In short: we collect only what is needed to run your account, menu, reservations and billing. We do not sell data to anyone. Analytics and marketing pixels activate only if you consent through the cookie banner. You can exercise your rights at any time by writing to office@menivo.io.
1. The data controller
The controller of personal data is WEB DESIGN BY PC MAINTENANCE S.R.L., J08/804/2018, tax ID 39172796, with its registered office at Str. Viitorului, Săcele, Brașov County, Romania.
For any data protection matter, write to office@menivo.io. We are not legally required to appoint a Data Protection Officer, but your requests are handled directly by the company's management.
This policy applies to processing carried out through the Menivo platform (menivo.io) and its related support channels.
2. Our two roles: controller and processor
It is important to distinguish between two different situations:
- We are the controller for the data of our direct customers — the restaurants and their representatives: account data, billing, support, commercial communications and website analytics.
- We are a processor for the end-consumer data that the restaurant collects through the Platform — reservations, online orders, reviews. In that case the restaurant is the controller and we process the data solely on its instructions.
The terms of that second situation are set out in our Data Processing Agreement, which forms an integral part of the contract with our customers.
3. What data we collect
3.1. Account data (Menivo customers)
- Name, email address, password (stored only as a hash, never in plain text).
- Email verification code and confirmation date.
- Subscription plan, status, start and end dates, Stripe customer and subscription identifiers.
- Date of last activity, used for inactive-account warnings.
3.2. Billing data
- Company name, tax code, Trade Register number, address, phone, postal code, activity code, IBAN, legal form — either entered by you or retrieved automatically from the public ANAF registers on the basis of the tax code.
- Invoice amount, currency, exchange rate, document series and number, payment status and transaction identifiers.
- We do not store bank card details. They are entered directly on Stripe's infrastructure and never reach us.
3.3. Restaurant data
- Name, logo, cover image, address, county, phone, WhatsApp number, email, website, social media, opening hours.
- Menu content: categories, products, prices, descriptions, images, allergens, nutritional values.
3.4. End-consumer data (processed on behalf of the restaurant)
- Reservations: name, phone, email, party size, date and time, notes.
- Online orders: name, phone, delivery address, pickup time, notes, order contents.
- Reviews: name, email, rating, title and text, together with IP address, user agent and language — retained as anti-fraud evidence and to prevent duplicate reviews.
- WhatsApp conversations: phone number and the content of messages exchanged with our support assistant.
3.5. Technical and usage data
- IP address, device and browser type, pages visited, time of access — in server logs, for security and diagnostics.
- Cookie consent evidence: an anonymous visitor identifier, the IP address as an irreversible hash (never in plain text), the categories selected, the policy version and the language.
- Traffic statistics through Google Analytics 4, only if you have accepted the "analytics" category.
- QR code scan counts and aggregated menu view statistics.
4. Why we process it and on what basis
| Purpose | Data categories | Legal basis (GDPR) |
|---|---|---|
| Creating and managing the account, providing the Platform | Account, restaurant, menu content | Art. 6(1)(b) — performance of a contract |
| Processing payments and issuing invoices | Billing, payment identifiers | Art. 6(1)(b) and Art. 6(1)(c) — legal obligation (Romanian Fiscal Code, Accounting Law 82/1991) |
| Technical support, including via WhatsApp | Account, conversations, technical data | Art. 6(1)(b) and Art. 6(1)(f) — legitimate interest in providing assistance |
| Transactional emails (confirmations, expiry alerts, setup reminders) | Account | Art. 6(1)(b) — performance of a contract |
| Platform security, fraud and abuse prevention | Technical data, IP, user agent | Art. 6(1)(f) — legitimate interest |
| Traffic analytics (Google Analytics 4) | Cookie identifiers, browsing data | Art. 6(1)(a) — consent |
| Marketing and remarketing (Meta Pixel, Google Ads via GTM) | Cookie identifiers | Art. 6(1)(a) — consent |
| Cookie consent evidence | Visitor UUID, hashed IP | Art. 6(1)(c) — legal obligation to demonstrate consent |
| End-consumer reservations, orders and reviews | Consumer contact details | The restaurant is the controller; we act as processor — see the DPA |
| Establishing or defending legal claims | Any relevant category | Art. 6(1)(f) — legitimate interest |
5. Processing through AI systems
Certain Platform features send content to artificial intelligence providers:
- Anthropic — allergen list generation, nutritional value calculation, translations, extracting products from menu photographs, the WhatsApp support assistant.
- OpenAI — image generation for blog articles.
The content transmitted is normally product information (names, ingredients, descriptions) rather than personal data. In the case of the WhatsApp assistant, however, the text of your messages is also transmitted and may contain personal data if you choose to include it. Please do not send sensitive data through the chat.
We do not take automated decisions producing legal or similarly significant effects on you within the meaning of Article 22 GDPR. AI suggestions are informative and require your validation before publication.
6. Who we share data with
We do not sell or rent personal data. We disclose it only to the following recipients, to the extent necessary for the service to operate:
| Recipient | Purpose | Location |
|---|---|---|
| ROMARG S.R.L. | Web hosting and infrastructure | Romania (EU) |
| Stripe Payments Europe, Ltd. | Card payment processing | Ireland (EU) |
| Intelligent IT S.R.L. (SmartBill) | Issuing fiscal invoices | Romania (EU) |
| Sendinblue SAS (Brevo) | Sending transactional emails | France (EU) |
| Anthropic PBC | AI features (allergens, nutrition, translations, support) | United States |
| OpenAI, L.L.C. | Image generation | United States |
| Meta Platforms Ireland Ltd. | WhatsApp Business Cloud API, Meta Pixel | Ireland (EU) / United States |
| Google Ireland Ltd. | Google Analytics 4, Google Tag Manager | Ireland (EU) / United States |
In addition, we may disclose data to public authorities where the law requires it, and to our accounting and legal advisers under a duty of confidentiality.
7. Transfers outside the EU
Anthropic, OpenAI and, in certain circumstances, Google and Meta may process data on servers in the United States. These transfers rely on the Standard Contractual Clauses approved by the European Commission and/or on the EU-US Data Privacy Framework, supplemented by additional technical measures such as encryption in transit.
You may request a copy of the applicable safeguards by writing to office@menivo.io.
8. How long we keep data
| Category | Retention period |
|---|---|
| Account data and menu content | For the life of the account, plus 30 days after deletion |
| Inactive free accounts | Warning after 6 months of inactivity, deletion 30 days later |
| Invoices and accounting records | 10 years, under Romanian Accounting Law no. 82/1991 |
| Reservations and orders | As instructed by the restaurant; by default, a maximum of 24 months |
| Published reviews | Until consent is withdrawn or the restaurant is deleted |
| WhatsApp conversations | 24 months from the last message |
| Server logs | Maximum 12 months |
| Cookie consent evidence | 3 years, as proof of compliance with a legal obligation |
| Google Analytics statistics | Per GA4 settings, maximum 14 months |
9. How we protect it
- All traffic encrypted with HTTPS/TLS.
- Passwords stored only as hashes, using modern algorithms; we cannot read them.
- IP addresses in consent logs stored as irreversible hashes.
- Database access restricted to strictly necessary technical staff.
- Regular backups of the database and files.
- Protection against automated attacks, login attempt throttling and signature verification for external integrations.
- Regular security updates of the platform and its dependencies.
In the event of a security breach posing a risk to your rights, we notify the Romanian supervisory authority within 72 hours and inform you directly where the law requires it.
10. Your rights
As a data subject you have the following rights:
- Access — to find out what data we hold about you and to receive a copy.
- Rectification — to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — under the conditions of Article 17 GDPR; it does not apply to data we are legally required to retain, such as invoices.
- Restriction of processing — to ask us to suspend processing temporarily.
- Portability — to receive your data in a structured, commonly used, machine-readable format.
- Objection — to object to processing based on our legitimate interest.
- Withdrawal of consent — at any time, without affecting the lawfulness of prior processing. For cookies, use the preferences panel in the consent banner.
- Complaint — to the supervisory authority.
Send requests to office@menivo.io. We reply within 30 days at the latest; this period may be extended by a further two months for complex requests, in which case we will inform you. To protect your data, we may verify your identity before acting on a request.
If the data concerns you as a restaurant's customer (a reservation, order or review), please contact the restaurant directly, as it is the controller of that data. If you write to us, we will forward your request to the restaurant.
Supervisory authority
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
www.dataprotection.ro ·
anspdcp@dataprotection.ro
11. Cookies
We use strictly necessary cookies without consent, and analytics and marketing cookies only with your prior agreement. The full list, the duration of each cookie and how to withdraw consent are described in our Cookie Policy.
12. Minors
The Platform is aimed at professionals and is not intended for persons under 18. We do not knowingly collect data from minors. If you become aware that a minor has provided us with personal data, please write to us and we will delete it.
13. Changes to this policy
We may update this policy. The version in force is the one published here, with the last-updated date shown in the header. Significant changes are communicated by email or through an in-app notice before they take effect.
WEB DESIGN BY PC MAINTENANCE S.R.L.
Trade Register: J08/804/2018 · CIF: 39172796 (not registered for VAT)
Registered office: Str. Viitorului, Săcele, jud. Brașov, România
Email: office@menivo.io · Phone / WhatsApp: +40 770 322 147
Web: menivo.io