Privacy Policy
Last updated: 01 SEP 2026
This Privacy Policy explains how SAEVE.APP ("Saeve", "we", "us", or "our"), operating the website and services at saeve.app, saeve.in, menu.saeve.in (together, the "Service"), collects, uses, shares and protects personal data. Saeve is offered to users internationally.
We act as the controller (a "Data Fiduciary" under Indian law) of the personal data described below. We aim to comply with applicable data protection laws, including India's Digital Personal Data Protection Act, 2023 and Rules, 2025 ("DPDP"); the EU and UK General Data Protection Regulation ("GDPR") where it applies to users in those regions; and the California Consumer Privacy Act / CPRA ("CCPA") where it applies to California residents.
By using the Service you acknowledge you have read this Policy. Where we rely on your consent, we ask for it separately and clearly.
1. Who this Policy covers
Saeve is a digital restaurant QR menu platform used by two kinds of people:
- Restaurant Owners / Admins — businesses and individuals who create an account, build menus, and manage them through our dashboard. We collect the most data from this group.
- Diners — people who scan a QR code or open a link to view a restaurant's public menu. Diners generally do not create accounts, and we collect only limited technical and analytics data from them.
This Policy applies to both groups. Where a section applies to only one, we say so.
2. Personal data we collect
From Restaurant Owners / Admins:
- Account and identity data: name, email address, phone number, business name, and password (stored only as a secure hash).
- Google sign-in data: if you sign in with Google, we receive your name, email address, email-verified status, and a Google account identifier ("sub"). We do not receive your Google password.
- Business and menu content: restaurant details, menu items, descriptions, prices, categories, images, logos and branding you upload or enter (see the "Menu content" note below).
- Uploaded menu files: photos or PDFs of physical menus you upload for our automated import feature.
- Billing data: subscription/purchase plan, currency, billing contact, and payment records. Card and payment-instrument details are handled by our payment processors and are not stored by us.
- Support and communications: messages you send us and our correspondence with you.
From Diners:
- Usage and device data: IP address, device and browser type, approximate location derived from IP, pages/menus viewed, and interaction events, collected to display menus, keep the Service secure, and produce aggregate analytics for the restaurant and for us.
Note on menu content: Menu items, prices, images and branding are the restaurant's business content, not personal data of diners. If a Restaurant Owner includes personal data of any third party in their content, the Restaurant Owner is responsible for having a lawful basis to do so, and acts as the controller for that content.
3. How we use personal data, and our legal basis
| Purpose | Legal basis (GDPR terms, where applicable) |
|---|---|
| --- | --- |
| Create and secure your account; build, host and display menus; generate QR codes | Performance of a contract; consent under DPDP |
| Run the automated menu-import feature (see Section 5) | Consent / your request to use the feature |
| Take payments and manage subscriptions and one-time purchases | Performance of a contract |
| Security, fraud prevention and service integrity | Legitimate interests; legal obligation |
| Aggregated analytics and Service improvement | Legitimate interests; consent where required |
| Marketing (Restaurant Owners only) | Consent (see Section 4) |
We use personal data only for the purposes for which it was collected, or a compatible purpose, in line with the purpose-limitation principle.
4. Marketing communications
First-party marketing. With your consent, we may use your contact information to send you updates, offers, tips and promotional messages about Saeve and its features. You give this consent through a separate opt-in when you sign up or in your account settings — it is not bundled into your acceptance of these terms.
Associated products. Separately, and only if you give distinct, specific consent, we may send you information about other products and services associated with Saeve. We will identify what these are, and if any are operated by a third party we will tell you before sharing your contact details.
Your control. You can withdraw marketing consent at any time — every marketing email contains an unsubscribe link, and you can also change your preferences in account settings or by contacting us. Withdrawing consent is as easy as giving it, and does not affect the core Service.
5. Automated menu import and third-party AI processing
When you use our menu-import feature, the photos or PDFs of menus you upload are processed using automated systems, including third-party artificial-intelligence providers (for example, OpenAI and Anthropic), solely to extract menu structure (items, categories, prices) into a draft that you review before publishing. We do not auto-publish this output.
- To run this feature, your uploaded content is transmitted to these AI providers and may be processed on their infrastructure, which may be located outside your country (see Section 8).
- We use these providers under their business/API terms and data-processing agreements. Under those terms, content submitted through their APIs is not used to train the providers' AI models by default, and we do not authorise such training. Where available, we use retention-minimising controls (such as zero-data-retention arrangements).
- We rely on these providers' contractual commitments and are not otherwise responsible for their independent conduct.
- By using the menu-import feature, you acknowledge and consent to this third-party AI processing. If you do not want your content processed this way, do not use the feature.
6. How we share personal data
We do not sell your personal data. We share it only with:
- Service providers / processors who help us run the Service — cloud hosting and infrastructure, payment processing, email delivery, and analytics. They act on our instructions and are bound to protect the data.
- AI providers — OpenAI, Anthropic and/or similar, for the menu-import feature (see Section 5).
- Authentication providers — Google, when you choose Google sign-in.
- Legal and safety — where required by law, regulation, legal process, or to protect our rights, users, or the public.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to this Policy.
7. Cookies and similar technologies
We use cookies and similar technologies to:
- keep you signed in securely (our dashboard uses secure, httpOnly authentication cookies);
- remember preferences; and
- measure and improve usage (analytics).
Public menu pages viewed by diners use only what is needed to display the menu and to produce aggregate analytics. You can control non-essential cookies through your browser or any cookie controls we provide..
8. International data transfers
Saeve operates globally, and our providers may process data in India, the United States, the European Union, and other countries. This means your personal data may be transferred to, and processed in, a country other than the one you live in, which may have different data-protection laws.
Where we transfer personal data internationally, we take steps to ensure it remains protected.
9. Your rights
Subject to applicable law, you have the right to access, correct, and erase your personal data, to withdraw consent you previously gave, and to complain to us or a regulator.
- India (DPDP): you also have the right to nominate another person to exercise your rights, and to grievance redressal via our Grievance Officer, with escalation to the Data Protection Board of India.
- EEA / UK (GDPR): you also have the rights to restrict or object to processing, to data portability, and to lodge a complaint with your local supervisory authority. Where processing is based on consent, withdrawal does not affect prior processing.
- California (CCPA/CPRA): you have the rights to know, delete, and correct personal information, and to opt out of "sale" or "sharing" — note that we do not sell personal data. We will not discriminate against you for exercising these rights.
To exercise any right, contact us using Section 12. We will respond within the timelines required by the law that applies to you.
10. Data retention
We keep personal data only as long as necessary.
When data is no longer needed, we delete or anonymise it.
11. Security, and children
We use reasonable technical and organisational measures — including hashed passwords, encrypted connections, access controls and secure hosting — to protect personal data. No system is perfectly secure, but we work to protect your data and will notify affected users and the authorities of a personal-data breach where required by law.
The Service is intended for users aged 18 or over. We do not knowingly create accounts for children. Where we become aware that we hold a child's personal data without verifiable parental consent, we will delete it.
12. Contact
For any privacy question, request, or complaint, contact:
Email: saeveapp(at)gmail(dot)com / hello(at)dexocode(dot)com
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date and, for material changes, notify Restaurant Owners by email or in-app. Continued use of the Service after changes take effect means you accept the updated Policy.