Version 1.3 · Last updated: September 2, 2026
Privacy Policy
This policy explains how personal data is processed on the MenuXS website, in professional accounts, and during the use of menus and the ordering system.
1. Data Controller and Contacts
The data controller for the platform's own processing activities is 3SIGMA SOCIETÀ A RESPONSABILITÀ LIMITATA SEMPLIFICATA, abbreviated as 3Sigma s.r.l.s. a socio unico, operator of the MenuXS service, with its registered office at Via Antonio Viri 16, 00124 Rome (RM), Italy; Tax Code, Company Register number, and VAT number 12847171001; Rome Company Register; REA RM-1404631; share capital €500.00 fully subscribed and paid up.
Contact: 3Sigma s.r.l.s. – Privacy Office; e-mail privacy@menuxs.io; Certified e-mail 3sigma@pec.it. The Privacy Office is an organizational contact point and is not qualified as a Data Protection Officer (DPO/RPD).
2. When the Restaurant is the Data Controller
When you consult a restaurant's menu, place an order, save an address, or communicate preferences to the establishment, the restaurant indicated on the menu or order confirmation determines the purposes of the processing and is the primary contact. MenuXS processes such data to provide the platform according to the restaurant's instructions.
To exercise rights related to an order or your relationship with the establishment, you can contact the restaurant directly. If you write to MenuXS, we will forward your request to the relevant restaurant and provide the assistance required by law.
3. Data Processed
- Navigation and Security Data: IP address, date and time, URL, user agent, technical events, session identifiers, access attempts, and anti-fraud logs.
- Advertising attribution, with prior consent: merchant-funnel pages visited, registration, checkout start, subscription activation,
oppref/obrefparameters, and pseudonymous event identifiers. - Merchant and Staff Accounts: email, name, phone number, avatar, role, associated stores, preferences, access, and contractual acceptances.
- Store Data: company name/trade name, contacts, address, domain, menu, images, settings, fiscal, and subscription data.
- Customers and Orders: name, email, phone number, provided addresses and coordinates, products, amounts, notes, order status, and history.
- Payments: transaction identifiers and status. Full card details are collected directly by the payment provider and are not stored by MenuXS.
- Support and Communications: requests, messages, attachments, and information necessary for resolution.
- Newsletter/Waiting List: email, consent, date, and source of subscription.
- Notifications: technical endpoints and keys for push subscriptions, or the delivery method chosen by the merchant.
Avoid entering unnecessary data or special categories of data in the notes. If you communicate allergies or health information, do so only when essential for order preparation and with the understanding that it will be received by the restaurant.
4. Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Creating and managing accounts, menus, orders, subscriptions, and support | Performance of a contract or pre-contractual measures |
| Invoicing, accounting, and regulatory compliance | Legal obligation |
| Security, abuse prevention, continuity, and defense of rights | Legitimate interest, balanced against the rights of data subjects |
| Orders, delivery, and customer management on behalf of the restaurant | Basis determined by the restaurant data controller, normally contract |
| MenuXS newsletters and promotional communications | Consent, which can be withdrawn at any time |
| Analytics or marketing via non-essential tools | Prior consent via cookie panel |
5. Processing Methods and Automated Decision-Making
Processing is carried out using electronic tools and measures to ensure confidentiality, integrity, and availability. MenuXS does not currently adopt solely automated decision-making that produces significant legal effects on users. Any AI functionalities for importing menus will produce drafts subject to human verification.
6. Recipients and Providers
Data may be processed by authorized personnel and by providers necessary for hosting, databases, storage/CDN, email and SMS sending, payments, notifications, support, security, newsletters, and AI functions. The public list of sub-processors and providers indicates services, declared locations, transfer guarantees, and applicable configurations.
The restaurant and its authorized users receive data related to their own customers and orders. Data may also be communicated to authorities or professionals when required by law or necessary to protect rights.
7. Transfers Outside the European Economic Area
Some providers may process data in non-EEA countries. In such cases, MenuXS applies the instruments provided for by Articles 44 et seq. of the GDPR, such as adequacy decisions or Standard Contractual Clauses, and assesses the necessary supplementary measures. Details depend on the provider and are available upon request.
8. Retention
- Account and operational content: for the duration of the service; after expiration, suspended or read-only mode for 30 days to allow export, then deletion or anonymization from active systems within a further 30 days.
- Fiscal and billing data: for the period required by applicable regulations, normally 10 years.
- Orders and customer profiles: according to the restaurant's instructions and policy; the application default will be documented in the settings.
- OTP: 15 minutes or until first use.
- Security logs: ordinary maximum of 12 months, unless an incident or defense necessity arises.
- Leads/newsletters: until withdrawal or, indicatively, 24 months of inactivity.
- Support tickets: normally 24 months from closure, unless further documented necessity arises.
- Original and intermediate AI import files: deleted upon completion or expiration of the job, with a maximum technical lifecycle configured at 24 hours. Each OpenRouter request imposes Zero Data Retention routing; the model, actual provider, declared region, and PDF parser are recorded in the technical audit without retaining prompts or extracted content in the log.
- Backups: deletion through normal rotation within 90 days of deletion from active systems; in case of emergency restoration, deletions are reapplied.
Exceptions for legal obligations, disputes, security, or documented restaurant instructions are applied limited to the necessary data. Deletion requests are not considered complete until the actions required on active systems and affected providers are registered.
9. Rights
Where applicable, you may request access, rectification, erasure, restriction, portability, objection, and withdraw consent without prejudice to prior processing. You may also lodge a complaint with the Italian Data Protection Authority.
Send your request to privacy@menuxs.io or via certified email to 3sigma@pec.it. We may ask for reasonable information to verify your identity and the scope of your request. When the restaurant is the data controller, we will collaborate with them.
10. Cookies and Browser Storage
The website and app use cookies or similar tools for technical functions and, only with consent when required, for analytics and marketing. Session tokens, shopping carts, and preferences may be saved in the browser. Details and controls are available in the Cookie Policy and via “Cookie Preferences” in the footer.
11. Minors
The SaaS service is intended for professional operators. Orders must be placed by individuals with the capacity to conclude contracts with the restaurant or under the responsibility of those exercising parental authority. MenuXS does not knowingly collect data from minors for marketing purposes.
12. Changes
We may update this policy due to service evolutions or regulatory changes. We will indicate the version and date, and for substantial changes, we will use an appropriate notice.