MenuXpose

Privacy Policy

Published at: https://menuxpose.com/privacy · Version 1.1 (Early Access) · Effective 31 August 2026

Early Access

MenuXpose is in Early Access, and this is a live document. It describes what we collect today. Where a statement here would have been favourable to us and inaccurate, it has been removed rather than qualified. Every claim in this policy is intended to be verifiable against what the service actually does.

It is also under external legal review. We expect the wording to be refined before general availability. Material changes are notified by email and in the app at least 30 days before they take effect (§12), and the version and date above always identify the text in force.

If anything here is unclear, or you believe it inaccurately describes our practices, contact privacy@menuxpose.com. We will correct it and record the change under §12.


MenuXpose is operated by WayExpose, LLC, a limited liability company formed in Delaware, United States ("we", "us", "our"). Our address is at §13.

This policy explains what personal data we collect, why, and what you can do about it. We have tried to write it so it can actually be read.

If you are a diner or visitor rather than a venue operator, the policy written for you is at xposego.com/privacy. This one is written for the person who runs the venue.


1. Three kinds of people

This policy covers three groups, and what we hold about each is very different.

WhoWhat we hold
Venue ownersYou have an account and a venue pageAn account's worth of information
Venue staffSomeone invited you to help run a venue you do not ownYour name, your email, and a log of what you did in the app
VisitorsYou scanned a QR code or opened a venue's linkAlmost nothing — no account, no cookie, and nothing that identifies you

If you are staff, §2a is written for you, and the part you are most likely to want is the last paragraph of it. If you are a visitor, §4 is the short version, and the full one is at xposego.com/privacy.


2. What we collect from venue owners

You give us

DataWhyBusiness purpose
Email addressYour account, and to contact youPerforming our contract with you
NameYour accountPerforming our contract with you
Phone numberShown on your venue page if you choosePerforming our contract with you
Venue name, address, locationYour public page and the directions linkPerforming our contract with you
Photos you uploadYour public pagePerforming our contract with you
Menu content and pricesYour public pagePerforming our contract with you
Opening hoursYour public pagePerforming our contract with you
CountryDetermining whether we operate where you arePerforming our contract with you
The location you drop on the mapTurning a pin into a street address for your page and its directions linkPerforming our contract with you

Your photos and videos are stored with Cloudflare, not on our own servers — see §6 and §7. They are meant to be public, because they go on your page. A photograph of your dining room can still catch a member of staff or a customer, so it is worth knowing where it is held.

If you use the 3D menu add-on

If your venue is on Elite and you buy the 3D menu add-on, a dish photo you choose is sent to a specialist provider that runs the graphics hardware which turns it into a 3D model. The photo is processed for the length of that job and the resulting model is stored with your other media. It is your dish and your photograph — we add nothing to it and use it for nothing else.

The add-on is not on sale yet. This paragraph describes it for the day it is.

Created when you use the service

DataWhyBusiness purpose
Login times, device type, app versionSecurity and supportDetecting security incidents
Actions in the appImproving the productInternal research and product improvement
Errors our systems recordFixing problemsMaintaining and repairing the service

If you subscribe

Payment is handled by Stripe. We receive confirmation that payment succeeded — we never receive or store your card number or any other detail of the card.

If you sign in with Google or Apple

From Google we receive your email address, name, and profile picture. Nothing else, ever.

From Apple we receive your email address — or, if you chose to hide it, the private relay address Apple creates for you — and your name if you shared it. We also hold the credential Apple requires us to keep so that, when you delete your account, we can tell Apple to revoke the sign-in.


2a. What we collect from venue staff

If a venue invited you, the venue is in charge of your data here and we are not. They chose to add you, they decide what you can open, and they can remove you. We hold your data on their instructions — in the language United States privacy laws use, the venue is the business and we are its service provider (elsewhere the same split is called controller and processor). That is the same split that applies to the venue's customers, and it is worth saying plainly because the person who invited you may not have said it.

What we holdWhyHow long
Your name and emailTo let you sign in and to show the owner who is on their teamLife of the account + 30 days
What you can open — the permissions the owner gave youTo enforce themLife of the account + 30 days
Your activity log — what you changed and whenSo the venue has a record of who did what13 months

The activity log is the venue's record, not yours, and that has a consequence you should know before you accept an invitation. If you ask us to erase your data, the activity log is retained.

