Privacy Policy
Last updated
This policy explains what personal data HeyMenus collects, why we collect it, who we share it with, and what you can ask us to do about it. It covers heymenus.com, the HeyMenus dashboard, and the menu pages we publish on behalf of restaurants.
1. Who we are
[LEGAL ENTITY NAME] (“HeyMenus”, “we”, “us”), registered at [REGISTERED ADDRESS], operates HeyMenus and is the controller of the personal data described below. For anything in this policy, including a request to exercise your rights, write to contact@heymenus.com.
2. Who this policy is about
Three different groups of people interact with HeyMenus, and we treat them differently:
- Customers — people who create an account and build menus.
- Visitors — people who browse heymenus.com.
- Diners — people who open a published menu page. They have no account with us, and we collect the least from them. See section 6.
3. What we collect, and why
Account data
When you sign up we store your email address and the display name you choose. Your password is stored only as a salted hash by our authentication provider — we never see or hold the password itself. If you sign in with Google we receive your email address, name and profile picture from Google instead of a password. We use this to create your account, sign you in, and contact you about the service. Lawful basis: performance of our contract with you.
The menus you build
Restaurant names, sections, dish names and descriptions, prices, dietary and allergen labels, and any photos you upload. This is mostly business information rather than personal data — but it becomes personal data when you put a person into it, such as a chef’s name or a photograph with a recognisable face. We store it to publish the menu you have asked us to publish. Lawful basis: performance of our contract with you.
Messages you send us
The contact form stores the name, email address and message you type, so that we can reply. Lawful basis: your consent when you submit the form, and our legitimate interest in answering people who write to us.
Technical data
Our hosting providers record ordinary server-log information for every request: IP address, timestamp, the URL requested, the browser user agent and the referring page. We use it to keep the service available, diagnose faults and investigate abuse. It is not used to build a profile of you. Lawful basis: our legitimate interest in running a secure, working service.
4. What we do not do
- We do not sell or rent personal data, and we do not share it for cross-context behavioural advertising.
- We do not run advertising, ad networks or third-party advertising trackers anywhere on HeyMenus.
- We do not profile you or make automated decisions that produce legal effects for you.
- We do not use analytics to build advertising profiles. We run PostHog on heymenus.com and on the dashboard, and only after you say yes — see section 5.
5. Cookies and browser storage
We use three things. The first two are strictly functional; the third is analytics, and it only runs if you agree to it:
- hm_lang — a cookie set only when you actively pick a language from the switcher, so the site remembers your choice. It expires after a year and holds nothing but a two-letter language code.
- Your login session — the dashboard keeps your session token in your browser’s local storage so you are not signed out on every page load. It is sent to us and to nobody else.
- PostHog analytics — how heymenus.com and the dashboard are used: pages visited, buttons clicked, and a replay of the screen while you are signing up or building a menu, so we can see where the product gets in your way. It is off until you accept, and it stores its cookies on heymenus.com so accepting once covers the dashboard too. Text you type — passwords, contact-form fields, everything else — is masked out of replays before they leave your browser.
If your browser tells us you are in the EU, the UK, Switzerland, Norway or Iceland, we ask before turning analytics on and set nothing until you answer. Everywhere else we enable it by default. Either way the decision is remembered in the hm_analytics cookie for a year, and the button below turns analytics off from any country at any time. Clearing your browser storage signs you out, forgets your language choice and brings the question back, and nothing else breaks.
Done — analytics is off in this browser.
6. Published menu pages
A published menu is a public web page. Anyone with the link can open it, and search engines may index it. There is no account, no login and no tracking script on it. Two things are worth stating plainly:
- The page loads its fonts from Google Fonts, which means your IP address and browser details reach Google’s servers as the page renders. We intend to self-host those fonts; until we do, this is the honest description.
- Everything the restaurant chose to publish is public, including the photos they uploaded and any names in the text.
7. Who else processes data for us
We keep the list of processors short on purpose. Each is bound by a data processing agreement, and we will update this list before adding another one that touches personal data.
- Supabase — database, authentication and file storage.
- Cloudflare — hosting and content delivery for heymenus.com and for published menu pages.
- Google — Google Fonts on published menu pages, and Google Sign-In if you choose to use it.
- PostHog — product analytics for heymenus.com and the dashboard, on their EU infrastructure, and only for visitors who accept.
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever part of a merger or acquisition, personal data may transfer with the business, and this page will say so before it does.
8. Where data is processed
Our providers operate globally, so your data may be processed outside the country you live in, including in the United States. Where data leaves the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where it applies. Our primary hosting region is [HOSTING REGION].
9. How long we keep it
- Account and menu data — for as long as your account exists. After you delete your account we remove it from live systems within 30 days; encrypted backups age out on their own rolling schedule.
- Contact messages — up to 24 months.
- Server logs — the short retention window set by our hosting providers, typically days rather than months.
10. Your rights
Depending on where you live you have some or all of the following rights over your personal data: to access a copy of it, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time without affecting what we did before you withdrew it.
To exercise any of them, email contact@heymenus.com. We will respond within 30 days, and we will not charge you or treat you differently for asking. If you are unhappy with our answer you can complain to your local data protection authority — ours is [SUPERVISORY AUTHORITY].
California residents additionally have the right to know what we collect, to delete it, to correct it, to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined under the CCPA, so there is nothing to opt out of.
11. How we protect it
Everything travels over HTTPS. Passwords are hashed by our authentication provider, never stored in readable form. Access to your data is enforced in the database itself with row-level security, so one account cannot read another account’s rows even if the application has a bug. Access to production systems is limited to the people who need it. No system is perfectly secure, and we will tell you and the relevant authority without undue delay if a breach puts your data at risk.
12. Children
HeyMenus is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16 (under 13 in the United States). If you believe a child has given us data, write to us and we will delete it.
13. Changes to this policy
When this policy changes we update the date at the top. If a change materially affects how we handle your personal data we will email account holders before it takes effect.
14. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Email contact@heymenus.com.
See also our Terms of Service.