Skip to content
FunktionerPriserPartnerHjälpOm ossKontakt
Kom igångLogga in
This page is available in:English— You are viewing the English version.

CCPA / CPRA — California Consumer Privacy Notice

Last updatedMay 29, 2026

1. Applicability

This notice applies to California residents under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). The business covered is Synaltix LLC (1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA), operating the Thmenu platform. Inquiries: contact@synaltix.io.

2. Categories of Personal Information Collected

Categories collected in the preceding 12 months (retention mirrors Privacy §5 and GDPR §5):

CategoryExamplesRetention
IdentifiersName, email, IP, account IDAccount lifetime + 30 days
Commercial informationSubscription tier, invoices, payouts7 years (US IRS)
Internet / network activityPage views, app interaction, error reports12 months (anonymised after)
Professional / employmentBusiness name, role, addressAccount lifetime + 30 days
InferencesUsage patterns informing recommendations12 months

Sensitive Personal Information (Cal. Civ. Code §1798.140(ae)): Thmenu does not knowingly collect government IDs, financial credentials, precise geolocation, racial/ethnic origin, religious beliefs, union membership, immigration status, contents of communications, genetic data, biometric data for unique identification, health data, or sex-life / sexual-orientation data. Payment-card details are tokenised and processed directly by Stripe. Affiliate KYC fields (Tax ID, IBAN, ACH) are encrypted at rest with pgcrypto AES; CPRA "Limit Use of Sensitive PI" applies to that field set.

3. Sources of Personal Information

Directly from you, automatically from your interactions (logs, strictly-necessary cookies, consent-gated analytics), and from sub-processors. The canonical sub-processor list is on our Compliance page: Cloudflare Inc., Supabase Inc., Stripe Inc., Resend Inc., PostHog Inc., Sentry / Functional Software Inc., Google Ireland Ltd. (Tag Manager), Wise Payments Ltd. (affiliate payouts).

Correction (2026-08-19): this section previously named "Sumsub" as a sub-processor. Synaltix LLC has never used Sumsub — the name appears nowhere in the platform. It has been removed.

4. Business Purposes for Use and Disclosure (Cal. Code Reg. §7012)

Service provision; payment + subscription management; legal compliance (tax, AML, sanctions, IRS 1099); customer support; fraud and abuse prevention; product analytics and quality improvement; AI-assisted features (Cloudflare Workers AI; no third-party model training).

5. Sale and Sharing of Personal Information

Thmenu does not sell personal information (§1798.140(ad)) and does not share for cross-context behavioural advertising (§1798.140(ah)).

Global Privacy Control (GPC). Because no sale or sharing occurs, there is no opt-out to apply and a GPC signal has no effect on our processing. We do not currently read the Sec-GPC header.

If our practices ever change so that a sale or sharing would occur, we will honour GPC as a binding opt-out under Cal. Code Reg. §7025, and we will update the cookie banner, this notice and account settings before any sale or sharing begins.

Correction (2026-08-19): this section previously stated that our servers treat a valid GPC signal as a legally binding opt-out and propagate it to signed-in accounts for 12 months. No part of the platform reads that header — the claim described a mechanism that did not exist. It has been replaced with what is actually true.

6. California Consumer Rights

• Know · Access · Delete · Correct · Opt out of sale/sharing · Limit use of Sensitive PI · Non-discrimination.

7. How to Submit a Request

Two channels per Cal. Code Reg. §7026:
• Email contact@synaltix.io
• The contact form at thmenu.com/contact — select "Privacy request".
• Account holders can also use the in-app portal at /dashboard/settings?tab=privacy.

We respond within 45 days and may extend by 45 days with prior notice (§1798.130(a)(2)).

Verification. Access/know — registered email plus a one-time code. Deletion/correction — sign in to the account. We do not require a notarised statement for any request: Cal. Code Reg. §7004 requires verification to be proportionate and not an unreasonable barrier, and a notary is neither.

Correction (2026-08-19): this section previously linked a web form at /legal/ccpa-request that does not exist (404), leaving only one of the two channels §7026 requires, and demanded a notarised statement for Sensitive-PI requests.

8. Authorized Agent (Cal. Code Reg. §7063)

You may designate an authorised agent. We verify:
1. Written and signed authorisation specifying agent and scope;
2. Direct confirmation from you (we email/text the registered contact);
3. Agent identity — government photo ID for sensitive requests; business registration for corporate agents.

For deletion requests we ask for the written authorisation above plus direct confirmation from you; a notarised power of attorney is not required (Cal. Code Reg. §7004 — verification must be proportionate). Access / know / correct requests need only written authorisation plus your confirmation. Agents must not retain personal information beyond what is necessary to complete the request.

9. Non-Discrimination and Financial Incentives

We do not deny services, charge different prices or provide a different level of service based on you exercising your CCPA/CPRA rights. We do not currently offer financial incentives for personal information.

10. Contact

Privacy contact: contact@synaltix.io · contact@synaltix.io · California Privacy Protection Agency: cppa.ca.gov.