Privacy Policy
What we collect, why, and what we don't do with it.
Effective 12 August 2026.
Version 3. Published and in force from 12 August 2026, replacing version 2.
Prepared with AI assistance and not yet reviewed by an attorney. Published because it is materially safer and more accurate than the version it replaces. We will have counsel review this policy and will publish their revisions as a new version.
This policy covers menuhosted.com, chairweasel.com and every restaurant site we host. The service is operated by CHAIRWEASEL LLC, a Texas limited liability company doing business as menuhosted.com. It was called Chair Weasel until August 2026; only the trading name changed, and chairweasel.com still works.
The short version. We collect what we need to run your account and bill you, and nothing else. We don’t track the people who read your menu, we don’t run analytics or advertising, and we don’t sell data to anyone. There is no third party here whose business model is watching your customers.
1. Two different relationships
Which one applies changes what we do with the data:
- For restaurant owners and staff — we decide how your account data is handled, so we’re the controller of it. This policy is our explanation to you.
- For what you put into your site — your menu, your photos, your contact details — we’re only the processor. It’s your content and you decide what goes in it. If you publish a phone number or a staff member’s name on your menu, that’s your call and your responsibility.
2. What we collect from restaurant owners
- Your name and email, so we can identify you and contact you.
- Your password, stored only as a bcrypt hash. We cannot read it, and we cannot tell you what it is if you forget it — only reset it.
- Your restaurant’s details — name, web address, time zone, and whatever contact information you choose to publish.
- Billing status: your plan, whether you’re on trial, and when you’re next due. We never see or store your card number — Stripe handles that and we only hold a reference to your Stripe customer record.
- Technical logs from our hosting, which include IP addresses and are used for security and debugging. Our host keeps these only briefly — currently about a week — and then discards them automatically.
- Our help guide includes short videos hosted on YouTube. Nothing is sent to Google unless you press play — the still image you see first is served from our own site, and the video is only loaded from YouTube once you ask for it. If you do play one, Google receives your IP address and may set cookies, as it would on any site embedding a video. Nothing on your restaurant’s own menu does this; your diners are never touched by it.
- When you accept the Terms of Service, a record of that acceptance: when it happened, which version you accepted, the email address that accepted it, and the IP address and browser it came from. We ask again, and record it again, if the Terms change materially.
3. What we collect from people reading your menu
Almost nothing, and this is deliberate. There are no accounts for diners, no analytics, no advertising or tracking pixels, no third-party cookies, and no profile is built of anyone.
- A session cookie, which is what makes the site work at all. It carries no personal information, isn’t used for tracking, and is strictly necessary for the site to function.
- Ordinary server logs — IP address, browser, page requested — kept by our host for about a week, then discarded automatically. We use them for security and troubleshooting.
One exception worth naming: web fonts. If a restaurant picks a lettering style other than the default, that font is fetched from Google Fonts, so the visitor’s browser contacts Google and Google sees their IP address. Choosing “System default” avoids this entirely — no request leaves our servers. Our own pages on menuhosted.com use a Google font throughout, so reading this site contacts Google whatever any restaurant has chosen. We disclose all of this because most sites doing it don’t.
4. Why we’re allowed to hold it
- To perform our contract with you — running your account, hosting your site, taking payment.
- Our legitimate interests — keeping the service secure, fixing faults, preventing abuse.
- Legal obligations — keeping billing records for as long as tax law requires.
5. Who else handles it
These companies process data on our behalf. We don’t sell data, and nobody here is given it for their own marketing.
| Who | What for | What they see |
|---|---|---|
| Heroku (Salesforce) | Hosting and database | Everything stored in the app |
| Amazon Web Services | Photo storage (US East) | Images you upload |
| Resend | Sending our email | Recipient address and message content |
| Stripe | Payments | Your billing details and card — we never see the card |
| Sentry | Error monitoring | Technical error reports. Configured not to attach personal data. |
| Google Fonts | Web fonts: always on our own site, and on a restaurant’s menu only if a non-default style is chosen | Visitor IP address (see section 3) |
| YouTube (Google) | Guide videos in our help pages | Your IP address, and cookies — but only if you press play (see section 2) |
If we add or change a sub-processor, we’ll update this table and the effective date at the top of this policy. For a change that materially affects how account holders’ data is handled, we’ll email you first.
Our servers and data are in the United States. If you’re outside the US, using the service means your data is handled there.
6. How long we keep it
- While your account is active — for as long as you keep it, plus 30 days afterwards.
- If a free trial ends without a subscription — your site goes dark after 14 days and everything is permanently deleted at day 44, which is 30 days later. We warn you by email first, several times. After that it’s gone and we can’t recover it. See section 6 of the Terms of Service.
- If you’ve paid us and then stop — different, and deliberately so. Nothing automatic ever deletes a paying customer’s data, and we keep it for at least 12 months after your subscription lapses. Your site may go dark, but erasing it is only ever a deliberate decision by a person, after we’ve tried to reach you, given you at least 30 days’ notice, and offered you a chance to export your content. See section 7 of the Terms.
- Billing records — kept as long as tax and accounting law requires, even after an account closes.
- Server logs — about a week, which is how long our host retains them before discarding them.
- Backups — we take a daily backup and our host keeps the last seven, so deleted content can persist in a backup for up to seven days before it ages out.
- Our record of warnings we sent you — kept after an account is deleted, and deliberately so. Section 6 of the Terms commits us to warning you repeatedly before deleting a trial, and a record destroyed along with the account would be no record at all. It holds only the address we wrote to, what we sent, and when.
- Our record of copyright complaints — section 2 of the Terms commits us to counting complaints against an account and closing it at three, so we keep that record for as long as the account exists and for two years afterwards. It holds the date, which account it concerned, what the complaint was about, what we did, and the contact details the complainant gave us — which the law requires a copyright notice to include, and which we need in order to pass on a counter-notice. If you send us a copyright complaint, expect the account holder to be told who complained; that is how the Digital Millennium Copyright Act works and we cannot operate the process otherwise.
7. Your rights
Email hello@menuhosted.com and we’ll act on any of these, normally within 30 days:
- See a copy of what we hold about you.
- Correct anything wrong — most of it you can edit yourself.
- Delete your account and its content.
- Export your menu content, in a readable format.
- Object to processing based on our legitimate interests.
Depending on where you live you may also have the right to complain to a data protection authority.
If a diner asks you to remove information you published about them, that’s your content to change — but ask us if you need help. If a diner contacts us directly about information on a restaurant’s menu, we’ll pass the request on to that restaurant, since only they can decide what their menu says.
8. Security
- Everything is served over HTTPS.
- Passwords are stored as bcrypt hashes, never in a form we can read.
- Card details never touch our servers.
- Each restaurant’s data is scoped to that restaurant, and we test that one tenant cannot read another’s.
No system is perfectly secure. If a breach affects you, we’ll tell you and any regulator we’re required to.
9. Email we send you
Account email — password resets, billing, trial expiry and deletion warnings — is part of the service and can’t be opted out of while you have an account, because it’s how we tell you something is about to happen to your site. We don’t currently send marketing email. If we ever do, it’ll be opt-in with an unsubscribe link.
10. Children
Menu Hosted is a business tool and isn’t directed at children. We don’t knowingly collect data from anyone under 13.
11. Changes
We’ll post any update here and change the effective date. For anything material affecting account holders, we’ll email you.
12. Contact
CHAIRWEASEL LLC, doing business as menuhosted.com
17350 State Highway 249, Ste 220, Houston, TX 77064
hello@menuhosted.com