MENIVO - Meniu digital QR GRATUIT pentru restaurante baruri si cafenele

5 questions about security and data protection in digital menu

Security and data protection in digital menu — topics that many restaurant owners ignore until it's too late. If you use or intend to use a QR digital menu, it is essential to know how your data, your employees' data, and your customers' data are protected.

1. What data is collected when someone scans my digital menu's QR code?

This is one of the first questions restaurant owners ask before implementing a QR digital menu. When a customer scans the QR code generated by Menivo, they are redirected to your menu's public page. In this process, standard technical data may be recorded, such as:

  • The number of QR code scans (for statistical purposes, to give you insights about restaurant traffic);
  • The type of device or browser used (anonymous, aggregated data);
  • The date and time of access.

No personally identifiable data of customers who scan the code is collected — they are not asked for their name, email, or phone number just to view the menu. Browsing data is processed in accordance with the Menivo platform's privacy policy.

2. How is my restaurant's data (products, prices, allergens) protected in the Menivo platform?

The data you enter into Menivo — including menu categories, products, prices, ingredients, food allergens, and nutritional values — are stored in secure databases, accessible exclusively through your authenticated account. Access to the administration panel is protected through:

  • Email and password authentication;
  • Secure sessions and CSRF (Cross-Site Request Forgery) protection tokens;
  • Encrypted data transmission via HTTPS protocol;
  • Strict validation of all entered fields (names, descriptions, prices, images).

Images uploaded for products are automatically processed and converted to WebP format, optimized for performance, and stored on secure servers. No external user can access or modify your restaurant's data without your authentication credentials.

3. Is the data of customers who place online orders safe?

If you use Menivo's online ordering functionality, customers will enter the contact data necessary to process the order: name, phone number, and, in the case of deliveries, the delivery address. This data is subject to strict security and menu data protection measures, including:

  • Data is transmitted exclusively through encrypted HTTPS connections;
  • Access to received orders is restricted exclusively to the restaurant owner (and authorized system administrators);
  • Fields are validated and sanitized before being saved in the database, to prevent SQL injections or XSS attacks;
  • Order notifications are sent via secure email and through the platform's internal notification system.

Customers are not automatically registered on the platform and their data is not used for marketing purposes without explicit consent. The responsibility for informing customers about data processing falls, as the data controller, on the restaurant.

4. Does menu data security and protection comply with GDPR requirements?

GDPR (General Data Protection Regulation) applies to any business that processes personal data of EU citizens, including restaurants. When it comes to digital menu data security and protection, there are several levels of responsibility:

  • Menivo, as a data processor, implements technical and organizational measures to secure the data stored on the platform;
  • You, as the restaurant owner (data controller), are responsible for informing customers about how you process their data — through a privacy policy displayed in the restaurant or on the ordering page;
  • Billing data (e.g., VAT code) is processed in accordance with applicable tax regulations and validated through authorized external services (e.g., ANAF).

We recommend all Menivo partners consult a legal specialist to ensure they have the appropriate GDPR documentation (processing register, privacy policy, data processing agreement with Menivo).

5. Who can access and modify my digital menu's data?

Access control is a fundamental pillar of the security of any digital platform. In Menivo, access to your restaurant's data and settings is structured around clear roles:

  • The account owner has full access to all functionalities: menu creation and editing, product management, allergens, nutritional values, orders, reservations, and reviews;
  • The platform superadmin can access data for technical and support purposes, in compliance with internal privacy policies;
  • Public visitors (customers who scan the QR code) can only see the information you have published in the menu — they do not have access to the administration panel.

Menu changes (adding products, editing prices, updating allergens or nutritional values) are made exclusively from the authenticated account, through the secure administration panel. Any important action (deleting the restaurant, modifying the slug, importing data) is additionally validated at the server level. If you want to learn how to correctly configure your restaurant's data, check out the restaurant settings configuration guide.

