Privacy notice
Last updated 7 October 2026
MyOwnMenu is run by Faresay Ltd, trading as Robin of Loxley, a company registered in England and Wales, company number 17302034. This notice says what we collect, why, who helps us run the service and what you can ask of us. It follows UK data protection law (the UK GDPR and the Data Protection Act 2018) and Japan's Act on the Protection of Personal Information (the APPI). Questions go to scarlet@robinofloxley.com.
Two kinds of data, two roles
Restaurants that sign up: your account, your store and your billing. We decide how that's used, so for it we're the controller, and under the APPI the business handling your personal information.
Guests who scan a table's QR code and order: their orders belong to the restaurant. The restaurant is the controller. We process them only on the restaurant's behalf, to run its menu and ordering. Under the APPI this is handling entrusted to us (委託). We don't use guests' orders for anything of our own and we never sell them.
What we keep about restaurants
- Account: your email address, a hash of your password (never the password itself) and your dashboard language.
- Store: its name, opening hours, greeting and footer text, logo, cover photo, colour, tables and menu (items, prices, photos, allergens and options).
- Billing: your plan, subscription status and dates, and the Stripe customer and subscription IDs. Stripe holds your card; we never see the number.
- Referrals: which store referred you, and any free months credited.
- Subsidy enquiries, if you make one: a contact name, a phone number if you give one, the number of employees, the bundle and your notes.
- Menu photo reading: how many pages were read and what each read cost us (tokens and time). Not the photos.
What we keep when a guest orders
Guests don't sign up. We don't ask for their name, email, phone number or card.
- The order: table, items, options, quantities, prices, any note the guest types, the time, and its progress in the kitchen.
- Staff calls: the table, whether it was a call or the bill, and when.
- A record each time a table's menu is opened: the table, the language and the time.
- A cookie that groups one guest's orders at a table for 6 hours (see Cookies).
A note can hold anything a guest types. Restaurants shouldn't ask guests to put personal details in it.
Why we use it
- To run the service you signed up for and bill you for it (contract).
- To keep it secure, stop abuse and fix faults (legitimate interests).
- To keep the billing records the law requires (legal obligation).
- To count visits and see which pages work, without cookies (legitimate interests).
We don't sell personal data, use it for advertising or use it to train AI models. We email you only about your account, your billing or a question you've sent us. Stripe may email you receipts and invoices.
Menu photos and AI
When you import a menu from a photo, the images go to Claude, made by Anthropic, to read the items. We don't keep the photos. Anthropic's commercial terms don't allow it to train its models on what we send. The reader can get things wrong, so you check every item before your menu goes live.
Who helps us run it
These providers process personal data for us, under written terms, only to run the service:
| Provider | What for | Where |
|---|---|---|
| Vercel Inc. | Hosts the site and app, keeps short-lived server logs (which include IP addresses), and stores the logos and photos you upload (Vercel Blob). | United States |
| Neon, Inc. | The database: accounts, stores, menus, tables, orders and billing status. | TODO(to fill in): the region the database (Neon) and Vercel's server functions run in, such as US East or Tokyo |
| Stripe | Subscriptions, card payments, invoices and the billing portal. Stripe receives your email address and store name, and holds your card details. | United States and other countries |
| Anthropic, PBC | Reads menu photos (Claude) when you import a menu from a photo. | United States |
| Plausible Insights OÜ | Counts visits to our pages, including guest menus, without cookies and without storing IP addresses. | European Union (Germany) |
| Resend, Inc. | Emails our own service alerts to us. They carry counts, not your details. | United States |
Logos and photos you upload sit at public web addresses so that guests' phones can load them. Anyone with the address can see them. Don't upload photos of people who haven't agreed.
If you ask us about the subsidy, we share your enquiry (store name, contact name, phone number, employees and notes) with our registered IT導入支援事業者 partner to prepare the joint application, which the programme requires. We do this only when you ask. Partner: TODO(to fill in): the name of our IT導入支援事業者 partner.
Fonts are served from our own site, so loading a page sends nothing to a font provider.
Transfers outside the UK and Japan
Some providers are in the United States. For data covered by UK law, transfers rely on the UK Extension to the EU–US Data Privacy Framework where the provider is certified, or otherwise on the International Data Transfer Addendum to the EU Standard Contractual Clauses.
For people in Japan, we entrust handling to the providers above, in the countries listed, and bind them by contract to protect the data to the APPI's standard. You can ask us for details of those measures and of the data protection rules in each country.
Cookies
| Cookie | What it does | How long |
|---|---|---|
| session | Keeps a restaurant signed in | 30 days |
| lang | Remembers the language you picked | 1 year |
| gs_ and a table code | Groups one guest's orders at a table | 6 hours |
| ref | Remembers a referral link until your store is set up | 30 days |
| track | Remembers that you came for the subsidy | 7 days |
Each one is needed for the service or remembers a choice you made. There are no advertising or tracking cookies, and Plausible counts visits without any.
How long we keep it
- Your account, store, menu and orders: while your account is open. Ask us and we delete the account, the store and everything in it within 30 days.
- Guests' orders, calls and menu opens: while the restaurant's account is open, or until the restaurant asks us to delete them.
- Billing records: as long as tax law requires, which in the UK is six years. Stripe keeps its own records under its own terms.
- Server logs: Vercel keeps them for a short time, then deletes them.
How we protect it
- Passwords are stored only as bcrypt hashes.
- Every page and request goes over HTTPS. The sign-in cookie can't be read by scripts on the page.
- Each store can reach only its own data. Only the people who run the service can reach the database.
- We choose providers that publish their security practices, and bind them by contract.
Your rights
You can ask to see, correct, delete or export your data, or ask us to restrict or stop using it. Email us and we'll answer within one month. You can also complain to the Information Commissioner's Office (ico.org.uk).
Under the APPI you can ask us to disclose, correct, add to or delete the personal data we hold about you, to stop using it or giving it to others, and to show our records of giving it to others. Email us and we'll answer without delay. You can also contact Japan's Personal Information Protection Commission (ppc.go.jp).
If you ordered at a restaurant, ask the restaurant first: your order is its data. We'll help it answer. If you write to us, we'll pass your request to the restaurant.
Who we are
| Business | Faresay Ltd, trading as Robin of Loxley. Company number 17302034, England and Wales. |
|---|---|
| Address | Disclosed without delay on request. |
| Representative | Disclosed without delay on request. |
| Contact | scarlet@robinofloxley.com |
If we change this notice in a way that matters, we'll tell signed-up restaurants first.