MenuXpose

Cookie Notice

Published at: https://menuxpose.com/cookies · Version 1.1 (Early Access) · Effective 31 August 2026

Early Access

MenuXpose is in Early Access, and this is a live document. It describes what these pages actually set and store. It is also under external legal review, and the wording may be refined before general availability.

The rule we hold ourselves to is stated in §4, and it is the important part of this page: if we ever introduce something that is not strictly necessary, this notice changes before the product does.


This notice is short because we use very few cookies. That is a design decision, not an omission.

It covers menuxpose.com and the venue dashboard — the pages a venue operator uses. The notice written for a diner, covering the venue pages and xposego.com, is at xposego.com/cookies.


1. This website

menuxpose.com sets no cookies.

No analytics cookies. No advertising cookies. No tag manager, no pixel, and no third-party SDK.

One thing is stored on your device: if you switch the site's language, that choice is kept in your browser's own local storage so the page opens in the language you picked next time. It is browser storage rather than a cookie. That is a difference in mechanism and not in law — what matters is that something is kept on your device, so this notice covers it on the same terms. It is never sent to us, and clearing this site's data removes it.

One third party is involved in loading the page: our typefaces are served by Google Fonts (fonts.googleapis.com, fonts.gstatic.com). Google sets no cookie for this, but the request tells them your IP address and browser, as any request for a file does. We name it because "no third parties" would not be true, and a notice that overstates is worth less than one that does not.


2. The venue dashboard

The dashboard sets no cookies. Signing in does not set one, and nothing you do afterwards sets one either. We checked this rather than assumed it: the compiled dashboard contains no code that can read or write a cookie, and the API never sends one back.

It keeps a small number of things in your browser's own storage instead, which this notice covers on the same terms:

WhatPurposeTypeCleared when
Your sign-in tokenKeeps you signed in. It is sent as an Authorization header on each request, not as a cookieStrictly necessaryYou sign out, or clear this site's data
Your preferencesLanguage and display settingsFunctionalYou clear this site's data

Neither is used for advertising, and neither is shared with a third party for marketing.

Blocking cookies will not stop you signing in, because there is no sign-in cookie to block. Clearing this site's data will sign you out, because the token that keeps you signed in lives there.

They cannot reach a venue's public page

Everything above is held against the exact web address you are signed in to. Browser storage is bound to its origin by the browser itself, so it cannot be widened to cover a whole domain the way a cookie can — the separation is stronger here than it would be with cookies, not weaker.

Your customers' pages sit on a completely separate web address — on xposego.app, where nothing of ours signs anyone in. So a dashboard cookie cannot travel to a venue page, and a venue page could not read one if it did. That separation is enforced by the browser, not merely promised by us.


3. Your customers' pages

A venue's public page sets no cookies at all. No analytics cookies, no advertising cookies, no third-party scripts of any kind.

One exception, and it is not the live service. The preview hosts we use for demonstrations and testing sit behind an access gate, and that gate sets a single cookie — mx_gate — which carries the access key and nothing else. It is HttpOnly, Secure, and lasts 30 days. It is not set on a live venue page, it is never used for analytics or advertising, and it identifies an environment rather than a person. We name it because a reader who opens the developer tools on one of those hosts would otherwise find a cookie this notice says is not there.

This is why your customers do not see a cookie banner when they scan your QR code. There is nothing to consent to.

The page does keep a few things in the visitor's own browser storage — a basket, a language, a table session, and a random number that names that browser to your venue so a mid-meal reload does not lose their seat. None of it is a cookie, and that is a difference in mechanism rather than in law — browser storage is covered by this notice on the same terms, because what matters is that something is kept on the visitor's device.

The browser key is a persistent identifier, and we do not claim it is anonymous. United States privacy law treats a unique device or browser identifier as personal information even when no name is attached to it, and this one is no exception: its whole purpose is to recognise the same browser again. It is kept because it is strictly necessary to run an order — without it a mid-meal reload loses the seat and the basket — and for nothing else. It is not used to profile anyone, not used for advertising, and no other operator can read any of it — your own outlets share one address, and share what it stores. The full item-by-item list is at xposego.com/cookies.

One exception, and it is the payment page. If you have enabled payments and a customer chooses to pay, checkout runs on a separate payment route where Stripe sets cookies to detect fraud on the payment that customer just asked to make. Stripe acts as our service provider for that check. Those cookies are strictly necessary for security and fraud prevention, they are not used for advertising and not used to measure anyone across sites, and they exist only on that route. The payment cannot safely run without them. The menu page itself still sets none.

We also do not, anywhere:


4. Your choices, and what would have to change

We set no cookies on this site or on the dashboard, and the browser storage we do use is strictly necessary or functional. There is nothing here to opt out of.
Global Privacy Control. If your browser sends a GPC signal, we honor it. There is nothing on this site for it to switch off — we set no advertising or analytics cookies, and we do not sell or share personal information — so we honor it by default, permanently, and for everyone, whether or not it is sent (Privacy Policy §9). A reader who came here looking for that should not have to go to another page to find it.

You can block or delete cookies in your browser settings, and it will change nothing here — the dashboard has no sign-in cookie to block, and venue pages set none. What does have an effect is clearing this site's data, which removes the token that keeps you signed in and signs you out of the dashboard. Venue pages work perfectly either way.

If we ever introduce a cookie that is not strictly necessary or functional — anything for analytics, advertising, or measurement across sites — we will update this notice and ask for your consent before setting it, and we will record that consent, per purpose, with the ability to withdraw it at any time.


5. Contact

privacy@menuxpose.com

WayExpose, LLC · 1401 Pennsylvania Ave, STE 105 2394 · Wilmington, DE 19806 · United States