Privacy Policy
Effective date: 17 July 2026
1. Controller
The controller of personal data processed through the Menqrly service at menqrly.com (the "Service") is:
I.F.O.S. s.r.o.
Koceľova 945/17, Bratislava, Slovak Republic
Company ID (IČO): 52 762 017
VAT ID (IČ DPH): SK2121125567
E-mail: [email protected]
We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and Slovak Act No. 18/2018 Coll. on the Protection of Personal Data. We have not appointed a data protection officer, as we are not required to do so; you can address any privacy matter to the e-mail above.
2. Two roles: our customers and their guests
- Customers (venue owners and staff who create a Menqrly account): we act as the controller of your data, as described in this Policy.
- Guests (diners who scan a venue's QR code or leave feedback): the venue is the controller of analytics data about its guests; we act as the venue's processor and process such data only to provide the Service, under the data-processing terms in our Terms and Conditions. Sections 3–6 below describe this processing for transparency.
3. What data we process, why, and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: name, e-mail address, Google account identifier (if you use Google sign-in), sign-in tokens | Creating and securing your account, signing you in, communicating with you about the Service (including onboarding and service e-mails) | Performance of a contract — Art. 6(1)(b) GDPR |
| Subscription and billing data: Stripe customer and subscription identifiers, subscription status and billing period | Managing your trial and subscription, invoicing, tax and accounting compliance | Performance of a contract — Art. 6(1)(b); legal obligation (tax and accounting law) — Art. 6(1)(c) GDPR |
| Payment card data | Processed solely by Stripe, our payment processor; we never receive or store card numbers | Performance of a contract — Art. 6(1)(b) GDPR (Stripe acts under its own terms) |
| Uploaded content: menu files (PDF/photos), venue name, QR design settings | Hosting and publicly serving your menu — the core function of the Service | Performance of a contract — Art. 6(1)(b) GDPR |
| Guest scan data: time of scan, IP address, browser user agent | Providing venues with scan analytics (counts, busiest hours, device types) and protecting the Service against abuse | Processed on behalf of the venue (Art. 28 GDPR); for security of the Service, our legitimate interest — Art. 6(1)(f) GDPR |
| Guest feedback: star rating and optional comment (submitted without name or contact details) | Delivering guest feedback to the venue | Processed on behalf of the venue (Art. 28 GDPR) |
| Technical logs: IP address, request data, error logs | Operating, securing and debugging the Service, preventing fraud and abuse | Legitimate interest in the security and reliability of the Service — Art. 6(1)(f) GDPR |
Providing account and billing data is a contractual requirement — without it we cannot provide the Service. We do not use personal data for automated individual decision-making or profiling with legal effects, and we do not sell personal data.
4. Cookies
The Service uses only strictly necessary cookies: a session cookie that keeps you signed in and protects forms against cross-site request forgery. These are essential for the Service to function and therefore do not require consent. We do not use advertising or third-party tracking cookies. If we introduce non-essential cookies in the future, we will ask for your consent first.
5. Recipients and sub-processors
We share personal data only with service providers who help us run the Service:
- Stripe — payment processing and subscription billing;
- Amazon Web Services (AWS) — application hosting and file storage;
- Google — optional Google sign-in;
- e-mail delivery providers — sending sign-in links and service e-mails.
These providers process data under data-processing agreements and only on our instructions. We may also disclose data where required by law or a binding order of a public authority.
6. Transfers outside the EEA
Some providers listed above are based in the United States or may process data there. Such transfers are carried out under Chapter V of the GDPR — in particular the European Commission's adequacy decision for the EU–U.S. Data Privacy Framework for certified providers, and/or the Commission's Standard Contractual Clauses with supplementary measures. You can request more information about the safeguards used at the contact above.
7. How long we keep data
| Data | Retention |
|---|---|
| Account data and uploaded content | For the duration of your account; deleted or anonymised within a reasonable period after account deletion, except where retention is required for the purposes below |
| Billing and accounting records | 10 years, as required by Slovak accounting and tax law (Act No. 431/2002 Coll.) |
| Guest scan data and feedback | For the duration of the venue's subscription, to provide historical analytics; deleted with the venue's account |
| Sign-in (magic-link) tokens | Short-lived; invalid after use or expiry |
| Technical and security logs | For a limited period necessary for security and troubleshooting |
| Data needed to establish, exercise or defend legal claims | Until expiry of the relevant limitation periods |
8. Security
We apply appropriate technical and organisational measures to protect personal data, including encrypted connections (TLS), access controls, tokenised sign-in without passwords, and payment processing delegated to a PCI-DSS-certified provider. No system is completely secure; we will notify you and the supervisory authority of personal data breaches where the GDPR requires it.
9. Your rights
Under the GDPR and Act No. 18/2018 Coll. you have the right to:
- access your personal data and obtain a copy (Art. 15);
- rectification of inaccurate data (Art. 16);
- erasure ("right to be forgotten") where the conditions are met (Art. 17);
- restriction of processing (Art. 18);
- data portability of data you provided to us (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time, where processing is based on consent, without affecting prior processing.
To exercise your rights, contact us at [email protected]. We will respond within one month; this period may be extended by two further months for complex requests, in which case we will inform you. If you are a guest of a venue, we may refer your request to the venue as the controller, or assist the venue in handling it.
You also have the right to lodge a complaint with the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky (Office for Personal Data Protection of the Slovak Republic), Hraničná 12, 820 07 Bratislava 27, Slovak Republic, dataprotection.gov.sk — or with the supervisory authority of your habitual residence.
10. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data of persons under 16. Menus served to guests do not require any registration or submission of personal data.
11. Changes to this Policy
We may update this Policy to reflect changes in the Service or in the law. The current version is always available at this page; material changes will be announced by e-mail or in the dashboard before they take effect.
See also our Terms and Conditions.