Privacy Policy
- Version:
- 2
- Last updated:
- 15 September 2026
- Effective date:
- 15 September 2026
This Privacy Policy explains how Menuzi handles personal data. It is designed to meet both the EU General Data Protection Regulation (GDPR) and Egypt's Personal Data Protection Law (Law No. 151 of 2020 and its Executive Regulations, as they come into force). The English version of this policy prevails in case of any discrepancy with a translation.
Who is responsible for your data
Bytes Maestros AB (Sweden, org.nr 559468-7831, Sjödalsvägen 18, 141 47 Huddinge, Sweden) provides and operates Menuzi and is the data controller for the Service, our website and our application.
In Egypt, the Service is operated under licence by Menuzi Software Solutions LLC (Alexandria, Egypt), which is the contracting party for customers in Egypt. It is the controller for the contract, invoicing and support data of those customers, and your local point of contact and representative for data-protection matters in Egypt.
Privacy contact for both: privacy@menuzi.com.
Scope and roles
This policy covers our marketing site (menuzi.com), our application (app.menuzi.com) and the guest-facing published menus (menus.menuzi.com and custom domains served by us). It covers personal data of business account holders and their team members, website visitors, and guests who view or order from published menus.
Two roles. For account holders, team members and website visitors, Menuzi is the controller. For guests, the business that publishes the menu is the controller, and Menuzi processes guest data on that business's behalf as its processor under our Data Processing Addendum. The section "Guests of published menus" describes that processing so that guests can understand it, but questions and requests about a specific menu should go to the business behind it. Menuzi is also an independent controller for a limited set of guest traffic data that it processes for its own purposes: security and abuse prevention (including rate limiting), error monitoring, aggregated service-improvement statistics, and verifying that accounts are used within their subscription. That processing is listed under "Why we use your data" and "Legal bases".
What we collect
Marketing-site visitors
We use a cookieless, pseudonymous analytics tool that does not track you across sites. We do not set advertising or cross-site tracking cookies, and we do not load third-party fonts or embeds that track you. If you contact us through the site, we receive what you send us.
Account holders and team members
First and last name, email address, a hashed password, your business name, country and the languages you operate in, and a short business profile (segment and branch-count range). We store the timestamp and version of your acceptance of our Terms and Privacy Policy and, separately, whether you opted in to marketing. Team members invited to an account provide their name, email address and password; the invitee's email address is stored from the moment a member invites them. We also record which roles each member holds. Your name, email address, business name and country are required to open an account; without them we cannot provide the Service. This policy applies to invited team members from the moment their invitation is sent, and the invitation names the member who invited them.
Billing
For paid plans: your billing contact, company details, VAT or tax registration number where applicable, the plan and branch count you subscribe to, and payment references. When you pay through one of our payment partners, that partner collects your payment details directly; card numbers never reach Menuzi.
Menu content
The menus, text, images, branding and prices you create or provide, including content you provide for menu import. This is mostly business content but may incidentally contain personal data (for example, a name or phone number printed on a menu).
Product usage
In the application we record cookieless, aggregate events about how the product is used (for example, which sign-up step was reached or whether a guided tour was completed). No advertising identifiers are used.
Support
Information you provide when you contact support@menuzi.com or reach us through the support channels shown in the application.
Guests of published menus
We do not ask guests to create an account or to identify themselves.
Viewing a menu
When a guest opens a published menu, our servers and providers process technical data to deliver and protect the menu: IP address, browser and device type, approximate location (country, region and city derived from the IP address), the referring site or QR code, and the language chosen. To give the business menu analytics, we count views and which sections and items are opened. A guest is counted using a pseudonymous identifier calculated from the IP address, the browser identifier, a secret key and the current date, so it changes every day; the raw IP address is not stored in analytics and the identifier cannot be linked across days. The business sees aggregated figures only.
Ordering from a menu
When a guest places an order on a menu that offers ordering, we process the items ordered, the service option chosen (for example, dine-in or take-away) and, for table service, the table number the guest enters. The cart and the chosen branch are kept in the guest's own browser storage. We do not ask for a name, phone number, address or payment details; the business handles payment and any further contact itself. The order, with a sequential order number, is shown to the business so it can prepare and serve it.
Why we use your data
- To provide and operate the Service (create, host, publish and serve your menus).
- To authenticate you and your team members and secure your account.
- To run menu import (extract a draft menu from what you provide).
- To bill you, issue invoices and collect payment for paid plans.
- To relay guest orders to you and to give you analytics about your menus.
- To communicate with you (transactional email; marketing only with your consent).
- To secure, monitor and debug the Service (error monitoring, abuse and rate-limit protection).
- To verify that accounts are used within their subscription (for example, where a menu is scanned).
- To analyse, improve and develop our products and services, including generating aggregated and/or de-identified insights and analytics. We do not use your content to train our own machine-learning models.
- To comply with legal obligations, including accounting and tax rules.
