Resumen de privacidad

Resumen de privacidad

Las tres fotos se envían primero a fal.ai para generar el modelo con Rodin v2. Si el servicio falla o no está disponible, las mismas fotos se envían a Tripo como alternativa.

Los archivos originales de captura se eliminan al terminar el procesamiento. Las copias archivadas para mejorar la calidad se eliminan en un máximo de 30 días.

La copia archivada del modelo 3D generado se conserva hasta que se elimine el restaurante o la cuenta correspondiente.

La IP se usa temporalmente para limitar abusos; su hash se guarda brevemente en un contador compartido y se elimina periódicamente. No se usa para rastrear entre sitios.

Texto legal completo (en inglés)

El texto original completo aparece abajo en inglés. La sección traducida anterior es un resumen informativo, no una traducción jurídica completa. Para conocer los requisitos legales de tu jurisdicción, consulta a un profesional local cualificado.

Data controller

The party operating MenuPort acts as the data controller and can be reached at the address below.

This policy is prepared to meet the information obligations under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the EU General Data Protection Regulation (GDPR).

Two kinds of users, two kinds of data

MenuPort has two kinds of users, and the data processed about them is entirely separate: restaurant owners who manage a menu (they create an account) and guests who scan a QR code to view a menu (they do not).

Data processed about restaurant owners

This data is necessary to create the account, provide the service and keep it secure.

Data processed about guests who make reservations

This information is processed to send the request to the restaurant you selected and allow the restaurant to manage it. A restaurant may provide its own privacy-notice and reservation-terms links in the booking form.

Data processed about menu visitors

No account is created for guests viewing a menu, no cookies are used, no advertising identifier or device fingerprint is generated, and no cross-site tracking takes place. Only aggregate counts that help the restaurant improve its own menu are kept:

These counts cannot be linked to a person

The records belong to the restaurant's menu rather than to individuals and consist of totals such as “this product was viewed 40 times”. Because no visitor identifier is created, these counts cannot be associated with a specific person.

The browser's `sessionStorage` is used only to avoid counting the same event more than once in a single visit. The value stored there is a marker, never leaves the device and is cleared when the tab closes; it is not a persistent identifier.

For abuse rate-limiting on the analytics endpoint, a truncated SHA-256 hash derived from the IP address is temporarily stored in the database with a one-minute counter window. The raw IP address is not written to that counter document. Counters expire after about 16 minutes and a cleanup job runs every 15 minutes. Because the hash can associate requests from the same source during this short period, it is pseudonymous rather than anonymous data.

Purposes and legal bases

Recipients and international transfers

The service is delivered through infrastructure providers, and data is processed by the following parties:

About transfers abroad

Some of the providers above are established outside Türkiye and may access data from abroad for support, backup or processing. Your personal data may therefore be transferred abroad.

Such transfers are carried out under KVKK art. 9 and Chapter V of the GDPR, relying on the providers' standard contractual clauses and equivalent security commitments. Using the service includes this transfer; if you do not want it, you should not use the service.

Retention periods

You can delete your account from the Profile screen in the app. Deleting the account permanently removes your restaurants, menus, products, uploaded images, generated 3D models and associated training-archive files. Purchased 3D credits are tied to the deleted account and can no longer be used, transferred or restored; mandatory consumer rights are unaffected. Limited store transaction records may remain for the purposes above, including service security, refund/dispute handling and financial/legal obligations. Deleting a single restaurant also removes that restaurant's archive. Source-photo copies are otherwise automatically removed within 30 days; generated model archive files remain until deletion. Deleted data also disappears from backups once the retention windows above have passed.

Your rights

Under KVKK art. 11 and the GDPR you have the right to:

How to exercise your rights

You can edit your menu content and account details in the app and delete your account at any time. For anything else, write to the contact address below; requests are answered within the statutory time limits.

If you are not satisfied with the outcome, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board or your local supervisory authority.

Security

Data is encrypted in transit, authorisation rules isolate each tenant's data from others, and clients cannot write directly to server-side records. That said, no system can offer absolute security; in the event of a security incident, the notifications required by law will be made.

Children

MenuPort is a service for businesses and is not directed at people under 18. Data is not knowingly collected from children.

Changes

When this policy is updated the date above changes. For significant changes affecting its scope, a separate notice is given in the app.

Contacto

Para preguntas sobre este documento: info@sorin.tech