Privacy

Privacy Policy

Last updated: 17 August 2026

Courtesy translation. Menustro is a French business and its contractual documents are written in French. This English version is provided for convenience only and has no contractual value. In the event of any discrepancy, only the French version is legally binding.

1. Data controller

Louis VICAT, sole trader operating Menustro, is the controller of the personal data collected through https://menustro.com and the Menustro dashboard.

Privacy contact: louis.vicat@menustro.com.

Definitions

Menustro means the data controller identified above.

Personal data means any information relating to an identified or identifiable natural person.

User means any person holding a Menustro business account to manage an establishment.

End customer means any person viewing a digital menu via a QR code, without necessarily holding an account.

Establishment means the restaurant or food service venue managed through a Menustro account.

Account means the business workspace giving access to the service’s features.

Processor means any provider processing personal data on Menustro’s behalf.

2. Data processed

Depending on your use, Menustro processes in particular: account identity (email, first name, last name, photo), establishment information (name, address, menu content), user preferences, business billing data, and technical session data.

Technical data may include the IP address, device, browser/user-agent and security logs.

At present, viewing a digital menu as an end customer requires no account and involves no collection of identifying personal data. Should an optional end-customer account be offered in future, this policy will be updated accordingly.

Authentication and user account management are operated by Clerk, our authentication provider, which handles in particular the email/password, Google and Apple sign-in methods described below.

3. Google data (Google Sign-In)

If you use Google sign-in, we request only the OAuth scopes openid, email and profile. We do not request access to Gmail, Drive, Calendar, Contacts or any other Google data not necessary for authentication.

The Google data received may include: email address, first/last name, profile picture and Google identifier (sub). This data is used solely to create/link your account, authenticate you and secure access to the service.

You may revoke Google access at any time from your Google account (myaccount.google.com/permissions) and request deletion of your data via louis.vicat@menustro.com.

Use of information received from Google complies with the Google API Services User Data Policy, including the Limited Use requirements where applicable.

4. Apple data (Sign in with Apple)

If you use Sign in with Apple, we receive your Apple identifier, your email address (possibly an anonymised relay address provided by Apple if you choose to hide your email) and, on first sign-in only, your name if you choose to share it.

This data is used solely to create/link your account and authenticate you. You may revoke access from your Apple ID settings (appleid.apple.com) and request deletion of your data via louis.vicat@menustro.com.

5. Purposes of processing

Menustro processes your data for: authentication, account management, management of establishments and their menus, business billing, session security, customer support, handling of GDPR requests, and service improvement.

Menustro currently uses no third-party analytics tool. Should such a tool be introduced, this policy will be updated to specify its purpose and provider.

Menustro may also produce and use aggregated and anonymised data (usage statistics, de-personalised menu content) in order to improve the service and to develop, train or improve features based on artificial intelligence. Once anonymised, such data can no longer identify you and no longer falls within the scope of this policy.

6. Legal bases

Processing is based, depending on the case, on: performance of the contract (provision of the service), compliance with legal obligations, legitimate interest (security and operation), and consent where required.

7. Recipients and processors

Data may be passed on, to the extent necessary, to technical providers involved in delivering the service, in particular:

  • Stripe: subscription payment and billing.
  • Clerk: authentication and account management (email/password, Google and Apple sign-in).
  • Google: identity provider for Google Sign-In (via Clerk).
  • Apple: identity provider for Sign in with Apple (via Clerk).
  • Vercel: hosting of the website and dashboard.
  • Google Cloud: server and API infrastructure.
  • Neon: database hosting.
  • Cloudflare: image storage (dish photos, establishment logos) via Cloudflare R2, as well as DNS and network infrastructure management.
  • Pusher: real-time synchronisation of the business dashboard (instant updates of orders and activity across the establishment’s devices).
  • Resend: delivery of messages sent through the contact form (name, email address and message content).
  • Mistral AI: machine translation of menus. Only dish names and descriptions are sent — text that is already public, since it is served to anyone scanning the QR code. No personal data is sent in the process, neither the restaurateur’s nor their guests’. Mistral AI is established in the European Union.

Menustro may also use other infrastructure and email-sending providers strictly necessary for the operation of the service.

8. Data transfers outside the European Union

Mistral AI is established in the European Union: no transfer outside the EU takes place on that basis. Stripe, Clerk, Google, Apple, Vercel, Google Cloud, Neon, Cloudflare, Pusher and Resend are established outside France (mainly in the United States; Pusher in the United Kingdom) and may process data outside the European Union, including where their servers are physically located in Europe. These transfers rely on the safeguards provided for by the GDPR, in particular the European Commission’s standard contractual clauses, the adequacy decision applicable to the United Kingdom, and/or those providers’ certification under the EU-U.S. Data Privacy Framework, where applicable.

9. Retention periods

Data is retained for as long as necessary to provide the service, and thereafter in accordance with the applicable legal obligations.

If deletion is requested, the account is deactivated immediately and then retained for 30 days, during which it can still be reactivated by signing in again. After that period, your personal data (account identity, establishment, menus, images, your employees’ accounts) is deleted or anonymised.

When a team member is removed, their contact details (first name, last name, email address) are retained for 30 days — so that you can reinstate them if this was a mistake — and are then anonymised automatically.

By way of exception, billing data (invoices) is retained for 10 years in accordance with our accounting and tax obligations. Accordingly, a billing customer identifier remains after your account is deleted: it contains neither your name nor your email address, but allows accounting reconciliation with our invoices. Your data is therefore pseudonymised, rather than fully anonymised, during that period. Truly anonymous data (usage statistics that cannot identify you) may be retained indefinitely.

10. Your rights

You have the rights of access, rectification, erasure, objection, restriction and portability, in accordance with the applicable regulations. Menustro undertakes to respond to any request within a maximum of one month from receipt, which may be extended by two months for complex requests, with prior notice to the requester.

To exercise your rights: louis.vicat@menustro.com. You may also lodge a complaint with the CNIL, the French data protection authority (www.cnil.fr).

For step-by-step account deletion instructions, see Delete your account.

11. Security

Menustro implements appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure.

12. Cookies and similar technologies

Menustro uses technical cookies strictly necessary for authentication (via Clerk) and for the security of business dashboard sessions. Cloudflare, our network provider, may also set technical cookies necessary for protection against attacks and for correct delivery of the site. No audience-measurement or advertising cookies are used at this time.

13. Changes

This policy may change. The reference version is the one published on this page as at its update date.

14. Related contractual documents

The general conditions for using the service are available in the Terms of Service.

For professionals operating an establishment, the applicable billing terms are set out in the Terms of Sale.

15. Language

This policy is written in French. Any translation into another language is provided for information only. In the event of any discrepancy, only the French version is legally binding.