How we collect, use, and protect your personal data
Last updated: February 23, 2026
Scan2Order ("we", "us", or "our") operates the scan2order.app platform and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our QR menu platform, website, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.
When you register for a Scan2Order account, we collect:
When you subscribe to a paid plan (Starter, Professional, Advanced, or Ultra) or purchase module add-ons, payment processing is handled by Stripe. We do not store your full credit card number, CVV, or banking details on our servers. Stripe processes and stores this information in accordance with PCI-DSS standards. We receive and store:
We store the content you create and manage through the platform:
We automatically collect certain information when you or your customers interact with the Service:
We use cookies and similar technologies to enhance your experience. For detailed information, please see our Cookie Policy.
We use the collected information for the following purposes:
We do not sell your personal data. We may share your information with the following categories of third parties:
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Scan2Order, our users, or the public.
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such change.
We retain your personal data for as long as your account is active or as needed to provide services. Specifically:
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at hello@scan2order.app. We will respond within 30 days.
We implement appropriate technical and organizational security measures to protect your data, including:
Your data may be transferred to and processed in countries outside your country of residence, including countries within the European Economic Area (EEA) and beyond. When transferring data internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions.
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information promptly.
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.
If you have questions or concerns about this Privacy Policy or our data practices, contact us at:
For GDPR-related inquiries, please see our GDPR Compliance page.
Consultez notre politique d'utilisation des cookies pour en savoir plus.
Essential
Session, security & basic functionality. Always active.
Analytics
Google Analytics & usage statistics to improve our service.
Preferences
Theme, language & personalization settings.
Third-party
Stripe payments, embedded content & external services.