This policy explains what personal information That Menu App, LLC ("That Menu App", "we", "us") collects, why, who we share it with, how long we keep it, and what choices you have.
It applies to:
- our websites, including thatmenuapp.com and its subdomains;
- the restaurant menus we publish for restaurants, including menus you reach by scanning a code;
- the operator application that restaurants use;
- emails we send.
We serve three kinds of people, and this policy is organized around them:
- Restaurant operators — the businesses that subscribe, and the people who sign up and manage the account.
- Restaurant staff — people a restaurant enters into the service or invites to use it.
- Guests — people who read a restaurant's menu through That Menu App, with or without an account.
1. Who is responsible for your information
That Menu App, LLC is responsible for the personal information described in this policy. Our address is PO BOX 803, Keller, TX 76244, United States.
There is one exception. Information a restaurant enters about its own staff and guests belongs to the restaurant. For that information the restaurant decides what to collect and why, and we process it on the restaurant's behalf and under the restaurant's instructions. Section 8 explains this in more detail.
We do not sell personal information, and we do not share it for other companies' advertising.
2. Information we collect from restaurant operators
When you sign up we collect:
- your restaurant or business name, and the name of your first concept;
- the primary contact's name, contact email, and an optional phone number;
- the plan, billing period, modules and setup services you chose;
- any promotion code, and how you reached the signup page;
- whether you allow us to show your restaurant's name or logo in our marketing;
- your agreement to our Subscription Terms and Terms of Use, with the version you were shown and the date and time you agreed.
We save these details before you reach the payment step, so that you can finish signing up later. A saved signup draft is kept for 30 days.
Payment. Card and other payment details go directly to our payment processor. We never receive or store your full card number. We receive confirmation of payment and your subscription's status. Invoices are held by the processor and shown to you through its billing portal.
Your account. Your email address (used as your username), first and last name, a protected form of your password and any PIN (we store only a one-way hash, never the password itself), and email verification codes, which we also store only in protected form.
After purchase. To confirm the account belongs to you, we email a six-digit code to the contact address. The code expires after 30 minutes and is stored only in protected form.
Your restaurant's content. Concepts, locations (including postal addresses, map coordinates and time zones), menus, dishes, prices, recipes and ingredient lines, descriptors, allergen records and who confirmed them, allergen incident records, kitchen tickets, order requests, reservations, gift cards and integration settings. Most of this is business information rather than personal information, but some of it names people — for example, which staff member confirmed a dish's allergen record.
Photos, logos and other media you upload, which are stored with our hosting provider.
White-Glove Setup. If you order setup services, we collect the contact name, email and phone you give us and the menu materials you upload (documents, spreadsheets, PDFs, images or archives).
Support. When you use our contact form or email us: your name, email, phone if given, restaurant name and your message.
Administrative records. When our staff act on your account in our admin console, we record who did what and when.
Customers moving from our earlier platform. If your restaurant is being migrated from the earlier That Menu App platform, we read your account and menu data out of that platform's database during the migration window and copy it into this one.
3. Information a restaurant enters about its staff
A restaurant may enter its employees into the service. The restaurant, not the employee, gives us this information, and the restaurant is responsible for having the right to do so and for telling its staff about it.
This can include: display name, first and last name, email address, phone number, an address description, employment start and end dates, roles and assignments, and training records. Training records — challenge sessions and answers, badges and certifications earned — are performance records about a named person.
We use this information only to provide the service to the restaurant: to send an invitation, let the person sign in, and show the restaurant its own team's training and scheduling.
If you are a restaurant employee and want to see, correct or delete this information, ask your restaurant. You can also contact us (section 11) and we will work with the restaurant to answer you.
4. Information we collect from guests
You can read a restaurant's menu without giving us any personal information. What we collect depends on what you do.
Reading a menu, filtering it, and saving things on your device. When you choose allergens or dietary needs to filter a menu, save favorite dishes or menus, choose a language or area, or acknowledge our allergen notice, that information is stored in your own browser (local storage). It stays on your device until you clear your browser data. Opening a menu is recorded by our first-party analytics as described in section 5, and the page address appears in our server logs. If you type words into the menu search, those words are part of the page address and so appear in those logs too. If you choose to sign in, some of these preferences are also saved to your account (see below).
