Menucore

Privacy Policy

Last updated: 14 March 2026

Privacy at a Glance

We know privacy policies can be long. Here is a plain-language summary of the most important things.

The full policy below provides the complete legal detail. If anything is unclear, please contact us at support@menucore.pro.

1. Who We Are and How to Contact Us

This Privacy Policy is published by:

Coderdex Ltd. Operator of the Menucore platform (https://menucore.pro) Incorporated in the Republic of Cyprus Email: support@menucore.pro Data Protection enquiries: support@menucore.pro (subject: “Privacy Request”)

Coderdex Ltd. is the data controller in respect of the personal data described in this Privacy Policy, meaning we determine the purposes and means of processing your personal data. Where Coderdex Ltd. processes personal data on behalf of a business customer (Controller), such processing is governed by our Data Processing Agreement, available at https://menucore.pro/dpa.

2. Scope of This Policy

This Privacy Policy applies to all personal data collected by Coderdex Ltd. in connection with:

  • your use of the Menucore platform and related services (the “Service”);
  • your visits to https://menucore.pro and any associated subdomains;
  • any communications you send to us, including support requests and enquiries.

This Policy does not apply to:

  • the processing activities of our payment provider, Paddle.com Market Limited, which acts as Merchant of Record and has its own privacy policy (https://www.paddle.com/legal/privacy);
  • third-party websites or services that may be linked from the Service.

3. Personal Data We Collect

3.1 Data You Provide Directly

When you register for or use the Service, you may provide us with the following personal data:

Data TypeExamplesWhen Collected
Identity DataEmail address; first name and last name (optional)Account registration; account settings
Business DataCompany name; restaurant or business name (optional)Account registration; account settings
Authentication DataHashed password (if using email/password login); OAuth access token (if using Google Sign-In). We never store your password in readable form.Account registration; login
Support CommunicationsContent of emails or messages you send to usWhen you contact support

3.2 Data We Collect Automatically

When you access or use the Service, we and our service providers automatically collect certain technical and usage data:

  • IP address and approximate geographic location (country/region level);
  • browser type, version, and operating system;
  • pages visited, features used, and time spent within the Service;
  • referring URL and exit pages;
  • session identifiers and authentication tokens (stored as cookies — see Section 7).

This data is collected via server logs and Google Analytics 4 (subject to your cookie consent). It is used to monitor Service performance, ensure security, and understand how users engage with the Service so we can improve it.

3.3 Data We Do Not Collect

We do not collect:

  • payment card details, bank account information, or CVV numbers — these are collected and processed exclusively by Paddle as Merchant of Record;
  • VAT numbers or billing addresses — these are collected by Paddle;
  • special category data as defined under Article 9 GDPR (such as health, biometric, or racial/ethnic data);
  • personal data from children under the age of 16. The Service is not directed at children. If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.

4. How and Why We Use Your Personal Data

We process your personal data only where we have a valid legal basis to do so under the GDPR. The table below sets out our processing purposes, the legal basis for each, the data involved, and how long we retain it.

PurposeLegal BasisData InvolvedRetention
Account registration and authenticationPerformance of contract (Art. 6(1)(b) GDPR)Email address, name (optional), hashed password or OAuth tokenDuration of account
Providing Service features (recipes, menus, costing)Performance of contract (Art. 6(1)(b) GDPR)Account identity data; operational data entered by the userDuration of account
Customer support and communicationsLegitimate interests (Art. 6(1)(f) GDPR) — providing assistance and resolving issuesEmail address, name, content of support communication3 years from last interaction
Service security and fraud preventionLegitimate interests (Art. 6(1)(f) GDPR) — protecting the integrity of the Service and our usersIP address, session logs, usage events90 days rolling
Sending product updates and service noticesPerformance of contract / legitimate interests (Art. 6(1)(f) GDPR)Email addressDuration of account
Sending marketing emails (optional)Consent (Art. 6(1)(a) GDPR)Email address, nameUntil consent is withdrawn
Analytics and Service improvementConsent (Art. 6(1)(a) GDPR) — via cookie consentAnonymised usage data via Google Analytics 414 months (GA4 default)
Compliance with legal obligationsLegal obligation (Art. 6(1)(c) GDPR)As required by applicable lawAs required by law

Legitimate Interests Assessment: Where we rely on legitimate interests as our legal basis, we have assessed that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time — see Section 8.

