MenuPort
Riepilogo della privacy
Ultimo aggiornamento: 2026-09-26
Questo riepilogo nella lingua del menu spiega il trattamento dei dati e delle foto usate per i modelli 3D.
Riepilogo della privacy
Le tre foto vengono inviate prima a fal.ai per generare il modello con Rodin v2. Se il servizio non è disponibile o non riesce, le stesse foto vengono inviate a Tripo come alternativa.
I file originali delle foto vengono eliminati al termine dell'elaborazione. Le copie archiviate per migliorare la qualità vengono eliminate entro 30 giorni al massimo.
Una copia archiviata del modello 3D generato viene conservata fino alla cancellazione del ristorante o dell'account associato.
L'indirizzo IP è usato temporaneamente per limitare gli abusi; il suo hash resta per breve tempo in un contatore condiviso e viene eliminato periodicamente. Non serve al tracciamento tra siti.
Testo legale completo (in inglese)
Il testo originale completo è riportato qui sotto in inglese. La sezione tradotta sopra è un riepilogo informativo, non una traduzione legale completa. Per conoscere i requisiti applicabili nella propria giurisdizione, rivolgersi a un professionista locale qualificato.
Data controller
The party operating MenuPort acts as the data controller and can be reached at the address below.
This policy is prepared to meet the information obligations under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the EU General Data Protection Regulation (GDPR).
Two kinds of users, two kinds of data
MenuPort has two kinds of users, and the data processed about them is entirely separate: restaurant owners who manage a menu (they create an account) and guests who scan a QR code to view a menu (they do not).
Data processed about restaurant owners
This data is necessary to create the account, provide the service and keep it secure.
- Identity and contact: email address, display name.
- Menu content: restaurant name, description, menu address (slug), categories, products, prices, allergen and nutrition details.
- Visual content: uploaded product photos and the frames captured for 3D model generation.
- 3D generation archive: a copy of source photos and the generated model may be kept separately for quality analysis and future internal improvements. Source-photo copies are removed within 30 days; archived GLB/USDZ model files remain until the related restaurant or account is deleted.
- Store purchase and 3D-credit records: store (Apple/Google), product and credit quantity, a transaction-identifier hash, verification/consumption/refund status, account binding, and the version and time of the purchase-terms acceptance. MenuPort does not store card or full payment details; the store processes payment.
- Operational security: session records, application crash and error reports.
Data processed about guests who make reservations
This information is processed to send the request to the restaurant you selected and allow the restaurant to manage it. A restaurant may provide its own privacy-notice and reservation-terms links in the booking form.
- Name, phone number, party size, requested date and time, any guest note, and the language used.
- Records needed to manage the reservation and its status. A marketing-contact preference is stored separately only when the guest opts in; it is never required to book.
Data processed about menu visitors
No account is created for guests viewing a menu, no cookies are used, no advertising identifier or device fingerprint is generated, and no cross-site tracking takes place. Only aggregate counts that help the restaurant improve its own menu are kept:
- How many times the menu and individual products were viewed.
- How many times the 3D/AR viewer was opened.
- Search terms that returned no results.
- Which filters (vegan, gluten-free, on sale) were used.
- Which language the menu was opened in and whether the device is a phone or a computer.
These counts cannot be linked to a person
The records belong to the restaurant's menu rather than to individuals and consist of totals such as “this product was viewed 40 times”. Because no visitor identifier is created, these counts cannot be associated with a specific person.
The browser's `sessionStorage` is used only to avoid counting the same event more than once in a single visit. The value stored there is a marker, never leaves the device and is cleared when the tab closes; it is not a persistent identifier.
For abuse rate-limiting on the analytics endpoint, a truncated SHA-256 hash derived from the IP address is temporarily stored in the database with a one-minute counter window. The raw IP address is not written to that counter document. Counters expire after about 16 minutes and a cleanup job runs every 15 minutes. Because the hash can associate requests from the same source during this short period, it is pseudonymous rather than anonymous data.
Purposes and legal bases
- Creating the account, enabling sign-in and providing the menu service — performance of a contract (KVKK art. 5/2-c; GDPR art. 6(1)(b)).
- Using the guest's necessary contact and booking details to receive and manage a reservation request. Marketing consent is separate and optional.
- Securing the service, preventing abuse and fixing errors — legitimate interests (KVKK art. 5/2-f; GDPR art. 6(1)(f)).
- Providing aggregate menu usage statistics to the restaurant — legitimate interests; no data relating to an identified person is processed for this purpose.
- Verifying subscriptions and purchased 3D credits, assigning them to the correct account, managing balances, and handling refunds or disputes — contract performance, service security, and applicable financial/legal obligations.