Creating a preference account. If you create an account so your preferences follow you between devices, we store:
- Your email address, in protected form only. We keep a scrambled form of your email that cannot be turned back into your email address, together with a masked version (for example,
j***@example.com) so we can recognize you and show you which address you used. We do not keep your email address in readable form. - Your first name, in readable form, so we can greet you.
- Your declared dietary and allergen preferences — each allergen or dietary term you tell us to avoid or look for, the language you entered it in, and any named preference sets you create. This is information about your health, and we treat it with extra care. It is used only to filter menus for you, it is never shared with restaurants or anyone else, and it is never used for advertising. You can ask us to delete it at any time (section 11).
- Your saved search terms, and your preferred language, currency, home country and region, and time zone.
- The version of the consent documents you accepted.
Verifying your email. When you create or sign in to a preference account we email you a link or code. We store the code only in protected form; the link expires after 24 hours.
Sending an order request or reservation to a restaurant. We keep the name you give in readable form so the restaurant can call your name. Your phone number and contact details are kept only in a protected form that cannot be turned back into the original; the readable values are not stored on our servers after the request is delivered. Anything you type into the special instructions box is passed to the restaurant exactly as you wrote it. Guests often write allergy notes there, so please write only what you want the restaurant to see.
Nominating a restaurant. If you ask us to bring a restaurant to That Menu App, we store the restaurant's name and area, your note, and protected forms of your email address and of your identity as the person who asked.
Loyalty accounts and gift cards. If a restaurant runs a loyalty program or sells gift cards through That Menu App, your membership and any card you buy are held against a protected form of the email address or phone number you give. You re-type that address or number to earn or redeem.
Reading a menu in another language. When you choose another language, the restaurant's menu text (dish names and descriptions) is sent to a machine-translation provider and translated. No information about you is sent with it. Safety wording is not machine-translated.
5. Information we collect automatically
First-party usage analytics. Our own analytics script runs on our public website, on the signup pages, and on published menus. It records which pages are viewed and which buttons are used. For each event we record:
- the page and its title;
- the referring website's domain, not the full address;
- your language, screen size, browser family, time zone and a country hint;
- campaign codes in the address, such as
utm_source; - a random visitor identifier that our script creates and stores in your browser;
- your IP address, stored only in a protected form that cannot be turned back into the original, never in readable form.
Email addresses, names, phone numbers and similar values are actively removed from these records. We honor the Global Privacy Control and Do Not Track browser signals: if either is set, no analytics events are sent. This analytics does not run on the restaurant operator application.
Server logs and error reporting. Our hosting provider records web requests, including your IP address in readable form, for security and troubleshooting. Our error and performance monitoring records request addresses, errors and timings, and may include identifiers that were part of the request. Section 10 gives the retention periods.
Cookies and local storage. Section 6 lists them.
Third-party content on some pages. Our pages load fonts from a font hosting provider, which receives your IP address and browser type when a page loads. Our videos page embeds videos from a video-hosting provider, which sets its own cookies when you watch. The payment step is served by our payment processor inside our page, and the processor sets its own cookies and collects its own fraud-prevention signals during checkout. Each of those companies handles that information under its own privacy policy.
We do not use advertising cookies, cross-site tracking, or third-party analytics services.
6. Cookies and local storage we use
Cookies. These are all first-party and strictly necessary; there is no advertising cookie.
| Cookie | Where | Purpose |
|---|---|---|
ARRAffinity, ARRAffinitySameSite | All our sites | Keeps your session on the same server so pages work correctly. Set by our hosting provider. |
.AspNetCore.Antiforgery.* | Forms | Protects forms against forged submissions. |
__Host-tma_surface | Operator application | Keeps a signed-in operator signed in. |
__Host-tma_issuer_session, __Host-tma_mfa_pending | Sign-in service (login.thatmenuapp.com) | Runs the sign-in flow. |
tma-app-access-token | Early-access pages | Remembers that you entered an access code. |
Local storage is data your browser keeps for our site. We use it so the menu app works quickly and so most of your choices never leave your device. Keys we use include:
- Consent: a key holding the current document version, showing that you accepted the current Terms of Use, Privacy Policy and Allergen Notice, and a second key showing that you acknowledged the allergen notice.
- Menu app: your chosen allergen and dietary filters, favorites, saved and recent menus, recent searches, recent orders, your area and language, an avatar choice, and a protected slot holding your signed-in account details.
- Site display: theme, navigation state, language choice, dismissed announcements, and values that help the site reload cleanly after an update.
- Analytics: a random visitor identifier and a per-day event counter.
You can clear local storage and cookies through your browser settings. Clearing the consent keys means you will be asked to accept our documents again the next time you open a menu.
7. Why we use information and on what basis
| Purpose | Information used |
|---|---|
| Create and run restaurant accounts, publish menus, provide add-on modules | Operator, staff and restaurant content |
| Take payment and prevent fraud | Signup and payment confirmation details |
| Filter menus for a guest according to their needs | Guest dietary and allergen preferences (on device, or in the guest's own account) |
| Deliver an order request or reservation to a restaurant | Guest name, protected contact details, and the special instructions the guest wrote |
| Run a restaurant's loyalty program or gift cards | Protected form of the guest's email address or phone number |
| Tell a restaurant that guests have asked for it | Restaurant nomination details |
| Show a menu in the guest's language | Restaurant menu text |
| Send the emails the service needs: verification codes, account setup, welcome, staff invitations, password resets | Contact email addresses |
| Answer support requests | Support form contents |
| Keep the service secure, find and fix faults, meet legal duties | Logs, error reports, audit records |
| Understand how our website and menus are used | First-party usage analytics, with protected IP address |
Where a law requires a legal basis, we rely on: performance of our contract with the restaurant or the guest; our legitimate interests in running, securing and improving the service; your consent, for guest dietary and allergen preferences and for marketing use of a restaurant's logo; and legal obligation, for records we must keep.
8. Restaurants and their own guests and staff
When a restaurant publishes its menu through That Menu App, guests interact with us directly, and we are responsible for the information described in section 4. We do not give restaurants a guest's dietary or allergen preferences, email, or account details.
When a guest chooses to send a restaurant an order request or reservation, the restaurant receives what the guest sent, including the special instructions the guest wrote, and is responsible for it from then on.
When a restaurant enters information about its staff, or records an allergen incident that describes a guest, the restaurant decides what to record and is responsible for it. We process it only to provide the service. Our Subscription Terms require restaurants to handle this information lawfully.
9. Who we share information with
We share personal information only with service providers who work for us, and only as needed to run the service. They may use it only for that purpose. By category:
- Payments — Stripe, Inc. (United States), which processes subscription payments and issues invoices. It receives the buyer's name, email, phone if given, payment details and the plan chosen.
- Hosting and database — Microsoft Azure (Microsoft Corporation), in the United States. All of our servers, databases, file storage and secret storage run there.
- Email delivery — Azure Communication Services (Microsoft Corporation), United States data location, which sends the emails described in section 7.
- Monitoring and error reporting — Azure Monitor / Application Insights (Microsoft Corporation), United States.
- Translation — Google Cloud Translation (Google LLC), which receives restaurant menu text for machine translation. It does not receive information about guests.
- Maps — Google Maps Platform (Google LLC), which receives restaurant addresses to find their coordinates and time zones. It does not receive guest information.
- Fonts and video — Google Fonts and YouTube (Google LLC), which receive your IP address and browser details when a page or video loads.
We may also share information: with a restaurant, as described in section 8; when the law requires it or to protect the rights and safety of guests, restaurants, our staff or the public; and with a buyer of our business, who must honor this policy.
We do not sell personal information and have not done so. We do not share it for cross-context behavioral advertising.
