Privacy Policy

Drafted 22 July 2026.

Draft — under review

This policy has not yet had a solicitor’s review (D47) and may change before launch. Bracketed placeholders like [COMPANY DETAILS] mark facts that will be filled in before this page is final.

Pic’enu (“we”, “us”) lets diners search and browse restaurant menus, scan a QR code at a table to see and rate dishes, and lets restaurants publish and manage a visual menu. This policy explains what personal data we collect through picenu.com, why we collect it, and the choices you have.

1. What we collect

  • Account email address — for diners and restaurant owners, via Supabase Auth (email + password).
  • First name + last initial — shown alongside any review you write.
  • Ratings and written reviews you submit for dishes.
  • QR-scan records — when you scan a restaurant’s QR code, we record the visit (and a verification token) to confirm you’re a genuine in-venue diner before you can rate or review, and to count scans for the restaurant’s dashboard.
  • Restaurant business details — for restaurant owners: business name, address, postcode, area, phone, cuisine, opening hours, and any logo/cover/dish images and menu content uploaded.

2. Why we collect it

To let anyone browse and search menus without creating an account; to verify a genuine in-venue visit before allowing a rating or review (this stops fake reviews); to display your first name and last initial next to reviews you write; to operate restaurant owner accounts — publishing and managing a menu, processing subscription payments, and showing dashboard stats (menu views, QR scans, ratings) — and to keep the service secure and meet our legal obligations.

3. Who else processes it

We use the following processors to run Pic’enu:

  • Supabase — our database, authentication, and file storage (dish/logo/cover images).
  • Stripe — processes restaurant subscription payments on their own hosted checkout page; we never see or store your card details.
  • Vercel — hosts and serves the Pic’enu application.

These providers process data on our behalf under their own data-processing terms. We do not sell personal data to anyone.

4. How long we keep it

Account and profile data is kept for as long as your account is active. Ratings and reviews are kept for as long as the dish/menu they relate to exists, so restaurant scores stay accurate — see account deletion below for what happens to your name on them. QR-scan records are kept for as long as needed to operate rating eligibility and scan analytics.

5. Account deletion

You can delete your account at any time from Settings, in-app (PRD §5.6). Deleting your account removes your profile and login. Your rating SCORES are anonymised, not deleted — the numeric rating stays linked to the dish (so restaurant and dish scores remain accurate) but is no longer linked to your name or account. Any written REVIEW TEXT you left is deleted, not kept — it is permanently cleared and no longer shown anywhere on the site.

6. Cookies

We only use essential and functional cookies — never analytics or marketing cookies — so we don’t show a cookie-consent banner. If that ever changes, we’ll add a consent banner and update this page first.

CookieTypePurpose
Supabase auth cookiesEssentialKeeps you signed in to your Pic’enu account.
picenu_anonFunctionalRemembers a verified QR scan so you’re eligible to rate or review before you sign up, and links that scan to your account once you do.
StripeOnly on Stripe’s hosted checkoutSet by Stripe on their own checkout page during a restaurant subscription payment — Pic’enu never sets or reads these.

7. Your rights

Under UK GDPR you have the right to access, correct, delete, or object to our processing of your personal data. Contact us using the details below to exercise any of these rights.

8. Contact

Questions about this policy, or a rights request: [CONTACT EMAIL]. Company details: [COMPANY DETAILS].

9. Changes to this policy

We may update this policy from time to time. Material changes will be reflected on this page with an updated date.