- Improving 3D generation quality: copies of source photos and the generated model may be placed in a separate archive for quality analysis and future internal improvements — legitimate interests. Archived source-photo copies are deleted within 30 days; archived GLB/USDZ model files are kept until the related restaurant or account is deleted. During generation, photos are sent first to fal.ai/Rodin v2; if that provider fails, the same photos are sent to Tripo. These provider transfers are separate from archive retention.
- Meeting legal obligations — legal obligation (KVKK art. 5/2-ç; GDPR art. 6(1)(c)).
Recipients and international transfers
The service is delivered through infrastructure providers, and data is processed by the following parties:
- Google Ireland Limited / Google LLC (Firebase and Google Cloud) — hosting, authentication, database, file storage and error reporting. Data is primarily held on servers within the European Union (europe-west1).
- fal.ai (Rodin v2) — primary 3D model-generation provider. If generation fails, the same three product photos are sent to Tripo as a fallback. Each provider receives the photos needed to generate the model.
About transfers abroad
Some of the providers above are established outside Türkiye and may access data from abroad for support, backup or processing. Your personal data may therefore be transferred abroad.
Such transfers are carried out under KVKK art. 9 and Chapter V of the GDPR, relying on the providers' standard contractual clauses and equivalent security commitments. Using the service includes this transfer; if you do not want it, you should not use the service.
Retention periods
You can delete your account from the Profile screen in the app. Deleting the account permanently removes your restaurants, menus, products, uploaded images, generated 3D models and associated training-archive files. Purchased 3D credits are tied to the deleted account and can no longer be used, transferred or restored; mandatory consumer rights are unaffected. Limited store transaction records may remain for the purposes above, including service security, refund/dispute handling and financial/legal obligations. Deleting a single restaurant also removes that restaurant's archive. Source-photo copies are otherwise automatically removed within 30 days; generated model archive files remain until deletion. Deleted data also disappears from backups once the retention windows above have passed.
- Account and menu data: until the account is deleted.
- Store purchase and 3D-credit records: kept to verify store transactions, bind credits to the correct account, prevent replay, handle refunds/disputes and meet financial/legal obligations. The transaction ledger currently has no automatic deletion period; access is restricted to these purposes and retention is reviewed against applicable legal requirements. A raw Google Play purchase token is deleted after consumption/refund reconciliation is complete. The current account/SKU assent record is removed during account deletion; the terms version and assent time captured with a verified purchase may remain in its transaction record.
- Reservation information: for the period configured by the restaurant; the system default is 90 days when no period is set or the setting is 0. On expiry, the name, phone, note, language, marketing preference and guest-management token are anonymized or removed; date, time, party size and status may remain for booking history.
- Original 3D-generation uploads: deletion is attempted as soon as processing finishes, and the server retries automatically after a temporary storage failure; archived source-photo copies: no more than 30 days.
- Archived generated model files (GLB/USDZ): until the related restaurant or account is deleted.
- Analytics rate-limit IP hash: short-lived counter window; expires after about 16 minutes and is removed by the next 15-minute cleanup run.
- Backups: daily backups for 7 days, weekly backups for 14 weeks.
- App diagnostic records: 30 days. Error and crash reports sent to Firebase Crashlytics: for the provider's standard retention period.
- Aggregate menu statistics: may be kept indefinitely as they cannot be linked to a person.
Your rights
Under KVKK art. 11 and the GDPR you have the right to:
- Learn whether your personal data is processed and request information about it.
- Learn the purpose of processing and whether it is used in line with that purpose.
- Know the third parties to whom data is transferred, in Türkiye or abroad.
- Request correction of incomplete or inaccurate data.
- Request erasure or destruction of your data.
- Request that correction, erasure or destruction be notified to the parties data was transferred to.
- Object to a result reached solely through automated analysis that works against you.
- Claim compensation if you suffer damage due to unlawful processing.
How to exercise your rights
You can edit your menu content and account details in the app and delete your account at any time. For anything else, write to the contact address below; requests are answered within the statutory time limits.
If you are not satisfied with the outcome, you retain the right to lodge a complaint with the Turkish Personal Data Protection Board or your local supervisory authority.
Security
Data is encrypted in transit, authorisation rules isolate each tenant's data from others, and clients cannot write directly to server-side records. That said, no system can offer absolute security; in the event of a security incident, the notifications required by law will be made.
Children
MenuPort is a service for businesses and is not directed at people under 18. Data is not knowingly collected from children.
Changes
When this policy is updated the date above changes. For significant changes affecting its scope, a separate notice is given in the app.
Contatti
Per domande su questo documento: info@sorin.tech