Last updated: 27 October 2025

Menuflux — Privacy Policy

Menuflux (“Platform”, “Services”) is operated by Arsbias L.L.C-FZ (Meydan Free Zone, Dubai, U.A.E.). By using the Platform, you consent to the practices described here. This Policy covers both Users (restaurants and their representatives) and Visitors/Customers (guests viewing menus via QR).

Contents

  • 1) Data We Collect
  • 2) How We Use Data
  • 3) Sharing with Third Parties
  • 4) International Transfers
  • 5) Data Retention
  • 6) Security
  • 7) Your Rights
  • 8) Children’s Privacy
  • 9) Cookies & Similar Technologies
  • 10) Roles & Responsibilities
  • 11) Changes to this Policy
  • 12) Contact / Data Controller

1) Data We Collect

  • Account Data (Users): Name, surname, business name, email, phone, business address, billing/tax details.
  • Payments: Card data is collected/processed directly by Stripe; we do not store raw card numbers. We may receive payment status, tokens, and metadata.
  • Usage Data: Device/browser/OS, IP-derived region, timestamps, language, pages/menu items viewed, clicks, referring/exit pages, diagnostics.
  • Customer Inputs (End-users): We do not intend to collect personal data from restaurant guests beyond what is needed to display menus (e.g., language choice).
  • Support & Comms: Messages you send us (email, forms, in-app), attachments, and metadata.
  • Cookies & Similar Tech: Essential cookies for login/session and preferences; optional analytics/performance cookies where permitted.
  • AI Features (if enabled): Prompts and outputs you choose to send to AI providers (e.g., for translations/descriptions) and related telemetry (latency, errors).

2) How We Use Data (Purposes & Legal Bases)

  • Provide & operate Services (accounts, menus, subscriptions via Stripe, support). Basis: contract necessity; legitimate interests.
  • Service communications (renewals, payment issues, material changes, security alerts) which may be mandatory. Basis: contract/legal obligation.
  • Marketing & product updates (B2B only) with consent where required, or under legitimate interests. You can opt out anytime.
  • Analytics & improvement (aggregate/anonymous wherever possible) to monitor performance and develop features. Basis: legitimate interests/consent where required.
  • Security & abuse prevention (fraud detection, rate-limiting, logs). Basis: legitimate interests/legal obligation.
  • Legal & tax compliance (records, invoicing, responding to lawful requests). Basis: legal obligation.

3) Sharing with Third Parties

We share personal data only as reasonably necessary:

  • Service providers / sub-processors under purpose-limited contracts:

    Hosting & DB: Vercel (cloud hosting), Supabase (database).

    Payments: Stripe (collects/processes card data).

    Analytics/Monitoring: If used, privacy-respecting analytics and error monitoring tools may collect de-identified/aggregate data.

    AI vendors (if enabled): Trusted LLM providers process the text you submit to generate outputs.

  • Corporate transactions: In a merger, acquisition, or insolvency, data may transfer subject to continuity of protection and notice where feasible.
  • Legal requests & safety: Disclosures required by applicable law, court orders, or competent authorities; or to protect rights, safety, or investigate fraud.
  • With consent: Any sharing beyond the above requires your consent.

We do not sell or rent personal data.

4) International Transfers

We are UAE-based, but data may be processed/stored in other countries (where Vercel, Supabase, Stripe, analytics and AI providers operate). Where local laws offer lower protection, we apply safeguards (contractual clauses, access controls, minimization, anonymization) consistent with UAE PDPL and, where applicable, GDPR-style standards. By using the Platform, you acknowledge such transfers.

5) Data Retention

  • Account & profile: While your Account is active; deleted or anonymized within a reasonable period after closure (typically within 30 days), subject to legal holds.
  • Billing & financial records: At least 5 years (or longer if required by law).
  • Technical/security logs: Typically 6–12 months absent incidents.
  • Support tickets: Up to 2 years.
  • Anonymous analytics: May be retained indefinitely.

6) Security

We implement technical and organizational measures, including encryption in transit/at rest where appropriate, credential hashing, least-privilege access controls, firewalls, periodic testing, and backups. Payment flows use TLS; AI calls use encrypted channels. No method is 100% secure; if a personal-data breach occurs, we will notify affected parties and authorities as required by law.

7) Your Rights

Depending on your jurisdiction (e.g., UAE PDPL, Türkiye KVKK, EU/UK GDPR), you may have rights to access, rectify, erase, restrict, object (including to direct marketing), data portability, and to lodge a complaint with a supervisory authority. Submit requests via the contact details below; we will verify identity and respond within statutory timelines (generally 30 days). Repetitive or manifestly unfounded/excessive requests may be refused or charged as permitted by law.

End-customer data controlled by Users. Where you (the restaurant) input or cause processing of your customers’ data, you are the controller; we act as your processor. Obtain necessary notices/consents and comply with your legal obligations. A Data Processing Addendum (DPA) is available on request.

8) Children’s Privacy

The Platform targets businesses, not children. We do not knowingly collect personal data from individuals under 18. If you believe a child’s data was provided to us, contact us to request deletion.

9) Cookies & Similar Technologies (Summary)

  • Essential cookies: Authentication/session management, security, preference storage. (Always on; strictly necessary.)
  • Analytics/performance (optional): Helps us understand usage and improve the Service.

Controls: Manage consent via our cookie banner (where applicable) and your browser settings.

10) Roles & Responsibilities (Controller vs Processor)

  • Controller (we): Account, billing, platform telemetry, service communications, B2B marketing.
  • Processor (we, on your instructions): Any personal data you choose to upload/store about your customers within the Services. Processing is governed by the DPA (on request). You must configure your notices/consents accordingly.

11) Changes to this Policy

We may update this Policy periodically. Material changes will be announced on the Platform and/or via email. The “Last updated” date reflects the latest revision. Continued use after updates constitutes acceptance; where required, we will seek renewed consent.

12) Contact / Data Controller

Data Controller: Arsbias L.L.C-FZ (Menuflux)

Address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.

Privacy email: legal@arsbias.com

Support: support@arsbias.com

DPA & Sub-processors list: Available on request at the privacy email.

See also:
Menuflux logoMenuflux
Privacy PolicyTerms of Service

We don’t sell personal data. Read our Privacy Policy

© 2026 Menuflux. All rights reserved.

Built & maintained by MediaPanda