Privacy
Last updated 28 August 2026
This policy says what personal data UnivMenu holds, why we are allowed to hold it, where it goes, how long it stays and what you can make us do about it. It is written to Vietnam's personal data protection rules: the Law on Personal Data Protection No. 91/2025/QH15 and Decree No. 356/2025/ND-CP, both in force since 1 January 2026. Each section states the rule in plain words first; where there is more to it, the detail sits in the panel underneath.
Your own market has a privacy supplement which carries what is different there, and for everything it covers the supplement is the one that applies: Hong Kong · Vietnam.
Who is responsible for your data
- The data controller is QUIKFORGE LIMITED, the company behind UnivMenu.
- Write to hello@univmenu.com about anything on this page. That address reaches the person responsible for personal data, not a queue.
Full detail — the controller, and how to reach it
QUIKFORGE LIMITED, a company incorporated in the Hong Kong Special Administrative Region, Business Registration No 79555262, registered office Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R. ("QuikForge", "UnivMenu", "we", "us"). QuikForge decides why and how personal data is processed on UnivMenu and is therefore the controller of it.
Data protection contact: hello@univmenu.com, telephone +370 665 10325. Please write rather than call where you can — a request in writing is one we can verify, act on and answer.
What we collect
- Menu photographs, and the text on them. A photograph of a paper menu, the dish names and prices we read out of it, and the dish pictures we crop from it. This is a restaurant's factual and photographic content, not personal data about you — but it is the heart of what we hold, so we say it first. The photograph is read by an automated vision model, and dish text we do not already hold is translated by an automated language model; both run outside the country you are in, and the section on where your data is held names who operates them.
- Account details. An email address, a password we keep only as a hash, and a name if you give one. The email address is how you log in, how a forgotten password is reset, and — for a finder — how we reach you about a reward.
- Payout details, for a finder we owe money to. The account holder's name, the bank and the country, the account number, the SWIFT/BIC, and — for a finder who is a Vietnamese tax resident — the 12-digit personal identification number on their Căn cước công dân, which has replaced the individual tax code as the tax identifier. Vietnamese law treats bank account details as sensitive personal data, and we hold that number to the same standard: the account number and the identification number are encrypted before they are written down.
- A record of what you agreed to. Which version of the terms you accepted and when; whether you consented to be emailed and against exactly which words; when you gave payout details and against which disclosure. Each record keeps a fingerprint of the text that was on screen, so neither side has to remember it.
- Technical and audit records. A session record once you are logged in, and an audit line for sensitive actions on an account — what was done, when, and from which IP address — so an owner can see what happened to their business.
- Where the registration came from, at country level. When an account is created we record two things and only two: which of the countries we operate in our own lookup places the connection in, and whether it came from a datacentre or VPN range. We do not store the network address itself. Both fields are derived once, at registration, and are not updated afterwards. They exist because the terms ask you to confirm that you are physically in a country we operate in, and a confirmation nothing can be checked against is not a confirmation.
What we do not collect, and what we never do
- Reading a menu needs no account. A guest scans the code at the table and reads; we ask them for nothing.
- Dietary and allergy filters a guest taps while reading stay in that guest's own browser. The published page sends them nowhere, so they never reach us.
- An order a guest builds travels in the code the waiter scans. It does not pass through our servers, and we keep no record of what was ordered at a table.
- There are no advertising or analytics trackers on a published menu. A published menu makes one request, and it is to us, not to anybody else: it asks our own server which dishes the kitchen has marked unavailable, so a sold-out dish can be greyed out. Nothing about the reader goes with it, and if the answer does not arrive the page carries on unchanged. Our server records that request in its ordinary logs, including the address it came from, for seven days, and uses them only to run and secure the service.
- We do not sell personal data, and we do not share it for anyone else's marketing.
- We do not use your personal data for direct marketing, and we do not provide it to anybody else to use for theirs. Email from us is about your rewards, your invoices, your menu and your account. You choose whether to receive it when you register, and you can stop it at any time from your account page.
- Nothing that identifies a person is ever sent to a model. The photograph and the menu text on it are. Account data, payout details, consents, audit records, a guest's order and a guest's dietary choices are not, and never will be.
- A finder does not publish anything, so nothing about a finder is shown on a menu. We build the site, and the venue's name is the venue's.
Why we are allowed to hold it
- To do what you asked us to do. An account, a menu, a subscription and a reward calculation cannot be run without the data that describes them.
- Because the law requires it. Tax and accounting rules oblige us to keep records of what was paid, to whom and what was withheld.
- To keep the service safe. Session and audit records exist so that an account cannot be taken over quietly, and so that an owner can see who did what.
- With your explicit consent, for two things only: your payout details, and being emailed by us. Consent is asked for separately from the terms, never bundled into them, never pre-ticked, and it can be withdrawn.
Full detail — the basis for each kind of data
Performance of the contract. Account data, business and menu data, subscription and invoice data, and the calculation of a finder reward are processed because they are necessary to provide the service you asked for and to bill it.
Legal obligation. Transaction records, invoices, withholding calculations and tax identifiers are processed because tax, accounting and consumer law require us to create and keep them.
Legitimate interest in the security of the service. Session records, audit lines and the IP addresses attached to them are processed to authenticate you, to detect and investigate abuse, and to give an owner an account of what was done to their business. We do not use them to profile anyone or to advertise.
Explicit consent. Sensitive payout data is processed only on your explicit, informed and separately given consent, recorded with a timestamp and a fingerprint of the disclosure you agreed to. Marketing and service email is a second, separate consent with its own record. Neither is a condition of using the service — declining either leaves the rest of the service working — although we cannot pay a reward without payout details.
Payout details, and the consent you give
- We ask for payout details only when there is a reward to pay you, and only for that purpose.
- The bank account number and the tax identifier are sealed with AES-256-GCM encryption before they are stored, under a key that lives only in the server's environment.
- Giving them is an explicit consent. We keep the date and a fingerprint of the exact words you consented to.
- To withdraw that consent, press the button on your own account page: the payout record is destroyed there and then. Emailing hello@univmenu.com does the same thing, and we act on it within the times below.
- Withdrawing consent means we can no longer pay you: what is still pending cannot be disbursed once the details are gone.
Full detail — sensitive data, and what withdrawal does
Under the Law on Personal Data Protection No. 91/2025/QH15, financial account information is sensitive personal data, and we hold a tax identifier to the same standard because it travels with it. We collect them from finders only, only at the point where a payment is due, and only to make that payment and to meet the tax obligations attached to it. They are never used for any other purpose, never used to profile anyone, and never disclosed except to the payment and banking providers that must see them to move the money, and to a tax authority where the law compels the disclosure.
Consent is taken separately from acceptance of the terms and is recorded in its own row, with the time it was given and the SHA-256 fingerprint of the disclosure text that was displayed. That record is kept as evidence of what was agreed, and it is not editable — a change of mind is a new record, never a rewritten one.
Withdrawal is effective from the moment we act on it. It does not undo a payment already made, and it does not erase the accounting record of that payment, which tax law requires us to keep. Any reward still pending at the moment of withdrawal cannot be paid, because we no longer hold anything to pay it into.
Cookies
- UnivMenu sets five cookies. They are all strictly necessary — one keeps you logged in, three remember a choice you made on purpose, and one ties a sign-in to the browser that started it.
- There are no advertising cookies, no analytics cookies and no third-party cookies anywhere on UnivMenu — including on a published menu, which sets none at all.
- There is no cookie banner, and none is required: a banner asks consent for cookies that are not necessary, and we set none of those.
- Named here, so this notice does not depend on a link to be complete: sid keeps you logged in and expires after thirty days; lang and country remember the language and the country you chose yourself, a year each; kds_view remembers which screen a kitchen tablet is on, a year; and oidcb ties a sign-in with an outside provider to the browser that started it, and lives ten minutes. Those are all of them.
- Each one is also explained and dated in the cookie policy, which forms part of this notice.
Where your data is held, and who else touches it
- QuikForge is a Hong Kong company, and the servers that run the portal and host the menus are outside Vietnam. Data you give us is transferred across borders and processed abroad.
