Skip to content
Legal

Privacy policy

Version 3.0 — September 2026

Privacy is not a slogan here; it is an engineering decision. This document says exactly what data we collect, where we keep it, who we share it with and what control you have over it. Everything written here is live in the product today — except where we explicitly say “from activation”. This document forms part of the terms of service. This English text is a courtesy translation — the Persian version governs (section 16).

1. Who this document covers

MenuYou is a multi-tenant platform, so several different groups hold data in it:

GroupWho they are
Business ownerThe café or restaurant owner with a MenuYou account
StaffAn employee, waiter or cashier invited into the panel by the owner
End customerAnyone who scans the QR code, places an order or joins the loyalty club
CourierThe person delivering orders, with their own panel
Brand ambassadorSomeone who refers businesses and earns commission
Site visitorAnyone browsing menuyou.app or using the chat and contact form

2. Our role: controller or processor

This distinction is the backbone of the whole document:

  • MenuYou is the data controller for: the business owner’s account, brand ambassador data, and technical information about site visitors. We decide why and how that data is processed.
  • MenuYou is only a processor for: the end customers, staff and couriers of each business. The controller of that data is the business itself. We hold and process it on their instruction and on their behalf.

What does that mean? The legal responsibility for collecting customer and staff data correctly and with consent rests with the business, not with MenuYou. The full responsibility boundary is set out in section 11 of the terms of service.

3. What data we collect

3.1 Account and business — first and last name, mobile number, email, password (hashed, never stored in the clear), business name, address and phone, logo, social handles, opening hours, and the entire menu (categories, items, prices, photos, video).

3.2 End customers (controller: the business) — mobile number (identity key, verified by SMS), name, email, date of birth (for occasion campaigns), owner’s notes, SMS consent date, full order history, loyalty points and tier, coupons and prizes, review text and ratings, survey answers, spin-wheel and Hafez records, credit-ledger balances, and the display name and share of each person in a table group order.

What is publicly visible: a review a customer submits is published on the menu page after the business approves it and is then visible to everyone. In a table group order, each person’s display name and share is visible to the others at that table. Everything else in this section is visible only to that business.

3.3 Orders, delivery and couriers — from the recipient: name, phone, full delivery address, geographic coordinates, the coordinates and code captured at the moment of delivery, and the proof-of-delivery photo. From the courier: name, mobile, national ID, vehicle type and plate number, customer ratings, and location during an active assignment.

Exactly what is kept of a courier’s location: the moment-to-moment route is not stored. Only the last reported position is held on the courier’s own record and is overwritten on every update, plus the coordinates at each assignment status change (picked up, delivered). No tracking happens outside an active assignment. Delivery addresses and coordinates are visible only to that business and to the courier the assignment was given to.

3.4 Staff — the HR plugin — clock-in and clock-out times, lateness and overtime, shift schedules, salary, benefits, deductions and payslips; all entered in the panel by the business manager.

No biometric data is processed or stored. The attendance kiosk works with a hashed numeric PIN — not fingerprints, not faces.

3.5 Brand ambassadors — national ID, card number and IBAN, solely for identity verification, commission settlement and tax obligations. These columns are excluded from the system’s public output and never appear in JSON responses. Changing a registered bank account requires MenuYou’s approval.

3.6 Financial and payment — amount, order reference, transaction status and time, and subscription billing records. From payment-gateway activation: the transaction tracking code is also recorded, and to settle each business’s share through the split system, the destination IBAN and the identity details required by the payment provider are registered.

Bank card details are entered directly on the payment provider’s secure page, never reach MenuYou’s servers and are never stored there.

3.7 Contacting us — from a support ticket: the conversation text and any attachments. From the live site chat: we do not ask for or store your name, email or phone number; only the conversation text, any attachments and the technical data needed to continue that conversation (IP address, browser details, page address and referring page). From the contact form: name, contact method, message text and IP address, to prevent spam.

3.8 Technical and statistical data:

  • Signed-in sessions: IP address and browser details, for account security.
  • IP address in anti-abuse limits (login, verification code, spin wheel, Hafez) — hashed only in the wheel and Hafez.
  • Short-link clicks in SMS campaigns, to count unique clicks — with a hashed IP, with no raw IP retained.
  • Menu view and QR scan statistics: aggregate, identity-free counters (date, hour, count). No individual behavioural profile of a menu visitor is built.
  • Panel change history (which user changed what and when), for auditing and dispute resolution.

3.9 What we do not collect — biometric data · bank card details · an end customer’s location beyond the address they enter themselves · a courier’s location outside an active assignment · any advertising tracking data.

