Cookie Policy
Effective: June 23, 2026 Last updated: June 23, 2026
This Policy explains how Muzan uses cookies and similar technologies (storing or accessing information on your device), what each category is for, and how you can control them. Our approach is to keep their use to the minimum needed to run the Service.
1. What cookies and similar technologies are
Cookies are small files placed on your device. “Similar technologies” include local storage, pixels, and device identifiers that store or read information on your device. Under EU/UK electronic-privacy law (ePrivacy / PECR), we must inform you about them and, except where they are strictly necessary, obtain your consent before using them.
2. Our approach
We keep cookies to the minimum needed to run the Service. Beyond strictly necessary cookies (and cookies set by our payment processor during checkout for fraud prevention), our marketing website uses Google Analytics for aggregate usage measurement. Analytics runs only after you consent: it is disabled by default (Google Consent Mode set to “denied”) and no analytics cookies are set unless you accept. We do not use advertising cookies, and the Public Menu does not set tracking cookies. You can change or withdraw your choice at any time via “Cookie settings” in the website footer.
3. Cookies we use
Strictly necessary — authentication & session
First-party cookies set by our authentication provider (Supabase) to sign you in to the Dashboard and keep your session secure. These are essential and exempt from consent. They typically last for the session or a short, renewable period and cannot be switched off without breaking sign-in.
Strictly necessary — security & preferences
Cookies or local storage used for security (for example, to protect forms) and to remember basic preferences such as language. These are essential to provide the features you request.
Payment fraud prevention (Stripe)
On pages where you enter payment details, our processor Stripe sets cookies to detect and prevent fraud. These support a service you request (secure payment) and are governed by Stripe’s own policies.
4. Analytics (anonymous)
Our public menu analytics (for example, counts of scans and views) are aggregated and anonymous and are derived from server-side request data, not from advertising or cross-site tracking cookies; they do not identify individual diners. Separately, our marketing website uses Google Analytics 4 to measure aggregate usage. It is governed by Google Consent Mode v2 and is denied by default, so it sets no analytics cookies and sends no measurement until you consent through our cookie banner. You can withdraw consent at any time via “Cookie settings” in the footer.
5. The Public Menu
The menu diners open by scanning the QR sets no tracking or advertising cookies. Any cookies there are limited to what is strictly necessary to display the menu.
6. Third-party resources and CDNs
Our pages load web fonts and assets from content-delivery networks (for example, Google Fonts), which requires a connection to those providers and may expose your IP address to them as a technical necessity of delivering the content. We do not use these resources to profile you. Third-party providers (such as Stripe) process data under their own privacy and cookie policies.
7. Consent and your choices
Strictly necessary cookies do not require consent. Where we use non-essential cookies that require consent, we will present a consent mechanism and you will be able to accept, reject, or change your choice. You can also withdraw consent at any time through that mechanism or your browser settings.
8. Managing cookies in your browser
Most browsers let you view, block, or delete cookies in their settings (commonly under “Privacy” or “Cookies”). Blocking strictly necessary cookies may prevent you from signing in or using parts of the Dashboard. For guidance, see your browser’s help pages (Chrome, Safari, Firefox, Edge).
9. Changes and contact
We will update this Policy when our use of these technologies changes and publish the current version with its date. Questions: privacy@muzan.app.