Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Your One Menu ("we") collects and uses personal data as a data controller under the UK GDPR and the Data Protection Act 2018.
Who we are
Your One Menu is operated from the United Kingdom. Contact: hello@youronemenu.com.
Data we collect
- Account: name, email, hashed password or Google identifier.
- Restaurant profile: trading name, contact details, logo, opening hours.
- Menu content: categories, items, prices, descriptions, images you upload.
- Billing: subscription status and Stripe customer identifiers. Card details are stored by Stripe, never by us.
- Technical: IP address, browser, and basic device information for security and abuse prevention.
How we use your data
- To provide and secure the service (contract).
- To process payments and manage subscriptions (contract, legal obligation).
- To send essential account and billing emails (contract).
- To improve the product and prevent abuse (legitimate interests).
Sharing
We share personal data only with processors that help us run the service: our cloud hosting and database provider, Stripe for payments, and our transactional email provider. We do not sell your data.
Retention
We keep account and menu data for as long as your account is active. On account deletion, personal data is removed within 30 days, except where retention is required for legal or accounting purposes (typically up to 6 years for invoices).
Your rights
You have the right to access, correct, delete, restrict, port, and object to processing of your personal data. Contact us to exercise any of these rights. You may also complain to the UK Information Commissioner's Office (ICO).
International transfers
Where data is processed outside the UK or EEA, we rely on adequacy decisions or Standard Contractual Clauses to protect it.
Security
We use encryption in transit, at rest, and row-level access controls in our database. Passwords are stored only as one-way hashes.