Back to Menufly

Privacy Policy

This page explains what personal data we collect, why we collect it, how long we keep it, and what rights you have regarding your data.

Last updated: 13 July 2026

Controller: Klemen Hrastnik s.p., Slovenia

Privacy contact: klemen.hrastnik@gmail.com

1. Who this policy covers

This policy applies to:

Website visitors
Anyone who browses menufly.app or related Menufly pages.
Potential customers
People who create a trial account, submit a contact form, or communicate with us before subscribing.
Restaurant operators
Businesses or individuals who register a Menufly account and use the platform to manage their digital menus.
Menu guests
End-users (restaurant customers) who scan a Menufly QR code to view a menu.

2. Our role in data processing

Depending on the context, Menufly acts in different roles:

  • As data controller for data we process for our own business purposes — account management, billing, security, and basic analytics.
  • As data processor on behalf of the restaurant operator for any content the operator uploads or manages inside their Menufly account (menus, dishes, photos).

When a restaurant guest scans a QR code, Menufly records only an anonymous, aggregate visit count with no personally identifiable information. The restaurant operator is the data controller for any additional data they independently collect from their guests.

3. What data we collect

Contact dataName, email address, phone number, company or restaurant name — provided when you register or contact us.
Account dataEmail address, hashed password, account role, language preference, plan tier, restaurant profile (name, slug, address, cover image).
Menu contentMenus, categories, dishes, prices, allergen tags, dish descriptions, and photos you upload to the platform.
Usage & analyticsAggregated visit counts and scan events per menu. No IP address, device fingerprint, or cross-site tracking of menu guests.
Billing dataSubscription plan, payment status, billing interval, Stripe customer ID, invoice history. Full card details are handled by Stripe and never stored by Menufly.
Technical logsServer-side access logs (IP address, timestamp, HTTP method) retained for security and diagnostic purposes.

Paid-plan waitlist. If you ask to be notified when our paid plans launch, we store the email address you provide, which plan you were interested in, and the date of your request. We use it for one purpose only: to email you once that plan is available. We do not share it with third parties and we do not add you to a marketing list. You can ask us to delete it at any time by contacting us, and it is deleted automatically if you delete your account.

4. Why we process it and legal bases

Providing the Menufly serviceCreating and maintaining your account, serving your digital menus, processing uploads, and managing your subscription. Legal basis: performance of a contract.
Billing and tax complianceIssuing invoices, processing payments via Stripe, and maintaining accounting records as required by Slovenian and EU tax law. Legal basis: legal obligation.
Security and fraud preventionDetecting unauthorised access, preventing abuse, and maintaining system integrity. Legal basis: legitimate interest.
Aggregated visit analyticsCounting QR scans per menu so operators can see how many times their menus were viewed. No personal data is stored. Legal basis: legitimate interest.
Transactional emailSending account confirmations, password resets, billing receipts, and service notices. Legal basis: performance of a contract / legitimate interest.
Analytics or marketing cookiesOnly activated on the basis of your explicit consent where required by applicable law. See Section 11.

5. Where we get data from

  • Directly from you when you register, fill in a form, or use the Menufly dashboard.
  • Automatically from your browser or device when you interact with the service (server logs).
  • From Stripe when a payment or subscription event occurs.

6. Who we share data with

We do not sell personal data. We share data only where necessary to operate the service:

  • Supabase — cloud database and authentication (EU region).
  • Vercel — application hosting and CDN.
  • Stripe — payment processing and subscription management.
  • Resend — transactional email delivery.
  • Google LLC (Google Analytics) — website analytics. Only activated after you give consent via the cookie banner. Data may be transferred to the US under the EU–US Data Privacy Framework.
  • Legal, tax, or regulatory authorities if required by law.

All processors are bound by data processing agreements and may only use data to provide the contracted service.

7. International data transfers

We aim to store data within the European Economic Area (EEA). Where sub-processors transfer data to third countries (e.g. Stripe and Vercel may process data in the United States), such transfers rely on the EU–US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer mechanism.

8. Retention periods

Account and restaurant dataRetained for the duration of your account. Deleted within 30 days of account closure, except where a legal retention obligation applies.
Menu content (menus, dishes, photos)Retained until you delete it or your account is closed.
Billing and invoice records10 years, as required by Slovenian tax and accounting law.
Aggregated visit analytics2 years from the date of collection.
Server and security logs90 days, then automatically deleted.
Inquiry and pre-sales contactsUp to 12 months from the last interaction, unless a contract is entered.

9. Your rights

Under the GDPR you have the following rights regarding personal data for which we are the controller:

  • Right of access — request a copy of the data we hold about you.
  • Right to rectification — correct inaccurate data via your account settings or by contacting us.
  • Right to erasure — delete your account at any time (Account → Delete account). All personal data is permanently removed.
  • Right to restriction of processing — ask us to limit how we use your data in certain circumstances.
  • Right to data portability — export your data as JSON via Account → Download my data.
  • Right to object — object to processing based on legitimate interest.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any right, email us at klemen.hrastnik@gmail.com. We will respond within 30 days. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Slovenian supervisory authority:

Information Commissioner of the Republic of Slovenia (IP RS)

Dunajska cesta 22, 1000 Ljubljana

gp.ip@ip-rs.si · www.ip-rs.si

10. Restaurant guests — special note

If you scan a Menufly QR code as a restaurant guest, Menufly records only an anonymous, aggregated visit count for that menu — no name, no email, no IP address, and no cross-site tracking. We do not build a profile of individual guests.

The restaurant that placed the QR code is the data controller for any information they independently collect (e.g. reservation systems, loyalty programmes). For questions about such processing, please contact the restaurant directly.

11. Cookies

Menufly uses the following cookies:

  • Essential cookies — strictly necessary for authentication and session management. These are set as httpOnly cookies and cannot be disabled without breaking the service.
  • Analytics cookies (Statistics) — Google Analytics cookies (_ga, _ga_*) are set only after you give explicit consent via the cookie banner. They measure page views and visitor behaviour in aggregate. You can withdraw consent at any time via Cookie settings in the footer.

You can manage your consent preferences at any time by clicking the “Cookie settings” link in the footer.

12. Changes to this policy

We may update this policy from time to time to reflect changes in our service, technology, or legal requirements. The updated version will be published on this page with a new “Last updated” date. For material changes, we will notify active subscribers by email at least 14 days in advance.

13. Contact

For any privacy questions or to exercise your rights, email us at klemen.hrastnik@gmail.com. We aim to respond within 5 business days.