1. Who we are
myQRMenu is operated by Selman GÜRBÜZER, trading as Sellsoft, 9605, 01100 Ankara, Türkiye ("myQRMenu", "we", "us").
We run three surfaces: the marketing site at getmyqrmenu.com, the operator dashboard at app.getmyqrmenu.com, and the public guest menus at {restaurant}.getmyqrmenu.com. This policy covers all three.
Questions, or any request about your own data, go to privacy@getmyqrmenu.com. We answer within 30 days.
2. Whose data, and who decides
Two different relationships run through the same product, and the difference decides who you ask about what.
| Data | Who decides | Our role |
|---|---|---|
| Your account and workspace: name, email, plan, sign-in activity | We do | Controller. This policy governs it. |
| Menu content a restaurant publishes: dishes, prices, photos, allergens, translations | The restaurant | Processor. We host and display it on the restaurant's instructions. |
| Guest activity on a restaurant's menu: scans, views, language and currency choices | The restaurant | Processor. The statistics belong to that venue's dashboard. |
If you scanned a code at a table and want to reach the party responsible for that menu, it is the restaurant, not us. We will pass a request on if you cannot identify the venue.
3. What we collect from restaurant accounts
Sign-in is handled by Clerk. We receive and store a Clerk user identifier, your email address, and the name on the account. Passwords, one-time codes, and social-login tokens stay with Clerk and never reach our database.
Beyond the account itself, we store what you create in the product: workspaces, locations, menus, categories, items, prices, price variations, QR codes, campaigns, uploaded images, and the AI drafts awaiting your approval.
Our servers write standard application logs, including request paths, status codes, timings, and error traces. These are operational records used to keep the service up and to investigate faults.
4. What we collect from menu guests
A guest scans a printed code and reads a menu. There is no sign-up, no app, no advertising identifier, and no cookie set by the menu itself.
So a restaurant can see how its own menu is performing, we record an event when a code is scanned, a menu is opened, an item is viewed, or a language or currency is switched. Each event carries the venue, a coarse device class (mobile, tablet, or desktop), the chosen language and currency, an approximate country and city, and a visitor hash.
The visitor hash is what separates a returning guest from a new one without identifying either. It is a SHA-256 digest of the guest's IP address combined with the venue, the calendar date, and a secret salt, truncated to 32 characters. The raw IP address is never written to our database. Because the date is part of the input, the same guest produces a different hash tomorrow, and yesterday's hashes cannot be linked to today's.
We do not build guest profiles, do not sell or share guest data, and run no advertising or cross-site tracking on menu pages.
5. Billing data
Subscriptions are processed by Dodo Payments as merchant of record. Card numbers, bank details, and billing addresses are collected and held by Dodo Payments under its own terms and privacy policy. They do not pass through our servers and we cannot retrieve them.
What we store against your workspace is the plan name, the subscription status, the features it unlocks, a provider reference used to match incoming payment webhooks, and the date the current period ends.
6. Product analytics and cookies
We run a self-hosted Umami instance to understand how the marketing site and the dashboard are used. It is served from our own domain, sets no cookie, and collects no cross-site identifier. It is deliberately not loaded on guest menu pages.
The only cookies in play are these:
| Cookie | Purpose | Lifetime |
|---|---|---|
| gmq_locale | Remembers the interface language you picked | 1 year |
| Clerk session cookies | Keeps you signed in to the dashboard. Set by Clerk on our behalf. | Session, per Clerk's policy |
Both are strictly necessary to deliver a service you asked for, so no consent banner stands between you and the product. We use no advertising, remarketing, or third-party analytics cookies anywhere.
7. AI features and what they send
Several features draft content by sending menu text or menu photographs to an AI provider. This happens only when you invoke the feature. Guest data is never included in any AI request.
| Feature | What is sent | Provider |
|---|---|---|
| Photo menu import | The menu photograph you upload | Google (Gemini) |
| Nutrition and allergen estimates | Item names and descriptions | Google (Gemini) |
| Menu translation | Item and category text | DeepSeek |
| Campaign copy | Item names, prices, campaign parameters | DeepSeek |
Everything these providers return is a draft. It is stored against your workspace and stays invisible to guests until you approve it. Each provider processes the request under its own terms; we do not grant them the right to train on your menu content, and we cache results only to avoid re-sending the same text.
8. Why we are allowed to process this
For anyone covered by the GDPR, the UK GDPR, or an equivalent regime, these are the grounds we rely on.
| Processing | Legal basis |
|---|---|
| Running your account and delivering the product | Performance of a contract |
| Taking payment and preventing payment fraud | Performance of a contract; legal obligation |
| Counting menu scans and views for the restaurant that owns the venue | Legitimate interest of that restaurant in understanding its own menu, weighed against the fact that no guest is identified |
| Keeping the service secure and diagnosing faults | Legitimate interest in a working, secure service |
| Sending service notices about your account or a plan change | Performance of a contract |
| Sending product marketing email, where we do so | Consent, withdrawable at any time |
10. International transfers
Our processors operate internationally, so data may be processed outside the country you are in. Where a transfer leaves the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision covering the destination.
11. How long we keep it
| Data | Retention |
|---|---|
| Account, workspace, and menu content | For as long as the account is open. Deleted or anonymised within 90 days of account closure. |
| Guest analytics events | Up to 24 months, so a venue can compare a season against last year's. Aggregated daily statistics may be kept longer; they identify no one. |
| Billing and invoice records | As long as tax and accounting law requires, typically 7 to 10 years. |
| Application and security logs | Up to 90 days, except where an incident requires keeping them longer. |
| AI drafts you never approved | Deleted with the workspace, or earlier if you discard them. |
12. Your rights
Depending on where you live, you can ask us to do the following. We do not charge for this and we do not treat you differently for asking.
- Get a copy of the personal data we hold about you.
- Correct anything inaccurate.
- Delete your data, subject to records we must keep by law.
- Receive your data in a portable, machine-readable format.
- Object to processing we base on legitimate interest, or ask us to restrict it.
- Withdraw consent where consent is what we relied on. This does not undo processing already carried out.
Write to privacy@getmyqrmenu.com from the address on the account. If we cannot resolve it, you may complain to your local data protection authority; you do not have to come to us first.
Requests about a specific restaurant's menu or its guest statistics belong to that restaurant, which decides them. Send those to the venue, or to us and we will forward them.
13. Security
Traffic is encrypted in transit with TLS and our domains are served under HSTS. The application sets a content security policy, blocks framing on every surface that carries a session, and switches off browser features it does not use. Access to production data is limited to the people who need it to operate the service.
The analytics salt that protects guest hashes is held as a server secret, and the application refuses to start in production without it. A known salt would make those hashes reversible.
No service is immune. If a breach affects your data and carries real risk to you, we will notify you and the relevant authority within the deadlines the law sets.
14. Children
myQRMenu is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16, and a guest reading a menu is never asked for any. If you believe a child has given us data through an account, write to us and we will remove it.
15. Changes to this policy
We update this policy when the product changes, and the date at the top always reflects the current version. For a change that materially affects your rights, we will email account holders at least 30 days before it takes effect.
16. Contact
- Privacy and data requests: privacy@getmyqrmenu.com
- Terms and legal notices: legal@getmyqrmenu.com
- Everything else: hello@getmyqrmenu.com
Postal address: Selman GÜRBÜZER, 9605, 01100 Ankara, Türkiye.
Your use of the product is also governed by our Terms of Service.