Privacy Policy
Last updated August 18, 2026
Menuray (“Menuray”, “we”, “us”) is a digital menu platform operated by an individual based in Egypt. Menuray is not currently a registered company — this policy describes what we actually do with your data today, and we’ll update it if that changes.
This policy covers three different kinds of people: restaurant owners who create an account (“owners”), the diners who scan a QR code and view a published menu (“diners”), and visitors to this marketing site.
What we collect
If you create an owner account: your name, email address, and a hashed password (we never store your password itself). If you sign in with Google, we store your Google account ID and the email address Google shares with us, and no password at all.
If you set up a restaurant: its name and address (in each language you enable), phone number, country, currency, and a URL slug used for its public menu and QR code.
If you upload images or a PDF menu: logos, cover photos, item photos, and PDF menus are stored in our object storage (Cloudflare R2) and served from a public URL — the same design that lets a diner’s phone load your menu instantly means anyone who has or guesses that URL can view the file directly, the same as any other public web page. Don’t upload anything you don’t want to be publicly reachable this way.
If you view a published menu as a diner: we do not collect any personal data about you. The public menu page sets no cookies and loads no analytics script. We record only aggregate, non-identifying counters per menu — how many times it was viewed and how many times its QR code was scanned.
If you sign up for early access on this site: your email address.
Cookies and local storage
| Name | Purpose | Duration |
|---|---|---|
locale |
Remembers whether you prefer English or Arabic | 1 year |
| Studio sign-in token | Keeps you signed in to the restaurant dashboard | Until you sign out, or your browser session ends if you didn’t choose “remember me” |
| Last-used restaurant | Reopens the restaurant you last worked on | Until cleared |
| PostHog analytics cookies | Distinguishes your browser/session for analytics (see below) | Set by PostHog, typically up to 1 year |
None of these are set on a public menu page (the pages diners scan into).
Analytics and session recording
We use PostHog, hosted in the European Union, to understand how people use the restaurant dashboard and this marketing site. This includes standard page-view and click tracking, and, on the restaurant dashboard only, session recording: a replay of the pages you interact with while signed in, so we can see and fix confusing or broken flows.
Password fields are always excluded from recordings. Other fields you type into — including menu item names, prices, and similar restaurant content — are not currently masked and may be captured in a recording. If you sign in, we also associate your account email address and role with your analytics profile, so we can tell, for example, that a bug report and a recorded session belong to the same account.
We do not currently show a cookie/analytics consent banner. If you’d rather we didn’t record or analyze your sessions, email us at [email protected] and we will exclude your account.
Error monitoring
We use Sentry to catch and diagnose crashes and errors in the restaurant dashboard and our servers. This runs only in production and is configured not to collect personal information beyond what’s needed to reproduce the error (page, action, and a stack trace).
We send account email — email verification and password-reset messages —
through Resend, a transactional email provider, from
[email protected].
Newsletter / early access signup
If you submit your email on this site’s early-access form, we store it in a Resend mailing list so we can email you when access opens, and we additionally send ourselves a one-line internal notification (to a private Telegram channel we monitor) containing that email address and the country your request appeared to come from, so we can track signup interest. That notification is for our own use only and is not itself a mailing list.
Other infrastructure
Menuray runs on Cloudflare (for our public sites, our API’s edge access, and file storage) and a private server we operate, which runs our database. Database backups are encrypted and stored in the same Cloudflare object storage described above, in a location diners’ and owners’ browsers never access directly.
International data transfers
Because our service providers (Cloudflare, PostHog, Resend, Sentry) operate internationally, your data may be processed outside Egypt, including in the European Union and the United States, under those providers’ own data protection commitments.
How long we keep data
We keep account and restaurant data for as long as your account is active. If you delete your account or ask us to, we delete your account data and uploaded files within a reasonable time, except where we’re required to keep something longer (for example, a backup that hasn’t yet been rotated out).
Your rights
You can ask us, at any time, to tell you what data we hold about you, to correct it, or to delete your account and its data. Email [email protected] and we’ll act on it as quickly as we reasonably can.
Children
Menuray is a business tool for restaurant owners and is not directed at children. We don’t knowingly collect data from anyone under 16.
Changes to this policy
We’ll update this page if what we do changes, and update the “Last updated” date above when we do. We won’t reduce your rights under this policy without telling you.
Contact
Questions about this policy, or a privacy request of any kind: email [email protected].