This is a statutory exception, not a preference. United States state privacy laws permit personal information to be kept, despite a deletion request, where it is needed to detect and respond to security incidents, to protect against fraudulent or illegal activity, and to comply with a legal obligation — and an audit trail that any of its subjects can delete serves none of those. In California the exceptions are at Civil Code §1798.105(d).

It is kept for that purpose and no other. The log is never used to profile you, is never used for marketing, and is not sold or shared. We route your deletion request to the venue, which is the business and the party that can act on the rest of it. The log goes when the account goes.

This section is where that is told, before it can matter — it is written for you to read before you accept an invitation. If anything about it is unclear or looks wrong — privacy@menuxpose.com.

Your name may also appear in the venue's own records — an order you handled, a booking you confirmed. Those retain with the record, not with you, for the same reason.


3. What we collect about menu content

Your menu content is business information, not personal data. We process it to display your page and, if you use the translation feature, we send item names and descriptions to a language model provider to produce a translation.

The model may only use facts you wrote. It is technically prevented from adding ingredients, origins, dietary claims, or certifications you did not state. You can edit every translation.


4. What we collect from visitors to your page

This section is a summary for you, the operator. The full version, written for the visitor, is at xposego.com/privacy.

We do not:

We do record, for the venue whose page was opened:

This is grouped into a session that exists only while the browser tab is open. When the tab closes, it is gone. Two visits to two different venues are two unrelated sessions — there is no way for us to connect them.

Each operator's pages have their own web address, on xposego.app — a browser treats two different operators as two different websites that cannot read anything of each other's. Outlets that belong to the same operator share one address, and share what it stores.

What the ordering page does keep on a visitor's device

Ordering software has to know which phone is holding seat 3. So a venue page stores a small number of things in the visitor's own browser — a basket, a language, a table session, and one random number that names that browser to that one venue and lasts between visits. It is not a cookie, it is readable only by that operator's pages, it says nothing about who the person is, and it is the reason re-scanning the table mid-meal keeps their seat instead of creating a new guest.

The full list, item by item, is in the Cookie Notice at xposego.com/cookies. We list it rather than summarise it, because "no account" should be checkable.

The order message

When a visitor orders on the Free plan, the send button opens their own messaging app or dialer, addressed to you. What they write and send goes directly from their phone to you.

It never reaches us. We do not receive, store, or transmit what was ordered or anything written with it. We record only that the button was used.

That is true of an order message. It is not true if they pay on the page. That is a different flow with a different answer, below.

If a visitor pays for an order

This is the one case where a visitor becomes someone we know. No venue can take payments on its page yet — this describes the flow from the day one does. It applies only on venues that have enabled payments, and only if the buyer actually checks out.

We collectWhy
Their email addressTheir receipt, and telling them what happened to the order. Asked for only where you have turned it on — the order can be placed without it
Their name, phone number (sometimes)Only where you need to call the order out or reach them about it
What they ordered, and any note they addedIt is the order. You have to see it
Payment status and amountReconciliation and refunds

We hold nothing about the card. Not the number, not the last four digits, not the brand, not the expiry. Card details go from the buyer's browser to Stripe, and what comes back to us is a payment reference and whether it worked.

Who sees itYou — it is your order — and Stripe, who processes the payment
Do we sell it?No. Never, to anyone
Do we market to them?No. They get a receipt and order updates. Nothing else
Can two venues connect a buyer's orders?No. An order at one venue is unrelated to an order at another. We do not build a cross-venue profile
How long we keep itSeven years. An order is a financial record and the law requires us to keep it — longer than your own account, and we cannot delete it on request before then. Anything held beyond that minimum can be deleted on request

On the payment page only, Stripe sets cookies for fraud detection. The menu page still sets none.

If a visitor books a table

Reservations are not live yet — this describes them from the day they are. To hold a table we ask the fields you chose — always a name, and usually a phone number and email so you can reach them.

