Privacy Policy
Last updated August 6, 2026
PlatePost turns a restaurant's menu into a video menu that guests can watch on a table QR code, a TV, a tablet, or a link in bio. This policy explains what we collect, why, and what you can ask us to do about it.
Two different people read this page. A restaurant is someone who signs up, pays for a plan, and manages a menu. A guest is someone who scans a QR code at a table and looks at a menu without ever making an account. Each section below says which one it applies to.
What we collect from restaurants
When you create an account or subscribe to a plan, we collect:
- Account details — your name, email address, restaurant name, and locations.
- Menu content you send us — PDFs, photos, links, dish names, descriptions, prices, and dietary tags.
- Billing details — handled by Stripe. Card numbers never reach PlatePost's servers; we store only the subscription status, plan, and the last four digits Stripe reports back.
- Support correspondence — emails and messages you send us.
What we collect from guests
You do not need an account, an app, or a login to look at a PlatePost menu. We deliberately keep this list short:
- Anonymous, aggregated menu activity — which dishes were viewed or tapped, and how long a video was watched. This is what powers the analytics a restaurant sees. It is not tied to a name, an email, or an advertising profile.
- Basic request data your browser sends to any website — IP address, browser type, and referring page — used to serve the page, and for security and abuse prevention.
- Messages you type into the on-menu AI assistant, so it can answer you and so we can improve its answers. Please don't type anything sensitive into it.
- Aggregate traffic measurement via Vercel Analytics, which does not use cookies and does not build a cross-site profile of you.
We do not sell guest data. We do not share it with advertising networks, and we do not use it to build cross-site advertising profiles.
Allergen and dietary information
Dietary tags and allergen labels shown on a menu come from the restaurant, and the restaurant is responsible for keeping them accurate. PlatePost's AI features can help draft them, but a tag is not a medical guarantee.
If you have a food allergy, always tell the restaurant's staff directly. Do not rely on a menu screen alone.
Who we share data with
We use a small set of vendors to run the product. They only receive what they need to do their job, and they are not permitted to use it for their own purposes:
- Vercel — website and application hosting, plus cookieless traffic analytics.
- Convex — the database that stores accounts, menus, and menu activity.
- Stripe — payment processing and subscription billing.
- UploadThing — storage and delivery of menu photos and videos.
- Resend — transactional email, such as sign-in codes and receipts.
- Mapbox — the maps shown on discovery and directions features.
- Anthropic — the AI models behind the guest assistant and the owner assistant.
- UserWay — an accessibility widget offered on some restaurant menus.
- Cal.com — scheduling, if you book a call with us.
We may also disclose information if the law requires it, or to protect the safety, rights, or property of PlatePost, our customers, or the public. If PlatePost is ever acquired or merges with another company, account data may transfer as part of that transaction; we would notify restaurant accounts before it took effect.
How long we keep things
Account and menu content is kept for as long as your account is active, and for a reasonable period afterwards so a menu can be restored if you come back. Billing records are kept as long as tax and accounting rules require.
Anonymous menu activity is kept in aggregate and is not linked back to an individual guest.
Your choices
Restaurants can view, correct, export, or delete their account and menu content at any time from the dashboard, or by emailing us.
Guests can ask what we hold about them and ask us to delete it, though in most cases guest activity is already anonymous and cannot be traced back to a person. Email support@platepost.io either way.
Depending on where you live — California, the wider United States, the UK, or the EU — you may have additional rights to access, correct, delete, or restrict the use of your personal information, and to complain to a data protection regulator. We honour these requests regardless of where you live, rather than checking your jurisdiction first.
We do not sell or share personal information as those terms are defined under California law.
Security
Data is encrypted in transit, access to production systems is limited to people who need it, and payment card details are handled entirely by Stripe and never stored on our servers. No system is perfectly secure, and we won't claim otherwise — if a breach ever affects your information, we will tell you.
Children
PlatePost is a product sold to restaurants and is not directed at children. We do not knowingly collect personal information from children under 13.
Changes to this policy
If we make a material change we will update the date at the top of this page and, for changes that affect restaurant accounts, email the account owner. Continuing to use PlatePost after a change means you accept the updated policy.
Contact us
Questions about this policy, or a request about your data: support@platepost.io.