Skip to content
功能特色定价方案合作伙伴帮助关于我们联系我们
免费开始登录
This page is available in:English— You are viewing the English version.

Privacy Compliance

GDPR · KVKK · CCPA/CPRA · Global Standards

Last updatedJune 4, 2026

Overview

Global
Thmenu is designed to meet the requirements of the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), and the California Consumer Privacy Act (CCPA/CPRA). These three are the regimes we have assessed ourselves against and the ones this page documents.

We do not claim compliance with every privacy law worldwide. If you are subject to another regime — Canada's PIPEDA, Australia's Privacy Act, Japan's APPI, Brazil's LGPD or any other — write to contact@synaltix.io and we will tell you honestly what we can and cannot support.

Data Controller / Veri Sorumlusu

All Regions
Synaltix LLC (Albuquerque, NM, USA — operating the Thmenu platform) acts as the Data Controller for personal data of platform users (restaurant owners and staff).

For end-customers of restaurants using Thmenu, the restaurant operator acts as the Data Controller and Synaltix LLC acts as the Data Processor under a DPA.

Contact for privacy requests: contact@synaltix.io · Legal & formal correspondence: contact@synaltix.io

Personal Data We Collect / İşlenen Kişisel Veriler

All Regions
Identity & Contact: Name, email address, phone number
Business Data: Restaurant name, address, tax information
Usage Data: Platform interactions, preferences, analytics
Payment Data: Subscription tier, transaction history (card details processed by Stripe — never stored by Thmenu)
Technical Data: IP address, browser type, device identifiers

Legal Basis for Processing

GDPR / KVKK
Contract Performance (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)): Processing necessary to provide our Services.

Legitimate Interests (GDPR Art. 6(1)(f)): Analytics, security, fraud prevention.

Legal Obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(ç)): Tax records, regulatory compliance.

Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)): Marketing communications (opt-in only).

Your Rights / Haklarınız

All Regions
🇪🇺 EEA Residents (GDPR):
Right of Access (Art. 15) · Right to Rectification (Art. 16) · Right to Erasure (Art. 17) · Right to Restriction (Art. 18) · Right to Portability (Art. 20) · Right to Object (Art. 21)

🇹🇷 Türkiye (KVKK Md. 11):
(a) Kişisel verilerinizin işlenip işlenmediğini öğrenme · (b) İşlenmişse buna ilişkin bilgi talep etme · (c) İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme · (ç) Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme · (d) Eksik veya yanlış işlenmişse düzeltilmesini isteme · (e) Silinmesini veya yok edilmesini isteme · (f) (d) ve (e) uyarınca yapılan işlemlerin aktarıldığı üçüncü kişilere bildirilmesini isteme · (g) Münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç doğmasına itiraz etme · (ğ) Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme

🇺🇸 California Residents (CCPA/CPRA):
Right to Know · Right to Delete · Right to Correct · Right to Opt-Out of Sale · Right to Non-Discrimination · Right to Limit Sensitive Data Use

🌐 Other jurisdictions:
If you are subject to another privacy regime — Canada's PIPEDA, Australia's Privacy Act, Brazil's LGPD, Japan's APPI or any other — write to contact@synaltix.io. We have not assessed the platform against those regimes and will tell you honestly what we can support rather than assert equivalence.

International Data Transfers / Uluslararası Veri Aktarımı

GDPR / KVKK
We transfer personal data outside the EEA and Turkey to the following sub-processors under EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (IDTA), and — where the provider is self-certified — the EU–US Data Privacy Framework:

Cloudflare, Inc. (USA) — edge compute, R2 object storage, DNS
Supabase, Inc. (USA) — authentication, primary database
Stripe, Inc. (USA) — payment processing
Resend, Inc. (USA) — transactional email
PostHog, Inc. (USA) — product analytics (opt-in via cookie banner)
Sentry / Functional Software, Inc. (USA) — error monitoring
Wise Payments Ltd. (UK/USA) — affiliate payouts (used only when affiliate enables Wise payouts; opt-in)
Google Ireland Ltd. / Google LLC (IE/USA) — Google Tag Manager container on the marketing site, loaded only after analytics or marketing consent; it in turn loads the measurement tags configured in the container

All transfers are designed to comply with GDPR Chapter V, the UK GDPR, and KVKK Article 9. A copy of the SCCs / IDTA is available on request at contact@synaltix.io.

Sub-processor change notification (LEGAL-25): We will publish updates to this list at least 30 days before a new sub-processor begins processing your data. Notification channels: this page (canonical), email to all account admins, and a banner on the admin dashboard. Customers may object in writing within the 30-day window; sustained objection is grounds for contract termination, refunded on the schedule in §2 of our Refund Policy.

We Do Not Sell Your Data

CCPA/CPRA
Thmenu does not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising.

Data Retention / Saklama Süreleri

All Regions
Account data: Duration of account + 30 days after deletion request
Transaction records: 7 years (legal obligation)
Analytics data: 12 months (anonymized thereafter)
Support communications: 3 years

Data Breach Notification

GDPR / Global
In the event of a personal data breach we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33), notify affected users without undue delay, and comply with KVKK, CCPA/CPRA, and other applicable breach notification requirements.

How to Exercise Your Rights / Başvuru Yöntemi

All Regions
Submit a request to: contact@synaltix.io

Response times: GDPR: 30 days · KVKK: 30 days · CCPA/CPRA: 45 days

You may also lodge a complaint with your local supervisory authority — ICO (UK), CNIL (France), BfDI (Germany), Kişisel Verileri Koruma Kurumu (Turkey), or the California Privacy Protection Agency (USA).