Privacy Policy
Draft v1.0 — 1 August 2026. Flagged for legal review before publishing.
Who we are
GhostMenu is operated by [Aaron’s legal name / autónomo registration details], based in Ibiza, Spain. For any question about how your information is handled, contact [privacy contact email — recommend a dedicated address like privacy@ghostmenu.[domain], not a personal inbox].
What we collect
When you use “Check yours,” we collect the restaurant name and location you provide, and the email address you give us to send your result to. If you go on to become a client, we also collect whatever’s needed to build and deliver your fix (menu content, hours, listing details you provide or that are already public).
Why we collect it
To run the check you asked for, send you the result by email, and — if there’s something worth fixing — let you know what the fix costs and how to go ahead with it. If we find nothing worth fixing, we’ll still email you to say so; we won’t sit on your details doing nothing with them.
What we don’t do
We don’t sell your information to anyone. We don’t use it for advertising unrelated to GhostMenu. We don’t share it with the restaurant we may mention as a comparison in your result — that comparison uses only publicly available information about them, never anything about you.
Legal basis for processing
We process your restaurant name, location, and email on the basis of your consent (you submitted the form) and our legitimate interest in responding to a request you made directly to us.
How long we keep it
[PLACEHOLDER — needs a real decision, not a legal-research answer: how long does a “Check yours” submission stay in the Candidate Log if the person never becomes a client? Common approach is a defined retention period, e.g. 24 months from last contact, then deletion or anonymization — but this should be a deliberate decision, not a copied number.]
Who we share it with
[Formspree / whatever form-handling service is in current use] — processes the form submission itself.
[Once the transactional email step is built — name the actual provider, e.g. Resend or Postmark] — sends you the result email.
Internal record-keeping (our own Candidate Log) — not shared outside GhostMenu.
Important note on international data transfers — needs confirming, not assumed
Several common tools in this space (form handlers, email delivery services, Airtable) are US-based companies. If any of these are used, this policy needs to name them specifically and disclose the transfer mechanism (typically EU Standard Contractual Clauses) — this is a real, specific GDPR requirement, not boilerplate, and depends on which actual vendors end up in use.
Your rights
Under GDPR, you can ask us to:
Show you what we hold about you
Correct anything that’s wrong
Delete your information
Restrict or object to how we use it
Give you a copy in a portable format
To do any of these, contact [privacy contact email]. You can also complain to Spain’s data protection authority, the AEPD (Agencia Española de Protección de Datos), at www.aepd.es, if you’re not satisfied with how we’ve handled a request.
Cookies
[PLACEHOLDER — depends on the actual hosting platform. If the site (via Claude Design/Framer or wherever it ends up hosted) sets any cookies — even basic hosting/analytics ones — this needs a real cookie disclosure, not a generic line. Needs checking against whatever the final hosting setup actually does.]
Changes to this policy
We’ll update this page if how we handle your information changes, and note the date at the top.
Last updated: [publish date].