Menoir
Guaranteed Operational Integrity

Privacy Practices

How we collect, verify, process, and safeguard merchant and guest interactions. Designed to guarantee absolute consumer privacy and compliance under USDA and global parameters.

Parent Identity:Brahma Origins LLC
Modified Date:April 1, 2025
Regulatory:GDPR & CCPA Compliant
Data Storage

Double Encrypted Cloud

Hosted on secure US AWS nodes with industry-leading protocol structures & file system access locks.

Zero Tracking

No Consumer Retargeting

We never track diner food decisions, behavioral vectors, or display third-party advertisements.

Billing Protection

Stripe Proxy Gateways

Raw credit cards are handled inside Stripe iframe sandboxes, ensuring zero physical database exposure.

Compliance

GDPR & CCPA Audits

Diners and merchants can coordinate deletions or request physical JSON logs at any time.

01
Basic framework governing digital QR operations.

1. Introduction

Menoir ("we," "our," or "us") is a digital menu platform operated by Brahma Origins LLC, located at 3442 Warren Rd, Cleveland, Ohio, USA. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at menoir.co, including our web application and QR-code-based digital menu services (collectively, the "Service").

By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please discontinue use immediately.

02
Direct scope detailing merchants, staff, and diners.

2. Who This Policy Applies To

This policy applies to all individuals who interact with Menoir, including:

Direct Actors & Diners

Restaurant owners and authorized account holders who subscribe to the Service.

Restaurant staff and employees added to an account.

Diners and guests who scan a QR code to view a restaurant's digital menu.

Visitors to our website.

03
Minimized vector logs with zero public sharing.

3. Information We Collect

We believe in radical minimization of collection vectors to guarantee zero user friction.

3.1 Information You Provide Directly

Account registration: name, email address, phone number.

Business details: restaurant name, address, operating hours, menu content, logo, and images.

Payment information: billing details processed securely through Stripe — we do not store raw card numbers.

Communications: messages or support requests you send us.

3.2 Information Collected Automatically

Session and authentication tokens (essential cookies only — see Cookie Policy).

Device type, browser type, and operating system for compatibility.

IP address and approximate geographic region for security and fraud prevention.

Usage logs: pages visited, features accessed, timestamps.

3.3 Information About Diners

When a diner scans a QR code and views a digital menu, we collect minimal technical data (IP address, device/browser type, and page view logs) solely for service operation and analytics. We do not require diners to create accounts or submit personal information to view a menu.

04
Service provisioning, invoice processing, and fraud defense.

4. How We Use Your Information

Your information is strictly mapped to operational requirements, never sold or leased.

We use the information we collect to:

• Provide, operate, and maintain the Service.

• Process transactions and manage subscriptions.

• Send transactional emails (account confirmations, invoices, subscription alerts).

• Provide customer support and respond to inquiries.

• Detect, prevent, and address security incidents or fraud.

• Improve and develop new features of the platform.

• Comply with legal obligations.

We do not sell your personal information to third parties. We do not use your data for targeted advertising.

05
Secured data handling with AWS and Stripe protocols.

5. How We Share Your Information

We coordinate exclusively with verified entities to enable dependable transaction rails.

5.1 Amazon Web Services (AWS)

We use AWS for cloud infrastructure and file storage (S3). Your account data and uploaded media (menu images, logos) are stored on AWS servers. AWS processes data in accordance with its Data Processing Addendum and applicable data protection laws.

5.2 Stripe

Payments from US-based customers are processed through Stripe, Inc. Stripe may collect and process billing and payment information directly. Please review Stripe's Privacy Policy at stripe.com/privacy.

5.3 Legal Requirements

We may disclose your information if required to do so by law, court order, or government authority, or to protect the rights, property, or safety of Menoir, our users, or the public.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction. We will notify affected users via email or a prominent notice on our website.

06
Automatic anonymization thresholds for consumer protection.

6. Data Retention

We retain your personal data for as long as your account is active or as necessary to provide the Service. Upon account deletion, we will delete or anonymize your data within 90 days, except where retention is required by law (e.g., financial records). Menu view logs from diners are retained for up to 12 months for analytics purposes, then deleted.

07
HTTPS/TLS encryption and audited JWT authentication.

7. Data Security

We implement industry-standard security measures including:

• Encrypted data transmission via HTTPS/TLS.

• JWT-based authentication with token expiry.

• Access controls limiting data access to authorized personnel only.

• Regular security reviews.

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

08
Secure processing inside United States data facilities.

8. International Data Transfers

Brahma Origins LLC is registered in the United States. If you access our Service from outside the US, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.

09
Explicit age barriers on telemetry trackers.

9. Children's Privacy

The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided personal data, we will delete it promptly. If you believe a child has submitted data to us, contact us at legal@brahma.company.

10
Access portals, deletions, and GDPR/CCPA directives.

10. Your Rights

Depending on your location, you may have the right to:

• Access the personal data we hold about you.

• Request correction of inaccurate data.

• Request deletion of your data (subject to legal retention obligations).

• Object to or restrict processing of your data.

• Data portability — receive a copy of your data in a machine-readable format.

To exercise any of these rights, contact us at legal@brahma.company. We will respond within 30 days.

10.1 EEA/UK Users (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process your personal data on the basis of our legitimate interests in providing the Service, the performance of our contract with you, and where required, your consent. You have the right to access, correct, delete, or restrict processing of your personal data by contacting us at legal@brahma.company.

10.2 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect, to request deletion of your personal information, and to opt out of the sale of your personal information. We do not sell your personal information. To exercise these rights, contact us at legal@brahma.company.

11
Exclusive cookieless operation with zero advertising targeting.

11. Cookies

We use only essential cookies necessary for authentication and session management. Please refer to our Cookie Policy for full details.

12
Hyperlink disclaimers for external domains.

12. Third-Party Links

The Service may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their policies independently.

13
Incremental amendment timeline and advisory notices.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on our website and updating the effective date. Continued use of the Service after changes constitutes acceptance.

14
Brahma Origins corporate legal correspondence details.

14. Contact Us

If you have requests, concerns or general questions on consumer privacy, our data operations vector can be reached directly:

Corporate Identity

ENTITY
Brahma Origins LLC
CORPORATE REGION
3442 Warren Rd, Cleveland, Ohio, USA
EMAIL REGISTER
legal@brahma.company
Menoir
DOMAINS ACTIVE
menoir.co