Skip to content
FunzionalitàPrezziAffiliatiAiutoChi siamoContatti
Inizia oraAccedi
This page is available in:English|Türkçe— You are viewing the English version.

Privacy Policy

Version 3.0

Last updatedJune 19, 2026Effective15 July 2026

1. Introduction and who we are

The data controller is Synaltix LLC, a single-member New Mexico limited liability company (New Mexico Secretary of State, Business ID 0008091868), 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA, represented by its managing member Kerim Sağlam, operating the Thmenu platform ("we", "our", or "us"). Privacy contact: contact@synaltix.io. (For personal data of a restaurant's own guests, the restaurant is the controller and we are the processor — see §4.) This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services at thmenu.com. By using Thmenu, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Account Information: When you register, we collect your name, email address, phone number and the country your business operates in. Country is not optional: it determines your tax treatment, currency, applicable legal texts and which payment provider your venue can use.

Menu & Business Data: Content you upload including menu items, photos, prices, and restaurant details.

Usage Data: We automatically collect information such as browser type, pages visited, time spent, and device information.

Customer Interaction Data: Anonymous analytics on how customers interact with your menus (views, clicks, orders).

Tax Identification: If you enable in-app card collection, Stripe collects and validates your VAT or tax identification number during checkout and account onboarding. Thmenu does not enter that number itself and cannot change it.

Support Access Records: When a member of Thmenu support opens a session on your account, we record who opened it, when, why, when it ended, and every request made during it. You can read this in your own admin panel under Audit Log — support entries are labelled separately from your own staff. This exists so that support access is never invisible to you.

Is providing this data required? Account data (name, email, restaurant details) is a contractual requirement — we cannot create or operate an account without it, so not providing it means we cannot supply the service. Billing and tax data is a statutory requirement where invoicing law applies. Everything else — optional profile fields, analytics, marketing consent — is entirely voluntary and refusing it has no effect on your account or the service you receive.

3. How We Use Your Information

We use the information we collect for the following purposes; each is tied to a legal basis under GDPR Article 6 (and the corresponding KVKK Article 5/6 basis for Turkish data subjects):

Provide, operate, and maintain the Thmenu platform — contract performance (GDPR Art. 6(1)(b))
Process transactions and manage subscriptions — contract performance (Art. 6(1)(b)) + legal obligation for tax records (Art. 6(1)(c))
Send service notifications and administrative messages — contract performance (Art. 6(1)(b))
Marketing email communications — your consent (Art. 6(1)(a)); you can withdraw at any time via the unsubscribe link in each message
Analyse usage to improve our services — legitimate interests (Art. 6(1)(f)); for cookie-based analytics, your consent (ePrivacy Art. 5(3))
Comply with legal obligations — legal obligation (Art. 6(1)(c))
Prevent fraud and ensure security — legitimate interests (Art. 6(1)(f))

You have the right to object to processing based on legitimate interests — see Section 7.

4. Data Sharing & International Transfers

We do not sell, trade, or rent your personal information to third parties. We may share data with:

Service Providers (sub-processors): Trusted third parties who assist in operating our platform: Cloudflare Inc., Supabase Inc., Stripe Inc., Resend Inc., PostHog Inc., Sentry / Functional Software Inc., Google Ireland Ltd. (Tag Manager), Wise Payments Ltd. (affiliate payouts). The full and current list is published on our Compliance page, which is the canonical version — this list mirrors it.

Google Tag Manager: Tag Manager is a container, not an analytics product: it loads whichever measurement tags we have configured (for example Google Analytics 4 or Google Ads conversion tags). It only loads after you accept analytics or marketing cookies, and the tags it may load are itemised on our Cookie Policy.

International transfers: The sub-processors above are based in the United States. Transfers of EEA / UK personal data are covered by EU Standard Contractual Clauses (SCCs) or equivalent UK IDTAs. Transfers of Turkish personal data follow KVKK Article 9 — see our KVKK page for the legal basis.

Legal Requirements: When required by law or to protect our rights.

Business Transfers: In connection with a merger, acquisition, or sale of assets — you will be notified of any change of controller.

5. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected and applicable legal obligations. The schedule below is canonical and mirrors the GDPR + Account-Deletion pages.

CategoryRetentionLegal basis
Account profileLifetime + 30-day graceGDPR Art. 6(1)(b)
Invoices & payments7y US IRS / 10y EU VAT / 10y TR TTK — longestArt. 6(1)(c) / KVKK md. 5(2)(ç)
Order data (end-customer)6m active + anonymised aggregatesLegitimate interest
Cookie consent13 monthsArt. 7(1)
Support access records24 monthsLegitimate interest — accountability, Art. 5(2)
Support / email3 yearsStatute of limitations
Push subscription token90d inactiveStorage limitation
Staff audit log24 months, then deletedArt. 32 / KVKK md. 12
Affiliate KYC (pgcrypto)7y post closureIRS 1099 + AML
AI inference cache7 daysStorage limitation

Request deletion at any time at contact@synaltix.io. See the Account Deletion page for the full procedure.

6. Data Security

We implement industry-standard security measures including:

• TLS/SSL encryption for all data in transit
• AES-256 encryption for data at rest
• Cloudflare DDoS and WAF protection
• Dependency and configuration scanning on every deploy. Third-party penetration testing has not been performed; it is planned before EU market launch, and this page will be updated when it has been.