Who holds itYou. Two venues a guest books with hold two unrelated records, and neither can see the other
No-showsYou may record a no-show. Repeated no-shows can lead your venue to require approval, ask for a card hold, or stop accepting that guest's bookings
Their rightsWhere that restriction was applied automatically, the guest can contest it and ask for a human to review it — privacy@menuxpose.com
Card holdsSome venues authorize a small amount against no-shows. It is an authorization, not a charge, and it is released when the guest arrives — but it can be taken if they do not. You set whether that applies to a no-show only, or to a no-show and a late cancellation, and the amount and the rule are fixed when the guest books

We are not a cross-venue reputation service and will not become one. There is no shared guest history, and no venue can see how someone behaved at another.

If an order arrives from a delivery platform

A person who ordered from you on DoorDash, Uber Eats or Grubhub is that platform's customer, not ours. They never opened your MenuXpose page and gave us nothing directly.

The platform still tells us about the order, so your kitchen sees a ticket and your daily totals are complete. What we model and show you is the order contents, its status, timestamps, totals, and the courier's first name.

No delivery platform can be connected yet. No order has ever reached us from one, and none will until the connection ships — these paragraphs describe it from the day it does. From that day, the platform sends us the order as a single message, and the guest's name, delivery address and phone are removed at the moment the message reaches us. They are never stored, never shown to you, and never used. What we keep is what you see — the order, its status, timestamps, totals, and the courier's first name.

A guest can exercise a data right with us directly, and does not have to go to the platform first. Send an access or deletion request to privacy@menuxpose.com and we will verify it and act on everything we hold, on the terms in §9, whether or not the platform is also contacted. The platform holds the order relationship and will hold data we never receive, so contacting them as well will usually be necessary to reach all of it — but that is a reason to contact them in addition to us, not instead of us.

What you see

You see numbers — how many people opened your menu, which items were popular, which QR code brought people in. You never see the person. There is no way for a venue to see who viewed its page, and we will not build one.


5. Why we process data

What we doBusiness purpose
Run the service you signed up forPerforming our contract with you
Take payment for a subscriptionPerforming our contract with you; processing payments
Keep the service secure and prevent abuseDetecting security incidents; protecting against fraudulent or illegal activity
Understand how the product is used, in aggregateInternal research and product improvement
Send marketing emailOnly with your opt-in consent, which you can withdraw at any time
Meet legal, tax and accounting dutiesComplying with a legal obligation

These are stated as business purposes, which is the disclosure United States state privacy laws ask for. We do not offer the service in the EU, EEA, UK or Switzerland (§9). When we open those markets, this table will also carry the lawful basis each purpose relies on under those laws, before the first account there is opened.


6. Who we share data with

We do not sell personal data. We do not share it for advertising. We never will.

We use service providers who process data on our behalf. This is the list, and we will update it here before we add to it.

Early Access, and this is one of the places it shows. Each provider below is engaged under its own standard terms. The separate data-processing agreements are not all executed yet — some are click-through terms we have not yet completed, and some are still to be requested. Our subprocessor record tracks each one and its state. We are completing them, and we would rather say that here than describe the whole table as being under contract when it is not.

ProviderForWhere
Amazon Web ServicesHosting, database, email deliveryUnited States
CloudflareStorage and delivery of every photo, video and 3D model you uploadPlaced near you — see §7
StripePayments — your subscription, and your customers' orders where you enable themUS and EU
SentryError reporting — not yet in use; it receives nothing today, and this row publishes before the first byte doesEU
A language-model providerMenu translation and copywriting — not yet in use; no menu text has reached any modelUS
Google Maps PlatformThe map and the pin picker — not yet in use; it receives nothing todayUS
GoogleSign-in, if you use itUS
AppleSign-in, if you use itUS
FirebasePush notifications to the app — not yet in use; it receives nothing todayUS
RunPodGPU inference, generating a 3D model from a dish photo — only with the 3D menu add-on, which is not available yet. No dish photo has reached them and none will until the add-on shipsUS
Square, Toast or CloverSending orders to your till — only if you connect a point-of-sale system, which is pending a partner connection and cannot be connected yetUS · Canada

Where a row names a category rather than a company, it is because that provider is only used for an optional feature that is not yet on sale. We will name it here before it handles anything of yours.

