Privacy
Privacy policy
This policy describes what information is collected from operators and diners, why it is processed, and how payment and operational data are handled across the platform.
Last updated 7 April 2026
1. Information we collect
Restaurant account details, contact details, subscription state, and connected billing identifiers.
Operational data including tables, tags, sessions, orders, receipts, and staff actions.
Optional guest data such as receipt emails, reservation or waitlist contact details, feedback messages, and payment references when supplied through venue flows.
2. Why we use it
To provide the ordering platform, authenticate staff, maintain live service state, and support restaurants using the product.
To process restaurant subscription billing and support connected customer payments where enabled.
To maintain reliability, investigate incidents, prevent abuse, and preserve audit visibility.
3. Sharing and service providers
Stripe is used for connected restaurant payouts and subscription billing where enabled.
Hosting, database, logging, analytics, and infrastructure providers may process technical data required to operate NFC Menu.
Information is shared only where reasonably required to provide the service, maintain security, or meet legal and accounting obligations.
4. Retention and security
Operational and billing records are retained for support, accounting, dispute handling, and audit obligations.
Access is bounded by tenant isolation, role-based permissions, and operational logging inside the platform.
No system can promise perfect security, but commercially reasonable technical and operational safeguards are used.
5. Restaurant responsibility
Restaurants remain responsible for the guest information they choose to collect through their own venue operations and service decisions.
Restaurants should only collect the information necessary to fulfil service, communicate with guests, and run venue operations.
Restaurants are responsible for responding to venue-specific guest requests relating to orders, reservations, or other venue-held records.
6. Rights and contact
Privacy and data-access requests about the platform should be sent to ozdemirewdo@gmail.com.
Requests may require identity verification before information is disclosed or changed.
Where a request relates to venue-level guest data, the platform may direct the requester to the relevant restaurant.