4. Cookies and local storage

MenuYou runs no third-party advertising or analytics tracker — no Google Analytics, no Tag Manager, no Clarity, no Hotjar, no ad network. Not on the site, not in the panel, not on business menus. All fonts are hosted on our own servers; no request is made to external font servers.

Because we have no advertising or analytics cookies, we have no cookie consent banner either; the cookies below all exist to make the service work.

CookiePurposeLifetime
Session cookie + XSRF-TOKENKeeping you signed in and preventing request forgeryUntil the session ends
menu_deviceRandom device identifier: counting unique visits and preventing fraud in surveys, the spin wheel and HafezOne year
menuyou_refRecording a brand ambassador referral for sign-ups arriving through their link30 days
sidebar_stateWhether the panel sidebar is expanded or collapsedOne year

The menu_device cookie is HttpOnly and, like every cookie in the system, is encrypted and signed; it can neither be read by script nor forged. None of these cookies is used for advertising or for selling data.

What stays only in your browser: these live in your device’s localStorage and are never sent to the server — the shopping cart, the favourites list (per branch), light/dark mode, panel display preferences, the identifiers of surveys you have answered, and the live chat conversation id.

If you sign in with a personal customer account, your favourites are stored on your account as well as in the browser so they follow you across devices. Until you sign in, none of this leaves your browser.

5. How we use data

We use data to deliver the service, show menus correctly to customers, process orders, compute statistics, provide support and improve the product. We never sell your data or your customers’ data, and we never hand it to anyone for independent third-party marketing.

5.1 Service SMS — verification codes (login and sign-up), order status updates, staff and courier invitations, and security alerts. These messages are a necessary part of the service and cannot be opted out of.

5.2 Marketing SMS and the loyalty club — marketing and occasion messages are sent only to customers whose consent has been recorded. This rule is locked into the system itself: a marketing message never goes out to a customer without recorded consent, even if the business wants it to. Every customer can withdraw consent at any moment through the unsubscribe link inside every message, and it takes effect immediately. The full text of sent messages, along with the recipient number and delivery status, is retained for dispute resolution (see section 8 for how long).

5.3 Personal customer account — a customer can sign in at account.menuyou.app with a verification code and see their own orders, coupons, prizes, reservations and favourites across every café they belong to, in one place.

That view is for the customer only. No café sees another café’s data; each business’s customer base stays separate and isolated. The only thing shared across businesses is the confirmation that “this number belongs to this person” — not the name, not the history, not the points.

5.4 Analytics and intelligent features — to keep improving MenuYou and to offer intelligent features (such as automatic product suggestions, purchase behaviour analysis, a review-reply assistant and sales trend forecasting), we may use data recorded on the platform — interactions, sales statistics, reviews and answers — to train, evaluate and develop machine learning and AI models.

Our commitment: all data used to train algorithms is fully anonymised before processing, so that no attributable identifying information — name, phone number, address or venue identifier — remains in it.

The only active AI transfer today: if you switch on the automatic menu translation plugin, the names and descriptions of your menu items are sent for translation to an AI service outside Iran. This happens only when you activate it, covers only public menu text, and contains no personal data, financial data or customer information. Manual translation sends nothing at all.

5.5 Our own aggregate reporting — for product planning and infrastructure capacity we use aggregate counters (number of active businesses, order volume, resource usage). These reports contain no individual data and nothing attributable to a single venue.

6. Suppliers, third-party services and cross-border transfer

For part of the service we have to entrust the necessary data to a specialist supplier. In every case only the minimum required data is sent, never more:

Type of supplierWhat data goesWhen
SMS operatorRecipient number and message text — for verification codes, notifications and campaignsAlways
Map serviceCoordinates and address — to display maps and convert coordinates to addressesWhen a map is used
AI service (outside Iran)Only menu item names and descriptions — for automatic translationOnly if you activate it
Payment gatewayAmount, order reference, tracking code and split-settlement IBAN detailsFrom activation
Third-party delivery fleetRecipient address and phone, branch address and phone, address notesOnly if you connect it
Fonts, scripts and imagesAll on our own servers; no external calls
  • Map rendering happens in your browser, which means the map service receives your browser’s IP address. Search and coordinate-to-address conversion, however, go through our server and do not carry your IP.
  • Legal disclosure: where legally compelled and on the documented request of the competent authorities of the Islamic Republic of Iran, we are obliged to provide information. Otherwise your data is not given to any third party.
  • If a supplier is added or replaced that would see a new category of data, it is announced in this document before it goes live.

7. Security

  • All traffic over HTTPS with a valid certificate.
  • Passwords hashed with bcrypt; the raw password is never stored.
  • Per-business data isolation at the application layer: every query is forcibly scoped to that business’s id, and cross-tenant access is not possible.
  • Three layers of access control on every panel request: plan → plugin → role and user permission. Every lock you see in the interface has a mandatory server-side equivalent.
  • Sensitive files on a private disk: expense invoice attachments, ticket and chat attachments, and proof-of-delivery photos — none of them readable from the internet by guessing a URL.
  • Rate limiting on login, verification codes, staff and courier sign-in, the wheel and Hafez.
  • Attendance uses a hashed numeric PIN, not biometrics.
  • Session cookies carry Secure and SameSite flags in production.
  • MenuYou support staff access to business data is limited, role-based and recorded in the audit trail.

No system is one hundred percent impenetrable; what we commit to is keeping these layers continuously up to date.

8. How long we keep data

DataRetention
Read panel notifications30 days
Other panel notifications90 days
Live site chat conversationsAuto-closed after 3 days of inactivity, fully deleted after 180 days
SMS records (number and text)180 days
Panel change and audit history365 days
Login session120 minutes of inactivity
Courier last positionOverwritten on every update; no history is retained
Account, menu and customer dataFor as long as the account is active
Delivery data (address, coordinates, proof photo)For as long as the account is active, or until the business requests deletion

Account deletion: on a written deletion request through support, your identity and access data and your customers’ data are deleted or anonymised within a maximum of 14 working days.

What remains after deletion: mandatory financial records — invoices, payments and the ambassador commission ledger — which we are legally and accountably required to keep; and aggregate anonymous data that cannot be attributed to any person or venue.

9. Your rights

9.1 If you are a business owner:

  • You can see and edit your account and business details in the panel at any time.
  • You can take an Excel export from the main areas of the panel — customers, invoices, expenses, inventory and reports — within your active plan and plugins. Export before your subscription period ends; after that, coordinate with support.
  • You can request full deletion of your account (section 8).

9.2 If you are a customer of a café:

  • Sign in at account.menuyou.app with a verification code to see and edit your details.
  • Withdraw marketing SMS consent from there, or from the unsubscribe link inside any message, at any moment.
  • To correct or delete your records held by a café, go to that business first — it is the controller of that data. If you get no answer, write to us; we follow up within 14 working days.

9.3 If you are staff, a courier or an ambassador — you can see your data in your own panel. For correcting or deleting operational data (attendance, payroll, assignments) go to the employing business; for ambassador data (national ID and bank details) write to us directly.

10. Minimum age

Creating a business account on MenuYou requires you to be 18 or older. Membership of a business’s loyalty club by customers under 18 requires the consent of a legal guardian, and responsibility for that rests with that business. If we find that data of a person under the legal age has been recorded without permission, we delete it.

11. Where data is stored

All MenuYou data is held on servers located inside Iran. The only cross-border transfer is the menu text sent to the AI translation service described in section 5.4, and that happens only if you activate it. If the storage location ever changes, it will be announced in this document before the transfer.

12. Security breach notification

If an incident or breach occurs that puts user information at risk, we commit to informing affected users within a maximum of 72 hours of detection, by SMS and panel notification — and by email where possible — together with an account of what happened and what they should do.

If a breach involves the data of a business’s customers, we notify that business as the data controller so that it can meet its own obligations.

13. Change of ownership

In the event of a merger, acquisition or sale of part or all of MenuYou’s assets, user information may transfer to the new owner as part of those assets. In that case we inform you before the transfer, and the new owner will be bound by this same policy.

14. Links and tools outside our servers

  • Third-party links: business menus, the blog and our site may link to other websites or social networks. Their privacy policies are their own and we bear no responsibility for them.
  • Thermal print bridge: if you use receipt printing, the receipt content goes from your browser to the print bridge application on your own computer and from there to the printer. That data does not leave your device and does not reach any third-party server; securing that computer is your responsibility.

15. Changes to this document

Any change is announced on this page and the version number and date at the top are updated; previous versions stay archived and available. For a material change — a new category of data, a new supplier, or a change of storage location — we give at least 30 days’ notice through panel notifications and SMS. Continuing to use the service after the announcement constitutes acceptance of the new text.

16. Language and contact

Where an English or any other translation of this document exists, the Persian text governs interpretation.

Provider: Noavar Farayand Zharf (PJSC) · Website: menuyou.app

For any privacy question, request or complaint: support@menuyou.app — or write to us through the contact form.

Related documents: terms of service · Brand Ambassador Agreement