Early Access
MenuXpose is in Early Access, and this is a live document. It describes what we collect today. Where a statement here would have been favourable to us and inaccurate, it has been removed rather than qualified. Every claim in this policy is intended to be verifiable against what the service actually does.
It is also under external legal review. We expect the wording to be refined before general availability. Material changes are notified by email and in the app at least 30 days before they take effect (§12), and the version and date above always identify the text in force.
If anything here is unclear, or you believe it inaccurately describes our practices, contact
privacy@menuxpose.com. We will correct it and record the change under §12.
MenuXpose is operated by WayExpose, LLC, a limited liability company formed in Delaware, United States ("we", "us", "our"). Our address is at §13.
This policy explains what personal data we collect, why, and what you can do about it. We have tried to write it so it can actually be read.
If you are a diner or visitor rather than a venue operator, the policy written for you is at xposego.com/privacy. This one is written for the person who runs the venue.
1. Three kinds of people
This policy covers three groups, and what we hold about each is very different.
| Who | What we hold | |
|---|---|---|
| Venue owners | You have an account and a venue page | An account's worth of information |
| Venue staff | Someone invited you to help run a venue you do not own | Your name, your email, and a log of what you did in the app |
| Visitors | You scanned a QR code or opened a venue's link | Almost nothing — no account, no cookie, and nothing that identifies you |
If you are staff, §2a is written for you, and the part you are most likely to want is the last paragraph of it. If you are a visitor, §4 is the short version, and the full one is at xposego.com/privacy.
2. What we collect from venue owners
You give us
| Data | Why | Business purpose |
|---|---|---|
| Email address | Your account, and to contact you | Performing our contract with you |
| Name | Your account | Performing our contract with you |
| Phone number | Shown on your venue page if you choose | Performing our contract with you |
| Venue name, address, location | Your public page and the directions link | Performing our contract with you |
| Photos you upload | Your public page | Performing our contract with you |
| Menu content and prices | Your public page | Performing our contract with you |
| Opening hours | Your public page | Performing our contract with you |
| Country | Determining whether we operate where you are | Performing our contract with you |
| The location you drop on the map | Turning a pin into a street address for your page and its directions link | Performing our contract with you |
Your photos and videos are stored with Cloudflare, not on our own servers — see §6 and §7. They are meant to be public, because they go on your page. A photograph of your dining room can still catch a member of staff or a customer, so it is worth knowing where it is held.
If you use the 3D menu add-on
If your venue is on Elite and you buy the 3D menu add-on, a dish photo you choose is sent to a specialist provider that runs the graphics hardware which turns it into a 3D model. The photo is processed for the length of that job and the resulting model is stored with your other media. It is your dish and your photograph — we add nothing to it and use it for nothing else.
The add-on is not on sale yet. This paragraph describes it for the day it is.
Created when you use the service
| Data | Why | Business purpose |
|---|---|---|
| Login times, device type, app version | Security and support | Detecting security incidents |
| Actions in the app | Improving the product | Internal research and product improvement |
| Errors our systems record | Fixing problems | Maintaining and repairing the service |
If you subscribe
Payment is handled by Stripe. We receive confirmation that payment succeeded — we never receive or store your card number or any other detail of the card.
If you sign in with Google or Apple
From Google we receive your email address, name, and profile picture. Nothing else, ever.
From Apple we receive your email address — or, if you chose to hide it, the private relay address Apple creates for you — and your name if you shared it. We also hold the credential Apple requires us to keep so that, when you delete your account, we can tell Apple to revoke the sign-in.
2a. What we collect from venue staff
If a venue invited you, the venue is in charge of your data here and we are not. They chose to add you, they decide what you can open, and they can remove you. We hold your data on their instructions — in the language United States privacy laws use, the venue is the business and we are its service provider (elsewhere the same split is called controller and processor). That is the same split that applies to the venue's customers, and it is worth saying plainly because the person who invited you may not have said it.
| What we hold | Why | How long |
|---|---|---|
| Your name and email | To let you sign in and to show the owner who is on their team | Life of the account + 30 days |
| What you can open — the permissions the owner gave you | To enforce them | Life of the account + 30 days |
| Your activity log — what you changed and when | So the venue has a record of who did what | 13 months |
The activity log is the venue's record, not yours, and that has a consequence you should know before you accept an invitation. If you ask us to erase your data, the activity log is retained.
This is a statutory exception, not a preference. United States state privacy laws permit personal information to be kept, despite a deletion request, where it is needed to detect and respond to security incidents, to protect against fraudulent or illegal activity, and to comply with a legal obligation — and an audit trail that any of its subjects can delete serves none of those. In California the exceptions are at Civil Code §1798.105(d).
