Vulu Menu

Privacy notice

Version: 9 September 2026.

Who operates Vulu Menu

VULU RAZI, Norway, operates Vulu Menu.

Organisation number: 921080840.

Business address: Munkestranda 6, 6076 Moltustranda, Norway.

Privacy contact: [email protected].

Account and menu information

We store staff names, email addresses, password hashes, account sessions, business and venue details, access roles, menu content and uploaded images. Published menu content and selected images are visible to anyone with the menu link.

We use the owner’s account and contact information to provide the requested service and administer our business relationship. This is necessary to perform our agreement with the account holder. For staff acting for a business, our basis is our legitimate interest in providing and administering that service. Security records, rate limits and audit events protect accounts and investigate misuse on the same legitimate-interest basis. We process information required by law to meet the relevant legal obligation. Account information is required to manage a menu; guests can read published menus without registering.

Your business controls which staff have workspace access and what it publishes. Where we process staff details or personal information in workspace content on its behalf, that business is the controller and we act as its processor under the data-processing terms in our terms of use. Do not publish private information about guests or staff in a menu.

Guests, cookies and analytics

Guests do not need an account. Authentication and display-language preferences use functional cookies. Anonymous analytics records page views, visible time and country totals through VULU Bid. Analytics does not use cookies, browser storage, fingerprinting or persistent visitor identifiers. A temporary identifier exists only in page memory.

Network providers process IP addresses to deliver and secure requests. Analytics uses a short-lived, salted rate-limit value; raw IP addresses are not included in the analytics collector payload.

Service providers

Railway hosts the application and PostgreSQL database. Cloudflare provides delivery, security and media storage. VULU Bid receives anonymous usage events. When email recovery is enabled, Resend receives the recipient address and reset email. Our support mailbox uses Google Gmail and receives the information you send to support. We do not use these messages for marketing.

The application and database are hosted in Amsterdam. Delivery, security, support and email providers use international infrastructure, including processing outside the European Economic Area. Applicable provider data-processing agreements describe their subprocessors and transfer safeguards, including EU Standard Contractual Clauses where required. Contact us to request information about the safeguards that apply to your data. Provider agreements are available from Railway, Cloudflare, Resend and Google.

Retention and deletion

Account and menu information is kept while it is needed to provide your workspace. Removing a staff member’s access does not delete an account they still use with another business. Contact the privacy address to close a workspace or request account erasure. We verify the request and normally complete it within one month, explaining any lawful extension or specific information we must retain.

Sessions expire after 12 hours unless renewed. Setup links expire after 24 hours and recovery links after one hour. The hourly cleanup removes expired sessions and links and rate-limit records older than 24 hours. Imported source files expire after one day; AI import is currently disabled. Published and draft menu images remain until removed or the workspace is closed, including older uploaded logos removed during workspace erasure.

Audit history is kept while needed to administer and secure the workspace and is included in the assessment of an erasure request. Support correspondence is kept while resolving the request and any related complaint or legal claim, then deleted when no longer needed. Deleted data may remain in restricted recovery backups until those backups expire; it is not used to operate the service and erasure requests are reapplied if a backup is restored. Recovery-email content and delivery records are retained by Resend for up to 30 days under the standard plan. We do not sell personal information or make decisions about you using automated profiling.

Your rights

Depending on the applicable law, you can request access, correction, deletion, restriction or portability of your personal data, and object to processing based on legitimate interests. You can complain to your local data protection authority, including Datatilsynet in Norway. Contact us using the privacy address above. We may request only the information reasonably needed to verify your identity. Never send your password or password-reset link.