Privacy Policy
This document is published in English. The English text is the binding version; any translation is provided for convenience. If you would prefer to review it in Arabic with your own counsel, write to support@menew.io and we will provide it.
In short
- If you are a diner: we hold your name and phone only when you order for delivery or pickup, because the restaurant needs them to reach you. Dine-in ordering needs neither.
- Your dietary and allergy filters never leave your phone. They are stored in your own browser and are never sent to us or to the restaurant.
- We do not sell personal data. To anyone. Ever.
- There is no advertising, no tracking pixel, no analytics cookie and no third-party ad network anywhere in Menew.
- Data is stored in the European Union (Frankfurt).
- We never see or store a payment card. Restaurant billing is by invoice.
This box is a summary. The sections below are the policy.
Contents
1. Who is responsible for your data
This matters, because it determines who you should talk to.
- The restaurant is responsible for the personal data of its diners — the orders placed, the reservations booked, the names and phone numbers given at checkout. In data-protection language, the restaurant is the controller and Menew is its processor. We handle that data only on the restaurant's instructions, under the Data Processing Terms. If you are a diner and want your data corrected or deleted, the restaurant is the right place to start — though you can write to us and we will help.
- Menew is responsible for the personal data of its own customers: the restaurant owners and staff who hold accounts with us, the people who fill in our contact form, and visitors to this website. For that data we are the controller, and this policy is our own.
2. If you are a diner
Menew is the menu you open by scanning a QR code at your table. Here is everything it handles about you.
Ordering at a table (dine-in)
We do not ask for your name, your phone number or your email. A dine-in order carries the table number, the items ordered, the time, and a display name you may optionally type so that people sharing a table can tell whose items are whose. That display name can be anything; it is shown to the others at your table and to restaurant staff.
Ordering for delivery or pickup
Here the restaurant needs to reach you, so we collect:
| What | Why |
|---|---|
| Your name | So staff know whose order it is |
| Your phone number | So the restaurant can call you about the order |
| Your delivery address | Delivery orders only. Not collected for pickup. |
These are given to the restaurant. They are not used for marketing by us, and the Terms of Service forbid the restaurant from using them for marketing through Menew.
Your device
When you first open a Menew menu, your browser generates a random device identifier and stores it locally. It is a random string. It is not your phone number, not your advertising ID, and it is not linked to any identity we hold. It exists so that your basket survives a page refresh, so a shared table can tell two devices apart, and so an order can be traced back to the device that placed it if there is a dispute about the bill.
Your allergy and dietary filters
This is the part we want to be unambiguous about, because it is the most sensitive thing Menew touches.
Your dietary filters — gluten-free, dairy-free, sesame-free, nut-free, no fish, egg-free, soy-free, no shellfish, halal, spicy — are stored only in your own browser. They are never transmitted to Menew's servers and never shown to the restaurant. Filtering happens on your phone, against the allergen tags the restaurant has published. We do not know, and cannot know, what you have filtered.
If you clear your browser data, they are gone. If you switch phones, they do not follow you. That is the trade-off of keeping them local, and we have taken it deliberately.
A safety note, not a legal one. The filter can only act on the allergen tags the restaurant has entered. A dish nobody tagged is not filtered out. If an allergy is serious, tell the restaurant directly — do not rely on a menu filter alone.
Reservations
If you book a table, the restaurant holds your name, phone number, party size, date and time, and any note you leave. This is entered either by you or by the restaurant's reception staff.
Ratings and order tracking
If you rate a completed order, we store the rating and any comment against that order. If you follow an order-status link, the page shows the order's progress and total — it deliberately carries no customer contact details, so the link is safe to forward.
3. If you are a restaurant or its staff
| What | Why |
|---|---|
| Owner name, email address, phone number | To create and administer the account, to invoice, and to reach you |
| Restaurant name, address, opening hours, branding | To run your menu and your console |
| Staff names and station PINs | To let waiters and reception staff sign in, and to attribute actions. PINs are stored as bcrypt hashes — we cannot read them, and a PIN reset issues a new one rather than revealing the old. |
| Device records for each login | A browser and operating-system hint plus a stable per-device identifier, so you can see which devices are signed in to your restaurant and remove one you do not recognise |
| Audit log | Who did what and when — menu edits, refunds, voids, discounts, permission changes. This is a security record and cannot be edited or deleted from the console. |
| Billing records | Plan, cycle, invoice history and payments received. No card details: Menew does not process card payments. |
4. If you are just visiting this website
The Menew marketing site sets no analytics cookies, no advertising cookies and no tracking pixels. There is no Google Analytics, no Meta Pixel and no third-party ad network on any page.
Your browser stores your language choice so the site opens in the language you picked. That is all, and it never leaves your device. See the Cookie Notice.
If you fill in the contact form, it opens WhatsApp with a message you can read before sending. The form itself does not transmit anything to us until you press send in WhatsApp, at which point WhatsApp's own privacy policy applies to the message.
Our hosting provider keeps standard server logs, including IP addresses, for security and abuse prevention. We do not use them to build a profile of you.
