Privacy Policy
Last updated: August 20, 2026
1. Introduction
This Privacy Policy explains what personal data Virtual Menu (virtualmenu.app) collects, why, and what rights you have over it. It applies to anyone who creates an establishment account and to anyone who visits a menu published through the service.
The data controller is [COMPANY NAME], based in Portugal. For any privacy question, or to exercise the rights described below, contact us at privacy@virtualmenu.app.
2. What data we collect
Account data: name, email, and your password (stored encrypted, never in plain text) — or, if you sign in with Google, the name and email Google gives us with your authorization.
Establishment data: whatever you enter in the panel to build your menu — name, address, phone, hours, categories, items, prices, photos, and the currency you charge in. This information is public by nature: it's what appears on the menu.
Order data: when a visitor places an order through a menu, we store the items ordered, the table number (where applicable), and, in prepaid mode, payment details are processed directly by Stripe — we never see or store your card number.
Technical data: IP address and request headers, kept briefly for rate limiting and security; and a change log for an establishment's data, kept for audit and security purposes.
Cookies: see section 6.
4. Why we use your data, and on what legal basis
To create and manage your account, and to provide the service you signed up for (performance of a contract — GDPR Art. 6(1)(b)).
To process subscription payments and prepaid order payments, through Stripe (performance of a contract, and compliance with billing-related legal obligations).
For security and abuse prevention — rate limiting, audit logging (legitimate interest — GDPR Art. 6(1)(f)).
To remember non-essential preferences, such as your chosen language (consent — GDPR Art. 6(1)(a); see section 6 on cookies).
We never sell your personal data or use it for third-party advertising.
7. How long we keep data
Account and establishment data is kept for as long as the account exists. After it's closed, it's deleted within 30 days, except what we're legally required to keep for longer — namely billing records, which Portuguese tax law requires us to retain for 10 years.
8. Your rights
You have the right to access, rectify, erase, restrict processing of, and request portability of your personal data, and to object to processing based on legitimate interest — under GDPR Articles 15 to 22 (or, if you're in Brazil, the equivalent rights under LGPD Articles 17 to 22). To exercise any of these rights, write to privacy@virtualmenu.app.
If you're not satisfied with our response, you have the right to lodge a complaint with Portugal's data protection authority, the CNPD (www.cnpd.pt), or, if you're in Brazil, with the ANPD (www.gov.br/anpd).
9. How to request deletion of your data
You can request deletion of your account and its associated personal data at any time, whether you created it with email and password, or through Google or Facebook.
To request deletion, email privacy@virtualmenu.app from the address associated with your account, with the subject "Data deletion". We confirm the request and delete the account and its associated personal data within 30 days — the only data we keep after that is what the law requires us to retain, such as billing records, and even that stops being linked to your name wherever the law allows it.
If you signed in through Facebook, this same process also deletes the data we received from Facebook at sign-in time (name and email) — we don't keep anything else from there.
If you delete your account from the panel (Account settings → Close account), the deletion request happens automatically and you don't need to email us.
10. Security
Each establishment's data is isolated from every other's at the database level (Row Level Security), not just by screen-side filters. Passwords are managed by our authentication provider and never stored in plain text. All communication with the service is encrypted (HTTPS).
11. International transfers
Some of our subprocessors (section 5) may process data outside the European Economic Area. When that happens, we ensure a valid transfer mechanism under GDPR is in place — namely the European Commission's Standard Contractual Clauses.
12. Children
Virtual Menu isn't directed at anyone under 18, and we don't knowingly collect data from minors. If you become aware of an account created by a minor, please contact us.
13. Changes to this policy
We may update this policy to reflect changes to the service or to applicable law. A material change will be flagged in the panel, and the date at the top of this page always shows when it was last revised.
14. Contact
For any question about this policy, or to exercise your rights, contact us at privacy@virtualmenu.app.
3. Signing in with Google or Facebook
If you choose to sign in with Google or Facebook instead of creating a password, we receive your name and email address from that provider, to create and identify your account. We don't receive or request access to anything else in that account.