Legal
Privacy policy
Last updated: 21 August 2026
1. Controller
The data controller is [OPERATOR NAME / COMPANY] ([TAX ID / NIF]), [REGISTERED ADDRESS], [COUNTRY]. Contact: hello@allegromenu.com. This policy explains how we process personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR).
2. What we collect and why
- Your menu (photo, PDF or text, the dishes, prices and allergens you confirm, and the translations). Purpose: providing the service. Legal basis: performance of the contract (art. 6(1)(b)). Menus usually contain no personal data; if a photo shows people or personal details, please crop it before uploading.
- Order and account data: email address, restaurant name, purchases, subscription status and the access links we send you. Purpose: delivering what you bought, letting you come back to edit your menu, invoicing and support. Legal basis: contract and legal obligations (tax and accounting records, art. 6(1)(c)).
- Payment data is collected and processed by Stripe Payments Europe Ltd. We receive only the payment status, the last digits of the card and the billing country. Stripe’s privacy policy applies to the payment itself.
- Technical data: IP address, browser and device information, pages visited and errors, used to operate and secure the site and to understand how it is used (legitimate interest, art. 6(1)(f), and your consent for analytics cookies where required).
3. Automated processing
Menus are read and translated by artificial-intelligence models provided by third parties acting as our processors (accessed through OpenRouter, Inc.; the models used are operated by Google, OpenAI and Anthropic, among others). The content you upload is sent to them solely to produce your menu and is not used by us to train models. No decisions with legal or similarly significant effects are taken automatically about you.
4. Recipients and transfers
We rely on the following providers, bound by data-processing agreements: Vercel Inc. (hosting, USA/EU), Neon Inc. (database, hosted in Frankfurt, Germany), Stripe (payments), Resend (transactional email), OpenRouter and the AI model providers (menu reading and translation), and analytics and error-monitoring tools described in the cookie notice. Some providers are established outside the EEA; transfers are covered by the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses.
Your web menu is public by design: anyone with the link or the QR code can see the dishes, prices and allergens you published, and the restaurant name you entered.
5. Retention
Menus and translations are kept while your purchase or subscription gives you access to them and for 12 months afterwards, so you can come back to them; then they are deleted or anonymised. Invoicing records are kept for the period required by tax law (generally 4 to 10 years depending on the country). Menus read for free and never purchased are deleted after 30 days. Technical logs are kept for up to 90 days.
6. Your rights
You can ask for access to, rectification or erasure of your data, restriction of or objection to processing, and portability, by writing to hello@allegromenu.com. Where processing is based on consent you can withdraw it at any time. You also have the right to lodge a complaint with your data protection authority (in Spain, the AEPD; in Cyprus, the Commissioner for Personal Data Protection; or the authority of the country where you live).
7. Security
Data is transmitted over TLS and stored with access restricted to the operator and the processors listed above. Access links sent by email are personal: do not forward them.
8. Changes
We will post any change to this policy on this page and, for material changes, notify subscribers by email.