- Your account, your payout details, your consents and every other personal record described above sit on one machine: a virtual private server we rent from Hostinger International Ltd., physically located in Kuala Lumpur, Malaysia. That is where the portal runs and that is where the database lives.
- Published menu pages are a separate thing and hold no personal data. They are served from Hostinger shared hosting in the United Kingdom and cached on Hostinger's delivery network, which has edge servers in several countries.
- No account is created without your consent to that transfer. The box on every registration form is empty when the page loads, we never tick it for you, and a form sent without it is refused: no account is made and nothing about you is kept.
- Using the service means accepting that transfer. If you are not willing for your data to leave Vietnam, the service cannot be provided to you.
- The outside parties who touch data are: the providers that host our servers; the provider that delivers an email where we send you one; the payment and banking providers that move money to your account; and the model providers that read and translate a menu. They act on our instructions and for no purpose of their own.
- A menu photograph and the text on it are sent to OpenRouter, which routes them to the provider running the model that reads or translates them, and the result comes back to us. Account details, payout details, consent records, audit records, guest orders and guest dietary choices are never included in such a request.
Full detail — cross-border transfer and processors
Personal data collected through UnivMenu is stored and processed on servers outside the territory of Vietnam, and is accessible to QuikForge in the Hong Kong Special Administrative Region. By creating an account, by claiming a menu, by subscribing or by giving us payout details, you consent to that cross-border transfer, which is necessary for us to provide the service at all.
The infrastructure processor is named, because a transfer you are asked to consent to is not one you should have to guess the destination of. QUIKFORGE LIMITED is the controller. Hostinger International Ltd. is the processor that hosts the data, on two separate estates: a virtual private server in Kuala Lumpur, Malaysia, which runs the portal and holds the database of accounts, payout details, consents and audit records; and shared hosting in the United Kingdom, which serves the published menu pages. Menu pages are static files that contain no personal data; the hosting provider's own server logs for them record the requesting IP address in the ordinary way. Consent to the transfer to Malaysia is a condition of registration and is taken on an unticked box at the point of registration, never inferred from use of the site.
We engage processors in three categories: infrastructure and hosting providers that run our servers and serve our pages; where an email is sent to you, the provider that delivers it; payment and banking providers; and the model providers that read and translate a menu, reached through OpenRouter. Each is bound to process the data only on our instructions and to protect it to a standard no lower than the one described in this policy. We do not appoint a processor that reserves the right to use the data for its own purposes.
Extraction and translation processors. A menu photograph submitted to UnivMenu, and the dish text read from it, are transmitted to OpenRouter, Inc. of New York, United States, which routes the request to the provider operating the model concerned. The vision model reads the text and locates the dish images; the language model translates a term not already held in our dictionary. Those providers process the content solely to return the result to us. A request contains the photograph and the menu text and nothing else: no account details, no payout data, no consent or audit record, no guest order and no dietary selection made by a guest is included in one, and none of that data is disclosed to a model provider for any purpose. Dish names and descriptions are restaurant content rather than personal data about a reader; a photograph may nonetheless show a person incidentally, and it is handled to the same standard as everything else we hold.
How long we keep things
- A lapsed restaurant's site. When a subscription is not paid, the menu is replaced by a holding page. Ninety days after that, the site and its photographs are permanently deleted, and data belonging to an add-on that has been switched off is deleted on the same ninety-day clock.
- The photographs a menu was built from. We keep them while the menu exists, because they are what it is re-rendered and re-cropped from, and they are deleted with it: ninety days after a subscription lapses and the menu is gated, or when a menu nobody claimed is released and purged. A photograph a build could not use is deleted at once.
- Payout details — three months. Ninety days after an account goes quiet, the payment credentials held for it are destroyed: the bank account number, the tax identifier, and the rest of what we only ever needed in order to pay somebody. Destroyed, not hidden.
- The account itself — six months. A hundred and eighty days after an account goes quiet, we erase it: the email address, the password, the name, the contact handles, the sign-in identities and the sessions. After that it cannot be signed into, and it holds nothing that identifies a person.
- Both are done by a scheduled job. Neither waits for a request, and neither waits on us remembering.