6. Are menu product images stored securely?

Yes. The images you upload for menu products go through an automatic validation and processing process before storage. The platform accepts only authorized image formats (JPG, JPEG, PNG, WebP), and files are resized and converted to WebP format for optimization. Files are stored on secure servers and served to customers through dedicated public URLs, without exposing the system's internal structure. The maximum accepted size per image is 10 MB, thus preventing the upload of large malicious files.

7. What happens to my data if I cancel my Menivo subscription?

This is a legitimate and important question from the perspective of digital menu data security and protection. Menivo's policy regarding data deletion at the end of the contractual relationship is detailed in the platform's terms and conditions. In general, your data (menu, products, images, order history) remains available for the duration of the active subscription period. We recommend exporting your data before cancellation, using the Excel export functionality available on the platform. You can cancel automatic renewal directly from your account, in the subscriptions section.

8. Can my restaurant's QR code be copied or forged by someone else?

The QR code generated by Menivo is unique per restaurant and redirects to your menu's public URL, identified by a custom slug. Although technically anyone can scan a publicly displayed QR code, the displayed data is exclusively what you have published — there is no risk of access to confidential information. If you want to change your menu's URL, you can modify the slug in the restaurant settings and generate a new QR code. Learn more about how a QR code works and how it stores information. No one can modify your menu's content just by accessing the QR code — editing data requires authentication into your account.

9. Is allergen and nutritional value data mandatory, and how is it protected?

According to current European and Romanian legislation, restaurants are required to inform customers about the allergens present in the products offered. In Menivo, allergens and nutritional values are entered by you and displayed publicly in the menu — they are part of the information you voluntarily publish for legal compliance. This data is not sensitive personal data, but information about products. To ensure you comply with all legal obligations, read the complete guide on food allergens in restaurants. The data is stored securely in the platform's database and can be updated at any time from the administration panel.

10. How can I create a secure and compliant digital menu for my restaurant?

Creating a secure digital menu that meets legal requirements is simpler than you think. Here are the essential steps you can follow in Menivo:

  • Sign up at menivo.io and create your restaurant's account;
  • Add the restaurant's information: name, address, hours, logo;
  • Create menu categories (e.g., Appetizers, Main Courses, Desserts);
  • Add products with photos, prices, descriptions, ingredients, allergens, and nutritional values;
  • Generate the unique QR code and display it in the restaurant.

For a detailed, step-by-step guide, check out the complete guide to creating a restaurant menu in Menivo. By following these steps, you will have an updated digital menu that is secure and compliant with both data protection standards and food allergen obligations.

Do you have other questions about menu data security and protection?

The Menivo team is available to answer any questions related to security, data protection, GDPR, or platform functionalities. Don't leave your questions unanswered — contact us and we'll provide the clarifications you need.

Contact us at Menivo.io
← Back to home

We use cookies

We use cookies to improve your experience. You can choose which categories you accept.

Cookie Policy · Privacy Policy

Cookie preferences

Necessary

Essential for the website to function. Cannot be disabled.

Always active
cv_consent
1 year HTTP Cookie

Provider: Cookie Consent

Stores the user cookie consent choices.

cv_version
1 year HTTP Cookie

Provider: Cookie Consent

Stores the accepted cookie policy version.

menivo_session
Session HTTP Cookie

Provider: Laravel

Maintains the application session between requests.

XSRF-TOKEN
Session HTTP Cookie

Provider: Laravel

Protects forms against CSRF attacks.

Analytics

Help us understand how you use the site (visits, pages, traffic sources).

_ga
2 years HTTP Cookie

Provider: Google Analytics

Distinguishes unique users for Google Analytics reporting.

_gid
24 hours HTTP Cookie

Provider: Google Analytics

Distinguishes users for one day for Google Analytics.

Marketing

Used for relevant ads and measuring campaign effectiveness.

Preferences

Remember your settings (language, chat, interface customization).