Privacy Policy
How we collect, use, and protect your personal information.
Effective date: 24 September 2026
1. Who is responsible
The controller responsible for processing personal data on this website and in our services is Smart Menu Solutions (owner: George Tsiafitsas), Greece. Further business details are given in the Imprint. You can reach us at any time at info@smartmenusolutions.com. We have not appointed a Data Protection Officer, as we are not legally required to do so.
2. Scope
This policy explains how we handle personal data of:
- visitors of smartmenusolutions.com,
- people who contact us,
- our customers (restaurants, bars, cafés, hotels and the people acting for them) who order or use our digital QR menus and add-ons,
- guests who open a QR menu of one of our customers or order through it, and staff who use our ServiceHub screens,
- businesses we may contact about our services (see section 9).
3. Visiting our website
Our website and the QR menus are hosted on GitHub Pages (GitHub, Inc., USA). When you open a page, your browser automatically transmits technical data such as your IP address, the date and time of the request, the page requested, browser type and operating system. GitHub processes this data to deliver the pages and to protect its service against abuse, and may keep it in server logs for a limited period. We do not use this data to identify you.
Legal basis: our legitimate interest in a secure and reliable website (Art. 6(1)(f) GDPR).
Fonts and images of our website are served from our own domain; your browser does not contact Google or other font services. We do not use analytics, tracking pixels or advertising cookies.
4. Contact form and email
If you use our contact form, we process your name, email address and message. The form is sent to a server function of ours at Supabase, which forwards it to our mailbox as an email via Resend; the message itself is not stored there. Our mailbox is provided by Microsoft (Outlook.com). The same applies if you email us directly.
We use this data only to answer your request. Legal basis: taking steps at your request before entering into a contract, or performing a contract (Art. 6(1)(b) GDPR), otherwise our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). We delete enquiries once they have been dealt with, unless they lead to a contract or we must keep them for legal reasons.
5. Orders, subscriptions and payments
When you order a plan or renew your subscription, we process:
- first and last name, email address, and optionally company name and phone number,
- the selected plan and add-ons, order and subscription details (dates, status, amounts),
- the menu file (PDF) and, if booked, the photo archive you upload,
- payment details, which are handled directly by Stripe (Stripe Payments Europe, Ltd., Ireland). We never see or store your full card number; Stripe only tells us whether a payment succeeded.
Order, customer and subscription data and uploaded files are stored with Supabase (Supabase, Inc.), which provides our database, file storage and server functions. Order confirmations, payment notices and renewal reminders are sent by email through Resend (Resend, Inc., USA).
Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and our legal obligations under tax and commercial law (Art. 6(1)(c) GDPR). We keep this data for the duration of the customer relationship; invoices and accounting records are kept for the periods required by Greek tax law and then deleted.
6. Using the Menu Builder and add-ons (customers)
To create and run your digital menu we store the content you or we enter for your business: business name, address, phone and WhatsApp number (if provided), logo, menu items, prices, descriptions and photos. This content is published on your public menu page, so menu photos and logos are publicly accessible by design.
- Automatic translation: to translate menus into other languages, menu texts are sent to DeepL (DeepL SE, Germany) or MyMemory (Translated srl, Italy). Please do not put personal data into menu texts.
- QR codes: QR code images for your menu and tables are generated by goQR.me (api.qrserver.com, Germany), which receives only the web address the code points to.
- Smart WeeklyReport™: if booked, we send you a weekly email with anonymous visit statistics for your menu (see section 7).
Legal basis: performance of the contract (Art. 6(1)(b) GDPR). The data is deleted when the contract ends, unless we must keep it for legal reasons.
7. Guests using a QR menu
Guests do not need an account and we do not ask for their name or contact details.
- Viewing a menu: the menu is loaded from our database. Apart from the technical data described in section 3, no personal data is collected.
- Smart WeeklyReport™: if a venue has booked it, the menu counts anonymous, aggregated visits per category and dish (for example “12 visits, 3 views of Starters”). No cookies, no IP addresses and no visitor identifiers are stored.
- Smart ServiceHub™ (ordering at the table): if a venue uses it, the items, quantities and notes a guest orders are processed in real time and routed to the venue’s kitchen, bar, service and cashier screens. An order is linked only to the table and to a random session code stored in the guest’s browser – never to a name. Please do not enter personal data in order notes.
For guest orders and statistics, the venue is the controller and we process the data on its behalf as a processor (Art. 28 GDPR, see our Terms of Service). Order data is kept as part of the venue’s order history until the venue deletes it or its contract with us ends. Guests can contact the venue or us to exercise their rights.
8. Staff screens (ServiceHub)
Kitchen, bar, service and cashier screens are opened with a secret link. We do not collect staff names or accounts; the screens only store the chosen language and display settings in the browser of the device.
9. Business contacts we may reach out to
To offer our services to restaurants and similar businesses, we may compile publicly available business information: business name, address, phone number, website and a business email address. We obtain it from the businesses’ own websites and from map services (TomTom, TomTom International BV, Netherlands; OpenStreetMap data services). Legal basis: our legitimate interest in business-to-business marketing (Art. 6(1)(f) GDPR). You can object to this at any time by emailing us; we will then stop contacting you and delete your data, keeping only what is needed to respect your objection.
10. Browser storage and cookies
We do not use cookies for tracking or advertising. Some functions store small amounts of data in your browser’s local storage because they are technically necessary:
- the selected language,
- on QR menus with ordering: the shopping cart and the random order session code of your table,
- on staff screens: language and which ready items have already been seen,
- on the Menu Builder: the login session of our administrator,
- for the installable app version (PWA): a copy of the pages and menu so they open without a connection.
This storage is strictly necessary for the service you request and therefore does not require consent (Art. 5(3) ePrivacy Directive). You can delete it at any time in your browser settings. More in our Cookie Policy.
11. Script library (jsDelivr)
The order and renewal pages, QR menus with ordering and the staff screens load a program library (supabase-js) from the content delivery network jsDelivr. Your browser transmits its IP address to jsDelivr in the process. Legal basis: our legitimate interest in reliable, fast delivery of these functions (Art. 6(1)(f) GDPR).
12. Recipients and service providers
We only share personal data with service providers we need to run our website and services. Where they process data on our behalf, this is governed by their data processing terms:
- GitHub, Inc. (USA) – website and menu hosting
- Microsoft Corporation (USA / EU) – email mailbox
- Spaceship, Inc. (USA) – forwarding of emails sent to our @smartmenusolutions.com addresses to our mailbox
- Supabase, Inc. – database, file storage, server functions (including the contact form)
- Stripe Payments Europe, Ltd. (Ireland) – payments
- Resend, Inc. (USA) – sending emails (including contact form messages to us)
- jsDelivr – delivery of a program library
- DeepL SE (Germany) and Translated srl / MyMemory (Italy) – menu translation
- goQR.me (Germany) – QR code images
- TomTom International BV (Netherlands) and OpenStreetMap data services – business search (section 9)
We do not sell personal data.
13. Transfers outside the EU
Some of these providers are based in the USA or may process data there. Such transfers take place on the basis of the EU-U.S. Data Privacy Framework where the provider is certified, and otherwise on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
14. Security
All connections are encrypted (HTTPS). Access to customer data is restricted to our administrator account, which is protected by a password and a second factor (authenticator app). Staff screens and table ordering links use long random secret codes.
15. Your rights
Under the GDPR you have the right to:
- access your data (Art. 15),
- have incorrect data corrected (Art. 16),
- have your data deleted (Art. 17),
- restrict processing (Art. 18),
- receive your data in a portable format (Art. 20),
- object to processing based on our legitimate interests, including direct marketing, at any time (Art. 21),
- withdraw consent you have given, with effect for the future (Art. 7(3)).
To exercise your rights, email info@smartmenusolutions.com. We may need to verify your identity before answering.
You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Our lead authority is the Hellenic Data Protection Authority, Kifisias 1–3, 115 23 Athens, Greece, www.dpa.gr. You may also contact the authority in the EU country where you live or work.
16. Required data and automated decisions
You do not have to provide personal data to visit our website. To order our services we need the data marked as required in the order form; without it we cannot conclude the contract. We do not use automated decision-making or profiling.
17. Marketing emails
We only send marketing emails with your consent or, to existing customers, about similar services of our own, where permitted by law. You can unsubscribe at any time using the link in the email or by writing to us.
18. Residents of the United States
If you live in a U.S. state with its own privacy law (for example California), you may have additional rights to know, correct and delete your personal information and to not be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioural advertising. Send requests to info@smartmenusolutions.com.
19. Changes to this policy
We update this policy when our services or legal requirements change. The current version is always available on this page; the effective date is shown at the top.