Legal Document

Privacy Policy

Last updated: January 29, 2025

Introduction

Magia Menu ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital menu and ordering platform.

Information We Collect

Information You Provide

Phone number, email address, name (optional)

Items ordered, preferences, special requests

Processed securely by Iyzico (we never store card details)

Automatically Collected Information

Device type, operating system, browser type

Pages visited, features used, time spent

Only when you use venue search (with your permission)

How We Use Your Information

Process and fulfill your orders

Send order status notifications

Improve our services and user experience

Provide customer support

Send promotional offers (only with your consent)

Comply with legal obligations

Data Sharing

We share your data only with:

Venues

Order details to fulfill your requests

Iyzico

Iyzico for secure payment processing

Providers

Cloud hosting, analytics (anonymized data only)

We never sell your personal data to third parties.

Your Rights (GDPR)

Under GDPR, you have the right to:

Access: Request a copy of your personal data
Rectification: Correct inaccurate data
Erasure: Request deletion of your data
Portability: Export your data in a machine-readable format
Object: Object to processing for marketing purposes
Withdraw: Withdraw consent at any time

To exercise these rights, contact us at magiamenu@gmail.com

Roles under GDPR (Controller / Processor)

Data Controller

For guest and user account data required to operate Magia Menu, Magia Menu acts as a Data Controller.

Data Processor

For venue-related processing (e.g., order fulfillment and venue operations), venues may act as Data Controllers and Magia Menu acts as a Data Processor on their behalf.

DSAR Response Time

We respond to GDPR data subject requests within 30 days. For complex requests, this period may be extended by up to 60 additional days, as permitted by GDPR.

Data Security

We protect your data using:

TLS 1.3 encryption for all data in transit
AES-256 encryption for data at rest
Role-based access controls
Regular security audits
24/7 monitoring

Cookies

We use essential cookies for:

  • Session management
  • Authentication
  • Language preferences

We do not use tracking or advertising cookies.

Children's Privacy

Our service is not directed to children under 16. We do not knowingly collect data from children.

International Transfers

Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place through Standard Contractual Clauses.

Changes to This Policy

We may update this policy periodically. We will notify you of significant changes via email or in-app notification.

Contact Us

For privacy-related inquiries:

magiamenu@gmail.com

Subject: Privacy Inquiry