Privacy Policy

Last updated: August 20, 2026

1. Introduction

This Privacy Policy explains what personal data Virtual Menu (virtualmenu.app) collects, why, and what rights you have over it. It applies to anyone who creates an establishment account and to anyone who visits a menu published through the service.

The data controller is [COMPANY NAME], based in Portugal. For any privacy question, or to exercise the rights described below, contact us at privacy@virtualmenu.app.

2. What data we collect

Account data: name, email, and your password (stored encrypted, never in plain text) — or, if you sign in with Google, the name and email Google gives us with your authorization.

Establishment data: whatever you enter in the panel to build your menu — name, address, phone, hours, categories, items, prices, photos, and the currency you charge in. This information is public by nature: it's what appears on the menu.

Order data: when a visitor places an order through a menu, we store the items ordered, the table number (where applicable), and, in prepaid mode, payment details are processed directly by Stripe — we never see or store your card number.

Technical data: IP address and request headers, kept briefly for rate limiting and security; and a change log for an establishment's data, kept for audit and security purposes.

Cookies: see section 6.

3. Signing in with Google or Facebook

If you choose to sign in with Google or Facebook instead of creating a password, we receive your name and email address from that provider, to create and identify your account. We don't receive or request access to anything else in that account.

5. Who we share data with

We use a small number of subprocessors, each only for what it needs to provide its own service: Supabase (database and authentication), Cloudflare (hosting, network, and photo storage), Stripe (payments), and Resend (sending authentication emails).

We don't share personal data with anyone else, except where the law requires it (for example, a court order), or as part of a potential sale or merger of the company — in which case you'd be notified before any transfer.

6. Cookies

We use only two first-party cookies: one that records your decision about cookies (strictly necessary, doesn't require consent), and one that remembers the language you picked (only set if you accept the "preferences" category in the cookie notice). We don't use advertising or cross-site tracking cookies.

You can review or change your decision at any time via the "Cookie preferences" link in the site's footer.

7. How long we keep data

Account and establishment data is kept for as long as the account exists. After it's closed, it's deleted within 30 days, except what we're legally required to keep for longer — namely billing records, which Portuguese tax law requires us to retain for 10 years.

8. Your rights

You have the right to access, rectify, erase, restrict processing of, and request portability of your personal data, and to object to processing based on legitimate interest — under GDPR Articles 15 to 22 (or, if you're in Brazil, the equivalent rights under LGPD Articles 17 to 22). To exercise any of these rights, write to privacy@virtualmenu.app.

If you're not satisfied with our response, you have the right to lodge a complaint with Portugal's data protection authority, the CNPD (www.cnpd.pt), or, if you're in Brazil, with the ANPD (www.gov.br/anpd).

9. How to request deletion of your data

You can request deletion of your account and its associated personal data at any time, whether you created it with email and password, or through Google or Facebook.

To request deletion, email privacy@virtualmenu.app from the address associated with your account, with the subject "Data deletion". We confirm the request and delete the account and its associated personal data within 30 days — the only data we keep after that is what the law requires us to retain, such as billing records, and even that stops being linked to your name wherever the law allows it.

If you signed in through Facebook, this same process also deletes the data we received from Facebook at sign-in time (name and email) — we don't keep anything else from there.

If you delete your account from the panel (Account settings → Close account), the deletion request happens automatically and you don't need to email us.

10. Security

Each establishment's data is isolated from every other's at the database level (Row Level Security), not just by screen-side filters. Passwords are managed by our authentication provider and never stored in plain text. All communication with the service is encrypted (HTTPS).

11. International transfers

Some of our subprocessors (section 5) may process data outside the European Economic Area. When that happens, we ensure a valid transfer mechanism under GDPR is in place — namely the European Commission's Standard Contractual Clauses.

12. Children

Virtual Menu isn't directed at anyone under 18, and we don't knowingly collect data from minors. If you become aware of an account created by a minor, please contact us.

13. Changes to this policy

We may update this policy to reflect changes to the service or to applicable law. A material change will be flagged in the panel, and the date at the top of this page always shows when it was last revised.

14. Contact

For any question about this policy, or to exercise your rights, contact us at privacy@virtualmenu.app.

Virtual Menu