Overview
NexaMenu ("we", "us", or "our") provides a comprehensive restaurant management platform that includes an Admin Panel, a Customer-facing web menu, and associated mobile applications. The platform is built on Google Firebase and enables restaurants to manage menus, orders, dining tables, staff, branches, subscriptions, and QR-code-based ordering.
This Privacy Policy applies to all users of the NexaMenu platform â including restaurant owners, administrators, employees (staff roles), and end customers who interact with the customer-facing web menu.
By using NexaMenu, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of the platform.
Data We Collect
We collect the following categories of data to operate and improve the platform:
2.1 Account & Identity Data
- Full name, email address, and mobile number
- Profile photo (optional, uploaded to Firebase Storage)
- Role assignment (Admin, Employee, Customer)
- Branch association and access permissions
- Firebase Authentication UID
2.2 Restaurant & Business Data
- Restaurant name, logo, and branding details
- Branch details (name, address, working hours)
- Menu items â names, prices, categories, images, attributes
- Tax rates and pricing configurations
- Dining table and floor layout data
- QR code configurations linked to tables and branches
- Subscription plan and payment transaction records
- Currency and language preferences
2.3 Order & Transaction Data
- Orders placed (table orders, takeaway, customer POS)
- Order status history (Placed, Accepted, Ready, Delivered)
- Payment method and payment status (Paid / Unpaid)
- KOT (Kitchen Order Ticket) data
- Applied offers, discounts, and loyalty points
2.4 Device & Usage Data
- Device type, browser, and operating system
- IP address and approximate location
- Firebase Cloud Messaging (FCM) tokens for push notifications
- App usage logs and error logs (for debugging purposes)
2.5 Payment Data
- Payment information processed via integrated gateways (Razorpay, Paystack, and others). We do not store raw card numbers or CVVs â these are handled directly by the respective payment gateway provider.
- Subscription transaction history stored in Firestore
How We Use Your Data
The data we collect is used for the following purposes:
Authentication
Verify your identity and manage secure login using Firebase Authentication.
Restaurant Operations
Enable menu management, order processing, table management, and branch operations.
Analytics & Reports
Generate sales reports, order summaries, and performance charts for restaurant owners.
Notifications
Send order updates, kitchen alerts, and system notifications via Firebase Cloud Messaging.
QR Code Ordering
Link customers to restaurant menus via dynamically generated QR codes for contactless ordering.
Subscription Management
Track and manage restaurant subscription plans, renewals, and payment statuses.
Multi-language Support
Store language preferences to serve the application in user's preferred language.
Platform Improvement
Use aggregated, anonymized data to improve platform features and fix issues.
Data Sharing & Third Parties
We do not sell your personal data. We share data only in the following cases:
| Service / Party | Purpose | Data Shared |
|---|---|---|
| Google Firebase | Authentication, Database (Firestore), Storage, Notifications | All user and restaurant data |
| Razorpay | Payment processing for subscriptions and orders | Payment amount, email, name |
| Paystack | Alternative payment processing | Payment amount, email, name |
| Firebase Cloud Messaging | Push notifications for order updates and alerts | FCM device token |
| Legal Authorities | Compliance with legal obligations | As required by law |
Third-party services have their own privacy policies. We recommend reviewing Google's, Razorpay's, and Paystack's privacy policies for more information on their data practices.
Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specifically:
- Active accounts: Data is retained indefinitely while your account is active.
- Order history: Retained for a minimum of 3 years for business reporting purposes.
- Payment records: Retained as required by financial regulations.
- Deleted accounts: Personal data is removed within 30 days of account deletion request, except where retention is required by law.
- Firestore data: Deleted from all collections (users, orders, roles, branches) upon confirmed account deletion.
Data Security
We take data security seriously and implement multiple layers of protection:
Firebase Authentication
All user logins are secured through Firebase Auth with email/password. Passwords are never stored in plain text.
Firestore Security Rules
Access to Firestore collections is controlled by security rules that restrict data access based on user roles and restaurant ownership.
Encrypted Transmission
All data transmitted between the app and Firebase is encrypted via HTTPS/TLS protocols.
Role-Based Access Control
Users are assigned specific roles (Admin, Employee, Customer) with scoped permissions to prevent unauthorized data access.
Firebase Storage Rules
Images and files uploaded to Firebase Storage are protected with access rules limiting download and upload permissions.
Multi-Restaurant Isolation
Each restaurant's data is stored under a unique restaurant ID in Firestore, ensuring complete data isolation between restaurants.
Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access Request a copy of the personal data we hold about you.
- Correction Request correction of inaccurate or incomplete data.
- Deletion Request deletion of your account and associated personal data (see Section 08 below).
- Portability Request a machine-readable export of your data.
- Objection Object to certain types of data processing, including marketing communications.
- Restriction Request that we restrict processing of your data in certain circumstances.
To exercise any of these rights, please contact us at support@nexamenu.com.
Delete Your Account
You have the right to permanently delete your NexaMenu account and all associated data. Once deleted, this action cannot be undone. Please read the information below carefully before proceeding.
đī¸ What Gets Deleted
- Your user profile (name, email, phone, photo)
- Your Firebase Authentication account
- Your role and permission assignments
- Your branch associations
- Your notification preferences
- Your session and preference data
đĻ What May Be Retained
- Order history (for restaurant business records â retained up to 3 years)
- Payment transaction records (required by financial regulations)
- Anonymized, aggregated analytics data
- Data required for legal or compliance purposes
How to Delete Your Account
Submit a Request via Email
Send an email to support@nexamenu.com from the email address associated with your NexaMenu account with the subject line: "Account Deletion Request".
Verify Your Identity
We will send a verification email to confirm your identity. You must respond within 48 hours to proceed.
Confirmation & Processing
Once verified, your account deletion will be processed within 7 business days. You will receive a final confirmation email once complete.
Data Removal
Personal data will be permanently removed from Firebase Authentication and Firestore within 30 days of the deletion request, unless retention is required by law.
Important: This Action Is Irreversible
Deleting your account will permanently remove your access to NexaMenu. If you are a restaurant Admin, deleting your account may affect your team's access to the platform. Consider transferring ownership or notifying your team before proceeding.
Request Account Deletion
Fill out the form below or email us directly at support@nexamenu.com
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last Updated" date at the top of this page
- Notify registered restaurant admins via email for significant changes
- Display an in-app notification for major updates
Continued use of NexaMenu after any changes constitutes acceptance of the updated Privacy Policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please reach out to us: