MenuMate

Privacy Policy

Last updated: July 23, 2026

This page is maintained by MenuMate to answer common privacy questions about how the app handles data for restaurant owners and their customers. It is not a legal certification and does not replace professional legal advice.

1. What we collect

  • Owner account: your email address (used for OTP sign-in).
  • Restaurant info you enter: name, contact, logo, promotions, and menu items.
  • Uploaded menu files: PDFs or images you upload for AI extraction.
  • Customer chats: anonymous session id, message text, timestamp.
  • Basic technical data: IP address for security and rate limiting.

2. How we use it

Only to run the app: authenticate you, store your menu, render your public QR menu, and power the AI waiter answering guest questions. We do not sell your data. We do not use it for advertising.

3. Third parties

The app relies on a small number of processors, each receiving only what they need:

  • Supabase (Lovable Cloud): database, auth, and file storage.
  • OpenAI / Lovable AI Gateway: menu extraction, chat, and voice transcription. Menu text and chat messages are sent for processing but not used for model training under the enterprise agreement.
  • Resend: transactional emails (OTP codes, notifications).

4. How long we keep it

  • Owner account & menu data: while your account is active.
  • After account deletion: removed within 30 days (backups purged within 90 days).
  • Customer chat messages: auto-deleted after 30 days.
  • Uploaded menu files: deleted when you remove them or delete your account.

5. Your rights (GDPR / CCPA)

You can, at any time:

  • Access the data we hold about you.
  • Export your restaurant and menu data as JSON.
  • Correct anything inaccurate directly in the dashboard.
  • Delete your account — all personal data is removed.

To exercise any of these rights, email privacy@menumate.app.

6. Cookies & tracking

MenuMate uses only the browser storage required to keep you signed in. No advertising cookies, no third-party tracking pixels. Do Not Track signals are respected.

7. Security

Data is transmitted over HTTPS and encrypted at rest by our infrastructure provider. Row-level security ensures each owner can only access their own restaurant data.

8. Contact

Questions? Email privacy@menumate.app.