Privacy Policy
Last updated August 2026.
ComplyMenu ("ComplyMenu," "we," "us") provides digital food-safety compliance tracking for restaurants. This policy explains what information we collect, how we use it, and what control you have over it. It applies to complymenu.com and the ComplyMenu application.
What we collect
We collect only what's needed to run the service:
- Account information: restaurant name, staff name and email address, and a securely hashed password. We never store your password in a form that could be read back — it's hashed with bcrypt, a one-way process, so even we can't see it.
- Operational data: the records you create in the app — locations, check templates, temperature and checklist logs, corrective action notes, and certification records. This is the actual compliance data ComplyMenu exists to track, and it belongs to you.
- Billing information: we do not collect or store your card details. Payment is handled entirely by Stripe, our payment processor. We retain only a Stripe customer reference and your subscription status — never your card number, expiry, or CVC.
- Basic technical data: standard web server logs (IP address, browser type, request timestamps) generated automatically by normal web traffic, and a session cookie used solely to keep you logged in.
What we don't do
- We don't sell your data, to anyone, under any circumstances.
- We don't use advertising or tracking cookies. There are no ads in ComplyMenu.
- We don't share your operational data (check logs, staff records, certifications) with any third party except where you explicitly choose to export it yourself.
Who we share data with
A small, deliberate list:
- Stripe — processes payments and manages your subscription. Stripe has its own privacy practices governing the payment details you provide directly to them.
- Our hosting provider — stores the application and database that run ComplyMenu.
That's the complete list. We don't use third-party analytics, marketing, or email-automation platforms — transactional emails (welcome, password reset, overdue reminders) are sent directly from our own mail server, not routed through an outside service.
How long we keep your data
Your data is retained for as long as your account is active. If you cancel your subscription, your account and its data remain accessible under trial-equivalent restrictions until you choose to delete it. Deleting your restaurant account from Settings permanently and immediately removes every location, staff record, check log, and certification tied to it — this action cannot be undone, and we don't keep a hidden backup copy after deletion completes.
Your rights and controls
- Access: everything ComplyMenu holds about your restaurant is visible directly in the app — there's no data we collect that isn't shown to you.
- Export: your full check-log history can be exported as a CSV file at any time, directly from the Checks page.
- Correction: staff can update their own name and email from Settings at any time; owners can correct restaurant details the same way.
- Deletion: restaurant owners can permanently delete the entire account and all associated data from Settings, at any time, with no need to contact us first.
Security
Passwords are hashed with bcrypt. All traffic to ComplyMenu is encrypted in transit (HTTPS). Access to your restaurant's data is restricted by role — staff, managers, and owners each see only what their role and location assignment permit. Every account-modifying action is protected against cross-site request forgery, and session cookies are configured to resist common browser-based attacks.
Children's privacy
ComplyMenu is a business tool for restaurant operators and staff. It is not directed at, and should not be used by, anyone under 18.
Changes to this policy
If we make a material change to how we handle your data, we'll update this page and, where appropriate, notify account owners directly by email.
Contact
Questions about this policy or your data can be sent to legal@complymenu.com.
