Privacy Policy

Last updated: 26 July 2026

1. Introduction

YumYum ("we", "our", "us") operates yyum.app, a service for building multilingual digital restaurant menus. This policy explains what personal data we process, on what legal basis, who receives it, and what rights you have. It applies to restaurant owners who hold an account with us and to guests who open a menu we host.

2. Our role

We act as the data controller for account data of restaurant owners: registration details, billing, support correspondence, and usage of the yyum.app website itself.

For data about menu guests (the analytics collected when someone opens a published menu), we act as a data processor on behalf of the restaurant that owns the menu. That restaurant is the controller and decides why the data is collected; we process it only on their instructions and make the resulting statistics available to them.

3. Data we process

3.1 Account data

Provided directly by restaurant owners when they register and use the service:

  • Name and email address, and the Google account identifier if you sign in with Google
  • Business details: restaurant name, contact details, working hours, address
  • Menu content: dish names, descriptions, prices and images you upload
  • Billing data: subscription plan, payment status and transaction identifiers. Card details are entered on the payment provider's page and never reach our servers
  • Support correspondence you send us by email or Telegram

3.2 Data collected automatically on our website

When you use yyum.app we and our providers record:

  • Technical request data: IP address, browser type, operating system, timestamps. Used to serve the site, apply rate limits and detect abuse; not used to build profiles
  • Language and theme preference, stored on your device so the interface stays as you left it
  • With your consent only: analytics about which pages you visited and how you arrived

3.3 Data about menu guests

When a guest opens a published menu and consents to analytics, we record on behalf of the restaurant:

  • A randomly generated visitor and session identifier stored on the guest's device: it contains no name, email or account link
  • Which menu, dishes and languages were viewed, and search terms entered in the menu
  • Device type, browser language, referring source and whether the menu was opened from a QR code

4. Cookies and similar technologies

4.1 What these are

Cookies and browser storage are small pieces of data saved on your device by a website. We use both, and group them into two categories: strictly necessary, and analytics.

4.2 Strictly necessary: no consent required

These are needed to deliver a service you have asked for and are set without consent, as permitted by the ePrivacy Directive:

  • Authentication and session cookies that keep you signed in and protect the account area
  • Security cookies used for rate limiting and abuse prevention
  • Your language and theme choice, so the interface renders the way you selected it
  • A record of your cookie choice itself, so we do not ask again on every page

4.3 Analytics: only with your consent

Nothing in this category runs until you press "Accept" on the cookie banner. Declining means these are never initialised and no identifier is written to your device. It covers three services:

  • Google Analytics (Google Ireland Limited / Google LLC) collects aggregate website usage: visitor counts, pages viewed, time on site, traffic sources
  • PostHog (PostHog Inc., EU region, hosted in the European Union) collects product analytics on how the account area is used, to find broken and confusing flows. This includes session replay: a reconstruction of your interaction with the interface (clicks, navigation and the content of the pages you saw) used to diagnose faults
  • Our own menu analytics: the guest statistics described above, shown to the restaurant that owns the menu. This is first-party and is not shared with advertising networks

Google Analytics may transfer data to servers operated by Google LLC in the United States. PostHog data stays in the European Union. See the section on international transfers below for the safeguards that apply.

We do not use advertising, retargeting or cross-site tracking cookies, and we do not sell data to advertising networks.

4.4 Changing or withdrawing your choice

Withdrawing consent is as easy as giving it, and has no consequences for using the service:

  • Select "Cookie settings" in the footer of any page. The banner reopens and you can decline
  • Declining stops all analytics immediately and deletes the analytics identifiers already stored on your device
  • We ask again after 12 months, and whenever this policy changes what analytics collects, so consent is never carried over to new processing

4.5 Browser-level controls

Independently of our banner, your browser lets you:

  • View stored cookies and delete them individually
  • Block third-party cookies or all cookies
  • Clear all cookies when you close the browser
  • Install the Google Analytics Opt-out Browser Add-on

Blocking strictly necessary cookies will stop you from being able to sign in.

