Last updated: 13 August 2026
This policy explains what we collect when you use MenuFly as a restaurant customer, and what is collected when a guest scans one of your QR menus.
We do not ask guests for their name, phone number or email to view a menu.
We do not sell personal information. We share data only with processors that run the service — hosting, email delivery and payments — each bound by contract to use it solely on our instructions.
Account and menu data is kept while your account is active. Analytics events are retained in aggregate for 24 months. Delete your account and we remove personal data within 30 days, except where law requires us to keep billing records.
You may request access, correction, export or deletion of your data at any time by writing to privacy@menufly.app. We respond within 30 days.
We use a session cookie to keep you signed in and a first-party analytics cookie on guest menus. We do not run third-party advertising trackers.
Data is encrypted in transit with TLS and at rest. Access to production systems is limited to staff who need it and is logged.
If we make a material change we will email account holders at least 14 days before it takes effect.
Questions? Write to privacy@menufly.app or use our contact form.