Legal
Privacy Policy
Last updated: 24/07/2026 · Effective: 24/07/2026
This Privacy Policy explains what personal data reach.menu ("reach.menu", "we", "us") collects, why, and what rights you have — whether you're an account holder, a card owner's visitor, or someone whose contact details a card owner has captured through the Service.
Who we are
reach.menu is operated by reach.menu (the "Company"). For most personal data described here, the Company acts as the data controller — we decide why and how it's processed.
One category is different: when a visitor submits their name, email, phone, or a message through a card's Connect form, the card owner is the data controller for that captured contact — they decide whether to follow up, how long to keep it, and how to use it. reach.menu is a processor for that data: we store and transmit it on the card owner's behalf and instructions, and we don't use it for our own purposes.
What we collect & why
We collect only what each feature needs, and no more:
- Account & authentication. reach.menu is passwordless: you sign in with an email magic link, or via Google, LinkedIn, or Apple sign-in. We store your email address and, for social sign-in, a provider identity (an opaque account identifier from that provider) — never a password. Legal basis: performance of a contract (Art. 6(1)(b)) — we need this to create and secure your account.
- Your card content. The name, title, company, bio, photo, and links you add to your card, plus your chosen handle (reach.menu/yourhandle). This is public by design — it's what your card shows. Legal basis: performance of a contract (Art. 6(1)(b)) and, where you add optional details, your consent (Art. 6(1)(a)).
- Contact capture. When a visitor to your card fills in the "Connect" form (name, email, phone, message), that data is stored as a Connection in the card owner's account. Legal basis: the visitor's explicit consent (Art. 6(1)(a)) — see "Consent & capture" below. reach.menu processes this only as instructed by the card owner (the controller).
- Analytics. Aggregate, cookieless counts of events — card views, link clicks, vCard downloads, wallet adds — tied to a card, not to a visitor. No visitor identifiers, no IP addresses, no tracking cookie are stored. Legal basis: because this data isn't personal data about an identifiable visitor, no consent is required; to the extent any element were considered personal data, our basis would be legitimate interest (Art. 6(1)(f)) in understanding how cards perform.
- Wallet passes. If you add a card to Apple Wallet or Google Wallet, the pass contains that card's own public fields (name, title, company, links, QR code to the public card URL, and colors) — the same information already on the card. We also store a device/pass registration so the pass can update itself when the card changes. Legal basis: performance of a contract (Art. 6(1)(b)) — provisioning the Wallet integration you asked for.
Consent & capture
Contact capture is the one place a third party's personal data enters the Service without them having an account, so we treat it carefully:
- The Connect form's consent checkbox is unticked by default and describes, in plain language, who the controller is (the card owner) and what the data will be used for (follow-up contact). The form cannot be submitted without checking it — legal basis Art. 6(1)(a) GDPR.
- Proof of consent is logged alongside every captured Connection: the exact wording version shown at the time (
consent_wording_version), the timestamp (consent_at), and the submitting IP address (captured_ip) — so the basis for processing can be demonstrated later.
- Withdrawal is honored by deletion: the card owner can permanently delete a Connection from their dashboard at any time, and a data subject can request withdrawal by contacting the card owner (or reach.menu, who will relay the request) at [email protected].
Cookies
Public card pages (reach.menu/handle, the Connect form, wallet links) are entirely cookieless. Only signed-in account holders receive cookies:
- Session cookie — keeps you signed in to your dashboard.
HttpOnly, Secure, SameSite=Lax.
- CSRF cookie — a short-lived, pre-authentication cookie that protects sign-in and OAuth flows from cross-site request forgery.
HttpOnly, Secure, SameSite=Lax.
Both are strictly necessary to operate the Service and carry no advertising or tracking purpose, so no cookie-consent banner is shown. We use no third-party advertising, analytics, or tracking cookies anywhere on the Service.
Sharing
We do not sell personal data, and we run no advertising. We share personal data only with:
- The card owner, for any Connection captured through their card (this is the point of the feature).
- Processors who run infrastructure on our behalf — e.g. our hosting provider, our transactional email provider (magic links), and, only when you choose to use them, Google, LinkedIn, Apple (sign-in) and Apple/Google (Wallet passes). Each is bound to process data only per our instructions.
- Authorities, if legally required of us.
Retention
- Account data is kept while your account is active and deleted when you delete your account (see "Your rights").
- Magic-link tokens are single-use and expire quickly (minutes), then are no longer valid.
- Captured Connections are retained until the card owner deletes them, or until the owning account is deleted — the card owner, as controller, decides retention.
- Analytics events are aggregate and contain no personal data, so they're retained for as long as needed for product measurement.
Your rights
If GDPR (or equivalent law) applies to you, you have the right to:
- Access your personal data — account holders can export their data from account settings.
- Erasure — delete your account and associated data from account settings; this also removes your cards, connections, and analytics tied to them.
- Rectification — correct inaccurate data by editing your account or card at any time.
- Portability — receive your data in a portable format via the same export.
- Withdraw consent — at any time, without affecting processing carried out before withdrawal.
- Complain to your local data protection supervisory authority if you believe your rights have been infringed.
If you submitted your details through someone's card's Connect form, the card owner is the controller for that data; contact them directly, or reach us at [email protected] and we'll relay your request as processor.
International transfers
Where personal data is transferred outside the European Economic Area or UK, we rely on appropriate safeguards recognized under GDPR (such as Standard Contractual Clauses) to protect it.
Changes
We may update this Privacy Policy from time to time. Material changes will be reflected here with an updated "Last updated" date; continued use of the Service after a change constitutes acceptance of the revised policy.
Contact
Questions or requests about this policy or your personal data: