Legal
Privacy Policy
Last updated
The short version. If you are a diner, you can read a menu without telling us anything at all. If you place an order you give us a first name and what you ordered, and we pass that to the restaurant serving you. If you run a restaurant with us, we hold your account details and your menu content.
We do not sell personal data, and we do not run advertising trackers. This summary is here to be read; the numbered sections below are the policy.
1. Who we are
Mellow Menu Ltd is a company registered in Ireland, and is the data controller for the personal data described in this policy where we decide how and why it is used. We trade as mellow.menu.
You can reach us about anything in this policy at privacy@mellow.menu. We have not appointed a Data Protection Officer, because we are not required to; questions go to that address and reach a person.
2. Our two roles
This is the most important thing to understand about how we handle data, because it decides who you should ask about what.
We are the controller for our own users
When a restaurant signs up, we decide how their account data, billing details and use of the product are handled. Ask us.
We are a processor for diners
When you scan a menu and order at a table, you are ordering from that restaurant, not from us. The restaurant decides what happens to your order and your details; we hold and move that data on their instructions, under a contract with them. If you want a copy of that data or want it erased you may ask us and we will help, but the restaurant is the controller and may need to make the decision.
3. What we collect
If you are a diner
- Nothing, if you only browse
- Reading a menu requires no account and no name.
- A first name, if you order
- You type it yourself at the order summary, so the restaurant and the people you are sharing a bill with can tell whose items are whose. A nickname works.
- Your order
- The items, quantities, notes, your table, and the order's status and totals.
- Allergen and dietary selections
- Only if you choose to use the filters. See section 5, which covers this separately because it deserves it.
- A contact detail, only if you ask for a receipt
- An email address or phone number you give us to send a receipt to, stored encrypted.
If you run a restaurant with us
- Account details
- Your name, email address and password, and your two-factor secret if you turn it on. Your name and email are encrypted in our database.
- Your business content
- Menus, items, prices, photographs, opening hours, tables, and the staff you invite.
- Billing
- Your plan and its status. Card details are handled by our payment providers and never reach our servers.
Everyone
- Technical data
- Your IP address, browser and device type, and the pages you view, in server logs and in our own usage counts.
4. Why we process it, and on what legal basis
- To take and serve your order — contract
- We cannot get your food to the right table without your first name, your items and your table.
- To run accounts and take subscription payments — contract
- For restaurants using the product.
- To keep the service working, safe and measurable — legitimate interests
- Error monitoring, fraud and abuse prevention, rate limiting, and counting how features are used so we can improve them. We use the least data that answers the question.
- To send you marketing — consent
- Only where you have ticked a box that was not pre-ticked. Every marketing email carries an unsubscribe link, and unsubscribing is honoured for good.
- To save a dietary profile — explicit consent
- See section 5.
- To meet legal obligations — legal obligation
- Tax and accounting records, and responding to lawful requests.
5. Allergen and dietary data
Allergen information is data about your health, and European law treats it as a special category needing stronger protection than an ordinary preference. We treat it that way.
You can filter a menu by allergen without an account, and those choices last only for that visit. If you are signed in you may also save a dietary profile so your filters follow you between restaurants. Saving that profile requires your explicit consent, asked for at the moment you save it, and the product will not store one without it.
You can switch a saved profile off, or delete it, at any time. Turning it off stops it being applied; deleting it removes it.
Please do not rely on our filters alone if an allergy is serious. Allergen information comes from the restaurant, kitchens change, and a filter is an aid rather than a guarantee. Tell your server.
6. How we use AI
We use third-party AI services to do specific jobs, and we would rather name them than leave it vague.
Menu and restaurant content
When a restaurant imports a menu from a photograph or a PDF, that file goes to Google Cloud Vision and to a large language model to be read. Menu text is sent to OpenAI or Google Gemini to write descriptions and suggest pairings, to DeepL to be translated, and to Google Gemini to generate item images. This is business content, not personal data.
Where a diner's data is involved
Two assistant features can involve your data. Where a restaurant uses our ordering assistant, your saved allergen exclusions are read so that it does not suggest something you cannot eat. Where a restaurant uses our message-drafting feature to follow up on an abandoned order, your first name may appear in the text sent to the model. Nothing else about you is sent, and we do not send payment details or contact details to any AI provider.
What we do not do
We do not use an AI model to make a decision that has a legal or similarly significant effect on you, and we do not permit our providers to train their models on the data we send them.
7. Cookies and analytics
We use a session cookie so the site knows you are signed in and can keep your order together while you add to it. It is necessary for the service to work, and there is no version of the product without it.
Your theme preference is kept in your browser's local storage. It never reaches us.
We count page views and feature usage ourselves, against a random identifier held in your session rather than against you. We do not run Google Analytics, or any advertising or cross-site tracking network.
One exception is worth naming: our marketing pages load a Calendly widget so prospective customers can book a demo, and Calendly may set its own cookies when it loads. That widget does not appear on the menus diners use.
8. Who we share it with
We do not sell personal data, and we never have. We share it in four situations.
- The restaurant you are ordering from
- Your first name, your items and any notes. That is the point of the order.
- Suppliers who run part of the service for us
- Hosting and databases (Heroku, in the European Union), file storage (Amazon Web Services), error monitoring (Sentry, in the European Union), payments (Stripe, Square or Razorpay, depending on the restaurant), email delivery, and the AI providers named in section 6. Each is bound by a contract limiting them to acting on our instructions.
- When the law requires it
- To comply with a legal obligation, or to protect our rights, our users or the public.
- If the business changes hands
- In a merger or acquisition, with notice to you and no reduction in the protection this policy gives.
9. Where your data goes
Our servers, our databases and our error monitoring are in the European Union.
Some of our suppliers are in the United States, principally the AI providers in section 6 and our payment providers. Where personal data reaches them, that transfer relies on the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the supplier.
10. How long we keep it
- Orders
- Kept while the restaurant needs them for its own records, and for as long as tax and accounting law requires, which in Ireland is six years.
- Restaurant accounts
- Kept while the account is open. An account created but never confirmed is deleted automatically.
- A saved dietary profile
- Kept until you delete it or close your account.
- Marketing consent
- Kept as the record that you opted in, and kept after you opt out so that we can honour that.
- Technical and security logs
- Kept for a short operational period and then deleted. Some are purged automatically after ninety days.
11. Your rights
Under the General Data Protection Regulation you have the right to:
- Access the personal data we hold about you, and get a copy.
- Correct anything inaccurate.
- Erase it, where we have no overriding reason to keep it.
- Restrict what we do with it while a dispute about it is resolved.
- Object to processing we base on our legitimate interests, and to direct marketing at any time.
- Portability: receive the data you gave us in a machine-readable form, and have it sent elsewhere.
- Withdraw consent at any time, where consent is what we relied on. Withdrawing does not undo what was lawful beforehand.
Write to privacy@mellow.menu and we will answer within one month. We do not charge for this. Where the data belongs to an order you placed at a restaurant, see section 2 — we may need that restaurant to decide, and we will tell you if so.
If you are unhappy with how we have handled your data you can complain to the Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, at dataprotection.ie. If you live elsewhere in the European Union you may complain to your own national authority instead.
12. How we protect it
Traffic to the site is encrypted in transit. Identifying fields, including names, email addresses and receipt contacts, are encrypted in our database rather than stored as plain text. Access to production data is limited to the people who need it, and where a member of our staff views an account on a restaurant's behalf that is recorded and shown on screen while it happens.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your rights we will tell the Data Protection Commission within seventy-two hours, and tell you without undue delay where the risk to you is high.
13. Children
The product is built for restaurants and their guests, and a menu is something anybody may read. We do not knowingly ask children for personal data, and we do not build profiles of them. An account for running a restaurant is for adults.
If you believe a child has given us personal data, write to privacy@mellow.menu and we will delete it.
14. Changes to this policy
We update this policy when the product changes. The date at the top is the date of the current version. Where a change materially affects your rights we will tell you, rather than relying on you noticing.
15. Contact us
Privacy questions and requests: privacy@mellow.menu.
Anything else: info@mellow.menu.
See also our Terms and Conditions and our Text and Data Mining Policy.
This policy is written in plain language on purpose. Where it summarises the law it is a summary and not a substitute for it, and nothing here limits a right you have under the General Data Protection Regulation.