Privacy Policy
Last updated: 14 March 2026
Privacy at a Glance
We know privacy policies can be long. Here is a plain-language summary of the most important things.
- We collect only what we need to run your account and provide the Service — primarily your email address and, optionally, your name and business name.
- We do not sell your personal data. Ever.
- We do not use your data for advertising or share it with ad networks.
- Billing and payment data is handled entirely by Paddle, our payment provider. We never see your card details or VAT number.
- You can delete your account — and all associated data — at any time directly from within the app.
- We use Google Analytics to understand how the Service is used. This requires your consent and can be declined or withdrawn at any time.
- We are based in Cyprus and process your data in accordance with EU GDPR.
The full policy below provides the complete legal detail. If anything is unclear, please contact us at support@menucore.pro.
1. Who We Are and How to Contact Us
This Privacy Policy is published by:
Coderdex Ltd. Operator of the Menucore platform (https://menucore.pro) Incorporated in the Republic of Cyprus Email: support@menucore.pro Data Protection enquiries: support@menucore.pro (subject: “Privacy Request”)
Coderdex Ltd. is the data controller in respect of the personal data described in this Privacy Policy, meaning we determine the purposes and means of processing your personal data. Where Coderdex Ltd. processes personal data on behalf of a business customer (Controller), such processing is governed by our Data Processing Agreement, available at https://menucore.pro/dpa.
2. Scope of This Policy
This Privacy Policy applies to all personal data collected by Coderdex Ltd. in connection with:
- your use of the Menucore platform and related services (the “Service”);
- your visits to https://menucore.pro and any associated subdomains;
- any communications you send to us, including support requests and enquiries.
This Policy does not apply to:
- the processing activities of our payment provider, Paddle.com Market Limited, which acts as Merchant of Record and has its own privacy policy (https://www.paddle.com/legal/privacy);
- third-party websites or services that may be linked from the Service.
3. Personal Data We Collect
3.1 Data You Provide Directly
When you register for or use the Service, you may provide us with the following personal data:
| Data Type | Examples | When Collected |
|---|---|---|
| Identity Data | Email address; first name and last name (optional) | Account registration; account settings |
| Business Data | Company name; restaurant or business name (optional) | Account registration; account settings |
| Authentication Data | Hashed password (if using email/password login); OAuth access token (if using Google Sign-In). We never store your password in readable form. | Account registration; login |
| Support Communications | Content of emails or messages you send to us | When you contact support |
3.2 Data We Collect Automatically
When you access or use the Service, we and our service providers automatically collect certain technical and usage data:
- IP address and approximate geographic location (country/region level);
- browser type, version, and operating system;
- pages visited, features used, and time spent within the Service;
- referring URL and exit pages;
- session identifiers and authentication tokens (stored as cookies — see Section 7).
This data is collected via server logs and Google Analytics 4 (subject to your cookie consent). It is used to monitor Service performance, ensure security, and understand how users engage with the Service so we can improve it.
3.3 Data We Do Not Collect
We do not collect:
- payment card details, bank account information, or CVV numbers — these are collected and processed exclusively by Paddle as Merchant of Record;
- VAT numbers or billing addresses — these are collected by Paddle;
- special category data as defined under Article 9 GDPR (such as health, biometric, or racial/ethnic data);
- personal data from children under the age of 16. The Service is not directed at children. If we become aware that we have inadvertently collected personal data from a child, we will delete it promptly.
4. How and Why We Use Your Personal Data
We process your personal data only where we have a valid legal basis to do so under the GDPR. The table below sets out our processing purposes, the legal basis for each, the data involved, and how long we retain it.
| Purpose | Legal Basis | Data Involved | Retention |
|---|---|---|---|
| Account registration and authentication | Performance of contract (Art. 6(1)(b) GDPR) | Email address, name (optional), hashed password or OAuth token | Duration of account |
| Providing Service features (recipes, menus, costing) | Performance of contract (Art. 6(1)(b) GDPR) | Account identity data; operational data entered by the user | Duration of account |
| Customer support and communications | Legitimate interests (Art. 6(1)(f) GDPR) — providing assistance and resolving issues | Email address, name, content of support communication | 3 years from last interaction |
| Service security and fraud prevention | Legitimate interests (Art. 6(1)(f) GDPR) — protecting the integrity of the Service and our users | IP address, session logs, usage events | 90 days rolling |
| Sending product updates and service notices | Performance of contract / legitimate interests (Art. 6(1)(f) GDPR) | Email address | Duration of account |
| Sending marketing emails (optional) | Consent (Art. 6(1)(a) GDPR) | Email address, name | Until consent is withdrawn |
| Analytics and Service improvement | Consent (Art. 6(1)(a) GDPR) — via cookie consent | Anonymised usage data via Google Analytics 4 | 14 months (GA4 default) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) | As required by applicable law | As required by law |
Legitimate Interests Assessment: Where we rely on legitimate interests as our legal basis, we have assessed that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time — see Section 8.
6. International Data Transfers
Coderdex Ltd. is based in the Republic of Cyprus, which is a member state of the European Union. Personal data is therefore collected and primarily processed within the EEA.
However, our service providers Vercel, Supabase, and Google LLC are based in the United States, which is a third country without an EU adequacy decision in respect of general commercial data transfers. Where personal data is transferred to these providers, we ensure appropriate safeguards are in place, specifically:
- Standard Contractual Clauses (SCCs) adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914 (Module Two: Controller to Processor), incorporated into our data processing agreements with each provider;
- for transfers from the United Kingdom: the UK International Data Transfer Addendum to the EU SCCs, as issued by the UK Information Commissioner’s Office.
You may request a copy of the relevant SCCs or further information about the safeguards in place for international transfers by contacting us at support@menucore.pro.
