Menuklaar

Privacy policy

Short and plain. Menuklaar collects only what it needs to run your menu, tracks no one and sells nothing.

Last updated: 2 October 2026

Draft: a lawyer checks this policy before Menuklaar launches. Details in square brackets are filled in then.

Who we are

Menuklaar is a service of:

  • [Company name B.V.]
  • [address]
  • KvK [number]
  • VAT [number]

We are the controller of the personal data in this policy. Questions about your privacy? Email [email protected].

What we process and why

What we process depends on what you do in Menuklaar:

  • Your account: your email address, your password (we only store a scrambled hash of it) and the language you use the app in, so you can log in.
  • Your venue and menu: venue name, address, opening hours, logo, brand colour and time zone, and your categories, dishes, prices, allergens and translations, so we can show your menu.
  • Photos: the dish photos you add, stored as smaller copies. Menu photos and PDFs you use to import a menu are only read, not stored by us.
  • Your team: the email address and role of the extra login you invite.
  • Billing: your plan, your subscription status and your customer number at Stripe. Stripe handles your payment details, billing address and VAT number; we never see your full card or bank details.
  • Emails: only the emails you need, such as confirming your address, resetting your password, team invites and trial reminders. No newsletters or marketing emails.
  • Technical data: like every website, our hosting and database providers process your IP address and browser details to deliver pages, keep logins secure and stop abuse, and may keep them in security logs for a limited time.

Cookies

We only use strictly necessary login cookies. They are set when you sign up, log in or reset your password, and they keep you logged in to the Menuklaar app. Because they are strictly necessary, they need no consent.

No analytics cookies, no advertising cookies, no tracking pixels and no third-party analytics. That's why you won't see a cookie banner anywhere on Menuklaar.

The public menu your guests see sets no cookies at all. When a guest picks a language, their browser remembers it in local storage, on their own device.

Anonymous menu insights

We show you how often your menu is opened, without tracking your guests:

  • When someone opens your public menu, our server adds one to a counter for that day and hour: a QR scan, a link visit or a view on your website.
  • Taps on dishes, language choices and the language a guest's phone is set to (when your menu doesn't offer it) are counted the same way, without any identifier.
  • We don't store IP addresses, don't use cookies or fingerprinting, and ignore requests from known bots.
  • Only totals are kept: daily and hourly totals for 13 months, and monthly totals for 5 years. After that they are deleted automatically.
  • If you turn on the weekly summary on the Insights page, we email you these totals once a week. You can turn it off there at any time.

Because nothing in these counts points to a person, they tell us nothing about who your guests are.

WhatsApp updates

On Pro you can change your menu by sending Menuklaar a WhatsApp message. It's off until you link your own phone number in Settings, by sending a code from that phone.

  • What we store: your linked phone number with your login; your messages and our replies (text only) for 30 days; and the changes you confirm, with who made them and when, for 13 months, as your team's change log.
  • Photos you send, such as a picture of your chalkboard, are read once to find the changes and never stored by us.
  • Meta Platforms Ireland delivers the messages through the WhatsApp Business Platform, as our processor under its WhatsApp Business data processing terms. It processes your phone number and the content of the messages.
  • DeepSeek reads the text or photo of a message to work out what you want to change, as with a menu import.

To stop, send stop in WhatsApp or tap Unlink in Settings. A link also ends after 90 days without messages, when you leave the team and when the account is deleted. The legal basis is our contract with your venue (article 6(1)(b)).

Who helps us

A few providers (subprocessors) help us run Menuklaar. They process data only on our instructions, under a data processing agreement. We are confirming the processing location with each of them before launch.

  • Supabase

    What for
    Database, logins and file storage
    Where
    EU (Frankfurt, Germany)to confirm
  • Vercel

    What for
    Hosting the website and the app
    Where
    EU (Frankfurt, Germany), pages served worldwide from its edge networkto confirm
  • Stripe

    What for
    Payments, invoices and VAT
    Where
    EU (Ireland), transfers to the US possibleto confirm
  • Resend

    What for
    Sending email
    Where
    EU regionto confirm
  • DeepSeek

    What for
    Translating menu text and reading menu photos for the import
    Where
    China, outside the EUto confirm
  • Meta Platforms Ireland

    What for
    WhatsApp Business Platform: the messages for WhatsApp updates
    Where
    EU or USto confirm

Data outside the EU

Most data stays in the EU. The exceptions:

  • DeepSeek, in China, translates your menu text and reads the menu photos and PDF pages you import. It receives only menu content, never your account details, and we don't store the import photos. Menu text rarely contains personal data, but please don't import photos that show people. The safeguard for this transfer, such as the EU standard contractual clauses, is still to be confirmed.
  • Stripe may transfer payment data to the United States, under the EU standard contractual clauses or the EU-US Data Privacy Framework (to be confirmed).
  • Meta may process WhatsApp messages outside the EU, such as in the United States. We use WhatsApp's EU storage option where Meta offers it; the safeguard for this transfer is still to be confirmed.

Signing in with Google

“Continue with Google” is optional; an email address and password work just as well. If you use it, Google confirms your email address and shares your basic profile: your name and profile picture. We use your email address to log you in. Your name and profile picture are stored with your login details, and we don't use them for anything else. Google acts under its own privacy policy and is not one of our subprocessors.

How long we keep data

  • Your account, venues, menus, photos and team: as long as your account exists.
  • Anonymous menu insights: daily and hourly totals for 13 months, monthly totals for 5 years.
  • Invoices and payment records: 7 years at Stripe, as Dutch tax law requires.
  • Security logs at our providers: for a limited time, set by each provider.
  • Backups: deleted data disappears from backups when they expire, within 30 days (to be confirmed).

Download or delete your data

In Settings, under Your data, you can download everything your account holds as one JSON file, whenever you like.

The account owner can delete the account there too. This stops your subscription right away, without a refund for the rest of the period, and immediately deletes your venues, menus, photos, translations, insights, QR links and team logins. Stripe keeps your invoices, because the law requires it.

Your rights

Under the GDPR you can ask us to:

  • show you the personal data we hold about you
  • correct it
  • delete it
  • limit or stop how we use it
  • give it to you in a format you can take elsewhere (the JSON download does this)

You can do most of this yourself in Settings. For anything else, email [email protected] and we'll answer within one month.

You can also complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens: autoriteitpersoonsgegevens.nl.

Changes to this policy

When we change this policy, we update the date at the top. If a change matters to you, we email you before it takes effect.