1. Data Controller
Vasileiadis Anastasios — Personal Business
THOUKIDIDI 16, KALAMARIA, THESSALONIKI, GREECE 55134
VAT: EL038169820 — Tax Office (ΔΟΥ): Kalamarias
Email: legal@menoo.online
2. What We Collect
Account holders (restaurant owners): name, email address, password (stored only as a secure hash), restaurant name and optional details (address, phone, logo), language preference, and the menu content you create. If you subscribe to a paid plan, payment is processed by Stripe; we store only subscription identifiers and status — we never see or store your card details.
Menu visitors (diners): visiting a public menu does not require an account. We record aggregated, privacy-preserving scan statistics for the menu owner: date, hour, display language, and a one-way daily hash used to estimate unique visits. We do not store diners' IP addresses in analytics, do not set advertising cookies on menu pages, and cannot identify individual diners from these statistics.
Contact form: name, email and your message, used solely to respond to you.
3. Why We Process It (Legal Bases)
We process account and menu data to provide the Service under our contract with you (GDPR Art. 6(1)(b)); billing records to comply with tax obligations (Art. 6(1)(c)); aggregated menu analytics and service security based on legitimate interest (Art. 6(1)(f)); and optional communications based on consent (Art. 6(1)(a)), which you may withdraw at any time.
4. Processors & Recipients
We use a small number of service providers, bound by data-processing agreements, strictly to operate the Service: Stripe (subscription payments), Brevo (transactional email), DeepL and/or Anthropic (machine translation of menu text you choose to translate — only the menu text itself is sent, never your account credentials), and our hosting provider in the EU. Where a provider processes data outside the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses. We do not sell personal data.
5. Retention
Account and menu data are kept while your account is active. Menus you delete are soft-deleted and permanently erased after 30 days. If a paid plan ends, premium content is hidden but retained so you can restore it by resubscribing. Billing records are kept as long as tax law requires. Aggregated scan statistics are pruned after approximately 13 months. Contact messages are kept for up to 24 months.
6. Your Rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time. To exercise them, email legal@menoo.online. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local supervisory authority.
7. Cookies
The main site uses only strictly necessary cookies: a session cookie for login and a language-preference cookie. If analytics/marketing tags are ever enabled on the main site, they load only after your consent via the consent banner. Public menu pages set no advertising or analytics cookies.
8. Security
Passwords are stored using strong one-way hashing; access to systems is restricted; connections are encrypted (HTTPS). No method of transmission or storage is 100% secure, but we take commercially reasonable measures appropriate to the risk.
9. Children
The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children; public menus are informational pages that require no personal data from visitors.
10. Changes
We may update this policy; material changes will be announced via the Service or email. Continued use after the effective date constitutes acceptance.