5. Who We Share Your Personal Data With

5.1 Service Providers and Sub-Processors

We share personal data with a limited number of trusted third-party service providers who help us operate the Service. These providers act as data processors on our behalf and are contractually bound to process personal data only on our instructions and in accordance with our Data Processing Agreement.

Our current service providers are:

ProviderCountryRolePrivacy Policy
Vercel Inc.United StatesApplication hosting and content deliveryvercel.com/legal/privacy-policy
Supabase Inc.United StatesDatabase hosting and user authentication (email/password)supabase.com/privacy
Google LLCUnited StatesGoogle Sign-In (OAuth 2.0) and Google Analytics 4policies.google.com/privacy
Paddle.com Market LimitedUnited KingdomPayment processing and subscription management (Merchant of Record — independent controller for payment data)paddle.com/legal/privacy

A full and up-to-date list of sub-processors is maintained at https://menucore.pro/sub-processors.

5.2 Legal Disclosures

We may disclose personal data to law enforcement authorities, regulators, courts, or other public authorities where we are legally required to do so, or where disclosure is necessary to protect our legal rights, prevent fraud, or protect the safety of our users or the public. We will notify you of any such disclosure where permitted by law.

5.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of all or substantially all of our assets, personal data may be transferred to the acquiring entity as part of that transaction. We will notify you via email or a prominent notice within the Service prior to any such transfer and inform you of any choices you may have regarding your personal data.

5.4 No Sale of Personal Data

We do not sell, rent, or trade your personal data to any third party for their own marketing or commercial purposes. We do not share personal data with advertising networks.

6. International Data Transfers

Coderdex Ltd. is based in the Republic of Cyprus, which is a member state of the European Union. Personal data is therefore collected and primarily processed within the EEA.

However, our service providers Vercel, Supabase, and Google LLC are based in the United States, which is a third country without an EU adequacy decision in respect of general commercial data transfers. Where personal data is transferred to these providers, we ensure appropriate safeguards are in place, specifically:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor), incorporated into our data processing agreements with each provider;
  • for transfers from the United Kingdom: the UK International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner’s Office.

You may request a copy of the relevant SCCs or further information about the safeguards in place for international transfers by contacting us at support@menucore.pro.

7. Cookies and Similar Technologies

7.1 What Are Cookies

Cookies are small text files stored on your device when you visit a website or use a web application. We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how the Service is used.

7.2 The Cookies We Use

CookieTypeDurationPurpose
sb-access-token / sb-refresh-tokenStrictly NecessarySession / up to 1 yearMaintains your authenticated session so you remain logged in between page visits.
mc_consentStrictly Necessary180 daysStores your cookie consent choices so we can honour them across menucore.pro and app.menucore.pro and avoid asking you again.
g_state / g_csrf_tokenStrictly NecessarySessionUsed by Google Sign-In to prevent cross-site request forgery attacks during the OAuth login flow.
mc_ui_prefsFunctional1 yearRemembers your interface preferences (such as selected view type) so you don’t have to reset them each visit.
_ga / _ga_* / _gidAnalytics (consent required)Up to 2 yearsGoogle Analytics 4 cookies used to understand usage patterns and improve the Service. IP addresses are anonymised. These cookies are only placed with your consent.

7.3 Your Cookie Choices

Strictly Necessary cookies are required for the Service to function and cannot be disabled. For all other cookies, you have the following options:

  • Cookie consent banner: when you first access the Service, you will be presented with a consent banner allowing you to accept or decline non-essential cookies;
  • Withdrawing consent: you may change your cookie preferences at any time by clicking the “Cookie Settings” link in the Service footer;
  • Browser settings: you can configure your browser to block or delete cookies. Note that disabling session cookies will prevent you from staying logged in.

8. Your Privacy Rights

Under the GDPR and other applicable Data Protection Law, you have the following rights in respect of your personal data. We will respond to all verified requests within thirty (30) days, with a possible extension of a further two months for complex or numerous requests (in which case we will notify you of the extension and the reason).

