Privacy

Restaurant invoices are commercially sensitive. Here is exactly what MenuLedger holds, who else touches it, and how to get rid of it.

Last updated 4 September 2026.

This is a draft. The company details and governing law are not filled in yet, so this document is not in force. It is published so you can read what we intend to commit to.

What we collect

  • Your email address and password, so you can sign in. Passwords are stored hashed; nobody here can read yours.
  • Your workspace: its name, business type, currency and target food cost.
  • The invoice files you upload, and everything read from them — supplier, invoice number, date, line items, quantities and prices.
  • The ingredients, recipes and prices you create, and the cost history derived from them.
  • Ordinary server logs, including IP addresses, kept for security and debugging.

We do not ask for card details. When payment is added, it will be handled by a payment provider and we will update this page before it is.

Why we hold it

To run the service you asked for: reading your invoices, keeping your costs current, and showing you what changed. We do not sell your data, we do not share it for advertising, and we do not use your business data to train AI models.

Who else touches it

MenuLedger runs on other companies' infrastructure. These are all of them:

ResendDelivers account-verification and password-reset emails.Your email address and the one-time code in the requested account email.
VercelHosts and serves the application.Requests to the site, including IP address.
ConvexDatabase and backend. Runs every query and mutation.Your account, workspace, suppliers, ingredients, recipes, invoices and price history.
Cloudflare R2Stores the invoice files you upload, in a private bucket.The invoice documents themselves.
Vercel AI GatewayRoutes invoice reading to a model provider.The contents of an invoice you ask us to read, at the moment you ask.

Invoices and AI

When you ask MenuLedger to read an invoice, that invoice is sent to a model provider through an AI gateway, read, and the result returned. We send the invoice and nothing else — not your recipes, not your margins, not your other suppliers.

Nothing the model returns changes your costs on its own. It is a draft until you review and confirm it.

How it is protected

  • Invoice files live in a private bucket. No public or shareable link to one exists.
  • Reading an invoice file goes through our server, which checks you belong to the workspace that owns it before sending a single byte.
  • Every record belongs to a workspace, and every request is checked against your membership of it. One restaurant cannot reach another's data.
  • Credentials for AI and file storage live on the server and are never sent to the browser.

How long we keep it

Your data stays while your workspace exists, because a confirmed invoice is the evidence behind a price — costing looks back over the last 90 days of purchases, and the history behind that is what lets you explain a figure months later.

Deleting your workspace, from its settings, deletes its data — invoice files included. Your account survives it, because you may belong to other workspaces. Server logs age out on their own.

What you can ask for

Write to [CONTACT EMAIL] and we will, within a month: tell you what we hold about you, give you a copy, correct it, or delete it. If you are in a place with data protection law — the UK and EU among them — those are rights you have, and you can also complain to your regulator.

Cookies

MenuLedger sets one cookie, to keep you signed in. There is no analytics cookie, no advertising cookie, and no third-party tracker on this site — which is why you were not asked to accept anything.

Changes

If we change what we collect or who touches it, we will update this page and the date at the top, and tell you where the change matters.

Who to write to

[LEGAL ENTITY], [REGISTERED ADDRESS]. Data questions: [CONTACT EMAIL].

Questions about any of this: [CONTACT EMAIL]