Privacy Compliance
GDPR · KVKK · CCPA/CPRA · Global Standards
Last updatedJune 4, 2026
Overview
GlobalThmenu is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), and the California Consumer Privacy Act (CCPA/CPRA). These three are the regimes we have assessed ourselves against and the ones this page documents.
We do not claim compliance with every privacy law worldwide. If you are subject to another regime — Canada's PIPEDA, Australia's Privacy Act, Japan's APPI, Brazil's LGPD or any other — write to contact@synaltix.io and we will tell you honestly what we can and cannot support.
We do not claim compliance with every privacy law worldwide. If you are subject to another regime — Canada's PIPEDA, Australia's Privacy Act, Japan's APPI, Brazil's LGPD or any other — write to contact@synaltix.io and we will tell you honestly what we can and cannot support.
Data Controller / Veri Sorumlusu
All RegionsSynaltix LLC (Albuquerque, NM, USA — operating the Thmenu platform) acts as the Data Controller for personal data of platform users (restaurant owners and staff).
For end-customers of restaurants using Thmenu, the restaurant operator acts as the Data Controller and Synaltix LLC acts as the Data Processor under a DPA.
Contact for privacy requests: contact@synaltix.io · Legal & formal correspondence: contact@synaltix.io
For end-customers of restaurants using Thmenu, the restaurant operator acts as the Data Controller and Synaltix LLC acts as the Data Processor under a DPA.
Contact for privacy requests: contact@synaltix.io · Legal & formal correspondence: contact@synaltix.io
Personal Data We Collect / İşlenen Kişisel Veriler
All RegionsIdentity & Contact: Name, email address, phone number
Business Data: Restaurant name, address, tax information
Usage Data: Platform interactions, preferences, analytics
Payment Data: Subscription tier, transaction history (card details processed by Stripe — never stored by Thmenu)
Technical Data: IP address, browser type, device identifiers
Business Data: Restaurant name, address, tax information
Usage Data: Platform interactions, preferences, analytics
Payment Data: Subscription tier, transaction history (card details processed by Stripe — never stored by Thmenu)
Technical Data: IP address, browser type, device identifiers
Legal Basis for Processing
GDPR / KVKKContract Performance (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)): Processing necessary to provide our Services.
Legitimate Interests (GDPR Art. 6(1)(f)): Analytics, security, fraud prevention.
Legal Obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(ç)): Tax records, regulatory compliance.
Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)): Marketing communications (opt-in only).
Legitimate Interests (GDPR Art. 6(1)(f)): Analytics, security, fraud prevention.
Legal Obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(ç)): Tax records, regulatory compliance.
Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)): Marketing communications (opt-in only).
Your Rights / Haklarınız
All Regions🇪🇺 EEA Residents (GDPR):
Right of Access (Art. 15) · Right to Rectification (Art. 16) · Right to Erasure (Art. 17) · Right to Restriction (Art. 18) · Right to Portability (Art. 20) · Right to Object (Art. 21)
🇹🇷 Türkiye (KVKK Md. 11):
(a) Kişisel verilerinizin işlenip işlenmediğini öğrenme · (b) İşlenmişse buna ilişkin bilgi talep etme · (c) İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme · (ç) Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme · (d) Eksik veya yanlış işlenmişse düzeltilmesini isteme · (e) Silinmesini veya yok edilmesini isteme · (f) (d) ve (e) uyarınca yapılan işlemlerin aktarıldığı üçüncü kişilere bildirilmesini isteme · (g) Münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç doğmasına itiraz etme · (ğ) Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
🇺🇸 California Residents (CCPA/CPRA):
Right to Know · Right to Delete · Right to Correct · Right to Opt-Out of Sale · Right to Non-Discrimination · Right to Limit Sensitive Data Use
🌐 Other jurisdictions:
If you are subject to another privacy regime — Canada's PIPEDA, Australia's Privacy Act, Brazil's LGPD, Japan's APPI or any other — write to contact@synaltix.io. We have not assessed the platform against those regimes and will tell you honestly what we can support rather than assert equivalence.
Right of Access (Art. 15) · Right to Rectification (Art. 16) · Right to Erasure (Art. 17) · Right to Restriction (Art. 18) · Right to Portability (Art. 20) · Right to Object (Art. 21)
🇹🇷 Türkiye (KVKK Md. 11):
(a) Kişisel verilerinizin işlenip işlenmediğini öğrenme · (b) İşlenmişse buna ilişkin bilgi talep etme · (c) İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme · (ç) Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme · (d) Eksik veya yanlış işlenmişse düzeltilmesini isteme · (e) Silinmesini veya yok edilmesini isteme · (f) (d) ve (e) uyarınca yapılan işlemlerin aktarıldığı üçüncü kişilere bildirilmesini isteme · (g) Münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç doğmasına itiraz etme · (ğ) Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
🇺🇸 California Residents (CCPA/CPRA):
Right to Know · Right to Delete · Right to Correct · Right to Opt-Out of Sale · Right to Non-Discrimination · Right to Limit Sensitive Data Use
🌐 Other jurisdictions:
If you are subject to another privacy regime — Canada's PIPEDA, Australia's Privacy Act, Brazil's LGPD, Japan's APPI or any other — write to contact@synaltix.io. We have not assessed the platform against those regimes and will tell you honestly what we can support rather than assert equivalence.
International Data Transfers / Uluslararası Veri Aktarımı
GDPR / KVKKWe transfer personal data outside the EEA and Turkey to the following sub-processors under EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), and — where the provider is self-certified — the EU–US Data Privacy Framework:
• Cloudflare, Inc. (USA) — edge compute, R2 object storage, DNS
• Supabase, Inc. (USA) — authentication, primary database
• Stripe, Inc. (USA) — payment processing
• Resend, Inc. (USA) — transactional email
• PostHog, Inc. (USA) — product analytics (opt-in via cookie banner)
• Sentry / Functional Software, Inc. (USA) — error monitoring
• Wise Payments Ltd. (UK/USA) — affiliate payouts (used only when affiliate enables Wise payouts; opt-in)
• Google Ireland Ltd. / Google LLC (IE/USA) — Google Tag Manager container on the marketing site, loaded only after analytics or marketing consent; it in turn loads the measurement tags configured in the container
All transfers are designed to comply with GDPR Chapter V, the UK GDPR, and KVKK Article 9. A copy of the SCCs / IDTA is available on request at contact@synaltix.io.
Sub-processor change notification (LEGAL-25): We will publish updates to this list at least 30 days before a new sub-processor begins processing your data. Notification channels: this page (canonical), email to all account admins, and a banner on the admin dashboard. Customers may object in writing within the 30-day window; sustained objection is grounds for contract termination, refunded on the schedule in §2 of our Refund Policy.
• Cloudflare, Inc. (USA) — edge compute, R2 object storage, DNS
• Supabase, Inc. (USA) — authentication, primary database
• Stripe, Inc. (USA) — payment processing
• Resend, Inc. (USA) — transactional email
• PostHog, Inc. (USA) — product analytics (opt-in via cookie banner)
• Sentry / Functional Software, Inc. (USA) — error monitoring
• Wise Payments Ltd. (UK/USA) — affiliate payouts (used only when affiliate enables Wise payouts; opt-in)
• Google Ireland Ltd. / Google LLC (IE/USA) — Google Tag Manager container on the marketing site, loaded only after analytics or marketing consent; it in turn loads the measurement tags configured in the container
All transfers are designed to comply with GDPR Chapter V, the UK GDPR, and KVKK Article 9. A copy of the SCCs / IDTA is available on request at contact@synaltix.io.
Sub-processor change notification (LEGAL-25): We will publish updates to this list at least 30 days before a new sub-processor begins processing your data. Notification channels: this page (canonical), email to all account admins, and a banner on the admin dashboard. Customers may object in writing within the 30-day window; sustained objection is grounds for contract termination, refunded on the schedule in §2 of our Refund Policy.
We Do Not Sell Your Data
CCPA/CPRAThmenu does not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising.
Data Retention / Saklama Süreleri
All Regions• Account data: Duration of account + 30 days after deletion request
• Transaction records: 7 years (legal obligation)
• Analytics data: 12 months (anonymized thereafter)
• Support communications: 3 years
• Transaction records: 7 years (legal obligation)
• Analytics data: 12 months (anonymized thereafter)
• Support communications: 3 years
Data Breach Notification
GDPR / GlobalIn the event of a personal data breach we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33), notify affected users without undue delay, and comply with KVKK, CCPA/CPRA, and other applicable breach notification requirements.
How to Exercise Your Rights / Başvuru Yöntemi
All RegionsSubmit a request to: contact@synaltix.io
Response times: GDPR: 30 days · KVKK: 30 days · CCPA/CPRA: 45 days
You may also lodge a complaint with your local supervisory authority — ICO (UK), CNIL (France), BfDI (Germany), Kişisel Verileri Koruma Kurumu (Turkey), or the California Privacy Protection Agency (USA).
Response times: GDPR: 30 days · KVKK: 30 days · CCPA/CPRA: 45 days
You may also lodge a complaint with your local supervisory authority — ICO (UK), CNIL (France), BfDI (Germany), Kişisel Verileri Koruma Kurumu (Turkey), or the California Privacy Protection Agency (USA).