Last updated: July 11, 2026
Privacy Policy
This Privacy Policy explains how WebMenu (“we”, “us”, “our”) collects, uses, and safeguards information when you create an account, manage a menu, or view a menu through our service at menu.webmv.info. By using WebMenu, you agree to the practices described below.
1. Who this policy applies to
WebMenu serves two groups of users with different data footprints:
- Restaurant account holders(“operators”) who sign up to build a digital menu.
- Diners who scan a QR code to browse a published menu. Diners do not create an account.
2. Information we collect
From restaurant account holders
- Account details: email address, display name, and a password you set. Passwords are never stored in plaintext — they are hashed with PBKDF2 (SHA-256, 100,000 iterations, random salt). Older hashes are upgraded after a successful login.
- Email verification & password reset tokens: time-limited tokens we email to you to confirm your address or reset your password.
- Business profile: the content you choose to upload — venue name, slug, logo, accent color, currency, phone number, address, menu categories, items, prices, photos, and dietary tags.
- Session records: a login session row tied to the device you use to sign in.
- Team invitations: an invited email address, inviter, intended manager role, and a time-limited one-way token hash used to grant workspace access.
- Security audit events: privileged workspace and platform actions, their time, actor, tenant, target, and limited change metadata such as a new plan or status.
From diners
- Anonymous ratings: when a diner submits a 1–5 star rating, we store the rating value and a one-way hash of a random browser token. The random token is kept in a first-party cookie for 30 days so the same browser can update, rather than duplicate, its rating for a dish. We do not ask diners for a name or email.
- Cloudflare Turnstile tokens: to prevent spam on ratings we verify each submission with Cloudflare Turnstile. The token itself is used once at submission time and is not retained.
Automatically collected
- IP address & request metadata: used to enforce rate limits on login, signup, password reset, and rating endpoints. We persist only a one-way scoped hash, a counter, and a short reset time so limits work across service instances. Rating records do not contain an IP address or IP-derived hash.
- Standard web server logs (processed by Cloudflare) for security and debugging.
3. How we use information
- To provide the service — authentication, storing your menu, rendering public pages, generating QR codes.
- To deliver transactional email (account verification, password reset, and team invitations). Team invitation messages include the invited address, workspace name, and inviter name.
- To aggregate anonymous ratings into per-dish averages shown on the public menu.
- To detect and prevent abuse, spam, and unauthorized access.
- To communicate service announcements or operational changes.
We do not sell your personal data. We do not run third-party advertising trackers on the app.
4. Cookies
WebMenu sets a small number of first-party cookies:
session_id— identifies a logged-in operator session. HttpOnly, Secure, SameSite=Lax. Expires after 30 days or on logout.- A rating deduplication cookie on public menu pages. It is HttpOnly, Secure in production, SameSite=Lax, and expires after 30 days.
Cloudflare Turnstile may set its own cookies on rating submissions to validate that a request is not automated. See Cloudflare’s privacy policy for details.
5. Third-party service providers
WebMenu relies on a small set of sub-processors. We share only what each one needs to function:
- Cloudflare — hosting (Cloudflare Workers), database (D1), object storage (R2) for uploaded images, and bot protection (Turnstile).
- Resend — transactional email delivery for account verification, password reset, and team invitations.
These providers may process data in jurisdictions outside the Maldives. We choose providers that publish security and privacy documentation, and we pass them the minimum data required.
6. Data retention
- Account and venue data is retained for as long as your account is active. If you delete your account, the associated tenant, venues, menus, and uploaded images are removed within a reasonable period.
- Login sessions expire after 30 days or when you log out. All sessions for a user are invalidated when that user resets their password.
- Password reset and email verification tokens are time-limited and consumed on use.
- Team invitations become unusable after 72 hours. They are deleted when accepted or cancelled, and replaced when an owner resends an invitation to the same address. Expired records are deleted by routine cleanup once they are 30 days old.
- Security audit events become eligible for routine deletion after 12 months. When an account or workspace is deleted, related actor and tenant links are removed and the remaining event is de-identified.
- Ratings are anonymous and are retained for the lifetime of the corresponding menu item. Operators and admins may reset ratings for a venue at any time.
- Rate-limit buckets contain a one-way scoped key, counter, and reset time. Expired buckets are removed automatically.
7. Security
- Passwords are stored as salted PBKDF2 hashes; the original password is never known to us.
- Password comparison uses constant-time equality to prevent timing attacks.
- Authentication endpoints are rate-limited to blunt brute-force attacks.
- Session cookies are
HttpOnly,Secure, andSameSite=Lax. - All traffic is served over HTTPS via Cloudflare.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at support@webmv.info.
8. Your rights
Subject to applicable law, you may request to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate information.
- Delete your account and associated data.
- Withdraw consent to email marketing (we currently only send transactional email).
To exercise any of these rights, email support@webmv.info from the address associated with your account.
9. Children
WebMenu is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has created an account, please contact us to have it removed.
10. Changes to this policy
We may update this Privacy Policy to reflect changes to our service or legal obligations. Material changes will be communicated by updating the “Last updated” date and, when appropriate, by an email to account holders. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this Privacy Policy or our data practices can be directed to support@webmv.info.