Menu Genius
← Back to home

Privacy Policy

Data Controller

Menu Genius by Marcello Barbieri, VAT no. 01854410196, Via Belcavezzo 10A, Cremona, Italy.

Controller's email address: info@menugenius.net

Types of Data collected

Among the types of Personal Data that this Application collects, by itself or through third parties, there are:

Complete details on each type of Personal Data collected are provided in the dedicated sections of this privacy policy or by specific explanation texts displayed prior to the Data collection.

Personal Data may be freely provided by the User or, in the case of Usage Data, collected automatically when using this Application.

Unless otherwise specified, all Data requested by this Application is mandatory. If the User refuses to provide it, it may be impossible for this Application to provide the Service. In cases where this Application indicates some Data as optional, Users are free not to communicate such Data, without any consequence for the availability of the Service or its operation.

Users who have doubts about which Data is mandatory are encouraged to contact the Controller.

Any use of Cookies — or of other tracking tools — by this Application or by the owners of third-party services used by this Application serves to provide the Service requested by the User, in addition to any further purposes described in this document and in the Cookie Policy.

The User assumes responsibility for the Personal Data of third parties obtained, published or shared through this Application.

Mode and place of processing of collected Data

Methods of processing

The Controller takes appropriate security measures to prevent unauthorized access, disclosure, modification or destruction of Personal Data.

Processing is carried out using IT and/or telematic tools, with organizational methods and logic strictly related to the stated purposes. In addition to the Controller, in some cases, Data may be accessed by other parties involved in the organization of this Application (administration, sales, marketing, legal staff, system administrators) or by external parties (such as third-party technical service providers, hosting providers, IT companies, communication agencies) also appointed, if necessary, as Data Processors by the Controller. The updated list of Processors may always be requested from the Controller.

Place

Data is processed at the Controller's operating offices and in any other place where the parties involved in the processing are located. For further information, contact the Controller.

The User's Personal Data may be transferred to a country other than the User's own. To obtain further information about the place of processing, the User can refer to the section on details about the processing of Personal Data.

Retention period

Unless otherwise specified in this document, Personal Data is processed and stored for as long as required by the purpose for which it was collected and may be retained for a longer period due to any legal obligations or based on the Users' consent.

Purposes of processing

The User's Data is collected to allow the Controller to provide the Service, comply with legal obligations, respond to enforcement requests, protect its rights and interests (or those of its Users or third parties), detect any malicious or fraudulent activity, as well as for the following purposes: Analytics and Access to third-party accounts.

Facebook permissions requested by this Application

This Application may request certain Facebook permissions that allow it to perform actions with the User's Facebook account and to collect information, including Personal Data, from it. This service allows this Application to connect with the User's account on the Facebook social network, provided by Facebook Inc.

The permissions requested are the following:

Basic information

The basic information of the User registered on Facebook that normally includes the following Data: id, name, picture, gender and the User's language, and in some cases the User's Facebook "Friends". If the User has made further Data publicly available, that Data will also be available.

Email

Provides access to the User's primary email address.

Trackers

"Tracker" means any technology — e.g. Cookies, unique identifiers, web beacons, embedded scripts, e-tags and fingerprinting — that enables Users to be tracked, for example by collecting or storing information on the User's device.

Details on the processing of Personal Data

Access to third-party service accounts

These services allow this Application to retrieve Data from your accounts on third-party services and perform actions with them. These services are not activated automatically but require express authorization by the User.

Stripe account access

Company: Stripe Inc — Place of processing: United States.

This service allows this Application to connect with the User's account on Stripe, provided by Stripe, Inc.

Personal Data processed:

Service provided by: Stripe Inc (United States) – Privacy Policy.

Facebook account access

Company: Meta Platforms, Inc. — Place of processing: United States.

This service allows this Application to connect with the User's account on the Facebook social network, provided by Meta Platforms, Inc.

Permissions requested:

Service provided by: Meta Platforms, Inc. (United States) – Privacy Policy – Opt out.

Analytics

The services in this section allow the Controller to monitor and analyze traffic data and are used to keep track of the User's behavior.

Contentsquare

Company: Content Square Inc — Place of processing: United States.

Contentsquare is an analytics service provided by Content Square Inc that allows the Controller to obtain information on the use of this Application by Users.

Personal Data processed:

Service provided by: Content Square Inc (United States) – Privacy Policy.

Cookie Policy

This Application makes use of Trackers. To learn more, Users can consult the Cookie Policy.

