Skip to content

Legal

Privacy Policy

Last updated: September 2026

1. Our Commitment to Privacy

MenuPane ("we", "us", or "our") provides physical NFC and QR menu cards paired with digital hosted menu platforms for restaurants, cafés, and hospitality venues. We believe privacy is an essential design principle, not an afterthought.

We divide our platform into two strictly separated user experiences:

  • Restaurant Guests (Diners): Anyone viewing a menu by scanning a QR code or tapping an NFC card.
  • Restaurant Operators (Subscribers): Business owners, chefs, and staff who create accounts to manage menus and branding.

2. For Restaurant Guests: 100% Anonymous Menus

When a diner taps an NFC card or scans a QR code on a dining table:

  • Guests do not need to download an app.
  • Guests do not create an account, log in, or provide a name, phone number, or email.
  • We do not track diners across other websites, apps, or physical venues.
  • Any menu engagement (such as viewing a dish, searching, or switching language) is recorded in aggregate without personal identifiers or persistent advertising IDs.

3. Information We Collect from Operators

When a restaurant owner or operator registers an account with MenuPane, we collect:

  • Account Credentials: Email address and encrypted password managed via secure Supabase Authentication.
  • Business Profile: Restaurant name, custom slug, branding assets (logos, typography, color palettes), address, and operating hours.
  • Menu Data: Item names, descriptions, prices, dietary labels, ingredients, photos, and video clips uploaded to your account.
  • Billing Information: Payment card details and invoicing records are processed securely by Stripe. MenuPane never stores complete credit card numbers on its servers.

4. Cookies & Local Storage

We hold a minimal, privacy-first approach to cookies:

TypePurposeDuration
Strictly EssentialMaintains authenticated operator sessions in the dashboard.Session / 30 days
Functional (Storage)Remembers cookie notice dismissal and guest language selection.Persistent (Local)
Advertising / Third-PartyNone. We do not sell user data or run retargeting ad pixels.N/A

5. Data Retention & Security

All operator and menu data is stored securely in encrypted Postgres databases with Row-Level Security (RLS) enforced at the database kernel. Uploaded photography and dish assets are hosted on secure, access-controlled cloud object storage. We retain business data for as long as your account remains active. When an account is terminated, operational data is purged according to our retention schedule.

6. Your Rights (GDPR & CCPA)

Depending on your location, you have rights regarding your personal data:

  • The right to access the personal information we hold about you.
  • The right to request correction of inaccurate data.
  • The right to request erasure ("right to be forgotten").
  • The right to export your restaurant menus and content.
  • The right to object to or restrict processing of your data.

7. Contact Us

If you have any questions regarding this Privacy Policy or your data, please reach us through the contact form on our homepage.