Privacy Policy
Effective: June 1, 2025
Menuella (hereinafter “Menuella”, “we”, “us” or “our”) takes the protection of your personal data very seriously and processes it in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG). This Privacy Policy applies to all services provided by Menuella, including the platforms menuella.link, menuella.site, menuel.la, mnel.la and all associated applications (collectively, the “Services”).
As a provider of a software-as-a-service (SaaS) service, we act in two roles that must be distinguished under data protection law (see section 2).
1. Data Controller
The controller within the meaning of the GDPR for data processing where Menuella determines the purposes and means of processing alone is:
Menuella
represented by: Nuh Kayran
Sulgauer Str. 28,
78713 Schramberg
Email: privacy@menuella.com
Data Protection Officer
We have not appointed a Data Protection Officer, as we are not legally required to do so under Art. 37 GDPR or § 38 BDSG (the applicable thresholds are not met). For any questions about this Privacy Policy or to exercise your data protection rights, you can reach our data protection contact at privacy@menuella.com.
2. Menuella’s Roles Under Data Protection Law (Controller vs. Processor)
Menuella acts in two different roles:
2.1 Menuella as controller (Art. 4 no. 7 GDPR)
Menuella is the controller for processing personal data that is required to process the contractual relationship with you as a customer (e.g. your name, email address and billing details). This processing is covered by this Privacy Policy.
2.2 Menuella as processor (Art. 28 GDPR)
Where you, as our customer, use the platform to process personal data of your own end customers/guests (e.g. order data, location information and the email addresses of people placing orders), Menuella acts as your processor. Processing this end-customer data is not governed by this Privacy Policy. Instead, it is governed by a separate data processing agreement (DPA) between you (as controller) and Menuella (as processor), which is a mandatory part of the service agreement.
3. Collection and Processing of Our Customers’ Data
We process the following categories of personal data from you as our direct customer:
- Contact data: name, form of address, business email address, telephone number and company/location address.
- Contract data: selected subscription plan, contract start and end dates, and billing address.
- Payment data: bank details or credit-card data for payment processing (usually transmitted in encrypted form directly to the payment provider).
- Usage and log data: IP address, browser type, login/usage time and API activity to ensure security and functionality.
Legal bases and purposes of processing
We process your data on the following legal bases:
- Performance of the contract and pre-contractual measures (Art. 6(1)(b) GDPR):
- Creating, administering and terminating your customer account.
- Providing the services and platform features you have booked.
- Processing payments and issuing invoices.
- Our legitimate interests (Art. 6(1)(f) GDPR):
- Ensuring IT security (e.g. logging access and implementing 2FA).
- Improving our services and analysing usage.
- Direct advertising where legally permitted.
- Compliance with legal obligations (Art. 6(1)(c) GDPR):
- Complying with commercial and tax-law retention obligations.
4. Security: Two-Factor Authentication (2FA)
We have implemented two-factor authentication (2FA) to provide additional protection for your accounts and data. Using 2FA helps us meet our obligation to ensure the security of processing (Art. 32 GDPR) and is in our legitimate interest (Art. 6(1)(f) GDPR) to prevent unauthorised access to customer data.
5. Disclosure to Third Parties and Processors
We transfer your personal data to third parties only where this is necessary for performance of the contract (Art. 6(1)(b) GDPR), based on a legitimate interest (Art. 6(1)(f) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR). All processors named below are bound by data processing agreements under Art. 28 GDPR; the relevant provider’s privacy policy is linked below. A detailed list of the cookies and SDKs set can be found on our “Technologies & Cookies” page.
Infrastructure & security
- Google Cloud Platform (EU · Frankfurt & Belgium) — hosting, compute and storage infrastructure for all Menuella services.
- Cloudflare (US · Standard Contractual Clauses) — content delivery network, DDoS protection and CAPTCHA.
Authentication
- Auth0 by Okta (EU) — merchant sign-in, session management and two-factor authentication.
