Privacy Policy

Last updated: 7 October 2026

DishLens ("we", "us") provides 3D and AR digital menus for restaurants at dishlens.app. This policy explains what data we collect from restaurant accounts and from diners who view a menu, why, and the choices you have.

1. Data we collect

  • Restaurant accounts: name, email address, password (stored only as a salted hash), restaurant details, menus, photos and 3D models you upload, and team members you invite.
  • Billing: plan, invoices and payment status. Card details are entered on Safepay's secure checkout and are never received or stored by DishLens.
  • Diners: we do not ask diners to sign up. When a menu is viewed we record anonymous usage events (pages and dishes viewed, 3D/AR opened) with a random session ID, device type and approximate region, so restaurants can see which dishes are popular.
  • Technical data: IP address, browser and request logs, used for security, abuse prevention and troubleshooting.

2. How we use data

  • To provide the service: host menus, generate QR codes, show analytics to the restaurant.
  • To send account emails: verification, password reset, invoices and important service notices.
  • To process payments through Safepay and keep accounting records.
  • To keep the platform secure: rate limiting, bot protection (Cloudflare Turnstile) and fraud checks.

We do not sell personal data and we do not use diner data for advertising.

3. Service providers

We share data only with providers that help us run DishLens, under their own security commitments:

  • Microsoft Azure — hosting, database and file storage.
  • Cloudflare — content delivery, DDoS protection and bot checks.
  • Safepay — payment processing.
  • Our email delivery provider — transactional emails.

4. Cookies and local storage

We use your browser's local storage to keep you signed in and to remember your theme, and session storage for an anonymous analytics session ID. We do not use advertising cookies. Cloudflare may set strictly necessary security cookies.

5. Retention

Account and menu data is kept while your account is active. After you close your account we delete or anonymise it within 90 days, except invoices and payment records we must keep for tax and legal reasons. Menu analytics are kept in aggregated, anonymous form.

6. Your rights

You can access and correct your account data from the dashboard, or ask us for a copy or deletion by writing to [email protected]. We reply within 30 days.

7. Security

Data is encrypted in transit (HTTPS) and stored with access controls, hashed passwords and restricted database access. No system is perfectly secure; if we learn of a breach that affects you, we will tell you without undue delay.

8. Changes and contact

We will post changes on this page and, for important changes, email account owners. Questions: [email protected].