← Back to MenuWright

Privacy Policy

Last updated: July 30, 2026

1. Who We Are

MenuWright is operated by Axiomancer Labs LLC, a California limited liability company. This policy explains what information we collect, how we use it, and the choices you have. It applies to menuwright.com and the MenuWright application, and should be read together with our Terms of Service.

2. Information We Collect

  • Account data: name, email address, restaurant name, and a hashed password.
  • Business data you provide: menu items, prices, food costs, and sales records you upload or sync, plus optional branding assets (logo, colors).
  • POS integrations: if you connect Square, we receive an access token (stored encrypted) and sync catalog and sales data. We never store your Square account password.
  • Billing data: subscription and usage records. Payment card details are handled directly by Stripe and never touch our servers.
  • Technical data: error reports and performance diagnostics via Sentry, and standard server logs.

3. How We Use Information

To operate the Service (analysis, recommendations, reports, billing, and support); to secure and improve the Service; to send service emails such as weekly digest reports; and to comply with legal obligations. We do not sell your data or use it for advertising.

4. AI Processing

To generate recommendations, your menu and sales data (de-identified of customer-level payment details) is transmitted to third-party AI model providers under commercial terms. By using AI recommendations, you consent to this processing. Aggregated, non-identifiable usage metrics may be used to improve product quality.

5. Service Providers

We share data only with processors required to run the Service: Stripe (payments), Square (POS data, at your direction), AI model providers (recommendation generation), Resend (email delivery), Sentry (error monitoring), and Railway and Vercel (hosting). Each processes data under contractual confidentiality and security obligations.

6. Security

Data in transit is protected with TLS. POS access tokens are encrypted at rest, authentication uses short-lived JWTs with refresh rotation, and access to production systems is restricted and monitored. No system is perfectly secure; we commit to prompt investigation and notification where a breach affects your data.

7. Retention

We keep your data while your account is active. You may request deletion of your account and associated data at any time by contacting us (address below); upon deletion we remove your business data from production systems within 30 days, except where retention is required by law.

8. Cookies and Local Storage

MenuWright does not use third-party tracking cookies. Authentication tokens are stored in your browser’s local storage to keep you signed in.

9. Your Rights

You may access, correct, export, or delete the personal information we hold about you by contacting us. California residents have additional rights under the CCPA/CPRA, including the right to know, delete, and correct, and the right not to be discriminated against for exercising these rights. We honor all such requests within the timeframes required by law.

10. Children

The Service is business software not directed at individuals under 13, and we do not knowingly collect their information.

11. Changes

We will announce material changes in the Service or by email at least 14 days before they take effect.

12. Contact

Privacy questions or requests: support@menuwright.com.