5. Why we are allowed to hold it
Under Lebanese Law No. 81/2018 on Electronic Transactions and Personal Data, and under the GDPR where it applies to a visitor in the European Union, our legal bases are:
- Performance of a contract — running your restaurant account, or fulfilling an order you placed.
- Legitimate interests — keeping the platform secure, preventing fraud and abuse, maintaining the audit log, and computing anonymous aggregate statistics. We have weighed these against your interests and consider them proportionate.
- Legal obligation — keeping billing records for the period tax law requires.
- Consent — where you have given it, for example by enabling browser notifications on a station. You can withdraw it at any time.
6. Where it is stored
Menew's database and file storage are hosted by Supabase in the European Union (Frankfurt, Germany). The website and application are served from Vercel's global edge network, which caches public pages close to visitors.
If you are in Lebanon, this means your data is stored outside Lebanon, in a jurisdiction with strong data-protection law. If you are in the EU, it means your data does not leave it for storage. Some of the service providers in the next section process data elsewhere; where they do, they are bound by standard contractual clauses or an equivalent safeguard.
7. Who else touches it
These are our sub-processors. We keep this list current, and the Data Processing Terms commit us to giving notice before adding one.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase (EU — Frankfurt) | Database, authentication, file storage | All platform data |
| Vercel (global edge) | Website and application hosting | Requests and server logs, including IP addresses |
| Resend | Transactional email — daily reports, backup alerts | The recipient's email address and the message |
| Anthropic | Optional AI features in the restaurant console: translating ingredients, estimating nutrition, suggesting a dish photo | Only the menu text sent for that task. No diner data is ever sent to an AI service. |
| Unsplash | Stock photography search for menu items | The search term only |
| api.qrserver.com | Renders QR code images for printable table codes | The URL being encoded. No personal data. |
| Have I Been Pwned | Warns if a chosen password appears in a known breach | Nothing. Only the first five characters of a hash are sent, and the check happens locally. Your password never leaves your device. |
| Google Apps Script | Optional. Only if a restaurant configures a Google Sheets webhook for its own billing records | The billing rows that restaurant chooses to sync |
There is no advertising network, no data broker and no analytics provider on this list, and we will not add one.
8. How long we keep it
| Data | Kept for |
|---|---|
| Orders and their contents | The life of the restaurant's account, so the restaurant can report on its own trading history. Deleted with the account. |
| Diner name, phone and address on an order | As above. A restaurant can ask us to purge contact details from orders older than a period it chooses. |
| Reservations | The life of the account |
| Table sittings and shared baskets | Cleared shortly after the table closes |
| Audit log | The life of the account. Deliberately not deletable from the console — an audit trail that can be erased is not an audit trail. |
| Device records | Until the restaurant removes the device, or the account closes |
| Backups | They age out on a rolling cycle. A deletion request is applied to live data immediately; backups containing the data expire on their own schedule and are not individually edited. |
| Billing records | As long as tax and accounting law requires, after the account closes |
| Account data after termination | Exportable for 30 days, then deleted — see Terms, section 14 |
9. How it is protected
- Every connection is encrypted in transit (TLS). Data is encrypted at rest by our hosting provider.
- Each restaurant's data is isolated at the database level by row-level security, not merely hidden in the interface. One restaurant's credentials cannot read another's data, and this is tested against the live system every night.
- Staff PINs and printer secrets are stored as bcrypt hashes. Nobody at Menew can read them.
- Station links and tokens are generated with a cryptographic random source, and can be rotated instantly from the console.
- Sensitive operations are rate-limited and throttled against brute force.
- New passwords are checked against known breach corpora without the password leaving the device.
- An automated end-to-end suite runs nightly against the live platform, including an adversarial pass that attempts tenant isolation breaches, privilege escalation and injection.
No system is perfectly secure. If we discover a breach affecting personal data, we will notify the affected restaurants without undue delay and in any case within 72 hours of becoming aware of it, with what we know and what we are doing about it.
If you believe you have found a vulnerability, please write to support@menew.io before disclosing it publicly. We will not pursue anyone who reports in good faith and does not access or alter other people's data.
10. Your rights
You can ask to access the personal data we hold about you, to have it corrected, to have it deleted, to object to how we use it, to restrict that use, and to receive it in a portable format.
If you are a diner, the restaurant holds your data and is the right first contact. Write to them, or write to us and we will pass it on and help them answer.
If you are a restaurant, write to support@menew.io. We will respond within 30 days. We may need to confirm who you are first — we are not going to hand someone else's data to whoever asks.
If you are in the EU or the UK, you also have the right to complain to your national data-protection authority.
11. Children
Menew is not directed at children and we do not knowingly collect personal data from anyone under 16. A child can of course look at a restaurant's menu — that requires no personal data at all. If you believe a child has given us personal data, tell us and we will delete it.
12. Changes to this policy
We will update this page when what we do changes. Every version carries a version number and an effective date at the top. For a change that materially affects how we handle your data, we will give restaurant customers at least 30 days' notice by email before it takes effect.
13. Contact
Privacy questions, requests and complaints: support@menew.io.
Please put "Privacy" in the subject line so it reaches the right place quickly.