Loading or processing
Wait for the visible stage. Do not submit again while a consequential request is active.
Six clear starting points · one authoritative product
Choose the guide that matches what you need to do. This page is guidance, not completion tracking. Selecting a guide never grants access, writes data, connects a provider, or publishes a menu.
Role selector
Each option loads a server-rendered guide. All core instructions and links work without client-side JavaScript.
A privacy request can begin without an account. The correct contact depends on whether the restaurant or the MenuFaro operator decides the purpose of the processing.
Public contact route plus a signed-in request ledger; production legal details still need review.Contact the restaurant first for its reservation, loyalty, feedback, or restaurant-contact data. Use the MenuFaro operator path for account, subscription, platform-security, or operator-controlled records.
Controller and processor roles follow the real purpose and configuration. This guide does not assign a universal legal role.Read the responsibility mapWhen signed in, select the applicable right and submit a concise scope. The server uses the trusted identity and does not ask you to repeat an email already supplied by sign-in.
The request ledger stores a receipt, identity-verification state, audit evidence, and an initial one-calendar-month response target. Received never means completed.Open the account-linked request formUse the public contact route if you cannot sign in, are a restaurant guest, or your identity is not linked to a MenuFaro user record.
Do not send passwords, one-time codes, card numbers, health information, or identity documents in the first message. Mailbox delivery still requires production provider testing.Open privacy contact without sign-inKeep the receipt and respond through the reviewed channel if proportionate identity evidence is requested. A restriction, legal hold, extension, or refusal must be explained.
Billing, audit, fraud, dispute, or other records may have justified retention. MenuFaro does not say everything was deleted until the authoritative workflow confirms it.No action is required from this guideYou may contact the competent national data protection authority when appropriate. The public contact page links to the European Data Protection Board member list.
The product notice is engineering guidance, not General Data Protection Regulation or worldwide legal certification.No action is required from this guideShared release model
The website and installed web app use the same release contract. A visual preview is never the live menu.
Dish, price, media, theme, translation, availability, tax/service, and safety changes remain private.
Resolve permission, plan, content, media, language, commercial-policy, allergen, and QR blockers.
Only an authorized owner or manager confirms the exact revision and fingerprint. Success waits for durable readback.
The stable token resolves the current immutable release. Republishing does not require reprinting the code.
State and recovery guide
Wait for the visible stage. Do not submit again while a consequential request is active.
Private work stays network-only. Reconnect, then reload the authoritative revision before editing or publishing.
Sign in with your own account, request the correct role, or ask an operator to restore the missing dependency.
Compare the newer server version with your work. Never force a blind overwrite from another browser or phone.
Trust a release, receipt, or provider state only after the page shows authoritative confirmation and identifiers.
Keep Plus pending, failed, or past due until the billing provider and signed lifecycle event confirm the result.
Optional connected iPhone access
Installation changes how you launch MenuFaro, not where data lives. It is not a native iOS release.