7. AI Usage Data

When you use Thmenu's AI features (AI product descriptions, AI menu chat):

Prompts and responses are not retained beyond the duration of the API call — no AI training on your content, no cross-restaurant caching
AI call counts (timestamp, restaurant_id, kind: ai_desc | ai_chat) are retained for:
  – 7 days for the per-restaurant daily quota counter
  – Forever in anonymized aggregate form for service capacity planning
• AI usage counters are never transmitted to Stripe: AI usage is not metered or billed.

If you delete your account, all AI usage data tied to your restaurant is anonymized within 30 days.

8. Your Rights

Depending on your location, you may have the right to:

Access your personal data
Rectification of inaccurate data
Erasure ("right to be forgotten")
Restriction of processing
Portability (machine-readable export)
Objection to processing for direct marketing or legitimate interests
Withdrawal of consent for consent-based processing
Lodge a complaint with a supervisory authority (GDPR Art. 77) — EU/EEA: your national authority, listed in the EDPB directory; UK: the ICO; Türkiye: Kişisel Verileri Koruma Kurumu; California: the CPPA. You do not have to contact us first.

To exercise these rights, use the in-app DSR portal at /dashboard/settings?tab=privacy or email contact@synaltix.io. We respond within 30 days (GDPR/KVKK) or 45 days (CCPA, extendable to 90 days with notice).

Is providing your data required? (GDPR Art. 13(2)(e)) Account name, email and payment details are needed to enter into and perform the subscription contract — without them we cannot provide the service. Everything else (logo, photos, phone number, marketing consent) is optional and refusing it has no consequence beyond the related feature being unavailable.

8.1 Automated processing and profiling

We are required to tell you where we evaluate you or your guests automatically (GDPR Art. 13(2)(f), Art. 22; KVKK md. 11(1)(g)). We do so in three places, and none of them makes a decision with legal effect on you — each one produces a signal a human then acts on:

Order risk scoring. Every table order is scored 0–100 from signals such as whether the device is on the venue's own Wi-Fi, Tor/VPN/threat indicators, GPS plausibility and ordering velocity. The score is shown to restaurant staff as a badge; staff accept or reject the order. Nothing is blocked automatically.
Customer segmentation. For restaurants on Pro and above, guest order history is grouped into segments (new, repeat, VIP, lapsed) using recency, frequency and spend. This is computed when the page is read, drives no automatic action, and the restaurant is the controller for it.
Affiliate anomaly detection. Referral patterns are checked for self-referral and coupon abuse; a hit flags the account for human review before any suspension.

You may ask for human review of any of these, or object to them, at contact@synaltix.io.

9. Cookies

We use cookies and similar tracking technologies. For details, please see our Cookie Policy.

10. Children's Privacy

Thmenu is a B2B platform aimed at restaurant operators (commercial users). Minimum account-holder age is 18 (or local age of majority).

GDPR Art. 8 (EU/EEA) — default 16, with member-state derogations: DE 16, IE 16, NL 16, FR 15, ES 14, IT 14, BE 13, SE 13. For users below the applicable threshold, processing requires verifiable parental consent.
UK DPA 2018 §9 + ICO Children's Code — 13.
USA — COPPA 15 USC §6501-6506 — verifiable parental consent for under-13s; suspended within 7 days of detection without verified consent.
Türkiye — TMK m. 11 — 18 for full contractual capacity.

End-customers (e.g. a 12-year-old scanning a QR code to view a menu) generate only pseudonymous browser-side data; no account is created. If a minor's admin account is detected, we delete it within 7 days. Report at contact@synaltix.io.

10. Children's Privacy

Thmenu is a B2B platform for restaurant operators. The minimum age to hold an account is 18. Data-protection thresholds:

GDPR Art. 8 (EU/EEA): 13-16 depending on member state: Germany 16, France 15, Belgium 13, Spain 14, Italy 14, Netherlands 16, Ireland 16.
UK — UK GDPR + DPA 2018 s.9: 13.
USA — COPPA 15 USC §6501-6506: verified parental consent under 13; suspension within 7 days.
Türkiye — Civil Code art. 11: 18 for full legal capacity.

An end customer (for example a 12-year-old guest scanning a QR code) generates only pseudonymised browser data; no account is created. If a minor's admin account is identified it is deleted within 7 days. Report to: contact@synaltix.io.

11. EU/UK Representative — Art. 27(2)(a) Exemption

Synaltix LLC has assessed its activities under GDPR Article 27(2)(a) (and the equivalent UK GDPR provision) and has determined that a formal EU/UK representative is not required at this time. Our processing of EU/EEA and UK personal data is occasional (restaurant operator accounts and their end-customer order data), does not include large-scale processing of special categories of data, and is unlikely to result in a risk to the rights and freedoms of natural persons.

An internal written assessment supporting this determination is maintained at docs/gdpr-art27-exemption-assessment.md (version-controlled, updated annually or on material change).

EU/EEA and UK data subjects may exercise all rights under GDPR Articles 15–22 and UK GDPR directly via:

Email: contact@synaltix.io
In-app DSR portal: /dashboard/settings?tab=privacy

We respond to all requests within 30 days (GDPR standard) or 45 days (CCPA standard, extendable to 90 days with notice).

12. Contact Us

For privacy-related questions or requests:

General privacy inquiries: contact@synaltix.io
DSR requests: /dashboard/settings?tab=privacy or contact@synaltix.io
Privacy contact: contact@synaltix.io (no formal DPO is designated under GDPR Art. 37)
Security disclosures: contact@synaltix.io

Postal: Synaltix LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA