Privacy policy
Last updated: September 27, 2026
What data Menly processes, why, for how long, with whom, and how to exercise your rights.
This translation is provided for convenience; the French version is the legally binding one.
Who is responsible
Menly's publisher is the controller for processing related to the menly.io site, restaurant owners' and their teams' accounts, and the commercial relationship.
For the data of a restaurant's guests (orders placed from its digital menu), the restaurant is the controller; Menly acts as processor and uses that data only to run the Service.
Data we process
- Account: name, email address, phone (optional), establishment name and details;
- Workspace use: menus, orders, tables, team and roles, cash sessions, a log of sensitive actions;
- Technical data: IP address, browser, date and time of requests, for security and troubleshooting;
- Restaurant guests: order contents and, for a pickup order, the name and — if the restaurant asks for it — the phone number;
- Menu visit statistics: anonymous events (menu viewed, dish opened, added to cart) tied to a random per-tab identifier, with no name or phone;
- Sales conversations: messages sent to the Menly team (WhatsApp, email).
Why
- Providing the Service and managing accounts — performance of the contract;
- Sending sign-in codes and account messages — performance of the contract;
- Securing the Service, preventing fraud and fixing faults — legitimate interest;
- Answering requests and managing subscriptions — performance of the contract or pre-contractual steps;
- Meeting accounting and legal obligations — legal obligation.
Menly does not sell your data, shows no advertising and does not use a restaurant's guest data for its own purposes.
Recipients and processors
Data is accessible only to authorised Menly staff and, for a workspace, to the Members the restaurant invited, according to their permissions. Menly uses:
- Vercel — hosting of websites and web applications;
- Google Cloud — hosting of the API;
- Supabase — database;
- an email delivery provider for sign-in codes;
- WhatsApp (Meta), only when you choose to contact the team that way.
Transfers outside Morocco
Some providers host data outside Morocco. These transfers are handled in accordance with Law No. 09-08 and the requirements of the National Commission for the Control of Personal Data Protection (CNDP), and rely on contractual data protection commitments.
Retention
- Account and workspace content: for the subscription, then deleted or anonymised after it ends, unless an export is requested;
- Accounting records and invoices: the legally required period;
- Technical connection data: a limited period, strictly what security requires;
- Restaurant guests' orders: according to the instructions of the restaurant, as controller;
- Sales conversations that led nowhere: three (3) years after the last contact.
Security
Traffic is encrypted (HTTPS), sessions rely on protected cookies that scripts cannot read, sign-in is passwordless with one-time codes, and access to a workspace's data is limited by each person's role.
Your rights
Under Law No. 09-08 you have the right to access and correct your data and, on legitimate grounds, to object to its processing. If you live in the European Union you also have the GDPR rights to erasure, restriction and portability.
For an order placed with a restaurant, contact that restaurant first; Menly will help it respond. You may also lodge a complaint with the CNDP (www.cndp.ma).
Minors
The owner workspace is for adult professionals. Digital menus can be viewed by anyone; no data is requested to view them.
Changes
This policy may change as the Service evolves. The update date is shown at the top of the page; customers are told about any significant change.
Contact us
- Message the Menly team on WhatsApp