Last updated: June 22, 2026
Privacy Policy
This Privacy Policy explains how YR Menu collects, uses, and protects information when you use our digital menu and restaurant-management platform (the "Service").
1. Who is responsible for your data
Depending on where your billing address or restaurant is located, the data controller for your account is one of the following entities:
-
TESLA KAFA LLC (Limited Liability Company (Foreign Enterprise) - O'OO "TESLA KAFA" Xorijiy korxona) — for all other customers.
Registered address: Guliston QFY, Sirg'ali mahallasi, Xonarik ko'chasi, 12-uy, Toshkent tumani, Toshkent viloyati, O'zbekiston. Registration No. 312477429. Contact: info@teslakafa.com. Phone: +998900039503.
2. Information we collect
- Account information: name, email, password (hashed), restaurant details, and billing information.
- Menu content: categories, products, prices, descriptions, images, and translations you upload.
- Customer/diner analytics: anonymized or pseudonymized data about menu views, language switches, popular dishes, table/QR scan activity, and device type. IP addresses are stored only in hashed form, never in plain text.
- Service requests: waiter-call and bill-request events, including table number, to operate that feature.
- Support communications: messages you send via our contact form or support channels.
3. How we use information
- To provide, maintain, and improve the Service.
- To process payments and send billing-related communications.
- To provide analytics dashboards to Restaurant Owners about their own menu's performance.
- To respond to support requests.
- To comply with legal obligations.
We do not sell your personal information.
4. Legal basis (EEA/UK users)
Where applicable data protection law requires it, we process personal data on the basis of: performance of a contract (providing the Service you signed up for), legitimate interests (service analytics, security), and consent (non-essential cookies - see our Cookie Policy).
5. Sharing of information
We share information only with: payment processors necessary to bill your subscription; infrastructure/hosting providers that store the Service's data; and email-delivery providers used for transactional messages. We do not share your data with third parties for their own marketing purposes.
6. Data retention
We retain account and menu data for as long as your account is active, and for a reasonable period after closure to allow reactivation and meet legal/accounting obligations, after which it is deleted or anonymized.
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact the relevant entity listed in Section 1, or use our Contact page.
8. Children's data
The Service is intended for business use by restaurant operators and their adult staff; it is not directed at children. Diners scanning a menu QR code are not required to provide any personal information to view a menu.
9. Security
We use reasonable technical and organizational measures (encrypted connections, hashed passwords, access controls) to protect data, but no method of transmission or storage is 100% secure.
10. International transfers
Depending on your contracting entity and our hosting infrastructure, your data may be processed in a country other than your own. Where required, we rely on appropriate safeguards for such transfers.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the dashboard or email.
12. Contact
Questions about this Privacy Policy can be sent via our Contact page or directly to the relevant entity's contact details listed in Section 1.
This document is a general template and has not yet been reviewed by qualified legal counsel in either jurisdiction listed above (including GDPR-specific requirements if serving EU customers). Please have it reviewed before relying on it for live, paid transactions.