Your data, explained plainly.
Last updated: May 13, 2026. This policy applies to menuregistry.com and any related services operated by MenuRegistry.
- →We don't sell your data.
- →We don't use your menus to train AI.
- →We don't track you across sites or run advertising pixels.
- →We don't store your credit card number. Stripe handles billing.
- →You can delete your account, and your data, anytime.
The full policy below is the binding version. The summary above is here to make it easier to read.
Who we are
MenuRegistry is a software-as-a-service product operated at menuregistry.com. We provide automated allergen audit reports for restaurant operators.
Questions about this policy or your data? Email hello@menuregistry.com.
What we collect
Account data
Your email address, and optionally your name. We collect email when you sign in via magic-link. We do not collect passwords, authentication is email-only.
Payment data
Payment processing is handled entirely by Stripe. We do not store, transmit, or ever see your credit card number, CVV, or full card details. What we receive from Stripe is a Stripe customer ID, a subscription status, and billing metadata (plan tier, billing period, renewal date).
Audit data
When you run an audit, we receive: (a) the menu file or text you upload (PDF, image, or pasted text), (b) the audit results our AI generates, and (c) audit metadata, timestamps, content hashes (SHA-256), and the plan tier under which the audit was run. Audit data is associated with your account.
Usage data
Standard server logs: IP address, browser user-agent, request paths, and HTTP response codes. We retain server logs for approximately 90 days for fraud detection and reliability monitoring. We do not build individual behavioral profiles from this data.
How we use your data
We use your data to operate the service: to authenticate you, run allergen audits on the menu content you provide, generate audit reports, manage your subscription, and send you transactional emails (magic-link sign-in, billing receipts, policy change notices).
We do not:
- ×Sell your data to any third party.
- ×Share your menu content or audit results with advertisers.
- ×Use your uploaded menus to train or fine-tune any AI or machine-learning model.
- ×Send unsolicited marketing email (you can opt out of product announcements at any time).
Data retention
We keep data only as long as we need it to run the service. Email hello@menuregistry.com anytime to delete your account and the data tied to it.
Kept while your account is active. Removed when you delete your account.
Removed about 90 days after upload, unless you have saved them to your account.
Removed 30 days after the audit runs.
About 90 days, then purged automatically.
We keep a record of your plan status while your account is active. Payment history itself lives with Stripe under their retention rules.
Your rights (GDPR + CCPA)
Whether you are in the EU, California, or anywhere else, we honor the following rights on request:
- →Access: Request a copy of all personal data we hold about you.
- →Correction: Ask us to correct inaccurate data (e.g., your name or email).
- →Deletion: Request that we delete your account and all associated data. We will complete verified deletion requests within 30 days.
- →Portability: Request a machine-readable export of your account data and audit history.
- →Opt-out of sale: We do not sell personal data. If that ever changes, you will have the right to opt out before it takes effect.
To exercise any of these rights, email hello@menuregistry.com from the address associated with your account.
Cookies
We use a single session cookie to keep you signed in. This cookie is HttpOnly, Secure, and SameSite=Lax. It contains an encrypted session token, not your email or any personally identifiable information in plaintext.
We use no third-party tracking cookies. There is no Google Analytics, no Meta Pixel, no advertising SDK, and no behavioral tracking on this site. We do not participate in any cross-site tracking network.
Changes to this policy
We will email registered users at least 30 days beforeany material change to this privacy policy takes effect. Minor clarifications (fixing typos, refining wording, etc.) may be made without advance notice, but the “last updated” date at the top will always reflect the current version. Continued use of the service after the effective date of a material change constitutes acceptance of the updated policy.
Governing law
This policy is governed by the laws of the State of California, USA, without regard to conflict-of-law principles.
Questions? Email hello@menuregistry.com.