Privacy policy
Last updated: 13 September 2026
1. Who processes your data
DZ-MeNU is published by [RAISON SOCIALE À COMPLÉTER], [ADRESSE À COMPLÉTER], [RC / NIF À COMPLÉTER]. Contact: [EMAIL DE CONTACT À COMPLÉTER].
Two roles coexist. For our merchant customers' own data (account, subscription) we are the controller. For the end-customer data a venue collects through its menu — reservations — the venue is the controller and we act as its processor, on its instructions alone.
This document covers Regulation (EU) 2016/679 (GDPR) for visitors and customers in the European Union, and Algerian law no. 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data.
2. What we process
Merchant account: name, e-mail, password (hashed, never readable), organisation name, and the identity Google passes us if you sign in with Google.
Sign-in log: date, IP address and browser for each sign-in and failed attempt. This is a security measure against account takeover.
Venue: name, address, city, phone, e-mail, map coordinates, and the photos and menus you publish.
Reservations (your customers' data): name, phone, optional e-mail, date, time, party size and any notes.
Payments: amount, date, method, reference, period covered. We never see or store a card number — entry happens at Stripe or Chargily.
Messaging: the content of your exchanges with our team and any attachments.
Menu visitors: an anonymous identifier is created only if you favourite a dish or tap Like. Reading a menu creates none. A visit counter is recorded with no identifier.
3. Why, and on what basis
Providing the service (building your menu, publishing it, receiving your reservations) — performance of the contract.
Billing, collection, accounting and the referral programme — performance of the contract and legal obligation.
Securing the platform: sign-in log, attempt limits, abuse detection — legitimate interest.
Writing to you about your licence, its expiry or an incident — performance of the contract.
Visitor favourites and likes — your explicit request, at the moment you tap.
We use no data for advertising and sell none.
4. For how long
Account and venues: as long as the account exists.
Reservations and end-customer contact details: twenty-four months, then automatic deletion.
Sign-in log: twelve months. E-mail delivery log: twelve months.
Password reset tokens: thirty days. Visit counters: twenty-four months.
Accounting records (payments, commissions): kept for the period required by applicable accounting and tax law, even after the account is deleted, in a form that no longer identifies anyone.
These periods are applied automatically by a task running on the server, not merely written here.
5. Who else has access
We share data only with the providers the service needs, each for the stated purpose alone:
Stripe (card payment outside Algeria) — Stripe Payments Europe, Ireland. Card details are entered with them, never with us.
Chargily (EDAHABIA / CIB card payment in Algeria) — a provider established in Algeria.
Google — Google Maps if you open the map, Google Fonts for display, and Google Calendar if you choose to connect your calendar.
Our hosting provider and our transactional e-mail provider.
None of this data is sold, rented or handed to a third party for commercial purposes.
6. Where your data lives
The platform's servers are located in the European Union.
Some of the providers above may process data outside the country where the person concerned lives. Those transfers rely on the European Commission's standard contractual clauses or an equivalent mechanism.
For people located in Algeria, transfer outside the national territory is governed by law 18-07; we will tell you on request which providers are involved for your account.
7. Your rights
You may at any time access your data, correct it, ask for its erasure, restrict or object to its processing, and receive a usable copy.
Two of these work straight from your dashboard, without writing to us: “Export my data” downloads everything we hold as JSON, and “Delete my account” erases the account, the venues, the menus and every reservation.
For anything else, write to [EMAIL DE CONTACT À COMPLÉTER]; we answer within one month.
If one of your venue's customers sends you a request about their reservation, you answer it: you are its controller, and the export above gives you the content.
You may lodge a complaint with the competent authority: in Algeria the Autorité nationale de protection des données à caractère personnel (ANPDP); in the European Union, your country's supervisory authority (in France, the CNIL).
8. Cookies and trackers
Strictly necessary, set without consent because the service cannot work without them: your sign-in session, the chosen language, the billing country, and a short-lived anti-fraud token during a Google sign-in.
At your request: the anonymous identifier behind favourites and likes, created at the moment you tap one, and never before.
Subject to your consent: the Google map, which sends your IP address to Google. Until you accept, the map does not load and the rest of the site works normally.
We use no advertising cookies and no third-party analytics.
9. Security
End-to-end HTTPS, passwords hashed with bcrypt, calendar tokens encrypted at rest, tenant isolation verified automatically on every release so one venue can never reach another's data, a sign-in log and attempt limiting.
No system is infallible. In the event of a breach likely to create a risk to your rights, we will inform you and the competent authority within the periods the regulation sets.
10. Changes
Any substantial change to this policy is announced by e-mail at least thirty days before it takes effect.