Nasıl çalışır Özellikler Fiyatlar SSS Giriş yap Ücretsiz başlayın

Gizlilik politikası

Son güncelleme 1 October 2026 · OBC REVOLUTION, North Macedonia

Kısaca
  • Yalnızca hizmetin çalışması için gerekenleri topluyoruz. Reklam yok, izleme çerezi yok ve kişisel verileri asla satmıyoruz.
  • Misafirler hesap oluşturmaz. Telefon numarası yalnızca bir işletme gerektirdiğinde istenir, tek bir kod göndermek için kullanılır ve misafir tarafından menü sayfasından istediği zaman kaldırılabilir.
  • Menüsünün ve misafirlerinin siparişlerinin içeriğine işletme karar verir. Bu siparişlerden işletme sorumludur, biz ise onları işletme adına işleriz.
  • Kartla ödemeler ödeme sağlayıcımız tarafından işlenir. Kart numaralarını asla görmeyiz ve saklamayız.
  • Eski veriler aşağıdaki takvime göre otomatik olarak silinir veya anonimleştirilir.
  • Verilerinizin bir kopyasını, düzeltilmesini veya silinmesini istediğiniz zaman isteyebilirsiniz: contact (at) barmenu (dot) pro.

Aşağıdaki tam metin İngilizcedir ve bağlayıcı sürüm odur.

1. Who we are

BarMenu.Pro is a QR menu and table-ordering service operated by OBC REVOLUTION, registered in North Macedonia (“we”, “us”). For questions about this policy or your data, write to contact (at) barmenu (dot) pro.

This policy applies to the website barmenu.pro, the venue panel, the order screens and every venue’s guest menu served by BarMenu.Pro. It is written to meet the EU General Data Protection Regulation (GDPR), the Law on Personal Data Protection of North Macedonia, and comparable laws in the countries where the service is used.

2. Whose data, and in which role

Four groups of people meet this service, and our role is different for each:

  • Visitors to barmenu.pro — we are the controller.
  • Venue customers: the owners, managers and staff who have a panel account — we are the controller.
  • Guests who use a venue’s QR menu. For the orders a guest sends to a venue (what was ordered, the table, a note, an optional name) the venue is the controller and we process them on its behalf, under the data processing terms in section 13. For phone confirmation (a number confirmed once and recognised at every venue) and for the security records that protect the platform, we are the controller.
  • Businesses we contact about the service (a venue we have not sold to yet) — we are the controller.

3. What we collect, why, and on what basis

Visitors to barmenu.pro

Our hosting provider’s web server records each request (IP address, browser, page, time) for security and to keep the service running — our legitimate interest. There is no analytics, no advertising tag and no tracking cookie on the website, and the fonts are served from our own server, so no third party is told that you visited.

Visitors who chat with us

If you write to us through “Chat with us”: your email address, your name if you give it, your messages and our answers, the website language you were reading and the page you started on, and your IP address and browser (to stop abuse of the chat). A person at BarMenu.Pro reads and answers them; if you have left the chat by then, the answer is sent to your email address. The chat runs on our own server — no chat service or third party receives it. Basis: answering the question you asked us, and our legitimate interest in keeping the chat free of abuse.

Venue customers

  • Account: name, email address, phone number (if given), your chosen language, and your password — stored only as a one-way hash that nobody, including us, can read.
  • Your venue: name, address, contact details, menu content, photos, tables, staff accounts and settings.
  • Billing: company name, contact name, billing email and phone, address, tax number, the packages bought and payments.
  • Security and support: sign-in records (time, IP address, browser), the emails we sent you, and a record of every support session in which our staff opened your panel.

Basis: performing our contract with you; legal obligations (accounting and tax records); and our legitimate interest in securing the service and preventing fraud.

Guests

  • What you order, from which table and when; a note to the staff and a first name, only if you type them; the menu language you choose.
  • Your device’s IP address and browser type — to apply the venue’s rule that orders may only come from its own Wi-Fi, to count scans of a table’s code, and to stop abuse.
  • If the venue asks for phone confirmation: your mobile number, the time it was confirmed and the venues where it was used. The code sent to you is stored only as a one-way hash. Orders are linked to the number so that a venue can block a number that abuses its code.

Basis: providing the service you ask for when you scan the code and order; the venue’s legitimate interest, and ours, in making sure orders really come from people in the venue and in stopping abuse. We do not use guest data for marketing and never send a guest anything other than the code they asked for.

Businesses we contact

Business name, address, and contact details a business has published (for example on its website or map listing), and notes of our conversations. Basis: our legitimate interest in offering our service to businesses. Tell us and we will not contact you again.

4. Cookies

We use only cookies that the service needs to work. None is used for advertising or analytics, so no consent banner is needed. The cookies are:

  • bmppro — the session, while your browser is open.
  • bmp_uilang — the language you chose, 1 year.
  • bmp_table, bmp_cart_…, bmp_lang_…, bmp_ordernum_… — on a guest’s phone: which table it is at, the basket, the menu language and the guest’s own order numbers, for up to 1 year.
  • bmp_guest — set only after a guest confirms a phone number, so they are not asked again; up to 2 years.
  • bmp_device — on a venue’s order screen, which screen it is.
  • bmp_chat — set only when you start a chat with us, so this browser can show you the conversation and our answers; 30 days.