It is kept for that purpose and no other. The log is never used to profile you, is never used for marketing, and is not sold or shared. We route your deletion request to the venue, which is the business and the party that can act on the rest of it. The log goes when the account goes.
This section is where that is told, before it can matter — it is written for you to read before you accept an invitation. If anything about it is unclear or looks wrong — privacy@menuxpose.com.
Your name may also appear in the venue's own records — an order you handled, a booking you confirmed. Those retain with the record, not with you, for the same reason.
3. What we collect about menu content
Your menu content is business information, not personal data. We process it to display your page and, if you use the translation feature, we send item names and descriptions to a language model provider to produce a translation.
The model may only use facts you wrote. It is technically prevented from adding ingredients, origins, dietary claims, or certifications you did not state. You can edit every translation.
4. What we collect from visitors to your page
This section is a summary for you, the operator. The full version, written for the visitor, is at xposego.com/privacy.
We do not:
- Set any cookie on a venue page — the page sets none at all
- Create an account for a visitor
- Track anyone across websites
- Fingerprint devices
- Use any advertising identifier
- Use any third-party analytics or advertising service
- Know a visitor's name, phone number, or email address — except where they make a reservation, pay for an order, or order through a delivery platform. See below
We do record, for the venue whose page was opened:
- That a page was viewed
- Which items were looked at or tapped
- Which buttons were tapped
- Whether the order button was used
- Whether the visitor arrived via a QR code, a link, or a shared post
This is grouped into a session that exists only while the browser tab is open. When the tab closes, it is gone. Two visits to two different venues are two unrelated sessions — there is no way for us to connect them.
Each operator's pages have their own web address, on xposego.app — a browser treats two different operators as two different websites that cannot read anything of each other's. Outlets that belong to the same operator share one address, and share what it stores.
What the ordering page does keep on a visitor's device
Ordering software has to know which phone is holding seat 3. So a venue page stores a small number of things in the visitor's own browser — a basket, a language, a table session, and one random number that names that browser to that one venue and lasts between visits. It is not a cookie, it is readable only by that operator's pages, it says nothing about who the person is, and it is the reason re-scanning the table mid-meal keeps their seat instead of creating a new guest.
The full list, item by item, is in the Cookie Notice at xposego.com/cookies. We list it rather than summarise it, because "no account" should be checkable.
The order message
When a visitor orders on the Free plan, the send button opens their own messaging app or dialer, addressed to you. What they write and send goes directly from their phone to you.
It never reaches us. We do not receive, store, or transmit what was ordered or anything written with it. We record only that the button was used.
That is true of an order message. It is not true if they pay on the page. That is a different flow with a different answer, below.
If a visitor pays for an order
This is the one case where a visitor becomes someone we know. No venue can take payments on its page yet — this describes the flow from the day one does. It applies only on venues that have enabled payments, and only if the buyer actually checks out.
| We collect | Why |
|---|---|
| Their email address | Their receipt, and telling them what happened to the order. Asked for only where you have turned it on — the order can be placed without it |
| Their name, phone number (sometimes) | Only where you need to call the order out or reach them about it |
| What they ordered, and any note they added | It is the order. You have to see it |
| Payment status and amount | Reconciliation and refunds |
We hold nothing about the card. Not the number, not the last four digits, not the brand, not the expiry. Card details go from the buyer's browser to Stripe, and what comes back to us is a payment reference and whether it worked.
| Who sees it | You — it is your order — and Stripe, who processes the payment |
| Do we sell it? | No. Never, to anyone |
| Do we market to them? | No. They get a receipt and order updates. Nothing else |
| Can two venues connect a buyer's orders? | No. An order at one venue is unrelated to an order at another. We do not build a cross-venue profile |
| How long we keep it | Seven years. An order is a financial record and the law requires us to keep it — longer than your own account, and we cannot delete it on request before then. Anything held beyond that minimum can be deleted on request |
On the payment page only, Stripe sets cookies for fraud detection. The menu page still sets none.
If a visitor books a table
Reservations are not live yet — this describes them from the day they are. To hold a table we ask the fields you chose — always a name, and usually a phone number and email so you can reach them.
| Who holds it | You. Two venues a guest books with hold two unrelated records, and neither can see the other |
| No-shows | You may record a no-show. Repeated no-shows can lead your venue to require approval, ask for a card hold, or stop accepting that guest's bookings |
| Their rights | Where that restriction was applied automatically, the guest can contest it and ask for a human to review it — privacy@menuxpose.com |
| Card holds | Some venues authorize a small amount against no-shows. It is an authorization, not a charge, and it is released when the guest arrives — but it can be taken if they do not. You set whether that applies to a no-show only, or to a no-show and a late cancellation, and the amount and the rule are fixed when the guest books |
We are not a cross-venue reputation service and will not become one. There is no shared guest history, and no venue can see how someone behaved at another.
