Skip to content
MenuPulse

Legal

Privacy Policy

Last updated: 1 July 2026

Template notice. This policy is a good-faith template for the MenuPulse product and is provided for information only. It is not legal advice. Before launch, have it reviewed by qualified counsel for your jurisdiction and business.

This Privacy Policy explains how MenuPulse ("MenuPulse", "we", "us") collects, uses, discloses, and safeguards personal data when you use our website at menupulse.io and our software-as-a-service platform (the "Service"). We are committed to protecting personal data in line with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where applicable, the EU/UK General Data Protection Regulation ("GDPR").

1. Who we are and our roles

For personal data of our own website visitors and the restaurant staff who administer an account, MenuPulse acts as a data controller / data fiduciary. For personal data that a restaurant collects about its own diners through the Service, the restaurant is the controller / fiduciary and MenuPulse acts as a data processor / data processor on their behalf, handling data only on the restaurant's documented instructions under a Data Processing Agreement.

2. Data we collect

From website visitors

  • Contact details you submit (name, email, restaurant name, message).
  • Basic usage and device data (pages viewed, approximate region, browser type).

From restaurant account holders

  • Account and billing information, authentication data, and team member details.
  • Configuration you create: menus, campaigns, loyalty rules, and settings.

Diner data processed on a restaurant's behalf

  • WhatsApp phone number and profile name, and message content exchanged with the restaurant.
  • Order history, reservations, feedback, loyalty status, preferences, and derived metrics such as visit frequency and lifetime value.
  • Consent records and communication timelines.

3. WhatsApp messaging data

The Service sends and receives messages through the Meta WhatsApp Business (Cloud API). When a diner messages a restaurant, we process the message content and metadata to deliver the Service — rendering menus, taking orders, sending confirmations, and enabling marketing that the diner has consented to. This processing is also subject to Meta's WhatsApp Business Messaging Policy and Meta's terms. We honour the WhatsApp 24-hour customer-service window and use approved message templates for outbound marketing as required by those policies. We do not sell WhatsApp data, and we do not use message content for advertising.

4. How we use data and our legal bases

  • To provide the Service — performance of a contract with the account holder.
  • To send marketing to diners — only where the restaurant has captured valid consent; diners may withdraw consent at any time.
  • To secure and improve the Service — our legitimate interests, balanced against your rights.
  • To meet legal obligations — tax, accounting, and lawful requests.

5. Consent management

Consent is central to the Service. When a diner first interacts with a restaurant, MenuPulse captures an explicit opt-in and records it in a consent ledger, including the time, source, and scope of consent. Diners can withdraw consent or opt out of marketing at any time, including by replying to a message, and we process such requests promptly.

6. Sharing and sub-processors

We share personal data only with service providers who help us run the Service under appropriate contractual safeguards. These include cloud hosting, the Meta WhatsApp Cloud API, payment processors (such as Razorpay and Stripe), and AI providers used to power assistant and analytics features, which process data under strict instructions and do not use it to train foundational models without authorisation. We maintain a current list of sub-processors and will notify account holders of material changes.

7. International transfers

Where personal data is transferred outside your country, we rely on lawful transfer mechanisms such as standard contractual clauses and equivalent safeguards required under the DPDP Act and GDPR.

8. Data retention

We retain personal data for as long as an account is active and as needed to provide the Service, then delete or anonymise it within a reasonable period, subject to legal retention requirements. Restaurants control the retention of their diner data and can export or erase it at any time.

9. Your rights

Subject to applicable law, you have the right to access, correct, update, and erase your personal data; to withdraw consent; to data portability; to object to or restrict certain processing; and to lodge a complaint with a supervisory authority (or the Data Protection Board of India under the DPDP Act). Diners should direct requests about their data to the restaurant that serves them; we will support restaurants in fulfilling those requests.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, per-tenant isolation, role-based access control, secret encryption, audit logging, and rate limiting. No system is perfectly secure, but we work continuously to protect your data and will notify affected parties of a reportable breach as required by law.

11. Children

The Service is intended for businesses and their adult customers. We do not knowingly collect personal data from children in a manner that would require verifiable parental consent; where such consent is required by law, restaurants are responsible for obtaining it.

12. Changes to this policy

We may update this policy from time to time. We will post the revised version here with an updated date and, where changes are material, provide additional notice.

13. Contact us

For any privacy question or to exercise your rights, contact us at hello@menupulse.io. WhatsApp is a trademark of Meta Platforms, Inc.; MenuPulse is an independent product and is not endorsed by or affiliated with Meta.