← Back

Data & Compliance

Last updated: August 5, 2026

This page is maintained by Our Menu Roulette to answer common privacy and data-handling questions about the app. It describes our current practices — it is not a certification, an audit result, or independent verification, and it is not legal advice.

1. Controller & contact

Our Menu Roulette is the data controller for personal data processed through the app.
Legal name: Our Menu Roulette
Business address: Business address to be updated
Privacy contact: through the app's in-app support channel.

2. What we collect and why

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

3. Payments

Purchases are handled by our payment providers (Paddle as Merchant of Record on the web, and Apple on iOS). Card details are collected and stored by those providers, never by us. We receive only order and entitlement metadata.

4. Service providers

5. Retention & deletion

We keep personal data only as long as needed for the purposes above. Account data is kept while your account is active and for a reasonable period afterwards to meet legal and accounting obligations, then deleted or anonymised. You can request deletion at any time.

6. EU / UK residents — GDPR

Where the GDPR (or UK GDPR) applies, our legal bases are:

Your rights: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent. You also have the right to lodge a complaint with your local supervisory authority.

International transfers: where data leaves the EEA/UK, we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision.

7. California residents — CCPA / CPRA

In the past 12 months we have collected the categories described in section 2 (identifiers, internet/network activity, commercial information, and customer-support content). We disclose these to service providers only, for the business purposes listed above.

8. How to submit a privacy request

Send your request through the app's in-app support channel and tell us which right you want to exercise. We verify requests using the email address associated with your account, and we aim to respond within 30 days (GDPR) or 45 days (CCPA/CPRA), extending only where the law allows. Authorised agents may submit requests on your behalf with written permission.

9. Children

The app is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided data, contact us and we will delete it.

10. Security

We use technical and organisational measures appropriate to the service, including encryption in transit, authenticated access, and database-level access rules. No system is perfectly secure; we do not guarantee that a breach can never occur.

11. Reporting a vulnerability

If you believe you have found a security issue, report it through the app's support channel with steps to reproduce. Please do not publicly disclose it before we have had a chance to respond.

12. Related pages

Privacy NoticeTerms & ConditionsRefund Policy