Controller vs processor roles
Restaurant operators are typically the data controller for guest-facing menu content and feedback they collect. MenuOnScan acts as a processor for account, billing, and platform operational data we store on your behalf. Contact forms on our marketing site are processed by MenuOnScan as controller.
Standard contractual terms
We offer a Data Processing Addendum (DPA) incorporating Standard Contractual Clauses (SCCs) for transfers outside the EEA/UK upon request for paid Pro and Enterprise plans. Email hello@menuonscan.app with your company name and billing email.
Subprocessors (current)
Vercel — application hosting and edge delivery (US/EU). MongoDB Atlas — primary database (region selected at provisioning). DigitalOcean Spaces — object storage and CDN for menu images. Resend — transactional email delivery. Stripe — payment processing (when billing enabled). Sentry — error monitoring (when DSN configured). Cloudflare Turnstile — bot protection on signup/contact (when enabled).
Subprocessor changes
We notify account owners of material subprocessor changes via email or in-app notice at least 30 days before a new subprocessor processes personal data, unless a shorter window is required for security remediation.
Data location
Production database region is configured at deployment time (typically EU for European customers). Object storage CDN endpoints may serve cached assets globally for guest menu performance.
Retention and deletion
Account data is retained while your subscription is active. GDPR export and account deletion are available in Settings. Account deletion includes a 7-day cooling-off period before permanent erasure.

