Logo
RistoSmart FM Menu
Create and translate your menu in 5 minutes
  • Login

RistoSmart FM Menu

Menu Privacy Notice

Version 2026-08-15

Terms Privacy Withdrawal
Provider / controller: Fiorenzo Mercanzin, Via XXV Aprile, 19 - 35037 Teolo (PD), Italia, MRCFNZ61R10L100Y
Email: info@ristosmartfm.app

This notice applies exclusively to RistoSmart FM Menu and describes processing carried out by the platform provider. It does not apply to RistoSmart FM Pro.

1. Privacy roles

The party identified above is the controller for accounts, payments, support, security and its own communications. For end-customer data, bookings and content entered by the restaurant, the restaurant determines the purposes and means and is normally the controller; the Menu provider acts as processor within the limits of the service.

2. Data processed

  • account and contact data: name, email, telephone number, language and password credentials protected by hashing;
  • business details, menus, prices, images, logos, allergens, translations and settings;
  • booking and CRM data entered by the restaurant or end customer: name, contact details, date, time, number of people, notes and status;
  • subscription data and Stripe references; full card details remain with Stripe;
  • technical and security data: IP address in server logs, date and time, requests, session identifiers, errors and browser information;
  • optional integration credentials supplied by the user, stored in protected form where provided.

3. Purposes and legal bases

  • creating and managing the account, supplying Menu and support: performance of the contract;
  • managing payments, invoices, withdrawal and tax obligations: contract and legal obligation;
  • protecting systems, preventing abuse and diagnosing errors: legitimate interest in security and continuity;
  • sending operational communications: contract;
  • sending promotional communications: consent where required or another legal basis permitted by law, with the right to object;
  • establishing, exercising or defending rights and handling disputes: legitimate interest and legal obligations.

4. Provision of data

Data marked as mandatory is required for the account, contract or request. Without it, the function cannot be provided. Telephone numbers, images, notes and optional integrations may be omitted unless required for the selected function.

5. Recipients and providers

Data may be processed by authorised personnel and providers needed for hosting and backup, email, Stripe payments, OpenAI translation when enabled by the user, Meta/WhatsApp messaging when configured, technical support, and professional or legal obligations. Each provider receives only the data needed for its task.

6. Publication and bookings

Menus, images, prices, allergens and venue information selected for publication are accessible through public URLs and QR codes. Personal booking data is not published: it is available to the restaurant that owns the menu and to technical providers needed to deliver email or messages.

7. International transfers

Some global providers may process data outside the European Economic Area. In that event, depending on availability and the provider’s role, an adequacy decision, the Data Privacy Framework, standard contractual clauses or another safeguard permitted by the GDPR is used. Further information is available on request.

8. Retention

Account data and content are retained for the duration of the relationship and as long as needed for closure, export and disputes; invoices and tax data for statutory periods; withdrawal requests and consent records for as long as needed to demonstrate their handling; and logs and backups for limited periods consistent with security and recovery. Restaurants determine retention periods for their own booking data in accordance with the law.

9. Cookies

Menu uses strictly necessary technical cookies for sessions, authentication, language, CSRF protection and security. Menu does not currently set advertising or profiling cookies. External services opened by the user, such as Stripe, apply their own cookie notice on their domain.

10. Security

Proportionate technical and organisational measures are adopted, including encrypted connections, access controls, account separation, backups and credential protection. No Internet-connected system can, however, guarantee zero risk.

11. Rights

Individuals may request access, correction, erasure, restriction, portability and objection, and may withdraw consent without affecting prior processing. They may also complain to the Italian Data Protection Authority or the competent authority in their country. Requests should be sent to info@ristosmartfm.app; reasonable identity verification may be required.

12. Children and changes

The service is intended for professional activities and not for children. Material changes to this notice are communicated by appropriate means; the published version states its update date.

© RistoSmart FM Menu

All rights reserved.

Contact: info@ristosmartfm.app

Menu Terms Menu Privacy Exercise your right of withdrawal