Legal bases
For users in the EU/EEA, we rely on the following GDPR legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, your account, and hosting and publishing menus | Performance of a contract (Art. 6(1)(b)) |
| Billing, invoicing and payment collection | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) |
| Security, fraud and abuse prevention, error monitoring, product improvement and insights | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails | Consent (Art. 6(1)(a)) — you may withdraw it at any time |
| Guest data processed through published menus on behalf of the business (views, analytics, orders) | Processed on the instructions of the business that publishes the menu (Art. 28); the business is responsible for its own legal basis |
| Menuzi's own processing of guest traffic: security and abuse prevention, error monitoring, aggregated service-improvement statistics, licence-compliance verification | Legitimate interests (Art. 6(1)(f)) |
| Legal and regulatory compliance | Legal obligation (Art. 6(1)(c)) |
For Egypt (PDPL), processing is based on your consent and/or the necessity grounds recognised under the PDPL; cross-border transfers are addressed below.
How long we keep it
We keep account, team and menu data for as long as your account is active. Guest orders are kept as part of your account records while your account is active. When you close your account (by contacting support), we may delete your data after 30 days and will delete or anonymise it within 90 days, except where we must keep certain records longer to meet a legal obligation (for example, accounting records, retained for the statutory period — currently up to 7 years in Sweden and 5 to 10 years in Egypt). We aim to delete material you provide for menu import within 90 days of the import. Raw analytics events are held by our analytics provider for a limited period (currently up to three months); Menuzi keeps daily aggregates only. Backups are rotated on a rolling cycle that we aim to keep within 90 days, and error-monitoring data is kept by our error-monitoring provider for around 90 days.
Who we share it with
We share personal data only with the subprocessors that help us run the Service (hosting, storage, email, error monitoring, analytics, payment processing, and providers that help process menu content). Each is listed with its role and location on our Subprocessors page, and is bound by a data-processing agreement. Payment partners that act as merchant of record process your payment data under their own privacy policies. Menuzi Software Solutions LLC receives the contract, billing and support data of customers in Egypt. We do not sell your personal data. We may disclose data where required by law or to protect our rights.
International data transfers
Our infrastructure is in the EU and, for some providers, the United States; our edge network and analytics provider operate globally. Where personal data is transferred outside the EEA, we rely on EU Standard Contractual Clauses and the providers' data-protection commitments.
For customers in Egypt: because our infrastructure is located outside Egypt, your data is transferred abroad to deliver the Service. We carry out these transfers under the PDPL's cross-border-transfer rules and any licence the Personal Data Protection Center requires, as those rules come into force, with appropriate safeguards in place.
Your rights
EU/EEA (GDPR): access, rectification, erasure, restriction, portability, objection (including to processing based on legitimate interests and to direct marketing), and the right to withdraw consent. You may lodge a complaint with your supervisory authority; our lead authority is the Swedish Authority for Privacy Protection (IMY).
Egypt (PDPL): access, correction, erasure, objection and withdrawal, and the right to be informed; you may complain to the Personal Data Protection Center (PDPC).
To exercise any right, email privacy@menuzi.com. We will respond within the time limits set by applicable law. Guests of a published menu should contact the business that publishes it; we assist that business with such requests.
Cookies and browser storage
We keep cookies to the minimum needed to run the Service. No consent banner is required for our current cookies because they are strictly necessary or functional, and our analytics is cookieless. The language cookie is set on your first visit with the language the site resolved for you and is updated when you switch language.
| Where | Name and purpose | Duration | Type |
|---|---|---|---|
| Marketing site and app | Language preference (PARAGLIDE_LOCALE): remember the language shown to you, set on first visit | Up to 400 days | Functional |
| App | Session cookie: keep you signed in | Up to 7 days, renewed while you use the app | Strictly necessary |
| App | Write-position cookie: show your own latest changes right after you save | 30 seconds | Strictly necessary |
| App | Menu content language and orders branch: remember the language and branch you last worked in | Up to 1 year | Functional |
| App | Sidebar state: remember whether the sidebar is collapsed | 7 days | Functional |
| App (browser storage) | Guided-tour progress, stored locally in your browser | Until you clear your browser data | Functional |
| Published menus (browser storage) | Cart and selected branch for the menu, stored locally in the guest's browser; no cookies are set | Until the order is placed or the guest clears browser data | Strictly necessary |
Our marketing-site and app analytics is cookieless and sets no tracking cookies. If we ever introduce advertising or non-essential cookies, we will add a consent mechanism first.
How we protect your data
We use technical and organisational measures including encryption in transit, hashed passwords, role-based access controls, rate limiting on public endpoints, and EU-region error monitoring. We avoid putting personal data in logs and error reports. No method is perfectly secure, but we work to protect your data and will notify you and the relevant authority of a breach as required by law.
Automated decision-making
We do not make decisions producing legal or similarly significant effects about you solely by automated means. Where we use third-party providers to help process the content you provide (see "Who we share it with" and our Subprocessors page), they act only on our instructions under data-processing terms and do not use your content to train their own models.
Children
The Service is for businesses and is not directed at children. We do not knowingly collect personal data from children. Guests are not asked to identify themselves.
Changes to this policy
We may update this policy and will change the "Last updated" date and version; for material changes we will give appropriate notice. Version 2 (15 September 2026) added the two controllers, guest ordering and analytics, billing, team members, and a corrected cookie table.
Contact
Privacy questions or requests: privacy@menuzi.com. Controller: Bytes Maestros AB, Sjödalsvägen 18, 141 47 Huddinge, Sweden. Egypt: Menuzi Software Solutions LLC, Safwet El Mostakbal Project No. 215, Port Said Street, Ground Floor, Sporting, Alexandria, Egypt.
