Privacy Policy
Effective: June 23, 2026 Last updated: June 23, 2026
This Policy explains how Dizblanc LLC (“we”, “us”) collects, uses, shares, and protects personal data in connection with Muzan. It covers two surfaces: the management dashboard used by restaurants and their staff (the “Dashboard”), and the public digital menu that diners open by scanning a QR code (the “Public Menu”).
1. Who we are and our role
Dizblanc LLC is a Wyoming limited liability company. For personal data of restaurant accounts and their staff, we are the data controller. For personal data that may be associated with a restaurant’s diners, the restaurant is the controller and we act only as its processor under our Data Processing Agreement (DPA).
Privacy contact: privacy@muzan.app.
2. Personal data we collect (Dashboard)
When you create and use an account, we collect:
- Identity and contact data — name, email address, restaurant or business name, and (optionally) phone or role.
- Account and profile data — credentials (stored hashed by our authentication provider), team members, and role assignments.
- Billing data — subscription plan, transaction history, and partial payment details; full card numbers are handled by Stripe and are not stored by us.
- Content — menus, dishes, descriptions, prices, images, and configuration you upload (which may include staff details if you choose to add them).
- Usage and device data — log data, IP address, browser/device type, timestamps, and actions taken in the Dashboard, used for security and to operate and improve the Service.
3. Public Menu data (diners)
The Public Menu is designed not to collect diners’ personal data. We generate only anonymous, aggregate analytics (for example, counts of scans and views) that do not identify individuals, and we do not set tracking or advertising cookies on it.
If we ever introduced a feature that processed diners’ personal data, we would do so only on the relevant restaurant’s instructions as its processor, and the restaurant’s own privacy notice would govern that processing.
4. How we collect data
- Directly from you — when you register, configure your menus, contact us, or subscribe.
- Automatically — through log and usage data generated as you use the Dashboard.
- From our providers — for example, billing status and events from Stripe.
5. Purposes and legal bases (GDPR / UK GDPR)
- Provide the Service and manage your account — performance of a contract (Art. 6(1)(b)).
- Process payments and issue invoices — performance of a contract and legal obligation (Art. 6(1)(b),(c)).
- Secure the Service and prevent fraud or abuse, and improve and develop features — legitimate interests (Art. 6(1)(f)).
- Send service and transactional messages — performance of a contract / legitimate interests.
- Send marketing messages, where we do — consent, where required (Art. 6(1)(a)); you can withdraw it at any time.
- Comply with legal, tax, and accounting obligations — legal obligation (Art. 6(1)(c)).
- Establish, exercise, or defend legal claims — legitimate interests.
6. Marketing communications
Where we send marketing emails, we do so in line with applicable law and you can opt out at any time using the unsubscribe link or by contacting us. Opting out of marketing does not stop essential service messages (for example, billing or security notices).
7. Who we share data with
We share personal data with the service providers (processors/sub-processors) that help us run the Service — including payment processing, hosting, storage, authentication, and email delivery — listed on our Subprocessors page. We may also disclose data to comply with law or to protect our rights, and in connection with a merger, acquisition, or sale of assets. We do not sell personal data.
8. International transfers
We are based in the United States and use providers that may process data in the USA and other countries. Where we transfer personal data from the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards, principally the Standard Contractual Clauses (and the UK Addendum), together with supplementary measures where needed. You can request more information using the privacy contact above.
9. Retention
We keep personal data while your account is active. After your account is closed or the Service ends, we delete or anonymize Account and Content data within 90 days, except where we must keep certain records longer — for example, billing, tax, and accounting records retained for the period required by law, and information needed to establish, exercise, or defend legal claims. Backups are overwritten on a rolling cycle.
10. Your rights (GDPR / UK GDPR)
Subject to applicable law, you may request access to your personal data and its rectification or erasure, restrict or object to processing, request portability, and withdraw consent where processing is based on it. You also have the right to lodge a complaint with your supervisory authority (in the UK, the ICO; in the EU, your national authority).
To exercise your rights, contact privacy@muzan.app; we will respond within the time limits required by law. If your data is processed by a restaurant through Muzan, please contact that restaurant as the controller — we will assist it as its processor.
11. CCPA/CPRA notice (California residents)
In the past 12 months we may have collected the following categories of personal information from account holders: identifiers (such as name and email); commercial information (such as subscription and transaction records); and internet or network activity (such as log and usage data). We collect these for the business purposes described above and do not collect sensitive personal information for the purpose of inferring characteristics.
We do not sell and do not “share” (for cross-context behavioral advertising) personal information, so we do not offer a “Do Not Sell or Share My Personal Information” link. California residents may request to know, access, correct, or delete personal information, and we will not discriminate against you for exercising these rights. To make a request, contact us at the privacy address above.
12. Security
We use reasonable technical and organizational measures to protect personal data, including encryption in transit, access controls, and reputable infrastructure providers. No method of transmission or storage is completely secure, but we work to reduce risk and respond to incidents. See our Security page for more.
13. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
14. Third-party links
The Service and our website may link to third-party sites or services that we do not control. Their privacy practices are governed by their own policies.
15. Changes and contact
We may update this Policy and will publish the current version with its date; we will give notice of material changes by email or in the Dashboard. Questions or requests: privacy@muzan.app.