Your RightWhat It MeansHow to Exercise It
Right of AccessRequest a copy of the personal data we hold about you and information about how we use it.Email request to support@menucore.pro
Right to RectificationAsk us to correct inaccurate or incomplete personal data. You can also update most information directly within your account settings.Account settings or email request
Right to ErasureRequest deletion of your personal data where we no longer have a lawful basis to retain it. You can also delete your account directly via the "Delete Account" button in the app, which triggers immediate deletion.In-app "Delete Account" or email request
Right to RestrictionAsk us to pause processing of your data in certain circumstances, such as while a dispute about accuracy is resolved.Email request to support@menucore.pro
Right to Data PortabilityReceive your personal data in a structured, commonly used, machine-readable format, or have it transmitted to another controller, where technically feasible.Email request to support@menucore.pro
Right to ObjectObject to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.Email request to support@menucore.pro
Right to Withdraw ConsentWhere processing is based on your consent (e.g. analytics cookies, marketing emails), withdraw that consent at any time without affecting the lawfulness of prior processing.Cookie settings or unsubscribe link in emails
Right to Lodge a ComplaintLodge a complaint with the competent supervisory authority. For EU residents: your national Data Protection Authority. For Cyprus: the Commissioner for Personal Data Protection (www.dataprotection.gov.cy).Directly with the supervisory authority

8.1 How to Submit a Request

To exercise any of the rights above (other than those available directly within the Service), please email support@menucore.pro with the subject line "Privacy Request" and include:

  • your full name and the email address associated with your account;
  • a description of the right you wish to exercise and the personal data it relates to;
  • sufficient information for us to verify your identity.

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on the request. We will inform you if this is the case.

8.2 Right to Complain

If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority:

  • Cyprus: Commissioner for Personal Data Protection — www.dataprotection.gov.cy
  • European Union: your national Data Protection Authority (list available at https://edpb.europa.eu)
  • United Kingdom: the Information Commissioner’s Office — ico.org.uk
  • United States (California): California Privacy Protection Agency — cppa.ca.gov

We would, however, appreciate the opportunity to address your concern before you contact a supervisory authority. Please contact us first at support@menucore.pro.

9. How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Our specific retention periods are:

Data CategoryRetention PeriodRationale
Account and identity dataDuration of active account + 90 daysProvides a grace period for account recovery after deletion
Authentication tokensSession duration (access) / up to 1 year (refresh)Required to maintain authenticated sessions
Support communications3 years from last interactionRequired to maintain support history and resolve disputes
Security and access logs90 days rollingRequired for security monitoring and incident investigation
Analytics data (Google Analytics 4)14 months (GA4 default)Standard GA4 retention period for aggregated usage data
Legal and compliance recordsAs required by applicable law (typically 5–7 years)Legal obligation

When personal data is no longer required, it is securely deleted or anonymised. Where anonymisation is not feasible, it is securely destroyed.

10. Deleting Your Account

You can permanently delete your Menucore account at any time by navigating to Account Settings and selecting "Delete Account" within the application. Deleting your account will:

  • immediately revoke your access to the Service;
  • schedule deletion of your account data (identity data, business data, and all Customer Data including recipes, ingredients, and menu items) within 90 days;
  • cancel your active subscription via Paddle (note: no refund will be issued for unused subscription time in accordance with our Terms of Service).

Account deletion is permanent and irreversible. We recommend exporting any data you wish to retain before deleting your account. We cannot recover your data after deletion is complete.

If you delete your account, certain data may be retained beyond the 90-day window where required by applicable law — for example, records required for tax or accounting purposes may be retained by Paddle for the legally mandated period.

11. How We Protect Your Data

We implement and maintain technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:

  • TLS 1.2 or higher encryption for all data in transit between your device and our servers;
  • encryption of data at rest within our database infrastructure (Supabase);
  • hashed storage of passwords using industry-standard algorithms — plaintext passwords are never stored;
  • role-based access controls limiting access to personal data to authorised personnel only;
  • regular security reviews of our infrastructure and third-party service providers;
  • logical separation of data between different customer accounts.

No method of electronic transmission or storage is 100% secure. While we take the protection of your data seriously, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with applicable law.

12. Children’s Privacy

The Service is intended for use by businesses and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at support@menucore.pro and we will delete such data promptly.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in applicable law, our data practices, or the services we use. We will notify you of material changes by:

  • posting a prominent notice within the Service before the change takes effect; and/or
  • sending an email to the address associated with your account.

The updated Privacy Policy will be published at https://menucore.pro/privacy-policy with a revised "Last Updated" date. We encourage you to review this Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acknowledgement of the updated Policy.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our data protection team:

Coderdex Ltd. — Data Protection Email: support@menucore.pro Subject line: "Privacy Request" or "Data Protection Enquiry" Website: https://menucore.pro

For formal complaints, you may also contact the Cyprus Commissioner for Personal Data Protection: Website: www.dataprotection.gov.cy

Related documents