Legal

GDPR Compliance

Last updated: January 2025

The General Data Protection Regulation (GDPR) grants individuals in the European Economic Area rights over their personal data. Menubar is committed to respecting those rights and maintaining GDPR-compliant data practices — including for venue operators and guests from the EEA using the platform.

We do not sell personal data
We use minimal, necessary cookies only
Data is encrypted in transit and at rest
Sub-processors are contractually bound
Data deletion requests fulfilled within 30 days
No advertising or tracking profiling

Data controller

Menubar acts as the data controller for account and usage data collected from venue operators. For orders and guest interactions, venue operators are the data controllers of their guests' data, and Menubar acts as a data processor on their behalf.

Legal bases for processing

  • Contract:Processing necessary to provide the service you signed up for (serving your menu, routing orders).
  • Legitimate interest:Platform security, fraud prevention, and service improvement.
  • Legal obligation:Compliance with applicable law.

Your rights under GDPR

Right to access

Request a copy of all personal data we hold about you.

Right to rectification

Ask us to correct any inaccurate or incomplete data.

Right to erasure

"Right to be forgotten" — ask us to delete your account and associated data.

Right to restrict

Ask us to pause processing while a dispute is resolved.

Right to portability

Request your menu and order data exported in a standard machine-readable format.

Right to object

Object to processing based on legitimate interest.

Exercising your rights

To exercise any of the rights above, email us at privacy@merakigroupltd.com with the subject line "GDPR Request". We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.