Menurium Privacy Policy

Effective date: 12 March 2026. This Policy explains how Menurium handles personal data across its public website, administration portal, mobile applications, QR menus, restaurant pages and related services.


1. Who we are and scope

1.1
The controller for the processing described as Menurium's own processing is LOW TAB STUDIO SRL, registered at Republic of Moldova (Menurium, we, us or our).
1.2
This Policy applies to the Menurium website and landing pages, administration portal, iOS and Android apps, restaurant websites and QR menus powered by Menurium, ordering, reservations, delivery, analytics, support and related services (the Services).
1.3
A Restaurant using Menurium may independently determine how it handles customer, reservation, order and employee data. For that processing, the Restaurant is normally the controller and Menurium may act as its processor. The Restaurant must provide any additional privacy notice required for its own processing.

2. Personal data we process

2.1
Account and identity data: name, email address, telephone number, authentication identifiers, language, account status, Restaurant or tenant membership, location assignments and role such as owner, administrator, manager, waiter, delivery or kitchen worker.
2.2
Restaurant and content data: legal and business contact details, locations, addresses, opening hours, menus, prices, product descriptions, allergens, photographs, branding, tables, delivery zones and other information uploaded or configured through the Services.
2.3
Order and reservation data: customer contact details, selected Restaurant Products, quantities, comments, table or fulfilment details, delivery or pickup address, scheduled time, order status, reservation details and payment status. Menurium does not need to store full payment-card numbers processed by a payment provider.
2.4
Subscription and transaction data: selected plan, billing interval, currency, transaction and subscription identifiers, status, invoices, tax information and limited payment-method details returned by the payment provider.
2.5
Technical and usage data: IP address, browser and device type, operating system, app version, language, session and security events, pages or features used, timestamps, referral information and diagnostic or error information.
2.6
Communications: support requests, complaints, feedback and related correspondence. We also process information you voluntarily provide in forms, uploads or communications.

3. Mobile application permissions

3.1
The mobile app may request access to the device camera when an authorised user chooses to take a profile photo. Camera access occurs only after the user initiates the feature and grants the operating-system permission. The permission can be withdrawn in device settings.
3.2
The mobile app uses local device storage for necessary settings, language, tenant context and authentication or session information. It also uses network-status information to provide and troubleshoot online functionality.
3.3
We do not use the mobile camera for advertising or unrelated tracking. If a future version introduces a new permission or materially different collection, this Policy and the relevant app-store disclosure will be updated before or when that feature is released.

4. How we use personal data

4.1
We process data to create and secure accounts; authenticate users; maintain roles and permissions; provide menus, orders, reservations, delivery, analytics and other requested functions; synchronise data across authorised devices; provide support; and communicate service or security information.
4.2
We process subscription and transaction data to provide plans, administer trials and renewals, reconcile payments, issue or support invoices, prevent fraud and maintain required financial records.
4.3
We use technical, security and diagnostic information to operate, protect, debug and improve the Services, prevent misuse, investigate incidents and comply with legal obligations.
4.4
We use optional analytics on the website or Admin only when required consent has been given. Consent may be withdrawn using the cookie settings. We do not sell personal data.

5. Legal bases

5.1
Depending on the context and applicable law, we rely on performance of a contract or steps requested before a contract, compliance with legal obligations, our legitimate interests, consent, or another basis recognised by law. Legitimate interests include securing and operating the Services, preventing fraud, providing support and improving reliable functionality, balanced against individual rights.
5.2
Consent is used where legally required, including for optional website or Admin analytics. Withdrawing consent does not affect processing already lawfully carried out and does not prevent processing based on another valid legal basis.

6. Sources and sharing

6.1
We receive data directly from users, from the Business Customer or Restaurant that creates or manages an account, from End Users interacting with a Restaurant, automatically from devices and browsers, and from service providers involved in authentication, billing or operation of the Services.
6.2
We share data only as necessary with the relevant Restaurant and its authorised personnel; hosting and database providers; authentication providers such as SuperTokens; billing providers such as Paddle; map providers used for addresses and delivery configuration; PostHog for consent-based product analytics; Sentry for Admin error and diagnostic reporting; professional advisers; and authorities where legally required.
6.3
Providers may process data only for contracted purposes and under appropriate confidentiality, security and data protection obligations. Paddle independently processes checkout and payment information under its own privacy notice. Apple, Google or an identity provider may also independently process data when their services are used.

7. International transfers

7.1
Some providers or support operations may process data outside Moldova or the European Economic Area. Where required, we use an adequacy decision, approved contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism, together with supplementary safeguards where appropriate.

8. Retention

8.1
We retain account and service data while the account or Business Customer relationship remains active and for a reasonable period afterwards to permit account closure, data export, dispute resolution and security review.
8.2
Transaction, invoice and legal records are retained for periods required by applicable accounting, tax and other laws. Security logs, support records, analytics and backups are retained only for periods reasonably necessary for their stated purposes, then deleted or anonymised where feasible.
8.3
Data processed for a Restaurant may be retained or deleted according to that Restaurant's instructions, our agreement with it, backup cycles and applicable legal obligations.

9. Security

9.1
We use reasonable technical and organisational safeguards appropriate to the risk, including access controls, role restrictions, secure communications, monitoring and backup practices. No internet or storage system is completely secure, so absolute security cannot be guaranteed.
9.2
Users must protect credentials, use appropriate account roles, keep devices secure and notify us promptly of suspected unauthorised access. Business Customers are responsible for promptly removing access no longer required.

10. Your rights and choices

10.1
Subject to applicable law, you may request access to personal data, correction, deletion, restriction, objection, portability, information about processing, or withdrawal of consent. You may also complain to a competent data protection authority.
10.2
Requests concerning data controlled by a Restaurant should normally be sent to that Restaurant. We will assist the Restaurant where Menurium processes the relevant data on its behalf.
10.3
To exercise a right or request account deletion, email [email protected]. We may request information necessary to verify identity and authority. We will respond within the period required by applicable law.
10.4
Moldova's supervisory authority is the National Center for Personal Data Protection, 48 Serghei Lazo Street, Chisinau MD-2004, email [email protected], website datepersonale.md.

11. Children

11.1
Business and staff accounts are not intended for children. Menurium does not knowingly permit a child to create a Business Customer or staff account. Restaurant-facing pages may be viewed by younger users, but a Restaurant is responsible for any age restrictions applicable to its Products. Contact us if you believe a child provided data improperly.

12. Cookies, changes and contact

12.1
Our Cookie Policy describes cookies and similar technologies on the website and Admin. Necessary technologies support security, sessions and preferences. Optional analytics technologies are controlled through available consent settings.
12.2
We may update this Policy when our Services, providers or legal obligations change. Material changes will be communicated through the Services, account email or another appropriate method. The effective date above identifies the current version.
12.3
Privacy questions and requests may be sent to LOW TAB STUDIO SRL, Republic of Moldova; email [email protected]; telephone +373 60 108 881.