Privacy Policy
This page explains what personal data we collect, why we collect it, how long we keep it, and what rights you have regarding your data.
Last updated: 13 July 2026
Controller: Klemen Hrastnik s.p., Slovenia
Privacy contact: klemen.hrastnik@gmail.com
1. Who this policy covers
This policy applies to:
- Website visitors
- Anyone who browses menufly.app or related Menufly pages.
- Potential customers
- People who create a trial account, submit a contact form, or communicate with us before subscribing.
- Restaurant operators
- Businesses or individuals who register a Menufly account and use the platform to manage their digital menus.
- Menu guests
- End-users (restaurant customers) who scan a Menufly QR code to view a menu.
2. Our role in data processing
Depending on the context, Menufly acts in different roles:
- As data controller for data we process for our own business purposes — account management, billing, security, and basic analytics.
- As data processor on behalf of the restaurant operator for any content the operator uploads or manages inside their Menufly account (menus, dishes, photos).
When a restaurant guest scans a QR code, Menufly records only an anonymous, aggregate visit count with no personally identifiable information. The restaurant operator is the data controller for any additional data they independently collect from their guests.
3. What data we collect
Paid-plan waitlist. If you ask to be notified when our paid plans launch, we store the email address you provide, which plan you were interested in, and the date of your request. We use it for one purpose only: to email you once that plan is available. We do not share it with third parties and we do not add you to a marketing list. You can ask us to delete it at any time by contacting us, and it is deleted automatically if you delete your account.
4. Why we process it and legal bases
5. Where we get data from
- Directly from you when you register, fill in a form, or use the Menufly dashboard.
- Automatically from your browser or device when you interact with the service (server logs).
- From Stripe when a payment or subscription event occurs.
6. Who we share data with
We do not sell personal data. We share data only where necessary to operate the service:
- Supabase — cloud database and authentication (EU region).
- Vercel — application hosting and CDN.
- Stripe — payment processing and subscription management.
- Resend — transactional email delivery.
- Google LLC (Google Analytics) — website analytics. Only activated after you give consent via the cookie banner. Data may be transferred to the US under the EU–US Data Privacy Framework.
- Legal, tax, or regulatory authorities if required by law.
All processors are bound by data processing agreements and may only use data to provide the contracted service.
7. International data transfers
We aim to store data within the European Economic Area (EEA). Where sub-processors transfer data to third countries (e.g. Stripe and Vercel may process data in the United States), such transfers rely on the EU–US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer mechanism.
8. Retention periods
9. Your rights
Under the GDPR you have the following rights regarding personal data for which we are the controller:
- Right of access — request a copy of the data we hold about you.
- Right to rectification — correct inaccurate data via your account settings or by contacting us.
- Right to erasure — delete your account at any time (Account → Delete account). All personal data is permanently removed.
- Right to restriction of processing — ask us to limit how we use your data in certain circumstances.
- Right to data portability — export your data as JSON via Account → Download my data.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any right, email us at klemen.hrastnik@gmail.com. We will respond within 30 days. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with the Slovenian supervisory authority:
Information Commissioner of the Republic of Slovenia (IP RS)
Dunajska cesta 22, 1000 Ljubljana
10. Restaurant guests — special note
If you scan a Menufly QR code as a restaurant guest, Menufly records only an anonymous, aggregated visit count for that menu — no name, no email, no IP address, and no cross-site tracking. We do not build a profile of individual guests.
The restaurant that placed the QR code is the data controller for any information they independently collect (e.g. reservation systems, loyalty programmes). For questions about such processing, please contact the restaurant directly.
11. Cookies
Menufly uses the following cookies:
- Essential cookies — strictly necessary for authentication and session management. These are set as
httpOnlycookies and cannot be disabled without breaking the service. - Analytics cookies (Statistics) — Google Analytics cookies (
_ga,_ga_*) are set only after you give explicit consent via the cookie banner. They measure page views and visitor behaviour in aggregate. You can withdraw consent at any time via Cookie settings in the footer.
You can manage your consent preferences at any time by clicking the “Cookie settings” link in the footer.
12. Changes to this policy
We may update this policy from time to time to reflect changes in our service, technology, or legal requirements. The updated version will be published on this page with a new “Last updated” date. For material changes, we will notify active subscribers by email at least 14 days in advance.
13. Contact
For any privacy questions or to exercise your rights, email us at klemen.hrastnik@gmail.com. We aim to respond within 5 business days.