5. What we use data for

We process personal data only for these purposes:

  • Providing the service: creating and hosting menus, translating them, generating QR codes, and keeping your account working
  • Billing: managing subscriptions, processing payments and keeping tax records
  • Support: answering your questions and investigating faults you report
  • Security: rate limiting, detecting fraud and abuse, and protecting accounts
  • Improving the service: understanding which features are used and where people get stuck
  • Legal compliance: meeting accounting, tax and data protection obligations

6. Legal bases

Under Art. 6(1) GDPR we rely on a specific basis for each purpose:

  • Providing the service and billing: performance of a contract with you, Art. 6(1)(b)
  • Support correspondence: performance of a contract, Art. 6(1)(b)
  • Security, abuse prevention and rate limiting: our legitimate interest in keeping the service available and protecting accounts from takeover and fraud, Art. 6(1)(f)
  • Analytics, and the storage of analytics identifiers on your device: your consent, Art. 6(1)(a) and Art. 5(3) ePrivacy Directive. You may withdraw it at any time
  • AI-assisted menu import and translation: performance of a contract, Art. 6(1)(b), since you request the feature
  • Retaining invoices and transaction records: compliance with a legal obligation, Art. 6(1)(c)

7. Who receives data

We share personal data only with the processors and partners needed to run the service:

  • Supabase: database, authentication and image storage
  • Vercel Inc.: application hosting and content delivery
  • Google (Google Ireland Limited / Google LLC): Gemini API for AI-assisted menu import and translation, Google Analytics with your consent, and Google Sign-In if you use it. Menu text and images you submit for import or translation are sent to this API for processing
  • PostHog Inc. (EU region): product analytics, with your consent
  • Stripe Payments Europe, Ltd.: payment processing. Card data is collected by them directly, not by us
  • Authorities and legal advisers: only where required by law or to establish or defend legal claims
  • An acquirer: if the business is merged or sold, subject to this policy continuing to apply

We do not sell personal data and we do not share it with advertising networks or data brokers.

8. International transfers

Some providers process data outside the European Economic Area, principally in the United States. Where that happens we rely on:

  • The EU–US Data Privacy Framework, where the recipient is certified under it; this currently applies to Google LLC
  • Standard Contractual Clauses approved by the European Commission, together with supplementary technical measures such as encryption in transit and at rest, where the Framework does not apply
  • PostHog is used in its EU region, so product analytics data is not transferred outside the European Union

9. Security

Data is encrypted in transit (TLS) and at rest. Access to production data is restricted to the people who need it, database access is governed by row-level security policies, and the analytics and administration paths are protected by server-side authorisation checks. No system is perfectly secure, so we cannot guarantee absolute security, but we will notify you and the supervisory authority of a personal data breach where the GDPR requires it.

10. How long we keep data

We keep personal data only as long as needed for the purpose it was collected for:

  • Account and menu data: for as long as the account exists, and deleted within 30 days of a deletion request
  • Invoices and transaction records: 7 years, as required by tax law
  • Guest analytics events: up to 26 months, after which they are deleted or irreversibly aggregated
  • Support correspondence: 24 months after the request is closed
  • Server logs: 30 days
  • Your cookie choice: 12 months, after which we ask again

11. Your rights

If the GDPR applies to you, you have the right to:

  • Be informed about how your data is used (Art. 13 and 14)
  • Access the personal data we hold about you (Art. 15)
  • Have inaccurate or incomplete data corrected (Art. 16)
  • Have your data erased (Art. 17)
  • Restrict processing (Art. 18)
  • Receive your data in a portable, machine-readable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time, without affecting processing carried out before withdrawal (Art. 7(3))

To exercise any of these rights, write to us at the address below. We may ask for information to confirm your identity, and only to that end.

We respond within one month of receiving the request. If the request is complex we may extend this by a further two months and will tell you why within the first month. Exercising your rights is free of charge.

If you are a menu guest, your request concerns data we process for the restaurant whose menu you opened; contact them, or contact us and we will pass the request on. You may also lodge a complaint with the data protection authority of the country where you live or work.

12. Children

The service is intended for businesses and is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

13. Changes to this policy

We may update this policy. Material changes are announced on this page and the "last updated" date is revised. If a change alters what analytics collects or who receives it, we ask for your cookie consent again rather than relying on the previous one.

14. Contact

For any privacy questions or to exercise your rights: