Privacy Policy — Scan My Menu
How we collect, use, and protect personal data for the Scan My Menu service.
Last updated: 17 July 2026
This Privacy Policy explains how [Your Company Legal Name] ("we," "us," "our"), the data controller for the Scan My Menu application (the "Service"), collects, uses, and protects your personal data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Data Controller: [Your Company Legal Name], [Company Address], [Country]
Contact / Data Protection queries: [privacy/support email]
EU representative / DPO (if applicable): [name and contact, if required]
1. What Data We Collect
a) Account and business data (provided by you)
- Name, email address, phone number
- Business name, address, and business details
- Login credentials (password stored in hashed/encrypted form)
b) Menu content
- Product names, descriptions, prices, categories
- Images you upload for your menu items
c) Payment data
- Billing information (e.g., plan selected, billing address)
- Payment card details are collected and processed directly by our payment processor [e.g., Stripe]; we do not store full card numbers.
d) Usage and technical data
- IP address, device/browser type, log data, pages viewed, timestamps
- Cookies and similar technologies (see Section 7)
e) End-customer data (if applicable)
- If end customers interact with your published menu (e.g., scanning a QR code), we may collect limited technical data (e.g., page views) but do not require them to create accounts unless you enable such features.
2. Legal Bases for Processing (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Creating and managing your account | Performance of a contract |
| Providing and maintaining the Service | Performance of a contract |
| Processing subscription payments | Performance of a contract / legal obligation (tax) |
| Improving and securing the Service | Legitimate interest |
| Sending service-related communications | Performance of a contract / legitimate interest |
| Marketing communications | Consent (opt-in; withdrawable at any time) |
| Complying with legal obligations | Legal obligation |
3. How We Use Your Data
We use your data to:
- create and manage your account and menu;
- process subscription payments and billing;
- provide customer support;
- maintain, secure, and improve the Service;
- send important notices (e.g., changes to Terms, security alerts);
- send marketing communications, only where you've opted in;
- comply with legal and regulatory obligations.
We do not sell your personal data.
4. Who We Share Data With
We share data only as necessary, with:
- Payment processors (e.g., Stripe) to process subscriptions;
- Hosting and infrastructure providers (e.g., cloud storage for images and data);
- Analytics providers, to understand usage and improve the Service;
- Professional advisors (e.g., legal, accounting), where necessary;
- Authorities, where required by law or to protect our legal rights.
All third-party processors are bound by data processing agreements consistent with GDPR requirements.
5. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses, or transfers to countries covered by an adequacy decision.
6. Data Retention
We retain your personal data for as long as your account is active, plus a reasonable period afterward to comply with legal, tax, or accounting obligations, resolve disputes, and enforce our agreements. Menu Content is retained until you delete it or close your account. You may request earlier deletion, subject to Section 8.
7. Cookies
We use cookies and similar technologies to:
- keep you logged in;
- remember preferences;
- understand usage (analytics);
- (if applicable) support advertising, only with consent.
You can manage cookie preferences via our cookie banner or your browser settings. Essential cookies cannot be disabled as they are necessary for the Service to function.
8. Your Rights (GDPR)
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), subject to legal retention requirements;
- Restrict processing in certain circumstances;
- Data portability — receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interest or for direct marketing;
- Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing;
- Lodge a complaint with your local data protection supervisory authority.
To exercise these rights, contact us at [privacy/support email]. We will respond within the timeframes required by GDPR (generally one month).
9. Data Security
We implement appropriate technical and organizational measures (e.g., encryption in transit, access controls, regular backups) to protect your data against unauthorized access, loss, or misuse. No system is completely secure, and we cannot guarantee absolute security.
10. Children's Data
The Service is intended for business users who are adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us so we can delete it.
11. Automated Decision-Making
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes (e.g., by email or in-app notice) before they take effect.
13. Contact Us
For any questions about this Privacy Policy or your data:
[privacy/support email] · [company legal address]
You also have the right to lodge a complaint with your national data protection authority.
This template is provided for general guidance and does not constitute legal advice. Please have it reviewed by a qualified lawyer familiar with your jurisdiction, data flows, and business model before publishing.