Privacy Policy for the MenuMonkeys website and platform
As of: August 2026
This privacy policy provides information on the processing of personal data in connection with the menumonkeys.com website and the use of the MenuMonkeys platform by operators (hospitality and hotel businesses). For the processing of guest data within an individual business, the separate provision in Section 11 applies.
1. Controller
The controller within the meaning of the GDPR is:
AzApp.one GmbH, Mitländerstrasse 20, 71642 Ludwigsburg, Germany.
Email: [email protected]. Represented by the managing director René-M. Bogislawski.
For data protection enquiries, you can reach us at the above address or email. A data protection officer has not been appointed, as the legal requirements for this are not met.
2. Principles and legal bases
We only process personal data insofar as this is necessary to provide a functional Service. Depending on the processing, the legal bases are Art. 6(1)(b) GDPR (contract/pre-contractual measures), (c) (legal obligation, e.g. commercial and tax retention), (f) (legitimate interest in secure, functional operation) and (a) (consent, revocable at any time).
3. Accessing the website (server log data)
When the website is accessed, technically necessary data is processed (including IP address, date and time, resource accessed, referrer, browser/device information). This processing serves delivery, stability and security (Art. 6(1)(f) GDPR). The website is preceded by the service Cloudflare (TLS termination, protection against attacks); hosting takes place with Hetzner in Germany.
4. Cookies and local storage
We do not use tracking or marketing cookies without your consent. For basic functions (e.g. language selection, favourites, consent status) we use your browser's local storage. A consent banner informs you on your first visit; without consent, no processing beyond the basic functions takes place. The legal basis for non-essential storage is your consent (Art. 6(1)(a) GDPR, Section 25 TDDDG).
5. Registration and operator account
If a business registers, we process the data provided for this purpose (including name, email address, contact and business data, access data). Login is by password (bcrypt-hashed) or magic link. The legal basis is Art. 6(1)(b) GDPR. For session management we use short-lived access tokens and an httpOnly cookie.
6. Contract processing and payment
To process paid plans, we use the payment service provider Stripe. Payment and card data is processed exclusively by Stripe and not stored in our database; we only store reference identifiers (customer/subscription ID, subscription status) and invoice data. The legal bases are Art. 6(1)(b) and (c) GDPR. Invoice-relevant data is retained in accordance with the statutory retention periods (Section 147 AO, Section 257 HGB).
7. Email dispatch
For sending transactional emails (login links, confirmations, notifications) we use the service Resend. The recipient address and message content are processed. The legal basis is Art. 6(1)(b) or (f) GDPR.
8. AI-assisted functions
For importing and translating menus and generating image content, we use services from Google (Gemini) and – as a fallback – OpenAI and Groq. In doing so, menu texts and uploaded menu photos are processed; personal guest data is not transmitted for this purpose. For stock images we use Pexels (search terms only, no personal data).
9. Push notifications
With your consent, we send push messages to your device. For this, a push registration (endpoint and key of your browser) is stored and delivered via your browser's respective push service (e.g. Google, Mozilla, Apple). We operate the underlying VAPID keys ourselves. The legal basis is Art. 6(1)(a) GDPR; consent can be revoked at any time via the device settings.
10. Recipients and processors
We only pass on personal data to carefully selected service providers who act for us as processors under Art. 28 GDPR:
- Hetzner Online GmbH – server hosting and backups (Germany)
- Cloudflare, Inc. – security and TLS delivery
- Resend, Inc. – email dispatch
- Google Ireland/LLC – AI functions (Gemini)
- OpenAI and Groq, Inc. – AI fallback
- Stripe, Inc./Stripe Payments Europe – payment processing
- Telegram – optional operator notifications (only when activated by the business)
11. Role regarding guest data in the business (processing on behalf)
Order, reservation and – where activated by the business – guest contact data that arise in the course of the ordering and service operation of an individual business are processed by us on behalf of the respective business. In this relationship, the business is the controller in the data protection sense and AzApp.one GmbH is the processor. The basis is the data processing agreement (DPA) pursuant to Art. 28 GDPR, which forms part of the contract with the business. As a guest, please contact the respective business as the controller to exercise your rights.
12. Transfer to third countries
Some of the services used (in particular Resend, Google, OpenAI, Groq, Stripe, Cloudflare, Telegram) may process data in third countries, in particular the USA. Insofar as there is a third-country connection, this is safeguarded by appropriate guarantees under Art. 44 et seq. GDPR – regularly through the EU standard contractual clauses (Art. 46(2)(c) GDPR) and, where the provider is certified, through the EU-U.S. Data Privacy Framework.
13. Storage period
We only store personal data for as long as is necessary for the stated purposes or as required by statutory retention periods. Account data is stored for the duration of the contractual relationship and deleted after its termination, unless retention obligations preclude this. Reservation data is automatically anonymised after 90 days. Contact details in orders (name, email, phone, notes) are also automatically anonymised after 90 days; order amounts and items are retained for statutory retention periods. Technical logs are only kept for the period necessary for security.
14. Your rights
Subject to the statutory requirements, you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and a right to object (Art. 21). You can revoke consent given at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI BW).
15. Data security
We take appropriate technical and organisational measures. Transmission is encrypted (TLS/HTTPS); sensitive access data and keys are stored encrypted (AES-256-GCM), passwords only as a hash (bcrypt). Access is restricted on a role basis, and security-critical endpoints are rate-limited.
16. Currency and amendments
This privacy policy will be adapted as needed to changed legal situations or functions. The version published on this page at any given time applies.