Restaurant as controller
A restaurant normally decides why and how guest reservation, loyalty, feedback, and menu-contact data is used when it enables those modules. Guests should contact that restaurant for restaurant-controlled data.
Privacy center · engineering notice
See how MenuFaro separates restaurant and platform responsibilities, limits local data, and records account-linked rights requests. This page does not claim automatic General Data Protection Regulation (GDPR) or worldwide legal certification.
Receipt ≠ completion Every consequential request keeps a review state.
Minimum data The request form does not ask for an email already supplied by trusted sign-in.
Responsibility map
One company can be controller for one purpose and processor for another. Contracts and the actual configuration determine the final role.
A restaurant normally decides why and how guest reservation, loyalty, feedback, and menu-contact data is used when it enables those modules. Guests should contact that restaurant for restaurant-controlled data.
Where MenuFaro handles guest data only on a restaurant’s documented instructions, the restaurant needs a reviewed data-processing agreement and MenuFaro must follow the agreed scope.
The service operator may decide the purposes for account authentication, subscription administration, platform security, abuse prevention, support records, and its own legal obligations.
Account privacy center
New request
Your ledger
Shows up to the 50 newest requests linked to this trusted signed-in identity. There is no cross-account search on this screen.
Data and retention
Retention is a maximum, not a reason to keep data. A shorter legal, contractual, or user-selected period can apply.
Used for sign-in, permissions, tenant isolation, and security. Users can request access, correction, restriction, or account review.
Exact post-account retention: production schedule requiredPrivate drafts are restricted to authorized restaurant roles. Only an explicit immutable release becomes public.
Owner-controlled, subject to contract and legal holdsAllowlisted, privacy-safe metadata only. MenuFaro does not retain a raw full IP address for analytics or create cross-site profiles.
Free raw events: up to 30 days · Plus: up to 12 monthsAccess is restricted by role. Erasure is reviewed against accounting, fraud, security, dispute, and other applicable legal-retention duties.
Exact jurisdiction-specific term: production schedule requiredPrivate exports and signed links must expire. A successful generation job does not make the result public.
Bounded lifetime; value must be configured and publishedApproved deletion must propagate through documented backup rotation. Deleted data must not be silently recreated from caches or analytics.
Rotation window: production schedule requiredProviders and international transfers
Before any production provider receives personal data, MenuFaro must record its purpose, data categories, role, region, retention, deletion path, subprocessors, security evidence, incident duties, and assistance with rights requests.
When data leaves the European Economic Area, the operator must document an applicable mechanism, such as an adequacy decision or approved safeguards including the European Commission’s Standard Contractual Clauses, plus any required transfer assessment.
State: not verified for production. No complete provider contract register has been supplied, so this page does not invent vendor, region, or transfer claims.
No account or no access
Use the public contact route if you cannot access the account, you are a restaurant guest, or your trusted sign-in is not linked to a MenuFaro record. Do not email passwords, card data, or identity documents.
These sources are general information. Product configuration, contracts, Member State law, and the facts of each request still require professional review.