If an order arrives from a delivery platform
A person who ordered from you on DoorDash, Uber Eats or Grubhub is that platform's customer, not ours. They never opened your MenuXpose page and gave us nothing directly.
The platform still tells us about the order, so your kitchen sees a ticket and your daily totals are complete. What we model and show you is the order contents, its status, timestamps, totals, and the courier's first name.
No delivery platform can be connected yet. No order has ever reached us from one, and none will until the connection ships — these paragraphs describe it from the day it does. From that day, the platform sends us the order as a single message, and the guest's name, delivery address and phone are removed at the moment the message reaches us. They are never stored, never shown to you, and never used. What we keep is what you see — the order, its status, timestamps, totals, and the courier's first name.
A guest can exercise a data right with us directly, and does not have to go to the platform first. Send an access or deletion request to
privacy@menuxpose.comand we will verify it and act on everything we hold, on the terms in §9, whether or not the platform is also contacted. The platform holds the order relationship and will hold data we never receive, so contacting them as well will usually be necessary to reach all of it — but that is a reason to contact them in addition to us, not instead of us.
What you see
You see numbers — how many people opened your menu, which items were popular, which QR code brought people in. You never see the person. There is no way for a venue to see who viewed its page, and we will not build one.
5. Why we process data
| What we do | Business purpose |
|---|---|
| Run the service you signed up for | Performing our contract with you |
| Take payment for a subscription | Performing our contract with you; processing payments |
| Keep the service secure and prevent abuse | Detecting security incidents; protecting against fraudulent or illegal activity |
| Understand how the product is used, in aggregate | Internal research and product improvement |
| Send marketing email | Only with your opt-in consent, which you can withdraw at any time |
| Meet legal, tax and accounting duties | Complying with a legal obligation |
These are stated as business purposes, which is the disclosure United States state privacy laws ask for. We do not offer the service in the EU, EEA, UK or Switzerland (§9). When we open those markets, this table will also carry the lawful basis each purpose relies on under those laws, before the first account there is opened.
6. Who we share data with
We do not sell personal data. We do not share it for advertising. We never will.
We use service providers who process data on our behalf. This is the list, and we will update it here before we add to it.
Early Access, and this is one of the places it shows. Each provider below is engaged under its own standard terms. The separate data-processing agreements are not all executed yet — some are click-through terms we have not yet completed, and some are still to be requested. Our subprocessor record tracks each one and its state. We are completing them, and we would rather say that here than describe the whole table as being under contract when it is not.
| Provider | For | Where |
|---|---|---|
| Amazon Web Services | Hosting, database, email delivery | United States |
| Cloudflare | Storage and delivery of every photo, video and 3D model you upload | Placed near you — see §7 |
| Stripe | Payments — your subscription, and your customers' orders where you enable them | US and EU |
| Sentry | Error reporting — not yet in use; it receives nothing today, and this row publishes before the first byte does | EU |
| A language-model provider | Menu translation and copywriting — not yet in use; no menu text has reached any model | US |
| Google Maps Platform | The map and the pin picker — not yet in use; it receives nothing today | US |
| Sign-in, if you use it | US | |
| Apple | Sign-in, if you use it | US |
| Firebase | Push notifications to the app — not yet in use; it receives nothing today | US |
| RunPod | GPU inference, generating a 3D model from a dish photo — only with the 3D menu add-on, which is not available yet. No dish photo has reached them and none will until the add-on ships | US |
| Square, Toast or Clover | Sending orders to your till — only if you connect a point-of-sale system, which is pending a partner connection and cannot be connected yet | US · Canada |
Where a row names a category rather than a company, it is because that provider is only used for an optional feature that is not yet on sale. We will name it here before it handles anything of yours.
Companies that are not our service providers
Two kinds of company receive data in connection with the service and are not processing it for us. They decide for themselves what to do with it, which makes them responsible to your customers directly:
| DoorDash, Uber Eats, Grubhub | If you connect a delivery platform, it sends us orders and we send it your menu. The platform runs the delivery and holds its customer's relationship, not us — a diner who ordered there is their customer. §4 has what we keep |
| Google Business Profile | If you show your Google rating on your page, that rating is public information Google already holds about your business |
We may also disclose data where legally required, or to protect our rights or someone's safety.
7. Where your data is stored
Personal data is stored in the United States.
We operate in the United States and Canada. We do not currently offer the service in the EU, EEA, UK or Switzerland, and we hold no data region there. If that changes, this section changes first.
