also contact MenuSnap and we will route or assist with the request. We may need to verify identity before disclosing or changing personal data.

Spanish Data Protection Agency

8. Website cookies and local storage

The public website uses a first-party language preference cookie so it can reopen in the selected language. At the date of this policy, the public website does not use advertising cookies or third-party behavioral analytics. Authenticated applications use necessary browser or device storage for security, session continuity, settings and offline operation.

9. Security and automated processing

MenuSnap applies access controls, tenant separation, encrypted transport, password hashing, audit logging, rate limits and operational monitoring. No security measure eliminates every risk, so suspected unauthorized access should be reported promptly.

Optional AI tools can help translate or prepare menu content, but merchants remain responsible for reviewing the result. MenuSnap does not use solely automated decisions that produce legal or similarly significant effects for guests or merchant staff.

10. Contact and policy changes

Privacy questions and rights requests can be sent to hello@menusnap.com. Include the account or restaurant involved, the nature of the request and a safe way to contact you. Do not send passwords, PINs, full card details or secret keys.

We may update this policy when the service, providers or legal requirements change. The effective date at the top identifies the current version. Material changes will be communicated through an appropriate service channel where required.

Start freeLive demo