- What survives, and only this. The accounting record the law of the market obliges us to keep — the payments made, the tax withheld, and the minimum identifying detail a tax declaration needs. It is kept for the period that law sets: ten years for an accounting document under Vietnam's Accounting Law 2015, at least seven under Hong Kong's Inland Revenue Ordinance. Where both reach the same record we keep it for the longer period and destroy it when the last of them ends. Payment records are append-only: never deleted, never edited.
- One deliberate delay. Where an account has money movements in a tax year whose annual finalisation has not yet passed, erasing the identity waits until that finalisation date — 31 March of the year after — so the full year can still be declared. That is why an erasure can fall later than six months.
- Doing it now. There is a button. Signed in, you can destroy your payout details, and you can erase your account, without writing to anybody. Email to hello@univmenu.com remains an alternative.
- Session records expire on their own and are not kept once they have.
Full detail — retention, and what the law holds back
Site content for a business whose subscription has lapsed is purged ninety days after the menu is gated; the same period applies to data held for an add-on that is no longer subscribed. That deletion is automatic and permanent — there is no copy left behind for us to restore afterwards.
The two account clocks are the ones our terms of service undertake, and they are carried out by a scheduled job rather than by hand. Ninety days of inactivity destroys the payout credentials held for an account; a hundred and eighty days erases the account itself, leaving nothing that can be signed into and nothing that identifies a person. A signed-in person can run either of them immediately from their own account page, and writing to us still works for anyone who would rather.
What an erasure does not reach is the accounting record. Rows that record something that happened — a payment, a tax withholding, an acceptance of terms, a consent given or withdrawn — are retained with the minimum identifying detail a tax declaration needs, for the ten years the Accounting Law 2015 sets for an accounting document used directly to record the books and the financial statements. Management and operational documents are kept five years. Payment rows are append-only: they are never rewritten and never removed. Where an account has money movements in a tax year whose annual finalisation — 31 March of the year after — has not yet passed, the identity erasure is held until that date so the year can be declared in full. Those records are kept for that purpose alone and are used for nothing else.
Your rights, and how to use them
- Know and access — ask what we hold about you and get a copy of it.
- Correct — fix what is wrong, from the portal for most fields, or by asking us.
- Delete — erase your account and the personal data attached to it from your own account page, or ask us to; either way the records the law makes us keep stay behind.
- Restrict or object — tell us to stop or to limit a particular processing.
- Withdraw a consent — for email and for payout details alike, from your account page; writing to us works too.
- Complain — to us first, and to the competent Vietnamese authority for personal data protection if we do not put it right.
- Write to hello@univmenu.com. We acknowledge every request within 72 hours and tell you then what we are doing and by when. We do not charge for any of this.
Full detail — how a request is handled
Send the request from the email address on the account, or tell us enough to let us verify that the account is yours. We may ask one verification question — we will not hand someone else's data to a person who merely knows their address, and we will not demand identity documents we do not need.
Every request is acknowledged within 72 hours of reaching hello@univmenu.com. Straightforward requests — access, correction, deletion, withdrawal of a consent — are completed within that acknowledgement or promptly after it; where a request is complex we tell you what is holding it up and give a date. If we refuse a request, in whole or in part, we say which part, and why, and what your next step is.
Where a right cannot be given effect because a legal retention rule overrides it, we say which records are affected and how long they will be kept. Exercising a right never costs money and never worsens the service you receive.
How we protect what we hold
- Sensitive payout details — the bank account number and the tax identifier — are encrypted at rest with AES-256-GCM, bound to the account they belong to, under a key held only in the server's environment.
- Passwords are never stored. What is stored is a salted cryptographic hash, so a password cannot be read back out of our database.
- Everything travels over an encrypted connection.
- Access to the production system is restricted to the people who operate it, and sensitive actions leave an audit line.
- Sensitive values are kept out of logs and out of anything that can be searched or sorted on them.
Changes to this policy, and how to reach us
- When this policy changes, the new version is published here with the date it was updated. A change that materially affects you is told to you directly, at the address on your account.
- Questions, requests and complaints: hello@univmenu.com · +370 665 10325 · QUIKFORGE LIMITED, Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R.
Hong Kong privacy supplement → · Vietnam privacy supplement → · Terms of service → · Cookies → · Refunds →