Your photos, videos and 3D models are stored differently, and we would rather be exact about it
They are held by Cloudflare, and placed in the region nearest you — North America today. This is a performance setting so your pages load quickly. It is not a guarantee about which country the files sit in, and we draw that distinction because it is real: we ask for placement near you and we get it, but we do not promise a country, and a policy that said otherwise would be promising something we have not bought.
8. How long we keep it
| Your account | While it exists, then 30 days |
| Your venue content | While your account exists, then 30 days |
| Detailed analytics | 90 days — removed in monthly sweeps, so a detailed row can live up to about 120 — then counts only |
| Aggregate statistics | While your account exists |
| Order records | 7 years — legally required |
| Billing records | 7 years — legally required |
| Staff activity log | 13 months |
| Shift handover notes | 90 days |
| Logs | 30 days |
| Backups | 7 days, then overwritten |
9. Your rights
Wherever you are, you can ask us to access, correct, delete, or export your personal data — email privacy@menuxpose.com, or use Settings → Delete account in the app. We respond within 30 days and verify identity first. We do not treat anyone differently for exercising a privacy right.
Two limits, stated here rather than discovered later: an order record cannot be deleted before its retention period ends (§8), and a venue's own records — a staff activity log, a guest's booking — are the venue's to decide about; we route the request to them and act on their instruction.
If you are in California, or a state with a similar law
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Not for money, not for anything else of value, not with advertising networks. Our Do Not Sell or Share My Personal Information page is at
xposego.com/do-not-sell— it exists so the required link resolves, and it explains why there is nothing to opt out of - We do not use or disclose sensitive personal information beyond what is necessary to provide the service
- The categories we collect are in §2 and §4; the purposes in §5; the recipients in §6; the retention periods in §8
- You may use an authorized agent to submit a request; we will verify the agent's authority
- Your browser's Global Privacy Control signal: our pages set no advertising or analytics cookies and we sell nothing, so there is nothing for the signal to switch off — we honor it by default, permanently, for everyone
If you are in Quebec
Quebec's Law 25 gives you rights to access, rectification, deletion (de-indexation), and data portability, and the right to withdraw consent. Our contact for privacy matters — the person in charge of the protection of personal information — is reachable at privacy@menuxpose.com. If a decision about you were ever made exclusively by automated processing, you have the right to be informed and to have it reviewed by a person. Nothing in the product makes such a decision today — a reservation restriction is always applied by a person at the venue.
Everywhere in Canada
PIPEDA gives you access and correction rights and requires your consent for collection beyond what the service needs. Complaints may go to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information.
If you are in the EU, EEA, UK or Switzerland
We do not offer the service in those markets yet, and we do not target them. If you are there anyway, we will honour a request under this section on the same terms as everyone else — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. When we do open those markets, this section will be replaced by a fuller one, and the transfer mechanisms and representative it requires will be in place before the first account is opened, not after.
9a. Records of what was agreed
Every published version of these documents is kept, with its date, and the version and date at the top always identify the text in force. You can ask at any time for the exact text that applied on a given day — privacy@menuxpose.com.
Consents are separate, and revocable. Where we ask for a consent — marketing is the only kind we would ask for — it is recorded per purpose and can be withdrawn at any time. Agreeing to the Terms is a contract, not a consent, and works differently.
10. Security
We encrypt data in transit and at rest, restrict staff access to what is necessary, and keep a record of who reaches the live systems.
No system is perfectly secure. If a breach occurs that puts your rights at risk, we will notify the relevant authority within 72 hours and you directly where the risk is high.
Good-faith security research is welcome: security@menuxpose.com.
11. Children
MenuXpose is a business tool for venue operators.
- It is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If we learn that we have, we delete it. This is the threshold the federal Children's Online Privacy Protection Act sets.
- We do not knowingly sell or share the personal information of anyone under 16, which is the threshold United States state privacy laws set for that. We do not sell or share anyone's personal information, at any age (§6, §9).
If you believe a child's personal information has reached us, contact privacy@menuxpose.com and we will delete it.
12. Changes
We will update this policy when the service changes. Material changes will be notified by email and in the app at least 30 days before taking effect. The version and date at the top always reflect the current text.
When we add a provider, a new use of your data, or a new place it is stored, this page changes in the same step — not afterwards. A privacy policy that lags the product is not out of date; it is wrong, and we would rather delay a change than publish one this page does not yet describe.
13. Contact
| Privacy | privacy@menuxpose.com |
| Support | support@menuxpose.com |
| Security | security@menuxpose.com |
| Address | WayExpose, LLC · 1401 Pennsylvania Ave, STE 105 2394 · Wilmington, DE 19806 · United States |