Last updated:
Privacy Policy
This policy explains what MenuBeacon collects, why, how long it is kept, and the choices you have. It covers restaurant owners and staff with MenuBeacon accounts, and diners who scan a MenuBeacon QR code or place an order through a MenuBeacon menu.
Data we collect from restaurant accounts
When you create and use a MenuBeacon account we collect your email address, password (stored as a bcrypt hash, never in plain text), restaurant profile details, menu content, uploaded images, QR code records, staff PINs, and billing status. If you enable optional integrations we also store the configuration you provide, such as notification phone numbers or printer addresses.
Data we collect from diners
When a diner scans a menu QR code, MenuBeacon records scan analytics: an anonymized IP address, approximate location (city and country), browser, operating system, device type, referrer, timestamp, the table or QR code identifier, and a daily session hash used to estimate unique visitors. When a diner places an order, we collect the order contents plus any details the diner chooses to provide, such as a name, phone number, email for a receipt, or delivery address. Card details are processed by Stripe and never touch MenuBeacon servers.
IP anonymization and geolocation
Raw IP addresses are anonymized by default before storage (the final octet is removed), and raw IPs are never exposed through analytics views or APIs. Approximate city/country geolocation is derived from the request IP using ipapi.co, a third-party geolocation service; the lookup is best-effort and processed according to ipapi.co's own privacy policy.
How we use data
- To operate the service: serving menus, processing orders, generating QR codes, and sending order notifications.
- To show restaurants aggregate analytics about how their menus are used.
- To send transactional email: password resets, email verification, receipts, and (if enabled) weekly digest reports.
- To bill subscriptions through Stripe.
MenuBeacon does not sell personal data and does not use diner data for advertising.
Third-party processors
- Stripe — subscription billing and card payments (when enabled by a restaurant).
- ipapi.co — approximate geolocation from scan requests.
- Twilio / WhatsApp Business — SMS and WhatsApp order notifications, only when a restaurant enables them.
- Amazon S3 (or the operator's configured object storage) — uploaded image hosting.
- Our hosting and email (SMTP) providers, which process data on our behalf to run the service.
Data retention
Scan analytics are retained for 365 days by default, after which they are automatically deleted; the service operator may configure a shorter window. Order records are kept while the restaurant account remains active, since restaurants need them for their own accounting. Account, restaurant, and menu data are kept while your account is active or as needed to provide the service, then deleted on account deletion.
Cookies
MenuBeacon uses a single httpOnly session cookie (a JWT) to keep you signed in, plus a CSRF token cookie to protect authenticated requests. These are strictly necessary for the service to function. Public menu pages viewed by diners do not set tracking cookies.
Your rights (GDPR / CCPA)
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to lodge a complaint with your local supervisory authority. To exercise any of these rights, email support@menubeacon.com from the address associated with your account; we respond within 30 days. Diners who provided contact details with an order can make the same request — include the restaurant name and approximate order date so we can locate the record.
Security
Passwords are hashed with bcrypt, sessions use httpOnly cookies, database access is credentialed and restricted, and uploads are validated before storage. No system is perfectly secure; if we become aware of a breach affecting your personal data we will notify affected accounts without undue delay.
Children
MenuBeacon accounts are for businesses and are not directed at children under 16. We do not knowingly collect personal data from children.
Changes to this policy
If we make material changes we will update the date at the top of this page and, for significant changes affecting account holders, notify you by email.
Contact
For privacy questions or data requests, contact support@menubeacon.com.