Back to Morcel

Privacy Policy

How Morcel collects, uses, shares and protects personal information when you visit our website, create an account, or browse a restaurant's Morcel menu.

Last updated: August 5, 2026

01Who we are

Morcel ("Morcel", "we", "us") provides software that turns restaurant menus into mobile-first, social-style browsing experiences accessed through QR codes. This policy covers www.morcel.app, the Morcel application, and the guest-facing menus we host on behalf of restaurants.

We act in two different roles, and it matters for your rights: for our own website visitors and account holders we are the data controller. For the menu content and guest interactions belonging to a restaurant that uses Morcel, that restaurant is the controller and we are its processor β€” we handle that data on their instructions. If you are a diner and want data removed from a specific restaurant's menu, contact the restaurant first; we will help them action it.

Questions about anything here can go to admin@commissary.app.

02Information we collect

We collect only what we need to run the service:

  • Account information β€” name, email address, password (stored hashed), restaurant name, business address, phone number, and preferred language.
  • Menu and business content β€” everything you upload to build your menu: item names, descriptions, prices, categories, photos, and branding assets.
  • Billing information β€” plan, billing cycle, invoices, and the last four digits and expiry of your card. Full card numbers are entered directly with our payment processor and never reach Morcel's servers.
  • Guest interaction data β€” when a diner scans a QR code we record non-identifying interactions such as which items were viewed, scroll and swipe activity, the menu template used, and coarse location derived from IP (city or region level). Diners do not need an account to browse a menu.
  • Device and log data β€” IP address, browser type and version, operating system, referring page, pages viewed, and timestamps. Logs are used for security, debugging and abuse prevention.
  • Cookies and similar technologies β€” see our Cookie Policy for the full list and how to control them.
  • Communications β€” messages you send us by email or through support channels, including any attachments.

We do not intentionally collect special category data (health, biometrics, religious or political beliefs, precise geolocation) and ask that you do not submit it through menu content or support messages.

03How we use information

  • Create and administer your account, and authenticate you when you sign in.
  • Host, render and deliver your menus, generate QR codes, and serve them in your guests' preferred language.
  • Process payments, issue invoices, and manage renewals, upgrades, downgrades and cancellations.
  • Provide support and respond to your questions.
  • Produce aggregated analytics for you β€” such as which items get the most attention β€” so you can improve your menu.
  • Monitor, secure and improve the service, including diagnosing faults and preventing fraud and abuse.
  • Send service and transactional messages (billing notices, security alerts, material changes to these terms). These are not marketing and you cannot opt out of them while you hold an account.
  • Send product news and marketing where we have your consent or a legitimate interest in doing so. Every marketing email contains a one-click unsubscribe link.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, and we do not use your menu content or guest data to train third-party advertising models.

05How we share information

We share personal information only in the situations below, and only to the extent needed:

  • Service providers (processors) who work on our behalf under contract β€” cloud hosting and content delivery, our payment processor, transactional email delivery, error monitoring, product analytics, and customer support tooling.
  • Analytics and advertising partners β€” Google (Google Analytics 4 and Google Tag Manager) and Meta (Meta Pixel), used to measure how our marketing site performs. See section 06.
  • Your restaurant β€” if you interact with a menu, the restaurant that owns it can see the aggregated interaction data for that menu.
  • Professional advisers β€” accountants, auditors and lawyers, bound by confidentiality.
  • Legal and safety β€” where we are legally required to disclose, or where disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers β€” if Morcel is involved in a merger, acquisition, financing or sale of assets, information may transfer as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy.

06Analytics and advertising tools

Our marketing site loads the following third-party tools. Each one is operated by the provider named, under that provider's own privacy policy:

ToolPurposeProvider policy
Google Analytics 4Aggregated traffic and engagement measurementGoogle Privacy Policy
Google Tag ManagerLoads and manages the tags listed hereGoogle Privacy Policy
Meta PixelMeasures the performance of our ads and website conversionsMeta Privacy Policy
Vercel AnalyticsCookie-less page and performance measurementVercel Privacy Policy

You can block these at the browser level or use the opt-out tools described in our Cookie Policy.

07International transfers

Morcel is delivered from globally distributed infrastructure, so personal information may be processed in countries other than your own, including the United States. Where we transfer data out of the UK or EEA, we rely on an adequacy decision where one exists, or on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary technical measures such as encryption in transit and at rest.

You can request a copy of the transfer mechanism we rely on for a specific vendor by emailing admin@commissary.app.

08How long we keep information

DataRetention period
Account and menu contentFor the life of your account, then deleted within 90 days of closure
Billing and tax recordsUp to 7 years, as required by tax law
Server and security logsUp to 12 months
Guest interaction analyticsUp to 26 months, in aggregated form
Support correspondenceUp to 24 months after the ticket is closed
Marketing contact recordsUntil you unsubscribe, plus a suppression record so we don't email you again

Backups are rotated on a rolling schedule, so deleted data may persist in encrypted backups for a short period after removal from live systems.

09Security

We use encryption in transit (HTTPS/TLS) and at rest, hashed passwords, least-privilege access controls for staff, and audit logging on administrative actions. Payment card data is handled entirely by a PCI-DSS compliant payment processor.

No system is perfectly secure. You are responsible for keeping your credentials confidential and for the actions of anyone you give access to your account. If you believe your account has been compromised, or you have found a vulnerability, email us immediately at admin@commissary.app.

10Your rights and choices

Depending on where you live, you may have some or all of the following rights:

  • Access β€” get a copy of the personal information we hold about you.
  • Correction β€” have inaccurate or incomplete information fixed.
  • Deletion β€” ask us to delete personal information we no longer have a lawful reason to keep.
  • Portability β€” receive your information in a structured, machine-readable format.
  • Restriction and objection β€” ask us to pause processing, or object to processing based on legitimate interests, including direct marketing.
  • Withdraw consent β€” where we rely on consent, withdraw it at any time without affecting processing that already happened.
  • Non-discrimination β€” we will not degrade the service you receive because you exercised a privacy right.
  • Opt out of sale or sharing β€” we do not sell personal information or share it for cross-context behavioural advertising as those terms are defined under the CPRA, so there is nothing to opt out of. If that ever changes, we will provide a clear opt-out mechanism first.

To exercise any of these, email admin@commissary.app from the address on your account. We respond within 30 days (or 45 days for CPRA requests, extendable once where permitted). We may need to verify your identity before acting. You can use an authorised agent, in which case we will ask for proof of authorisation.

If you are in the UK or EEA and are unhappy with how we handled your request, you can complain to your local supervisory authority β€” in the UK, the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to resolve it with you first.

11Children's privacy

Morcel is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

12Changes to this policy

We may update this policy as the service and the law evolve. The "last updated" date at the top of this page always reflects the current version. For changes that materially affect your rights, we will notify account holders by email or an in-product notice at least 14 days before they take effect.

13Contact us

Privacy questions, requests and complaints: admin@commissary.app. Please put "Privacy" in the subject line so it reaches the right person quickly.

Questions?

Email us at admin@commissary.app and we'll get back to you.