Venue Menus is operated by Max Howell, 167 E. Chatham Street, Suite 300, Cary, NC 27511, USA. For privacy questions or requests, email hello@venue-menus.com.
Who this policy covers
This policy covers people who visit Venue Menus, create or use a venue account, buy credits, connect an integration, contact support, or view a menu hosted by Venue Menus. A venue remains responsible for the information it chooses to publish about its business, staff, or other people.
Information we collect
| Category | Examples | Why we use it |
|---|---|---|
| Account and contact | Email address, venue and location names, team role, communications | Create and secure accounts, send sign-in links, provide support, and operate the service |
| Menu and website content | Items, prices, descriptions, images, public contact details, hours, and events you submit | Save drafts and publish the outputs you choose |
| Integration data | Square authorization credentials, catalog identifiers, item quantities, totals, currencies, dates, and Untappd menu URLs | Run integrations you enable, synchronize menus, report sales, and support optional keg estimates and discounts |
| Payments | Credit purchase amount, Stripe customer, checkout, and payment identifiers, and credit ledger entries | Complete purchases, maintain balances, prevent duplicate fulfillment, handle reversals, and keep financial records |
| Optional AI work | Your brief, selected menu or website content, reference images, generated results, source links, and provider usage metadata | Quote, generate, save, and recover the assisted work you explicitly request |
| Usage and security | Daily aggregate menu views by source and broad device class; request time, IP address, user agent, and limited error details in operational logs | Show basic analytics, keep the service reliable, investigate abuse, and protect accounts |
| Advertising measurement | When enabled under the regional controls in our Cookie Notice: ad-click and browser identifiers, page address, connection information, and a signup event with a random receipt | Measure which Google Ads lead to new accounts; personalized advertising is disabled |
We collect information from you, your authorized teammates, services you connect, and public pages you ask us to import or research. Local PDF and photo imports are processed in your browser; only rows you review and save are sent to Venue Menus. We do not intentionally collect card numbers or Square customer and card details.
Legal bases
Where the GDPR or UK GDPR applies, we process account, content, integration, and support information because it is necessary to provide the service you request and perform our agreement with you. We process security, limited analytics, service improvement, and legal-claim information for our legitimate interests in operating a safe and useful service. We process transaction records where necessary to meet legal obligations. When the law requires consent for a particular activity, you may withdraw it at any time without affecting earlier lawful processing.
How we share information
We disclose information only as needed to operate Venue Menus, follow your instructions, complete a transaction, protect the service, or comply with law. Current categories of recipients include:
- Amazon Web Services for hosting infrastructure and transactional email.
- Stripe for one-time credit purchases, payment processing, fraud prevention, and legally required payment records.
- Square when you choose to connect a Square seller account.
- OpenAI only when an owner starts optional assisted writing, research, translation, or image work. OpenAI states that API inputs and outputs are not used for model training by default and may retain abuse-monitoring data for up to 30 days under default controls.
- Google Fonts when your browser requests the site’s hosted typefaces from Google; the request can disclose ordinary connection information such as your IP address and user agent.
- Professional advisers, authorities, or a successor operator when reasonably necessary for legal compliance, claims, security, or a business transfer.
Venue Menus does not sell personal information. Marketing and signup pages may load Google Ads to measure ad performance under the regional controls in our Cookie Notice. We do not send email addresses, venue names, or menu content to the tag, and personalized advertising is disabled. Hosted customer menus and the Studio do not load this tag. You can decline or withdraw using Cookie preferences at the bottom of marketing and signup pages. See our Cookie Notice for storage and regional details.
Public information
Menus, venue websites, contact details, events, and translations become public only when an authorized user publishes them. Public information can be copied, cached, indexed, or archived by other people and services. Unpublishing stops Venue Menus from serving that content publicly but cannot recall copies made elsewhere.
International processing
Venue Menus is operated from the United States. Information may be processed in the United States and in other countries where our providers operate. Those countries may have different privacy laws. Where required, we rely on appropriate contractual or legally recognized transfer safeguards and make information about those safeguards available on request.
How long we keep information
- Sign-in links expire after 15 minutes and authenticated sessions after 30 days.
- Square sales reports retain a rolling 90-day history and exclude customer and card details.
- Account content, publication history, integration settings, AI job records, and credit records are generally retained while the account is active so the service and saved results continue to work.
- Payment, audit, security, backup, and dispute records may be retained longer where reasonably necessary for law, fraud prevention, accounting, security, or legal claims.
- Aggregate statistics that no longer identify a person may be retained.
When you request deletion, we delete or de-identify information that is no longer needed, subject to the limits above and reasonable backup cycles.
Your privacy rights
Depending on where you live, you may have rights to know or access your personal information, correct it, delete it, restrict or object to processing, receive a portable copy, or withdraw consent. You may also complain to your local data protection authority. We do not discriminate against anyone for exercising a privacy right.
Your right to object: where we rely on legitimate interests, you may object based on your circumstances. You may always object to direct marketing; Venue Menus currently does not send behavioral advertising or sell mailing lists.
California residents may also request the categories and specific pieces of personal information collected, correction, deletion, and information about disclosures. Because Venue Menus does not sell or share personal information for behavioral advertising, there is no sale or sharing to opt out of. These statements do not concede that every privacy law applies to Venue Menus in every circumstance.
Browser privacy signals: Global Privacy Control and Do Not Track disable optional Google Ads measurement, even when you previously allowed it.
Send a request to hello@venue-menus.com. Describe the account and request. We may verify your identity and authority before acting. An authorized agent may submit a request where local law permits.
Security and children
We use technical and organizational measures intended to protect information, including scoped account access, expiring sign-in links, secure session cookies, request validation, and limited error reporting. No service can guarantee absolute security. Venue Menus is a business service and is not directed to children under 18.
Changes
We may update this policy as the service or law changes. We will update the effective date and provide additional notice when a material change requires it.
Contact
Max HowellVenue Menus
167 E. Chatham Street
Suite 300
Cary, NC 27511
USA
Email: hello@venue-menus.com