Menuflux — Privacy Policy
Menuflux (“Platform”, “Services”) is operated by Arsbias L.L.C-FZ (Meydan Free Zone, Dubai, U.A.E.). By using the Platform, you consent to the practices described here. This Policy covers both Users (restaurants and their representatives) and Visitors/Customers (guests viewing menus via QR).
1) Data We Collect
- Account Data (Users): Name, surname, business name, email, phone, business address, billing/tax details.
- Payments: Card data is collected/processed directly by Stripe; we do not store raw card numbers. We may receive payment status, tokens, and metadata.
- Usage Data: Device/browser/OS, IP-derived region, timestamps, language, pages/menu items viewed, clicks, referring/exit pages, diagnostics.
- Customer Inputs (End-users): We do not intend to collect personal data from restaurant guests beyond what is needed to display menus (e.g., language choice).
- Support & Comms: Messages you send us (email, forms, in-app), attachments, and metadata.
- Cookies & Similar Tech: Essential cookies for login/session and preferences; optional analytics/performance cookies where permitted.
- AI Features (if enabled): Prompts and outputs you choose to send to AI providers (e.g., for translations/descriptions) and related telemetry (latency, errors).
2) How We Use Data (Purposes & Legal Bases)
- Provide & operate Services (accounts, menus, subscriptions via Stripe, support). Basis: contract necessity; legitimate interests.
- Service communications (renewals, payment issues, material changes, security alerts) which may be mandatory. Basis: contract/legal obligation.
- Marketing & product updates (B2B only) with consent where required, or under legitimate interests. You can opt out anytime.
- Analytics & improvement (aggregate/anonymous wherever possible) to monitor performance and develop features. Basis: legitimate interests/consent where required.
- Security & abuse prevention (fraud detection, rate-limiting, logs). Basis: legitimate interests/legal obligation.
- Legal & tax compliance (records, invoicing, responding to lawful requests). Basis: legal obligation.
4) International Transfers
We are UAE-based, but data may be processed/stored in other countries (where Vercel, Supabase, Stripe, analytics and AI providers operate). Where local laws offer lower protection, we apply safeguards (contractual clauses, access controls, minimization, anonymization) consistent with UAE PDPL and, where applicable, GDPR-style standards. By using the Platform, you acknowledge such transfers.
5) Data Retention
- Account & profile: While your Account is active; deleted or anonymized within a reasonable period after closure (typically within 30 days), subject to legal holds.
- Billing & financial records: At least 5 years (or longer if required by law).
- Technical/security logs: Typically 6–12 months absent incidents.
- Support tickets: Up to 2 years.
- Anonymous analytics: May be retained indefinitely.
6) Security
We implement technical and organizational measures, including encryption in transit/at rest where appropriate, credential hashing, least-privilege access controls, firewalls, periodic testing, and backups. Payment flows use TLS; AI calls use encrypted channels. No method is 100% secure; if a personal-data breach occurs, we will notify affected parties and authorities as required by law.
7) Your Rights
Depending on your jurisdiction (e.g., UAE PDPL, Türkiye KVKK, EU/UK GDPR), you may have rights to access, rectify, erase, restrict, object (including to direct marketing), data portability, and to lodge a complaint with a supervisory authority. Submit requests via the contact details below; we will verify identity and respond within statutory timelines (generally 30 days). Repetitive or manifestly unfounded/excessive requests may be refused or charged as permitted by law.
End-customer data controlled by Users. Where you (the restaurant) input or cause processing of your customers’ data, you are the controller; we act as your processor. Obtain necessary notices/consents and comply with your legal obligations. A Data Processing Addendum (DPA) is available on request.
8) Children’s Privacy
The Platform targets businesses, not children. We do not knowingly collect personal data from individuals under 18. If you believe a child’s data was provided to us, contact us to request deletion.
10) Roles & Responsibilities (Controller vs Processor)
- Controller (we): Account, billing, platform telemetry, service communications, B2B marketing.
- Processor (we, on your instructions): Any personal data you choose to upload/store about your customers within the Services. Processing is governed by the DPA (on request). You must configure your notices/consents accordingly.
11) Changes to this Policy
We may update this Policy periodically. Material changes will be announced on the Platform and/or via email. The “Last updated” date reflects the latest revision. Continued use after updates constitutes acceptance; where required, we will seek renewed consent.
12) Contact / Data Controller
Data Controller: Arsbias L.L.C-FZ (Menuflux)
Address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.
Privacy email: legal@arsbias.com
Support: support@arsbias.com
DPA & Sub-processors list: Available on request at the privacy email.