Privacy for restaurant owners
Last updated 17 August 2026.
This notice is about the account you use to run your restaurant's menu — not about the people who read it. Mango Labs Ltda. decides how your account data is handled, which makes us responsible for it. What your menu records about your guests is a separate notice, and there the decisions are yours.
Who is responsible
Menoodo is operated by Mango Labs Ltda., CNPJ 39.718.566/0001-99, at Rua São João Evangelista 656, apto. 1002, Santo Antônio, Belo Horizonte – MG, 30330-140, Brazil. privacy@menoodo.com is our channel for everything to do with personal data — questions about this notice, complaints, and requests to exercise any of the rights below. It reaches the people who can act on them.
What we hold about you
Your account: your email address, your name and profile picture if you set them, the language you chose for the dashboard, and which restaurants you belong to. Your sign-in: passwords, sessions and sign-in security information are held by our authentication provider, not by us. We never see your password. What you upload: the photos, logos and menu text you add. If you use menu import or automatic translation, the file or page you submit is sent to our AI provider to be read. Technical records: our hosting provider logs the network address, browser and pages requested for each request, which is how the service stays available and resists abuse. We keep no access log of our own and store no network address in our database. Your subscription: the plan you are on, its billing cycle and its status. Payment details — your card number, billing address and invoices — are collected by our payment provider, Paddle, and never reach us.
Why we may do this
To provide the service you signed up for — your account, your restaurants and your menus. Under the LGPD this is execution of a contract (Art. 7, V); under the GDPR, Art. 6(1)(b). To keep the service secure, available and free of abuse. Under the LGPD this is our legitimate interest (Art. 7, IX); under the GDPR, Art. 6(1)(f). We do not sell your data, we do not advertise to you, and nothing about your account is used to make automated decisions about you.
Who else sees it
Only the companies that run parts of the service for us: our application hosting and database providers, our authentication provider, our image storage provider, and the AI provider behind menu import and translation. Each may process your data only on our instructions. We keep a full list of them, including what each receives and where it is held, and we give notice before adding or replacing one. There are no advertisers, no data brokers and no third-party analytics anywhere in the product. Payments are the one exception: paid plans are sold by Paddle, which acts as merchant of record. When you buy a plan, Paddle collects your payment and billing details under its own privacy policy, as an independent controller rather than on our instructions. We receive from Paddle only your plan, its status and a customer reference — never your card number.
Where your data goes
Your account data is stored on servers in the European Union, and our team administers the service from Brazil. Brazil and the European Union have formally recognised each other as providing an adequate level of data protection, so this exchange needs no additional safeguard. One exception: sign-in data is held by our authentication provider in the United States, which participates in the EU–U.S. Data Privacy Framework and offers standard contractual clauses. Payment and billing data is held by Paddle in the United Kingdom and the United States, under Paddle's own transfer safeguards.
How long we keep it
Your account data for as long as your account exists. Deleting your account removes your user record, the restaurants you own, their menus and their images, and your sign-in account with our authentication provider. Technical logs are kept for a limited period by our hosting provider and are used for nothing else. Invoices and payment records are kept by Paddle for as long as tax and accounting law requires.
Your rights
You may ask us to confirm what we hold, obtain a copy, correct it, delete it, restrict or object to how we use it, and ask with whom we have shared it. Under the LGPD these are the rights in Art. 18. Two of them you can exercise yourself, straight away: change your name, email or password from your account settings, and delete your entire account — including your restaurants, their menus and their images — from the danger zone on the account page. Deletion there is immediate and cannot be undone. For anything else, write to privacy@menoodo.com. If you are not satisfied with our answer, you may complain to the Brazilian data protection authority, the ANPD.
If you are in the EU, the UK or Switzerland
The same rights apply under the GDPR: access, rectification, erasure, restriction, portability and objection (Art. 15 to 21). Where we rely on legitimate interest you may object to it; for your account itself we rely on our contract with you rather than on consent. You may complain to your national supervisory authority as well as to the ANPD.
Cookies in the dashboard
The dashboard stores only what it needs to work: your sign-in session, which restaurant you are currently editing, your dashboard language, and whether the sidebar and preview panel are open. There is no advertising, no tracking and no third-party analytics here, which is why you are not asked to accept cookies. The public menu is different, and asks your guests before measuring anything.
Your guests' data is a separate matter
This notice covers your account. What your menu records about the people who read it — their reviews, and the measurement of how the menu is used — is covered by a separate notice, and there you are the one who decides: we process that data on your instructions rather than our own. That also means the requests your guests make about their data reach you first, and our processing terms set out what we do to support you.
Who to contact
Write to privacy@menoodo.com for any question about this notice, to make a complaint, or to exercise any of your rights. It is the channel we maintain for data protection matters, and we answer within the time the law allows.