Companies that are not our service providers

Two kinds of company receive data in connection with the service and are not processing it for us. They decide for themselves what to do with it, which makes them responsible to your customers directly:

DoorDash, Uber Eats, GrubhubIf you connect a delivery platform, it sends us orders and we send it your menu. The platform runs the delivery and holds its customer's relationship, not us — a diner who ordered there is their customer. §4 has what we keep
Google Business ProfileIf you show your Google rating on your page, that rating is public information Google already holds about your business

We may also disclose data where legally required, or to protect our rights or someone's safety.


7. Where your data is stored

Personal data is stored in the United States.

We operate in the United States and Canada. We do not currently offer the service in the EU, EEA, UK or Switzerland, and we hold no data region there. If that changes, this section changes first.

Your photos, videos and 3D models are stored differently, and we would rather be exact about it

They are held by Cloudflare, and placed in the region nearest you — North America today. This is a performance setting so your pages load quickly. It is not a guarantee about which country the files sit in, and we draw that distinction because it is real: we ask for placement near you and we get it, but we do not promise a country, and a policy that said otherwise would be promising something we have not bought.


8. How long we keep it

Your accountWhile it exists, then 30 days
Your venue contentWhile your account exists, then 30 days
Detailed analytics90 days — removed in monthly sweeps, so a detailed row can live up to about 120 — then counts only
Aggregate statisticsWhile your account exists
Order records7 years — legally required
Billing records7 years — legally required
Staff activity log13 months
Shift handover notes90 days
Logs30 days
Backups7 days, then overwritten

9. Your rights

Wherever you are, you can ask us to access, correct, delete, or export your personal data — email privacy@menuxpose.com, or use Settings → Delete account in the app. We respond within 30 days and verify identity first. We do not treat anyone differently for exercising a privacy right.

Two limits, stated here rather than discovered later: an order record cannot be deleted before its retention period ends (§8), and a venue's own records — a staff activity log, a guest's booking — are the venue's to decide about; we route the request to them and act on their instruction.

If you are in California, or a state with a similar law

If you are in Quebec

Quebec's Law 25 gives you rights to access, rectification, deletion (de-indexation), and data portability, and the right to withdraw consent. Our contact for privacy matters — the person in charge of the protection of personal information — is reachable at privacy@menuxpose.com. If a decision about you were ever made exclusively by automated processing, you have the right to be informed and to have it reviewed by a person. Nothing in the product makes such a decision today — a reservation restriction is always applied by a person at the venue.

Everywhere in Canada

PIPEDA gives you access and correction rights and requires your consent for collection beyond what the service needs. Complaints may go to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information.

If you are in the EU, EEA, UK or Switzerland

We do not offer the service in those markets yet, and we do not target them. If you are there anyway, we will honour a request under this section on the same terms as everyone else — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. When we do open those markets, this section will be replaced by a fuller one, and the transfer mechanisms and representative it requires will be in place before the first account is opened, not after.


9a. Records of what was agreed

Every published version of these documents is kept, with its date, and the version and date at the top always identify the text in force. You can ask at any time for the exact text that applied on a given day — privacy@menuxpose.com.

Consents are separate, and revocable. Where we ask for a consent — marketing is the only kind we would ask for — it is recorded per purpose and can be withdrawn at any time. Agreeing to the Terms is a contract, not a consent, and works differently.


10. Security

We encrypt data in transit and at rest, restrict staff access to what is necessary, and keep a record of who reaches the live systems.

No system is perfectly secure. If a breach occurs that puts your rights at risk, we will notify the relevant authority within 72 hours and you directly where the risk is high.

Good-faith security research is welcome: security@menuxpose.com.


11. Children

MenuXpose is a business tool for venue operators.

If you believe a child's personal information has reached us, contact privacy@menuxpose.com and we will delete it.


12. Changes

We will update this policy when the service changes. Material changes will be notified by email and in the app at least 30 days before taking effect. The version and date at the top always reflect the current text.

When we add a provider, a new use of your data, or a new place it is stored, this page changes in the same step — not afterwards. A privacy policy that lags the product is not out of date; it is wrong, and we would rather delay a change than publish one this page does not yet describe.


13. Contact

Privacyprivacy@menuxpose.com
Supportsupport@menuxpose.com
Securitysecurity@menuxpose.com
AddressWayExpose, LLC · 1401 Pennsylvania Ave, STE 105 2394 · Wilmington, DE 19806 · United States