Privacy Policy
This policy explains what [[ENTITY_NAME]] ("we") collects when you use blueplate, why, and what you can do about it. It covers two different groups: merchants who hold an account, and guests who scan a QR code to read a menu.
Guests scanning a menu
If you are a diner looking at a menu, we do not collect anything that identifies you. We record that a menu was viewed, on what date, and a coarse size bucket for the screen (mobile, tablet, or desktop) derived from the browser window's width. We do not record your IP address, your user agent, or any cookie or advertising identifier, and we do not build a profile of you.
Your browser stores a single short-lived marker so the same visit is not counted twice if you refresh. It never leaves your device and is discarded when you close the tab.
Menus may link out to delivery platforms or a phone number. Following those links takes you to another company's service, governed by their policy, not this one.
Merchants with an account
We collect and store:
- Your email address and the name you provide, so we can identify your account.
- The restaurant information you enter — name, address, contact details, menu content, and any images you upload. This is published deliberately: it is the menu your guests read.
- If you subscribe to a paid plan, identifiers issued by our payment processor linking your account to your subscription, plus your plan and its renewal date.
We never see or store your card details. Payment information is entered directly with our payment processor and does not pass through our servers.
Your sign-in session is kept in your browser's local storage rather than a cookie. We do not use cookies for analytics or advertising, and there are no third-party trackers on this service.
Uploaded images
Logos, banners, and dish photographs you upload are stored in a public bucket so guests can load them. Anyone holding the direct URL can view an uploaded file, whether or not the menu is published — please do not upload anything you would not put on a printed menu.
Who else processes this data
We rely on these providers, each acting on our instructions:
- Supabase — database, authentication, and file storage.
- Cloudflare — hosting and content delivery.
- Stripe — subscription payments.
- [[EMAIL_PROVIDER]] — transactional email, such as confirmations and resets.
- Google — only if you use the optional business lookup while creating a venue, in which case what you type in that field is sent to Google Places to fetch an address.
How long we keep it
Account and restaurant data is kept until you delete it. Menu view records are deleted automatically once they pass the longest retention window any plan offers, currently 90 days.
Deleting your account
You can delete your account at any time from your account page. This is immediate and permanent: it cancels any active subscription, removes your restaurants and their menus, deletes your uploaded images, and erases your view history. There is no grace period and we cannot restore a deleted account. Menus you were invited to as staff belong to their owner and are not affected — only your access to them is removed.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data, to object to or restrict processing, and to complain to a supervisory authority. Most of this you can do directly: your data is editable in the admin at any time, and deletion is self-service. For anything else, write to [[CONTACT_EMAIL]] and we will respond within the period [[JURISDICTION]] law requires.
Where data is held
Our infrastructure providers operate globally and may process data outside [[JURISDICTION]]. Where that happens, it is covered by the safeguards those providers maintain.
Children
blueplate is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If this policy changes materially we will tell account holders by email before the change takes effect. The date at the foot of this page always reflects the current version.
Contact
[[ENTITY_NAME]], [[ENTITY_ADDRESS]]. Questions about this policy: [[CONTACT_EMAIL]].