Privacy Policy
Last updated 9 October 2026
MenuHub is a platform that lets restaurants publish a QR menu, take orders and payments, run a POS and a kitchen screen, and keep in touch with their guests. This policy explains what personal data we handle, why, who we share it with, and the choices you have. It is written with Law No. 13 of 2016 on Personal Data Privacy Protection of the State of Qatar in mind.
- Operator: [Company legal name]
- Registered address: [Registered address, Qatar]
- Commercial registration number: [CR number]
- Contact email: [Contact email]
1. Who is responsible for your data
There are two groups of people in MenuHub, and our role is different for each.
- Restaurant owners, managers and staff who use MenuHub. For their account data we decide why and how it is used, so we are the controller.
- Guests of a restaurant who scan its QR menu, order, join its loyalty club or leave feedback. For their data the restaurant is the controller: it decides why guests' data is collected and how it is used. MenuHub only processes that data on the restaurant's behalf and on its instructions.
If you are a guest and want to see, correct or delete what a restaurant holds about you, ask the restaurant first. You can also write to us and we will pass the request on or help the restaurant act on it.
2. What we collect from restaurant owners and staff
- Account details: name, email address, password (stored only as a one-way hash), staff ID and role, and the language you use.
- Business details: restaurant and branch names, address, phone, logo and photos, menus, prices, tax settings, opening hours and the settings you choose.
- Subscription and billing details: your plan, trial dates and invoices. Subscription payments are handled by Lemon Squeezy (our reseller and merchant of record) or Stripe, so we never see or store your full card number.
- Activity records: sign-in times, an audit log of actions taken in the dashboard and POS, and technical data such as device type, browser and IP address, used to keep the service secure and working.
- Product analytics on the business dashboard (see Cookies and analytics below).
3. What we process about guests, for restaurants
- Contact details: name and mobile number, after the guest verifies the number with a one-time code. An email address or birthday only if the guest or the restaurant adds it.
- Orders: items, notes, table or pickup details, amounts, tips, payment status and receipts.
- Loyalty: points, tier and visit history with that restaurant.
- Feedback: ratings and comments a guest chooses to leave.
- Preferences recorded by the restaurant, such as language, allergies or dietary needs the guest has asked it to remember.
- Marketing choice: whether the guest agreed to receive offers, and when.
Guests can browse a restaurant's menu without creating an account or giving us any personal details. Card details are entered on the payment provider's page and never reach MenuHub.
4. How we use data
- To provide the service: show menus, take and route orders, process payments, run loyalty and send order or verification messages.
- To keep accounts and payments secure, prevent fraud and abuse, and fix problems.
- To support restaurants and answer your questions.
- To understand how the business dashboard is used and improve it. We do not do this on guest pages.
- To meet legal obligations.
We do not sell personal data and we do not use guests' data for our own marketing.
5. Marketing messages
A restaurant can send offers to a guest by WhatsApp or SMS only if the guest agreed to receive them. The box that asks for this is never ticked for you. Order updates and one-time verification codes are service messages, not marketing.
To stop offers, reply STOP to any message, or switch the setting off in the loyalty card on the restaurant's menu page. You can also ask the restaurant to remove your consent. Withdrawing consent does not affect messages already sent.
6. Service providers we use
We share data only with providers that help us run MenuHub, and only what each one needs:
- Tap Payments and MyFatoorah: card payments for guest orders.
- Lemon Squeezy (our reseller and merchant of record) and Stripe: subscription payments from restaurants.
- Twilio and Meta (WhatsApp): sending SMS and WhatsApp messages, including verification codes and offers.
- Cloudflare R2: storing images such as logos and dish photos.
- Neon: our database.
- Render and Vercel: hosting the application and website.
- Resend: sending email, such as password reset links.
- PostHog: product analytics on the business dashboard and public website only, not on guest pages.
We may also disclose data when the law or a competent authority requires it, or to protect the rights and safety of users and of MenuHub.
7. Where data is stored
Some of these providers store or process data outside Qatar. When we use them we rely on written agreements and security measures intended to give your data a level of protection consistent with the law.
8. How long we keep data
- Restaurant accounts: while the account is active and for [retention period after closure, e.g. 12 months] afterwards, unless we must keep records longer for accounting or legal reasons.
- Guest records (contacts, loyalty, feedback): for as long as the restaurant keeps them, unless the guest or restaurant asks for deletion earlier.
- Orders and payment records: as long as accounting, tax and dispute rules require.
- Verification codes expire within minutes. Password reset links work for 30 minutes and only once.
- Backups are overwritten on a regular cycle.
9. Your rights
Under Qatari law you can ask to access your personal data, have it corrected, withdraw consent, object to its processing in certain cases, and ask for it to be erased. To make a request, email [Contact email] from the address or phone number linked to your account and tell us what you want. We may ask you to confirm your identity first, and we aim to reply within 30 days.
You can also complain to the National Cyber Governance and Assurance Affairs (NCGAA) or the other competent authority in Qatar.
10. Security
We protect data with encrypted connections, hashed passwords, role-based access, limits on repeated sign-in attempts, an audit log and restricted access to production systems. No system is completely secure. If a breach is likely to harm you, we will tell you and the relevant authority as the law requires.
MenuHub support may open a restaurant's account to help with a support request. Access is read-only unless the restaurant owner allows support to make changes for a limited time from their settings, and every access is logged and visible to the owner.
Keep your password private. If you think someone else knows it, change it in the dashboard, which also signs out your other devices.
12. Changes to this policy
We may update this policy. The date at the top shows when it last changed. If a change is significant we will tell restaurant owners by email or in the dashboard.
13. Contact
Questions or requests about privacy: [Contact email]. Postal address: [Registered address, Qatar].