5. Who receives it

  • The venue receives the orders sent to it, including the note, the name if typed, and the phone number behind an order when the venue uses phone confirmation.
  • Our hosting provider (MK-Host, North Macedonia), which runs the servers, the database and our email server.
  • Our SMS provider (smsmk.com, North Macedonia) and the mobile networks it uses, which receive the phone number and the text of a code or a reminder in order to deliver it.
  • Our payment provider and its bank, which take card payments on their own page; we receive only the result.
  • Authorities, courts or advisers, when the law requires it or to defend a legal claim; and a buyer of the business, under the same obligations, if the business is ever sold.

Each provider processes the data only to do that job for us, under an agreement that obliges it to keep it confidential and secure. We never sell personal data and never pass it to advertisers.

6. International transfers

We are based in North Macedonia, which is outside the European Union. Data about EU residents is therefore processed outside the EU. Where the GDPR applies, such transfers are made under the European Commission’s standard contractual clauses (which, between us and a venue, are part of the data processing terms in section 13), or where the transfer is necessary to provide the service you have asked for. North Macedonia’s own data protection law follows the GDPR.

7. How long we keep it

  • Venue accounts, menus and order history: for as long as the account exists. When a venue is deleted, its data is deleted with it; backups that contain it are deleted within 30 days.
  • Invoices, payments and the orders that bought a package: as long as accounting law requires (up to 10 years).
  • The IP address and browser of a menu scan: 30 days. The IP address of a guest order: 90 days.
  • A first name a guest typed with an order: 13 months, then removed from the order.
  • A confirmed guest phone number: until it has not been used at any venue for 2 years, or until the guest removes it. Verification codes: 30 days. The text of any SMS: 1 day; the record that it was sent: 13 months.
  • Sign-in records: 13 months. Records of emails sent: 25 months.
  • A chat with us: 13 months after its last message, or sooner if you ask; the IP address and browser recorded with it: 90 days.
  • A number blocked for abuse stays blocked, with only the number and the reason kept.

8. Security

The service is served only over encrypted connections (HTTPS). Passwords and verification codes are stored as one-way hashes. Access inside the service is limited by role; support staff enter a venue’s panel only through a recorded support session and never by asking for a password. Backups are kept outside the public part of the server and can be downloaded only by the platform owner after re-entering a password. If a breach puts your data at risk, we will tell the authority and, where required, you, without undue delay.

9. Your rights

You may ask us for access to your data and a copy of it, for a correction, for deletion, for processing to be restricted, for your data in a portable format, and you may object to processing based on our legitimate interest. Write to contact (at) barmenu (dot) pro; we answer within one month, and may first need to confirm that the request comes from you.

Guests can remove their phone number themselves: the link “Forget my phone number” is at the bottom of every menu page on the phone that confirmed it. For an order sent to a venue, you can also ask the venue, which is responsible for it; we will help it answer.

You may complain to a supervisory authority — in North Macedonia the Agency for Personal Data Protection (azlp.mk), in the EU the authority of the country where you live — though we would like the chance to put things right first.

10. Children

The panel is for businesses. A guest menu can be used by anyone at a venue, but we do not knowingly collect a phone number from anyone under 16; a parent or guardian who believes we have should write to us and we will delete it.

11. Automatic checks

Two checks run automatically when a guest orders: whether the phone is on the venue’s own Wi-Fi, and whether the phone number has been confirmed or blocked. They decide only whether an order can be sent from the phone; a guest can always order with the staff instead. No other automated decision is made about anyone.

12. Changes

When this policy changes, the date at the top changes with it. A change that affects venue customers materially is sent to the email address on the account before it takes effect.

13. Data processing terms (between BarMenu.Pro and each venue)

These terms form part of our Terms & conditions and apply to the personal data of a venue’s guests that we process for the venue (its orders). The venue is the controller and we are the processor.

  1. Instructions. We process guest data only to provide the service as the venue configures it in its panel, which is the venue’s documented instruction, and as required by law.
  2. Confidentiality. Everyone at BarMenu.Pro who can access the data is bound to confidentiality.
  3. Security. We apply the measures described in section 8.
  4. Sub-processors. The venue authorises the providers listed in section 5 (hosting, SMS, email). We will announce a new sub-processor on this page before using it; a venue that objects on reasonable grounds may end its subscription and receive a refund of the unused period.
  5. Assistance. We help the venue answer guests who exercise their rights, and with any security or impact assessment it has to make, as far as the data is in our hands.
  6. Breaches. We notify the venue without undue delay after becoming aware of a breach affecting its guests’ data.
  7. End of the service. A venue may delete its data at any time, and when it asks us to close its account we delete it; backups that contain it are deleted within 30 days.
  8. Proof. We make available the information needed to show that these terms are met, and allow reasonable audits on written request with fair notice.
  9. Transfers. Where GDPR applies to the venue and the data is processed in North Macedonia, the European Commission’s standard contractual clauses (Module 2, controller to processor, Decision 2021/914) are incorporated into these terms by reference.

The venue is responsible for having a lawful basis for the processing it instructs, and for telling its guests about it. The “Privacy” link at the bottom of every guest menu page points to this policy for that purpose.

14. Contact

OBC REVOLUTION, North Macedonia · contact (at) barmenu (dot) pro

The English text of this policy is the binding version; translations of the summary are provided for convenience.