Privacy Policy
Last updated: August 30, 2026
This Privacy Policy describes how Rumizi (“we”, “us”, “our”) collects, uses, and discloses personal information in connection with our websites, applications, and related services (the “Service”) when you use the Service in Canada.
We are committed to handling personal information in accordance with Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), where it applies, and with substantially similar provincial private-sector privacy laws where they apply (for example, in Alberta, British Columbia, and Quebec).
Most people meet Rumizi as guests: you scan a QR code at a table, browse a venue’s menu, and perhaps ask the menu assistant a question—no account needed. We designed the guest experience to work with as little personal information as possible, and this policy explains what is and is not collected along the way. Venues that use Rumizi may collect or process additional information on their own behalf; their practices are described in their own notices.
Who this policy covers
This policy applies to guests who browse menus, chat with menu assistants, or use other guest features we host; venue owners and staff who use vendor tools; visitors to our marketing sites; and individuals who contact us for support or sales.
Rumizi generally acts as a service provider for venues when processing guest personal information on their instructions; venues may be separately responsible for their own privacy compliance. Where we determine the purposes and means of processing for a given activity, we are responsible for that processing as described here.
Personal information we collect
What we collect depends on how you use the Service:
• Guests browsing a menu: standard technical data such as IP address, browser type, approximate region inferred from your IP address or browser settings (for example, language or timezone), diagnostic logs, and aggregate usage events described under “Cookies, local storage, and analytics”. Browsing a menu does not require an account, a name, an email address, or a phone number.
• Guests using the menu assistant: the messages you type or dictate, optional onboarding answers (whether it is your first visit, your region or country, and your preferred chat language), and taste signals you choose to share (for example, dishes you decline or ingredients you avoid). See “How guest features handle your information” for where each of these lives.
• Venue owners and staff: account and contact details (name, email address, phone number, business name, role), authentication and security records (session tokens, login timestamps, verification and sign-in-link flows), menu and operational content you upload (files, text, and images, which may incidentally contain personal information if present in a document), and support communications.
• Payment information: billing contact details and payment status for venue subscriptions; card details are collected directly by our payment processor and are not stored on our servers. Guests never pay Rumizi anything.
• Technical and cookies: cookie and local-storage data as described under “Cookies, local storage, and analytics”.
How guest features handle your information
Menu assistant chat. When you send a message, it travels to our servers together with the venue’s menu data and, if you completed the short onboarding, your answers, so a reply can be generated. Chat content is processed by the third-party AI model providers that power the assistant, only to provide the feature. We keep a log of assistant conversations—your message and the reply, linked to the venue but not to a name or contact details (we do not have them)—to operate, secure, and improve the assistant and to show venues how it is used. Please do not type sensitive personal information into the chat beyond the dietary preferences you choose to share.
Voice input. If you use the microphone, your audio clip is sent to our speech-to-text provider to produce a transcript, which appears in the message box for you to review and edit before sending. We do not use voice audio to identify you.
Taste preferences. Preferences you share—declined dishes, ingredients you avoid, things you like—are saved in your browser on your device and accompany your chats so suggestions can be personalized. We do not build a server-side taste profile linked to you. If you use the dislike button on a dish, we record that signal under a random device identifier that is not connected to your name or contact details, so venues see only aggregate feedback.
Ingredient explanations, pairing suggestions, and translations. These are generated by AI from menu data, not from your personal information, and are cached and reused across guests and venues.
Dietary choices can reveal sensitive things, such as allergies or religious practice. That is why the personalization signals live on your device—where you can clear them at any time by clearing your browser data for the site—and why what reaches our servers is kept to the minimum the feature needs.
Purposes for which we use personal information
We use personal information to:
• provide, maintain, secure, and improve the Service;
• authenticate users, prevent fraud and abuse, and enforce our terms;
• process venue subscriptions and payments;
• operate AI features—generating assistant replies, transcribing voice input, extracting menus from uploaded documents—using prompts and context only as needed for those features;
• keep guest features safe;
• communicate with you about the Service, including transactional messages, service announcements, and (where permitted) marketing—see “Commercial electronic messages” below;
• comply with legal obligations and respond to lawful requests from public authorities;
• analyze usage in aggregate or de-identified form to understand product performance; and
• exercise or defend legal claims.
We do not use your conversations or personal information to build advertising profiles or to train our own AI models.
Consent and legal bases
We collect, use, and disclose personal information with meaningful consent where required, including for collections that are not obvious from context. You may withdraw consent subject to legal or contractual restrictions and reasonable notice; withdrawing consent may limit your ability to use some features.
For certain processing (for example, security logging, fraud prevention, or legal compliance), we may rely on purposes that do not require consent under applicable law, provided use is reasonable and proportionate.
Where venues instruct us to process guest data on their behalf, they are responsible for obtaining any required consent from guests and for the lawfulness of their own marketing.
Service providers and disclosure
We rely on trusted service providers to run the Service: cloud hosting and content delivery, database and file storage, AI model providers that generate assistant replies and other AI content, speech-to-text transcription, payment processing, transactional email and SMS delivery, product analytics, and error monitoring. Providers may access personal information only as needed to perform services for us and are subject to contractual obligations consistent with this policy and applicable law.
We may disclose personal information if required by law, court order, or legal process, or to protect the rights, property, or safety of Rumizi, our users, or others. We may disclose information in connection with a merger, acquisition, or financing, subject to confidentiality obligations.
We do not sell personal information, and we do not share guest conversations with advertisers.
International transfers
Your personal information may be processed and stored in Canada and in other countries where we or our service providers operate. Those countries may have different data protection rules. Where we transfer personal information across borders, we take steps that are appropriate in the circumstances, such as contractual clauses or reliance on adequacy mechanisms recognized under Canadian law, to protect the information.
Retention
We retain personal information only as long as necessary for the purposes described in this policy, including to meet legal, accounting, or reporting requirements. For example: account data is kept while an account is active and for a reasonable period afterward; assistant conversation logs are kept while needed to operate, secure, and improve the assistant; backups persist for a limited additional period; and aggregated or de-identified information may be retained longer where it no longer identifies you.
Chat history, onboarding answers, and taste preferences stored in your browser stay on your device until you clear your browser data for the site.
Security
We implement reasonable physical, organizational, and technical safeguards appropriate to the sensitivity of the information we handle, including access controls, encryption in transit where standard for the Service, and monitoring. No method of transmission or storage is completely secure; you should protect your credentials and devices.
Your privacy rights in Canada
Subject to applicable exceptions, you may have the right to request access to personal information we hold about you, to ask for correction of inaccuracies, and in some circumstances to challenge our compliance with applicable privacy laws.
To exercise these rights, contact us using the contact section below. We may need to verify your identity. We will respond within the time frames required by law, which may vary by province.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (OPC) or, where applicable, a provincial privacy commissioner or ombudsman (for example, in Alberta, British Columbia, or Quebec).
Cookies, local storage, and analytics
We use cookies sparingly: to keep signed-in users authenticated, to protect the Service, and to hold the random device identifier that keeps anonymous feedback (like the dislike button) from being counted twice. That identifier is not linked to your name or contact details. We do not use third-party advertising cookies.
We use your browser’s local storage to keep guest features on your device: assistant chat history per venue, onboarding answers and chat language, taste preferences, and display settings such as light or dark theme. This data leaves your device only as described under “How guest features handle your information”.
We use a product analytics service to understand feature usage through events designed not to contain personal identifiers (venue staff signed in to vendor tools may be identified so their workspace works properly), and an error monitoring service to detect crashes and bugs. You can control cookies and clear local storage in your browser settings; blocking some may affect functionality.
Children, changes, contact, and commercial electronic messages
Public menus can be read by anyone, but accounts are not directed at children under the age of majority, and we do not knowingly collect personal information from children without appropriate parental or guardian consent. If you believe we have collected information from a child in error, contact us and we will take steps to delete it where required.
We may update this Privacy Policy from time to time. We will post the revised policy and change the “Last updated” date. For material changes, we will provide additional notice where appropriate.
For privacy questions or requests, contact us using the contact options published on our website, or through your vendor workspace if you are a venue customer.
Canada’s Anti-Spam Legislation (“CASL”) restricts commercial electronic messages without consent. We send commercial emails or texts only where permitted—typically because you have an existing relationship with us, you have expressly consented, or an exemption applies. You can unsubscribe from marketing messages using the link in those messages or by contacting us, without affecting transactional or legal notices we must send.