Skip to privacy information
MenuFaro

Privacy center · engineering notice

Privacy controls with receipts, not promises.

See how MenuFaro separates restaurant and platform responsibilities, limits local data, and records account-linked rights requests. This page does not claim automatic General Data Protection Regulation (GDPR) or worldwide legal certification.

Private by defaultNo cross-site profile. No raw full IP in analytics. No private dashboard cache.

Receipt ≠ completion Every consequential request keeps a review state.

Minimum data The request form does not ask for an email already supplied by trusted sign-in.

Responsibility map

The legal role follows the processing purpose.

One company can be controller for one purpose and processor for another. Contracts and the actual configuration determine the final role.

Restaurant as controller

A restaurant normally decides why and how guest reservation, loyalty, feedback, and menu-contact data is used when it enables those modules. Guests should contact that restaurant for restaurant-controlled data.

MenuFaro as processor

Where MenuFaro handles guest data only on a restaurant’s documented instructions, the restaurant needs a reviewed data-processing agreement and MenuFaro must follow the agreed scope.

MenuFaro operator as controller

The service operator may decide the purposes for account authentication, subscription administration, platform security, abuse prevention, support records, and its own legal obligations.

Account privacy center

Submit a request and keep its receipt.

MenuFaro records receipt before showing success and sets an initial response target one calendar month after receipt. Receipt starts review; it does not mean that access, correction, export, or erasure is complete.
Trusted sign-in required

New request

Tell us what right you want to exercise

Required fields are marked “required”.

Use the smallest amount of detail needed. Do not include passwords, payment-card data, identity documents, health information, or information about another person.

Describe the account, data, or processing activity precisely. 10–1000 characters.

Do not upload identification now. If verification is needed, the privacy team must explain a secure, proportionate method.

An erasure request is reviewed against legal-retention duties and other people’s rights. It is never reported as immediate deletion.

Submission stays unavailable until MenuFaro confirms the trusted identity and durable request ledger. The non-account contact route remains available below.

Your ledger

Request receipts and review status

Shows up to the 50 newest requests linked to this trusted signed-in identity. There is no cross-account search on this screen.

Checking the durable request ledger…

Data and retention

Keep only what a documented purpose needs.

Retention is a maximum, not a reason to keep data. A shorter legal, contractual, or user-selected period can apply.

Owner identity and memberships

Used for sign-in, permissions, tenant isolation, and security. Users can request access, correction, restriction, or account review.

Exact post-account retention: production schedule required

Menu and brand content

Private drafts are restricted to authorized restaurant roles. Only an explicit immutable release becomes public.

Owner-controlled, subject to contract and legal holds

Guest engagement events

Allowlisted, privacy-safe metadata only. MenuFaro does not retain a raw full IP address for analytics or create cross-site profiles.

Free raw events: up to 30 days · Plus: up to 12 months

Billing, audit, and security records

Access is restricted by role. Erasure is reviewed against accounting, fraud, security, dispute, and other applicable legal-retention duties.

Exact jurisdiction-specific term: production schedule required

Exports and signed links

Private exports and signed links must expire. A successful generation job does not make the result public.

Bounded lifetime; value must be configured and published

Backups and deletion

Approved deletion must propagate through documented backup rotation. Deleted data must not be silently recreated from caches or analytics.

Rotation window: production schedule required

Providers and international transfers

A vendor name is not a transfer assessment.

Before any production provider receives personal data, MenuFaro must record its purpose, data categories, role, region, retention, deletion path, subprocessors, security evidence, incident duties, and assistance with rights requests.

When data leaves the European Economic Area, the operator must document an applicable mechanism, such as an adequacy decision or approved safeguards including the European Commission’s Standard Contractual Clauses, plus any required transfer assessment.

Public subprocessor register

State: not verified for production. No complete provider contract register has been supplied, so this page does not invent vendor, region, or transfer claims.

  • Vendor and service purpose
  • Data categories and processing region
  • Subprocessors and advance-change notice
  • Retention, deletion, security, and transfer mechanism
Ask for the current provider register

Cookies and device storage

Core access does not depend on optional tracking.

Strictly necessary

Identity, security, load-balancing, or a user-requested preference may use necessary storage. It must be limited to the purpose and explained at collection.

Cannot be turned off inside the product when essential to the requested service

Optional analytics and advertising

This Sites release does not expose an enabled optional-tracking control because no verified consent-aware optional tracker is connected. Future optional tracking must remain off until the applicable valid choice.

Current product state: unavailable / off

On this device

Clear guest preferences and sample favorites

This removes only MenuFaro entries in this browser’s local storage, such as sample favorites and an unfinished onboarding draft. It does not erase server records, end a server session, or change another device.

Checking local MenuFaro preferences on this device…

Strictly necessary identity/session storage is managed separately. Use Sign out of MenuFaro to end the current server session, then use your browser controls if you also want to remove site cookies.

No account or no access

A rights request must not depend on signing in.

Use the public contact route if you cannot access the account, you are a restaurant guest, or your trusted sign-in is not linked to a MenuFaro record. Do not email passwords, card data, or identity documents.

Open non-account privacy contact route

Official guidance used for this engineering notice

These sources are general information. Product configuration, contracts, Member State law, and the facts of each request still require professional review.