Privacy Policy

Last updated: March 2026

1. Who We Are

BearMenu (“we”, “us”, “our”) is a food and dining discovery platform operated from Romania. We help users find restaurants, dishes, and drinks near them. You can reach us at [email protected].

2. Data We Collect

We collect the following categories of data:

  • Account data — your name and email address when you sign in.
  • Location data — your approximate GPS position when you grant permission, used to show nearby restaurants and dishes. We do not store your location history.
  • Usage data — pages visited, searches performed, and features used, collected via Google Analytics (anonymised IP).
  • Preferences — your selected city, language, and theme, stored locally on your device.
  • Favourites — dishes and places you save, stored in our database and linked to your account.

3. How We Use Your Data

  • To provide personalised restaurant and menu recommendations.
  • To authenticate your account and keep your saved favourites.
  • To improve the app based on aggregated usage patterns.
  • To communicate important service updates (no marketing emails without consent).

4. Legal Basis (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — to provide the service you signed up for.
  • Legitimate interests — to improve the app and prevent fraud.
  • Consent — for location access and analytics (you may withdraw at any time).

5. Data Sharing

We do not sell your personal data. We share data only with:

  • Our authentication provider (for secure sign-in).
  • Google Analytics (anonymised usage statistics).
  • Our hosting infrastructure provider for app operation.

6. Cookies

We use essential cookies for authentication and your locale preference. Analytics cookies (Google Analytics) are only set after you explicitly accept via our cookie consent banner — they are never loaded without your permission. You can withdraw consent at any time by clearing your browser cookies and reloading the page. For full details, see our Cookie Policy.

7. Data Retention

We retain your account data for as long as your account is active. Usage analytics are retained for 14 months per Google Analytics defaults. You may request deletion at any time.

8. Your Rights

Under GDPR, you have the right to:

  • Access — request a copy of your personal data.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your account and data.
  • Portability — receive your data in a machine-readable format.
  • Objection — object to processing based on legitimate interests.

To exercise your rights, email us at [email protected]. We respond within 30 days.

9. Security

We use industry-standard security practices including HTTPS encryption, secure authentication, and access controls. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes by updating the date at the top of this page.

11. Contact

For privacy questions or requests, contact us at [email protected].