1. Introduction & Scope
ServeScan (“we”, “our”, “us”, operated by CreoForge) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, process, and disclose personal and operational information when you:
- Register and use our digital menu management platform at
servescan.appand its administrative subdomains (“Platform Users” / “Restaurant Owners”). - Visit, scan, or browse a digital menu hosted on our edge infrastructure at
servescan.app/m/[slug]or custom subdomains (“Diners” / “Menu Visitors”).
2. Roles & Data Controller / Processor Distinction
- For Restaurant Account Data: ServeScan is the Data Controller for the account details (name, email address, password hashes, Google authentication identifiers, billing history) provided by restaurant owners.
- For Menu Content & Diner Edge Requests: ServeScan acts as a Data Processor / Service Provider hosting the menu content on behalf of the restaurant owner. Restaurant owners are the Data Controllers for the menu details, contact numbers, Wi-Fi credentials, and branding uploaded to their pages.
3. Information We Collect
A. From Restaurant Owners & Platform Users
- Account & Authentication Credentials:
- Standard Registration: Full name, restaurant/business name, email address, and cryptographically hashed passwords.
- Single Sign-On (Google OAuth 2.0): If you choose to register or log in using Google, we receive your basic public profile information permitted by your Google Account settings, including your full name, verified email address, Google account ID, and profile picture. We do not access your Google password, personal contacts, or private Google Drive/Gmail data.
- Menu Data & Business Information: Food and beverage item names, descriptions, pricing (in any of our 60+ supported global currencies), ingredient/dietary tags (e.g., spicy, vegan, vegetarian, gluten-free, halal, chef's recommendation), allergen indicators, promotional banners, business physical address, operating hours, public phone numbers, and guest Wi-Fi network credentials (if voluntarily provided).
- Uploaded Media: Restaurant logos, dish photos, and promotional graphics uploaded to the ServeScan Media Library.
- Billing & Transaction Data: Subscription tier selections (Starter, Pro, Bespoke), billing cycles, transaction reference IDs, and payment statuses. (Note: We do not directly collect, store, or process full credit card numbers or banking passwords; these are handled directly by our certified payment processors).
B. From Diners & Public Menu Visitors
- No Account Required: Diners are not required to create an account, register, or provide their name, phone number, or payment details to view menus.
- Automated Edge Logs: When a diner accesses a QR menu URL, Cloudflare edge servers automatically log standard network metadata necessary to deliver the page securely: IP address (used for geolocation routing and DDoS defense), browser user-agent, operating system, referring URL, timestamp, and requested menu slug. These logs are processed strictly for security, edge caching, and service availability.
- Zero Location Tracking: We do not track GPS coordinates, bluetooth beacons, or physical diner locations.
4. How We Use Your Information
We use the collected information for the following specific purposes:
- Service Provision: Creating and maintaining restaurant accounts, authenticating administrators via passwords or Google OAuth, rendering digital menus (both continuous vertical feed and paginated canvas booklet modes), generating high-resolution vector QR codes, and synchronizing live menu states (such as instant sold-out toggling and automated off-peak daily resets).
- Edge Optimization & Caching: Caching public menus across global edge points of presence (PoPs) to ensure sub-second menu loading speeds for diners.
- Quota & Plan Enforcement: Monitoring account storage limits (25MB on Starter, 250MB on Pro, dedicated on Bespoke), daily upload caps, and active menu limits.
- Transactional Communications: Sending critical service emails, including password resets, renewal reminders, security alerts, and system status updates.
- Fraud Prevention & Platform Security: Detecting and mitigating bot attacks, brute-force login attempts, scraping, Distributed Denial of Service (DDoS) attacks, and unauthorized system access.
5. Third-Party Sub-processors & External Assets
We partner with certified third-party service providers to deliver our platform. These providers process data solely as necessary to perform their respective services:
Google LLC (Identity & SSO)
Facilitates secure Single Sign-On (SSO) authentication for restaurant administrators via Google Identity Services and OAuth 2.0.
Lemon Squeezy (LLC)
Acts as our Merchant of Record (MoR) for global credit/debit card billing, international subscriptions, and international tax compliance (VAT, GST, sales tax).
PT Midtrans
Authorized payment gateway for Indonesian domestic transactions (QRIS, GoPay, ShopeePay, Bank Virtual Accounts, local cards) under PCI DSS Level 1 protocols.
Cloudflare, Inc.
Edge compute (Workers), serverless SQLite databases (D1), distributed media storage (R2), and global CDN caching. Encrypted with TLS 1.3/1.2.
Google Fonts (Google LLC)
Serves optimized web typography (Inter, Playfair Display, Cinzel, Space Grotesk, Outfit, EB Garamond). Standard HTTP asset request headers are processed by Google's CDN.
7. Data Retention & Deletion
- Account Data: Maintained for as long as your account remains active.
- Media & Menu Deletion: When you delete a menu item or image from your Media Library, it is marked for deletion and permanently purged from active database tables and Cloudflare R2 object storage.
- Account Termination: Upon account closure or verified deletion requests, your personal data, OAuth connections, and uploaded assets will be permanently deleted within thirty (30) days, except where retention is required by applicable accounting, tax, or legal retention laws.
8. Data Security & International Transfers
We implement technical and organizational security measures—including PBKDF2 SHA-256 password hashing, OAuth 2.0 token verification, TLS 1.3 encryption in transit, strict tenant data isolation, and distributed edge firewalls—to protect against unauthorized access, loss, or alteration. Because we utilize Cloudflare's distributed edge infrastructure, data may be processed in secure data centers worldwide.
9. Your Rights
Depending on your jurisdiction (such as under GDPR, CCPA, or the Indonesian Personal Data Protection Law / UU No. 27 Tahun 2022 UU PDP), you have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete information.
- Request deletion (“Right to be Forgotten”) of your account and personal data.
- Disconnect linked third-party authentication providers (such as Google Sign-In).
- Object to or restrict specific data processing activities.
- Export your menu data in a structured format.
Exercise Your Privacy Rights
Contact our Data Protection team to submit a request.