OpenFood For restaurants

Privacy Policy

Last updated: 2026-09-07

The short version

  • No cookies, no tag managers, no advertising, no third-party analytics.
  • We count how often things happen — pages opened, filters used, menus published — on our own servers, with no cookie and no identifier of any kind. We cannot tell how many people that is, and we cannot tell it was you.
  • We do not log IP addresses and keep no request logs.
  • We do not locate you by IP. The map opens using the time zone your browser already reports — no permission prompt, no third party.
  • Webfonts are served from our own servers, so reading a menu does not hand your IP address to Google.
  • An ordinary order is never stored anywhere. It lives in the page address itself and never reaches a server.
  • You can read every menu on this site without an account and without being identified.

Who we are

This site is operated by Eden Yefet, Israel, as a personal, non-commercial project. For anything about privacy, write to privacy@openfood.edeny.dev.

What we collect, and why

Diners without an account: nothing. Your dietary filters, language, currency and your order are kept in your own browser and are never sent to us.

Diners with an account: the user id, email address, display name and photo Google gives us when you sign in; your dietary preferences (see below); and up to 30 saved orders. The lawful basis is performing the service you asked for.

Contributors: your display name is shown next to accepted contributions. We keep a history of your contributions and a standing derived from it, and reviewers may attach an internal note about a contributor. Those notes are not shown in the interface, but they are disclosed to you if you ask to see your data — we do not keep hidden records about people. The lawful basis is our legitimate interest in moderating a community-edited site.

Restaurant owners: when you claim a listing we collect your email, name, phone number and any message you write, in order to check the claim is genuine.

"Order together": this feature creates an anonymous account with our identity provider so several phones can build one order. It is created only if you use the feature, and the shared order document deletes itself within 24–48 hours.

Allergens are health data

The allergens you choose to avoid, and preferences such as the pregnancy filter, are information about your health. Under EU law that is a special category of personal data and gets stricter treatment.

It does not leave your device unless you are signed in and have chosen to sync preferences across devices. Filtering a menu while signed out happens entirely in your browser. If you are signed in, the lawful basis is your explicit consent, and you can withdraw it at any time by turning sync off or deleting your account.

Who else sees it

Data is stored in Google Cloud Firestore in the European Union (eur3), and the server runs in europe-west4. Beyond that:

  • Anthropic (US) — when a restaurant owner or contributor uploads a menu photo or PDF to be read automatically, that file is sent there. Restaurant names are sent to be transliterated. Both happen only when someone asks for them.
  • Google Cloud Translation (US) — menu text, to translate it.
  • CARTO — map tiles load from their servers, so your IP address and the part of the map you are looking at reach them. We send no referrer, so they are not told which page you are on.
  • Google Places — only in the restaurant dashboard, while an owner types their own business address.
  • Google — for signing in, and only on account pages. Public pages load no Google code at all.
  • Amazon Web Services (Ireland) — we send service emails through Amazon SES, in the eu-west-1 region. Your address and the contents of each message pass through it. Nothing about our email leaves the EU.

The European Commission recognises Israel as providing an adequate level of data protection, so transfers from the EU to us need no additional safeguard.

How we contact you

We send email about things you did, or about decisions made on something you sent us. We send no newsletters, no marketing, and nothing you did not ask for by using the site. To do that we keep your address, the language you read in, and which categories you have switched off.

  • About your account — a welcome when you first sign in, and the two receipts about deleting your account. The receipts cannot be switched off: they are the record that you asked and that we acted, which is a legal obligation rather than a notification.
  • About your suggestions — that we received one, and what a reviewer decided, including their reason. Our legitimate interest in running a community-edited site, and you can switch it off.
  • About a restaurant you claimed or help run — the outcome of a claim, suggestions waiting for you, and someone joining your team. Also our legitimate interest, and also switchable.

Everything except the deletion receipts can be turned off, per category, on your profile. Every message we send also carries a List-Unsubscribe header, so a mail client that offers its own unsubscribe button will work.