Further information for users in the European Union

Legal basis of processing

The Controller processes Personal Data relating to the User if one of the following conditions applies:

It is always possible to ask the Controller to clarify the specific legal basis of each processing operation and in particular to specify whether the processing is based on law, provided for by a contract or necessary to enter into a contract.

Further information about retention time

Unless otherwise specified in this document, Personal Data is processed and stored for as long as required by the purpose for which it was collected and may be retained for a longer period due to any legal obligations or based on the Users' consent. Therefore:

When the processing is based on the User's consent, the Controller may retain Personal Data longer until such consent is withdrawn. In addition, the Controller may be required to retain Personal Data for a longer period to fulfill a legal obligation or upon order of an authority.

At the end of the retention period, Personal Data will be deleted. Therefore, upon expiry of this period, the right of access, deletion, rectification and the right to data portability can no longer be exercised.

The rights of Users based on the General Data Protection Regulation (GDPR)

Users may exercise certain rights with respect to their Data processed by the Controller. In particular, within the limits provided by law, the User has the right to:

Users are also entitled to be informed about the legal basis for the transfer of Data abroad, including to any international organization governed by international law or set up by two or more countries — such as the United Nations — and about the security measures taken by the Controller to safeguard their Data.

Details on the right to object

When Personal Data is processed in the public interest, in the exercise of official authority vested in the Controller or to pursue a legitimate interest of the Controller, Users have the right to object to the processing on grounds relating to their particular situation.

Users are reminded that, should their Data be processed for direct marketing purposes, they may object to the processing at any time, free of charge and without providing any justification. Should Users object to processing for direct marketing purposes, Personal Data will no longer be processed for such purposes. To find out whether the Controller processes Data for direct marketing purposes, Users may refer to the relevant sections of this document.

How to exercise these rights

Any requests to exercise User rights may be directed to the Controller through the contact details provided in this document. Requests are free of charge and the Controller will respond as soon as possible, in any case within one month, providing the User with all the information required by law. Any rectification, deletion or restriction of processing will be communicated by the Controller to each recipient, if any, to whom Personal Data was transmitted, unless this proves impossible or involves a disproportionate effort. The Controller will inform the User of such recipients upon request.

Additional information about processing

Legal defense

The User's Personal Data may be used by the Controller in court or in the stages leading up to possible legal action arising from improper use of this Application or the related Services by the User.

The User is aware that the Controller may be required to disclose Data by order of public authorities.

Specific notices

At the User's request, in addition to the information in this privacy policy, this Application may provide the User with additional and contextual information about specific Services, or the collection and processing of Personal Data.

System logs and maintenance

For operation and maintenance purposes, this Application and any third-party services it uses may collect system logs — that is, files that record interactions and that may also contain Personal Data, such as the User's IP address.

Information not contained in this policy

More details on the processing of Personal Data may be requested from the Controller at any time using the contact information.

Changes to this privacy policy

The Controller reserves the right to make changes to this privacy policy at any time by notifying Users on this page and, if possible, on this Application as well as, whenever technically and legally feasible, by sending a notice to Users through one of the contact details in its possession. Please regularly consult this page, referring to the date of last modification indicated at the bottom.

Should the changes affect processing activities whose legal basis is consent, the Controller will collect the User's consent again, if necessary.

Definitions and legal references

Personal Data (or Data)

Any information that directly, indirectly, or in connection with other information — including a personal identification number — allows the identification or identifiability of a natural person.

Usage Data

Information collected automatically through this Application (or third-party services employed in this Application), which can include: the IP addresses or domain names of the computers utilized by the Users who use this Application, the URI addresses (Uniform Resource Identifier), the time of the request, the method utilized to submit the request to the server, the size of the file received in response, the numerical code indicating the status of the server's answer (successful outcome, error, etc.), the country of origin, the features of the browser and the operating system utilized by the User, the various time details per visit (e.g., the time spent on each page within the Application) and the details about the path followed within the Application with special reference to the sequence of pages visited, and other parameters about the device operating system and/or the User's IT environment.

User

The individual using this Application who, unless otherwise specified, coincides with the Data Subject.

Data Subject

The natural person to whom the Personal Data refers.

Data Processor

The natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller, as described in this privacy policy.

Data Controller

The natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Data, including the security measures concerning the operation and use of this Application. The Data Controller, unless otherwise specified, is the Owner of this Application.

This Application

The hardware or software tool by which the Personal Data of the User is collected and processed.

You may freely give, refuse or withdraw your consent at any time by accessing the preferences panel. Refusing consent may make the related features unavailable.