10. How long we keep information
Some of the periods below are limits we apply by hand rather than automatically. Where that is so, the table says "up to".
| Information | How long |
|---|---|
| Restaurant account and content | While the subscription is active, then 30 days so the restaurant can ask for an export or restart, then deleted, or anything that identifies the restaurant removed. We do this by hand on request or on review. |
| Allergen confirmation and incident records | Up to 3 years after the subscription ends, because they may be needed for safety or legal reasons. |
| Invoices and payment records | 7 years, as required for tax and accounting. Held by our payment processor. |
| Unfinished signups | The saved draft is kept for 30 days and then treated as expired. We delete expired drafts when we next review them. |
| Verification codes and links | 30 minutes for post-purchase codes; 24 hours for guest email links. |
| Guest preference account | Until you ask us to delete it. Your device's local storage is under your control. |
| Order requests and reservations | While the restaurant's subscription is active, and then as restaurant content above. |
| Support requests | Up to 3 years. |
| Administrative audit records | Up to 2 years. |
| Usage analytics | Each event is stamped to expire 90 days after it is recorded, and expired events are removed when the cleanup runs. |
| Web server logs | 30 days for request logs; 3 days for detailed diagnostic logs. |
| White-Glove Setup materials | While the subscription is active, then up to 12 months, unless we are legally required to keep them longer. We delete them by hand. |
| Backups | Rotate on a fixed schedule; a deleted record leaves backups when they expire. |
11. Your rights and choices
Depending on where you live, you may have the right to:
- know what personal information we hold about you and receive a copy;
- correct it;
- delete it;
- receive it in a portable format;
- limit how we use sensitive information — for guests, your dietary and allergen preferences;
- opt out of sale or sharing (we do neither);
- not be treated differently for exercising these rights; and
- appeal if we refuse a request.
How to exercise them. Use our privacy request form, or email legal@thatmenuapp.com or write to the address in section 16. Tell us which right you are exercising and, for a guest account, the email address you used.
We will confirm your identity first. For a guest account we do that by sending a code to that email address. We will answer within 45 days. If we need longer, we will tell you, and we may take up to 45 more days.
You may ask someone to act for you if you give them written authority; we will still confirm your identity with you. If we refuse, we will say why, and you can appeal by replying to our answer. We will respond to an appeal within 45 days. If you are still unhappy, you can contact your state's Attorney General or privacy regulator.
Restaurant staff and guest data entered by a restaurant. We will pass your request to the restaurant, or act on it together with the restaurant, and tell you which.
Guest preferences on your device can be cleared at any time from your browser settings, without contacting us.
Marketing emails. We send only the emails the service needs. If we ever send marketing email, each one will include an unsubscribe link.
Do Not Track and Global Privacy Control. We honor both signals: when either is set, our analytics does not run.
12. Children
Our service is for adults and businesses. We do not knowingly collect personal information from anyone under 16. A restaurant's menu can be read by anyone without providing any information. A guest preference account is not intended for anyone under 16. If you believe a child under 16 has given us personal information, email legal@thatmenuapp.com and we will delete it.
13. Where information is stored and international transfers
All of our systems are in the United States, and our service providers process information there. If you use the service from outside the United States, your information is transferred to and stored in the United States, where privacy law may differ from your country's. We take the steps described in section 14 to protect it wherever it is.
14. Security
We protect information with measures that include:
- encryption of all traffic between your browser and our servers;
- one-way hashing of passwords and PINs, of guest email addresses and sign-in identifiers, of guest phone and contact details on order requests, and of IP addresses in our analytics, using keys kept in a separate secret store so that a copy of the database alone cannot reverse them;
- never receiving or storing full card numbers — payment details go straight to our payment processor;
- access controls that limit our staff to what their role needs, and a record of administrative actions;
- regular backups and monitoring for faults and attacks.
No system is perfectly secure. If we learn of a breach that affects your personal information, we will tell you and any regulator as the law requires.
15. Changes to this policy
We may update this policy. When a change is important for guests, the next time you open a menu you will be asked once to review and accept the current version. When a change is important for restaurant operators, we will email the account owner before it takes effect. Every version carries its version number and "Last updated" date at the top, and the current version is always at thatmenuapp.com/privacy-policy. We review this policy at least once every twelve months.
16. Contact
That Menu App, LLC Privacy team PO BOX 803, Keller, TX 76244, United States Email: legal@thatmenuapp.com