8. Your Privacy Rights
Under the GDPR and other applicable Data Protection Law, you have the following rights in respect of your personal data. We will respond to all verified requests within thirty (30) days, with a possible extension of a further two months for complex or numerous requests (in which case we will notify you of the extension and the reason).
| Your Right | What It Means | How to Exercise It |
|---|---|---|
| Right of Access | Request a copy of the personal data we hold about you and information about how we use it. | Email request to support@menucore.pro |
| Right to Rectification | Ask us to correct inaccurate or incomplete personal data. You can also update most information directly within your account settings. | Account settings or email request |
| Right to Erasure | Request deletion of your personal data where we no longer have a lawful basis to retain it. You can also delete your account directly via the "Delete Account" button in the app, which triggers immediate deletion. | In-app "Delete Account" or email request |
| Right to Restriction | Ask us to pause processing of your data in certain circumstances, such as while a dispute about accuracy is resolved. | Email request to support@menucore.pro |
| Right to Data Portability | Receive your personal data in a structured, commonly used, machine-readable format, or have it transmitted to another controller, where technically feasible. | Email request to support@menucore.pro |
| Right to Object | Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests. | Email request to support@menucore.pro |
| Right to Withdraw Consent | Where processing is based on your consent (e.g. analytics cookies, marketing emails), withdraw that consent at any time without affecting the lawfulness of prior processing. | Cookie settings or unsubscribe link in emails |
| Right to Lodge a Complaint | Lodge a complaint with the competent supervisory authority. For EU residents: your national Data Protection Authority. For Cyprus: the Commissioner for Personal Data Protection (www.dataprotection.gov.cy). | Directly with the supervisory authority |
8.1 How to Submit a Request
To exercise any of the rights above (other than those available directly within the Service), please email support@menucore.pro with the subject line "Privacy Request" and include:
- your full name and the email address associated with your account;
- a description of the right you wish to exercise and the personal data it relates to;
- sufficient information for us to verify your identity.
We will not charge a fee for handling your request unless it is manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act on the request. We will inform you if this is the case.
8.2 Right to Complain
If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the relevant supervisory authority:
- Cyprus: Commissioner for Personal Data Protection — www.dataprotection.gov.cy
- European Union: your national Data Protection Authority (list available at https://edpb.europa.eu)
- United Kingdom: the Information Commissioner’s Office — ico.org.uk
- United States (California): California Privacy Protection Agency — cppa.ca.gov
We would, however, appreciate the opportunity to address your concern before you contact a supervisory authority. Please contact us first at support@menucore.pro.
9. How Long We Keep Your Data
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Our specific retention periods are:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account and identity data | Duration of active account + 90 days | Provides a grace period for account recovery after deletion |
| Authentication tokens | Session duration (access) / up to 1 year (refresh) | Required to maintain authenticated sessions |
| Support communications | 3 years from last interaction | Required to maintain support history and resolve disputes |
| Security and access logs | 90 days rolling | Required for security monitoring and incident investigation |
| Analytics data (Google Analytics 4) | 14 months (GA4 default) | Standard GA4 retention period for aggregated usage data |
| Legal and compliance records | As required by applicable law (typically 5–7 years) | Legal obligation |
When personal data is no longer required, it is securely deleted or anonymised. Where anonymisation is not feasible, it is securely destroyed.
10. Deleting Your Account
You can permanently delete your Menucore account at any time by navigating to Account Settings and selecting "Delete Account" within the application. Deleting your account will:
- immediately revoke your access to the Service;
- schedule deletion of your account data (identity data, business data, and all Customer Data including recipes, ingredients, and menu items) within 90 days;
- cancel your active subscription via Paddle (note: no refund will be issued for unused subscription time in accordance with our Terms of Service).
Account deletion is permanent and irreversible. We recommend exporting any data you wish to retain before deleting your account. We cannot recover your data after deletion is complete.
If you delete your account, certain data may be retained beyond the 90-day window where required by applicable law — for example, records required for tax or accounting purposes may be retained by Paddle for the legally mandated period.
11. How We Protect Your Data
We implement and maintain technical and organisational security measures designed to protect your personal data against unauthorised access, disclosure, alteration, and destruction. These measures include:
- TLS 1.2 or higher encryption for all data in transit between your device and our servers;
- encryption of data at rest within our database infrastructure (Supabase);
- hashed storage of passwords using industry-standard algorithms — plaintext passwords are never stored;
- role-based access controls limiting access to personal data to authorised personnel only;
- regular security reviews of our infrastructure and third-party service providers;
- logical separation of data between different customer accounts.
No method of electronic transmission or storage is 100% secure. While we take the protection of your data seriously, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with applicable law.
12. Children’s Privacy
The Service is intended for use by businesses and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at support@menucore.pro and we will delete such data promptly.
13. Links to Third-Party Services
The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access. We are not responsible for the privacy practices of third parties.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in applicable law, our data practices, or the services we use. We will notify you of material changes by:
- posting a prominent notice within the Service before the change takes effect; and/or
- sending an email to the address associated with your account.
The updated Privacy Policy will be published at https://menucore.pro/privacy-policy with a revised "Last Updated" date. We encourage you to review this Policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acknowledgement of the updated Policy.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our data protection team:
Coderdex Ltd. — Data Protection Email: support@menucore.pro Subject line: "Privacy Request" or "Data Protection Enquiry" Website: https://menucore.pro
For formal complaints, you may also contact the Cyprus Commissioner for Personal Data Protection: Website: www.dataprotection.gov.cy
Related documents
- Terms of Service
- Refund Policy
- Data Processing Agreement (DPA) — including Cookie Policy and Sub-Processor List