Role-scoped access
Owners, managers, and staff get different surfaces. Permissions are scoped per branch and per module, so a cashier at one branch cannot open another branch reports or billing.
Security and trust
You are handing Menuraq your menu, your orders, and your money. This page says plainly what protects them, and what we do not claim.
Authentication, then role, then plan, then consent, then the audit record. A request that fails any step does not continue.
Who is making this request, and have they proved it.
Is this person allowed to act on this branch and this module.
Does the branch subscription include the capability being used.
For guest-facing actions, what was the guest told and what did they agree to.
What changed, who changed it, and when.
Each of these is a control you can see and change in your own workspace, not a policy statement about our intentions.
Owners, managers, and staff get different surfaces. Permissions are scoped per branch and per module, so a cashier at one branch cannot open another branch reports or billing.
Available on owner and team accounts. Sensitive actions can require a second verification before they proceed.
Access rules live in the database itself, not only in application code, so a request cannot read another business data by taking a different route in.
Menu, access, billing, refund, and deletion activity is recorded with the acting account and a timestamp.
Guest-facing flows carry privacy notices and cookie choices, and the resulting consent is stored so you can answer a request with evidence.
Paid capabilities check the branch plan at the point of use, so access matches what the branch is actually subscribed to.
Software that holds your menu and your guest list has real leverage over you. We would rather remove that leverage than rely on it.
Export your data
Menus, orders, and customer records can be exported from your own workspace.
Delete your account
Account and workspace deletion is a self-service workflow, not a support ticket.
Leave without a hostage negotiation
Your menu, your guests, and your history belong to you. Take them with you.
Most security pages only list wins. These are the limits, so you can judge the risk before you commit rather than after.
We do not currently hold SOC 2, ISO 27001, or PCI DSS certification. If your procurement process requires one, tell us before you commit.
We are not a payment processor. Card details are handled by our payment provider and do not reach Menuraq servers.
We do not sell, rent, or share your business data or your guests data with advertisers.
We are an early-stage product. If you need contractual guarantees such as an SLA or a DPA, ask us and we will put it in writing rather than point at a badge.
Terms, privacy, cookies, consent, customer privacy, and acceptable use are all published, not available on request.