Skip to content

Legal document

Privacy Policy

How Menly collects, uses, and protects your personal data.

Version 1.0Effective March 2025

Overview

Menly SA ("Menly", "we", "us") operates the menly.ch platform, including the restaurant management dashboard and public-facing guest menu pages. This Privacy Policy explains what personal data we collect, how we use it, your rights, and how to contact us.

We process personal data in accordance with the Swiss Federal Act on Data Protection (revFADP) and, where applicable, the EU General Data Protection Regulation (GDPR). Our data is hosted in Switzerland.

Data we collect

Account data: When you register, we collect your name, email address, and a hashed password. We never store plain-text passwords.

Organisation data: Restaurant name, address, logo, and configuration settings you provide.

Menu content: Dish names, descriptions, prices, allergen information, and translations you create.

Usage data: Page views on guest menu pages (dish, section, and language), time of visit, and device type. We do not use fingerprinting or cross-site tracking.

Payment data: Billing is processed by Stripe. We receive only a Stripe customer ID and subscription status — we never see or store your card details.

Communication data: If you contact us by email, we retain that correspondence.

How we use your data

To deliver and operate the Menly platform, including authentication, menu publishing, and QR code generation.

To provide your in-app analytics dashboard showing menu view counts and language adoption.

To process your subscription and send billing-related communications.

To send transactional emails (email verification, password reset) and occasional product updates if you opted in.

To improve the platform based on aggregated, anonymised usage patterns.

We do not sell your data to third parties. We do not use your data to train AI models.

Data retention

Your account and menu data is retained for as long as your account is active. If you delete your account, we begin a 30-day deletion window after which all personal data is permanently removed.

Aggregated, anonymised analytics (total view counts without identifying information) may be retained indefinitely for internal benchmarking.

Billing records are retained for 10 years as required by Swiss financial law.

Your rights

You have the right to access the personal data we hold about you, receive a copy in a portable format, correct inaccurate data, and request deletion of your data (subject to legal retention obligations).

You may also object to or restrict certain processing activities. To exercise any of these rights, email privacy@menly.ch. We will respond within 30 days.

If you believe we have infringed your rights, you may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.

Cookies & tracking

We use a session cookie for authentication (HttpOnly, Secure, SameSite=Lax). No persistent tracking cookies are set on the marketing site without your consent.

Guest menu pages do not set any cookies. View counts are recorded server-side without a client-side identifier.

See our Cookie Policy for full details on what cookies we set and how to manage them.

Third-party processors

Stripe — payment processing (servers in the EU).

Cloudinary — image hosting for menu photos (servers in the EU).

Our email provider — transactional email delivery.

Our hosting provider — application and database hosting in Switzerland.

All processors are bound by Data Processing Agreements compliant with the revFADP and GDPR.

Contact

Data controller: Menly SA, Geneva, Switzerland.

Data protection enquiries: privacy@menly.ch

General contact: hello@menly.ch

Privacy Policy — Menly | Menly