Support & consent management
- Intercom (EU) — support chat and CRM for merchant and operator teams.
- Menuella consent management — we manage your cookie settings ourselves (first-party). Your choice is stored in your browser and in a minimal server-side record; no external consent provider is used.
Payments
- Stripe (EU) — card payment processing and PCI-DSS compliance. Stripe offers additional payment methods at checkout (e.g. Link, Apple Pay, Google Pay and Klarna); these are subject to Stripe’s Privacy Policy.
- PayPal (EU) — PayPal payment processing.
Analytics & monitoring
- PostHog (EU Cloud) — product analytics, loaded on menuella.com only after consent.
- Sentry (EU) — error monitoring and crash reporting.
- Google Analytics & Tag Manager (EU) — website analytics on menuella.com, loaded only after consent.
Maps & real-time
- Apple MapKit JS (US · Standard Contractual Clauses) — delivery-area maps in the merchant dashboard.
- Google Maps Platform (EU) — address search and geocoding for setting up locations.
- Microsoft Azure SignalR (EU) — real-time order notifications in the merchant dashboard.
Marketing & advertising (consent-only, menuella.com only)
The following providers are used for audience building and ad measurement. They receive data only if you have expressly consented via the cookie banner on menuella.com:
As part of our legal obligations (Art. 6(1)(c) GDPR), we may be required to disclose information to authorities or courts. Transfers to third countries (outside the EU/EEA) take place only where the legal requirements are met, in particular through the conclusion of EU Standard Contractual Clauses (SCCs).
6. Cookies and Tracking Technologies
We use cookies and similar technologies throughout the Menuella ecosystem. They can be divided into four categories:
- Technically necessary — security, session management and your privacy settings. These cannot be deactivated. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
- Functional & preferences — language, currency, theme and support chat. These are activated when you use the relevant feature. Legal basis: Art. 6(1)(f) GDPR.
- Analytics & performance — product analytics (PostHog) and error monitoring (Sentry). These are loaded only after your express consent (Art. 6(1)(a) GDPR).
- Marketing & advertising — advertising pixels from Google, Meta, Pinterest, TikTok and Microsoft. These are loaded only after your consent and used exclusively on Menuella’s own sites, not on customer storefronts (Art. 6(1)(a) GDPR).
A complete overview of all cookies, SDKs and third parties used — including their purpose, storage period and the parts of the Menuella ecosystem in which they are used — can be found on our “Technologies & Cookies” page. You can adjust or withdraw your consent at any time via Privacy settings in the website footer.
7. Your Rights as a Data Subject (GDPR)
With regard to data for which Menuella acts as controller (see section 2.1), you have the right at any time to:
- Access the data we process (Art. 15 GDPR).
- Request correction of inaccurate or incomplete data (Art. 16 GDPR).
- Request erasure of your data (“right to be forgotten”) (Art. 17 GDPR), unless statutory retention obligations apply.
- Request restriction of processing (Art. 18 GDPR).
- Receive your data in a structured, commonly used format (data portability) (Art. 20 GDPR).
- Object to processing (right to object) (Art. 21 GDPR).
- Lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular in your habitual place of residence or at our registered office.
You may withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
8. Data Retention and Erasure
We store your personal data only for as long as necessary to fulfil the purpose of the contract. After the contractual relationship ends, we delete your data unless statutory retention obligations prevent this. Such obligations arise in particular from:
- Commercial law: retention periods of 6 years (§ 257 HGB).
- Tax law: retention periods of 10 years (§ 147 AO).
Erasure takes place after these periods expire. Immediate erasure under Art. 17 GDPR (“right to be forgotten”) is possible only where none of these statutory obligations or a legitimate interest on our part (e.g. asserting legal claims) prevents it.
9. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy to reflect changed legal requirements or changes to our services. Customers will be informed of changes in advance within a reasonable period and the changes will be published on our website. The current version is available on our website at any time.


