Privacy Policy

Last updated: [publishing date]

SiMenu is a digital menu and real-time ordering platform, operated by Sayyam Ijaz ("we," "us," "our," or "SiMenu"). This Privacy Policy explains exactly what information SiMenu collects, why, and how it's protected.

Contact: [business email — publishing soon, once our domain is active]

1. Who this applies to

  • Restaurant Owners — create an account to manage a restaurant's menu, receive live orders, and generate table QR codes.
  • Customers / Diners — scan a table's QR code to view a menu and place an order. Customers never create an account, and there is no customer login, profile, or password anywhere in SiMenu.

2. What SiMenu actually collects

From Restaurant Owners: email and password (stored only as a one-way cryptographic hash — we never see your actual password), or your verified Google account email/name if you sign in with Google; restaurant name, web address, logo, cover image, and brand colors; menu content including dish names, prices, sizes, photos, and allergen/dietary tags; and your own restaurant's sales data.

From Customers: order details (items, sizes, modifiers, table number, total), and a temporary, anonymous table session created when a QR code is scanned, used only to confirm an order comes from that physical table for a few hours. We deliberately do not collect a customer's name, phone number, email, or payment details — SiMenu's ordering flow was built so a diner never has to hand over personal information just to order food.

3. Cookies and local storage

  • One login cookie for Restaurant Owners, marked httpOnly so no script can read it — used solely to keep you logged in.
  • Local browser storage for Customers (not a tracking cookie) to remember an active order and a verified table session on your own device — never sent anywhere else.
  • No third-party advertising cookies, and we never sell cookie-derived data.

4. Google Translate

If a customer uses the language switcher, page text is translated using Google's Translate widget, subject to Google's own privacy practices. Dish names are deliberately excluded from translation to avoid mistranslating a menu item's actual name.

5. How we protect your information

  • Passwords are hashed with bcrypt — we cannot see or recover your actual password.
  • All traffic is encrypted (HTTPS).
  • Each table's QR code carries a unique security key checked on every order.
  • Table sessions automatically expire after a few hours.
  • A restaurant owner's login only ever grants access to their own restaurant's data.

6. Where information is stored

Database: MongoDB Atlas. Images: Cloudinary. Hosting: Render and Vercel. Email: Resend. Data may be processed outside Pakistan depending on these providers' regions.

7. Your rights

You may request access to, correction of, or deletion of your personal information at any time by contacting us at the email above.

8. Governing law

This policy is governed by the laws of the Islamic Republic of Pakistan.