Smart Digital Menu

smartdigital.menu

Privacy notice

This notice transparently explains which data Smart Digital Menu uses, why it is used and the choices available to you.

Effective 1 September 2026Version 1.2
This notice covers the Smart Digital Menu app, its APIs, venue profiles and public menus opened through a link or QR code.

1. Controller and scope

The data controller is Smart Digital Menu (smartdigital.menu). For questions, requests or to exercise your rights, email info@smartdigital.menu.

The app is intended for hospitality and food-service owners and operators. Public menus can be viewed by anyone with the relevant link or QR code.

2. Data processed and its source

Data comes from you, use of the app and public menus and, for sign-in, Firebase Authentication and your selected identity provider. We do not intentionally collect external-provider passwords, payment data or advertising data.

Account and authentication

  • Firebase UID, verified email address or phone number, language, account status and linked sign-in providers;
  • Firebase ID token checked for the individual request without retaining it as a proprietary session token;
  • IP address, user agent, date, outcome and technical request identifiers required for security and diagnosis.

Venue profile, menus and content

  • venue name and type, contact details, address, opening hours, images and visibility settings;
  • menus, categories, items, prices, ingredients, allergens, tags, descriptions, translations, themes and QR codes;
  • versions, identifiers and technical information required for synchronization, cache and conflict management.

Optional data

  • support requests and communications you choose to send;
  • pseudonymized technical events about use, errors and performance only if the feature becomes available and is enabled with consent; this collection is disabled in the current version.

3. Purposes and legal bases

Data required for authentication, security, saving and publishing is necessary to provide the service. Public profile details, images, requested translations and optional analytics depend on choices made in the app.

PurposeLegal basis
Create and manage the account; authenticate, synchronize, save and publish menusPerformance of the contract
Protect accounts and infrastructure, prevent abuse and respond to incidentsLegitimate interest in security and legal duties
Generate user-requested automatic translationsPerformance of the contract
Handle support, privacy requests and disputesLegal duty, performance of the contract and protection of rights
Optional analytics and diagnostics, if introducedPrior, specific and revocable consent

4. Firebase Authentication and external sign-in

Firebase Authentication, a Google service, verifies identity using the method selected in the app: email and password, phone, Google or Apple where available. Smart Digital Menu keeps the Firebase UID and, when available and verified, email, phone and linked providers; the backend does not receive external-provider passwords.

Firebase Authentication may process email, phone, passwords, user agents and IP addresses for authentication, security and abuse prevention. Google states that the service runs from US data centres and applies its processing terms and relevant transfer safeguards.

Disconnecting Google, Apple or another provider does not automatically delete the Smart Digital Menu account.

5. Automatic translations through OpenAI

Only when you request a translation, we send OpenAI the selected text and source and target languages. The request is configured with store=false and should not contain unnecessary personal data.

OpenAI states that API data is not used to train its models by default unless the customer explicitly opts in. Abuse-monitoring logs may contain inputs and outputs and be retained for up to 30 days, subject to legal requirements or different data-retention controls applying to the API account.

Translations may contain errors. The menu owner must review them before publication, especially allergens, ingredients and consumer information.

6. Public menus, QR, logs and technical cookie

When you publish a menu, selected content becomes available through a link or QR code without requiring visitors to create an account. Do not publish unnecessary personal data or content for which you lack rights.

To deliver the page and protect it against abuse, the server processes IP address, user agent, date and technical request identifiers. Logs are limited to what is required for security, diagnosis and protection of the service.

A strictly necessary HttpOnly cookie linked to the menu and valid for approximately five minutes may be used to load public-menu images securely. It is not used for advertising, profiling or cross-site tracking.

The website and landing page do not set advertising cookies or include profiling tools.

7. Recipients and international transfers

We may use hosting and infrastructure providers to store and protect data, Google for Firebase Authentication, the selected identity provider and OpenAI for requested translations. They act as processors or independent controllers depending on the service and receive only the required data.

Data may also be disclosed to authorities or advisers where required by law or necessary to establish, exercise or defend a legal claim. We do not sell personal data or disclose it for behavioural advertising.

Where a provider processes data outside the European Economic Area, the transfer relies on GDPR safeguards such as adequacy decisions or standard contractual clauses, as applicable.

8. Retention and deletion

You can delete the account in the app after a recent identity check or, when a verified email is available, on the website using a single-use link sent to that address. The account, content and linked events are removed from active systems unless retention is required for law, security or disputes.

Deletion from Smart Digital Menu also starts removal of the Firebase identity. Google specifies its technical live-system and backup deletion periods in Firebase documentation. Residual copies are not restored for ordinary use and disappear through backup rotation.

CategoryPeriod or criterion
Account, venue profile and menusUntil account deletion or for the duration of the relationship
Authentication identifiers in the backendUntil account deletion; no proprietary access tokens are retained
Optional analytics, if enabledUp to 90 days
Optional diagnostics, if enabledUp to 30 days
Public-menu technical cookieApproximately 5 minutes
Technical logs and support requestsAs required for security, diagnosis, request handling or legal claims
Protected backupsUntil replacement under the normal disaster-recovery cycle

9. Rights, complaints and choices

Where applicable, you may request access, rectification, erasure, restriction, portability and objection. You may withdraw consent at any time without affecting prior lawful processing.

To protect the account, we may request reasonable information to verify the requester’s identity. We will respond within the deadlines set by applicable law.

You may complain to the Italian Data Protection Authority or the competent authority in the European country where you live or work.

10. Security, children and updates

We use proportionate technical and organizational measures including HTTPS, Firebase Authentication, access controls, protected media, request limits and deletion procedures. No system is entirely risk-free.

The service is intended for professional operators and is not designed for children to hold accounts directly. If you believe a child improperly provided data, contact us.

We may update this notice when the service, providers or law changes. The date and version above identify the current text; material changes will be communicated through appropriate means.