Your Privacy Matters to Us
Effective Date: February 7, 2026
Note: This privacy policy has been drafted to provide transparency about our data practices. However, we recommend you have it reviewed by a qualified legal professional to ensure it fully complies with all applicable privacy laws in your jurisdiction.
Introduction
MenuFlo ("we," "us," "our," or "Company") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, mobile application, and related services (collectively, the "Service").
We operate as a restaurant menu platform based in Ontario, Canada. We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL).
Please read this Privacy Policy carefully. If you do not agree with our policies and practices, please do not use our Service.
Information We Collect
We collect information in several ways to provide and improve the MenuFlo Service:
Information You Provide Directly
When you create an account, set up a restaurant profile, or interact with our Service, we collect:
- Account Information: Email address, password (encrypted), and account preferences
- Restaurant Information: Restaurant name, URL slug, phone number, business address, and logo
- Menu Data: Menu categories, item names, descriptions, prices, and optional photos
- Communications: Messages you send us through contact forms or support channels
Information Collected Automatically
When you access our Service, we automatically collect usage information:
- Analytics Data: Page views, feature interactions (menu views, tap-to-call events, tap-for-directions events, tap-to-order attempts), and timestamps
- Device Information: IP address, browser type, operating system, referral source, and device identifiers
- Cookies and Tracking: We use cookies and similar technologies to track user behavior and preferences (see Cookies and Tracking Technologies section)
Information from Menu Visitors
When customers view your published menu, we collect data about their interactions:
- Visitor Intent Data: Interactions with your menu (views, button clicks, searches), timestamps, and device information
- Waitlist and Newsletter: Email addresses provided when customers join your waitlist or subscribe to your newsletter
How We Use Your Information
We use the information we collect for the following purposes:
- Providing and Maintaining the Service: To create and manage your account, deliver menu functionality, process transactions, and provide customer support
- Analytics and Improvement: To understand how users interact with our Service, identify trends, and improve features and user experience
- Communications: To send you service-related updates, transactional emails, and (with your consent) marketing communications about new features or improvements
- Legal Compliance: To comply with legal obligations, enforce our terms of service, and protect against fraud or misuse
- Business Operations: To monitor Service performance, troubleshoot technical issues, and conduct security measures
How We Share Your Information
We do not sell your personal information. However, we share information with trusted third-party service providers who assist us in operating our Service:
Third-Party Service Providers
- PostHog: We use PostHog for analytics and event tracking to understand user behavior and improve our Service. PostHog processes analytics data and may place cookies on your device.
- Infrastructure Providers: We use third-party cloud infrastructure providers, including CapRover and Railway, to host our applications and supporting services in secure data centers.
- Loops.so: We use Loops.so to send transactional emails (password resets, account confirmations) and marketing communications (feature updates, newsletters). Loops.so processes email addresses and communication preferences.
We require all third-party service providers to agree to confidentiality obligations and to use personal information only for the purposes we specify.
Legal Requirements
We may disclose your information if required by law, such as in response to valid government requests, court orders, or to protect our legal rights or the safety of our users.
Cookies and Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience:
- Essential Cookies: Required for authentication, security, and basic Service functionality
- Analytics Cookies: Placed by PostHog to track user interactions, page views, and feature usage
- Preference Cookies: Remember your choices and settings for a personalized experience
Most browsers allow you to refuse cookies or alert you when cookies are being sent. Please note that refusing cookies may affect your ability to use certain features of our Service.
Data Retention
We retain your personal information for as long as necessary to provide the Service and fulfill the purposes outlined in this Privacy Policy:
- Account Data: Retained while your account is active. After account deletion, we retain certain data in anonymized form for 30 days before permanent deletion, and for legal compliance purposes
- Analytics Data: Typically retained for 12 months for performance and improvement analysis
- Email Communications: Retained in compliance with Canadian email regulations (CASL) for 12 months
- Transactional Records: Retained as required for business operations and legal compliance
When you delete your account, we will remove your personal information from our active systems, though we may retain anonymized or aggregated data for analytics purposes.
Your Rights Under PIPEDA
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
- Access Your Information: Request a copy of the personal information we hold about you
- Request Correction: Request that we correct inaccurate or incomplete personal information
- Withdraw Consent: Withdraw consent for the collection, use, or disclosure of your personal information (though this may affect your ability to use the Service)
- Lodge a Complaint: If you believe we have violated your privacy rights, you may file a complaint with the Privacy Commissioner of Canada
To exercise any of these rights, please use our contact page. We will respond to your request within 30 days.
Canadian Anti-Spam Legislation (CASL)
We comply with Canada's Anti-Spam Legislation (CASL) in all our commercial email communications:
- Consent-Based Marketing: We only send marketing emails to users who have explicitly consented to receive them
- Clear Identification: All marketing emails clearly identify MenuFlo as the sender
- Unsubscribe Option: Every marketing email includes a clear, functional unsubscribe link. You can unsubscribe from marketing communications at any time
- Transactional Emails: Service-related emails (confirmations, password resets, account updates) do not require opt-in consent but include unsubscribe information
If you receive any communication from us that violates CASL, please report it through our contact page.
Children's Privacy
MenuFlo's Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will delete such information and terminate the child's account.
For restaurant owners who use MenuFlo, you are responsible for ensuring that customer data collected through your published menu complies with applicable laws regarding minors.
Data Security
We implement reasonable technical and organizational measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction:
- Encrypted passwords and secure authentication mechanisms
- HTTPS encryption for all data in transit
- Secure data storage with access controls
- Regular security audits and updates
However, no method of transmission over the Internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
International Data Transfers
Your personal information may be processed, stored, and transferred outside of Canada, including to the United States and other jurisdictions. When we transfer data outside Canada, we ensure appropriate safeguards are in place, such as standard contractual clauses or your explicit consent.
By using MenuFlo, you acknowledge and consent to the processing of your personal information in jurisdictions outside Canada, which may have different privacy laws than Canada.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the "Effective Date" above.
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy. We encourage you to review this policy periodically to stay informed about how we protect your information.
Contact Us
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise any of your rights, please use our contact page.
MenuFlo Privacy Team
Contact form: menuflo.com/contact
We will respond to your inquiry within 30 business days.