Data protection

Privacy policy

This policy explains what data we process, why we use it and how you can exercise your rights.

Last updated · 18 July 2026

Data controller

menudoQR is responsible for the personal data processed to operate the website, accounts, commercial relationship and platform support.

Controller: menudoQR

Website: https://menudoqr.com

Privacy contact: hola@menudoqr.com

Data we process

  • Account and access: email, technical identifiers, protected credentials and session data.
  • Restaurant details: name, contact details, address, opening hours, menu, products, images and other configured information.
  • Billing: plan, subscription, invoices, tax details and payment references. Full card details are processed by Stripe.
  • Orders, reservations and reviews: information submitted by customers when the restaurant enables these features.
  • Support and security: communications, attachments and technical records needed to protect and maintain the service.

Purposes and legal bases

We process data to provide the platform, manage payments and billing, respond to requests, prevent fraud, resolve incidents and send essential communications. Depending on the circumstances, processing is based on performance of a contract, compliance with legal obligations, consent or legitimate interests.

When a restaurant receives customer data through orders, reservations or reviews, the restaurant is normally the data controller and menudoQR acts as its technology provider.

Service providers and international transfers

We do not sell personal data. We may use hosting, database, payment, email and infrastructure providers subject to confidentiality and security obligations. Where an international transfer takes place, we apply the safeguards required by the GDPR.

Retention and security

We retain data for as long as needed to provide the service and meet legal obligations. After an account is deleted, data is erased or anonymised, subject to any applicable statutory retention periods.

We apply technical and organisational measures appropriate to the level of risk. No system is infallible, so we recommend using a unique password and reporting any suspected unauthorised access immediately.

Your rights

You may request access, rectification, erasure, restriction, objection or portability, and withdraw consent where applicable, by emailing hola@menudoqr.com. You may also lodge a complaint with the competent data protection authority.