Our email contains no tracking pixel and no rewritten links. The one image in it is our logo, loaded from this site at an address identical for every recipient and carrying no identifier — so it cannot tell us who opened a message, and we have deliberately not turned on the open- and click-tracking our mail provider offers.

How long we keep it

  • Shared orders — deleted automatically within 24–48 hours.
  • Ordinary orders — never stored by us at all.
  • Account and preferences — until you delete them, which you can do yourself.
  • Decided contributions — kept, because community standing is computed from them. If you delete your account they are disconnected from your identity rather than removed, so the moderation history survives and you do not.
  • Ownership claims — deleted automatically a year after they are made.
  • Counters recording how many menu scans you used on a given day — deleted automatically after 30 days.
  • Your email address and which messages you want — until you delete your account, which removes them with it.
  • A record that a particular message was sent to you, and when — kept 90 days, so we can answer a question about a message you did or did not receive. It holds a one-way fingerprint of the address rather than the address itself.
  • The record that you asked us to delete your account, and that we did — kept for a year, because we have to be able to show the request was honoured.

Your rights

You have the right to see the data we hold about you, correct it, delete it, restrict or object to how we use it, and receive it in a portable format. Write to privacy@openfood.edeny.dev and we will deal with it within 30 days.

Two of those you can do yourself, on your profile page, without asking anyone. Download my data builds a file of everything we hold about you, in your browser — it is not sent anywhere and we are not told you did it. Delete my account removes your preferences, saved orders, ownership claims and any suggestion still awaiting review, immediately.

Two things survive that deletion, deliberately. Suggestions a reviewer already decided on are kept but disconnected from you, because the standing of every other contributor is worked out from that history — the record stays, your name does not. Photos that were approved and are now part of a restaurant's public menu also stay, but are moved so their address no longer identifies you. A few of these steps need a person, and happen within 30 days; we keep a dated record that the request was made and finished, because we have to be able to show it was.

If you own a restaurant, the site will ask you to release or delete it first. Deleting your account will not do it for you: a published restaurant is a public page other people rely on, and it should not disappear as a side effect.

If you are in the EU and unhappy with how we handle it, you can complain to the data protection authority in your country. In Israel, that is the Privacy Protection Authority.

Storage in your browser

We use no cookies. We keep twelve values in your browser's local storage, all of them serving the site itself: your theme, language and currency choices, your dietary filters, your current order and order history, recently visited places, where you last left the map, whether you are signed in, and two sign-in tokens. The anonymous one behind "order together" expires 30 days after it is created and is then discarded — a shared order deletes itself within 48 hours, so nothing needs that identity for longer. These are necessary for features you asked for, which is why the site does not ask for consent to them. None of them is a tracker, and none is shared.

A thirteenth value exists only if you turn usage counting off below. Opting out is the only thing on this site that writes a preference about being measured; opting back in removes it again, so somebody who never opted out and somebody who changed their mind leave exactly the same trace, which is none.

Usage measurement

We count how often things happen on this site: how many pages of a given kind were opened, how often an allergen filter was used, how many menus were published. The counting happens on our own servers. Nothing is sent to Google Analytics or to any other company, and no third party is involved at any point.

What is stored is a number per day per kind of event, and nothing else. There is no cookie, no device identifier, no session identifier and no fingerprint, and we do not keep your IP address, the page you arrived from, or what browser you use. Because there is no identifier, we cannot tell how many people visited, how often one person came back, or in what order anybody did anything. That is a real loss and we accept it deliberately: the alternative is keeping a record of behaviour, and then having one to lose.

This needs no consent banner under the EU's ePrivacy rules, because consent there attaches to storing or reading information on your device, and this does neither. You can still switch it off, and we honour the Global Privacy Control and Do Not Track signals if your browser sends them.

Counting is on in this browser.

Children

This service is not intended for children under 16, and we do not knowingly collect data from them.

Changes

We will update this page as the service changes. The date at the top says when it last did.