Dishcard stores your account, restaurant, ingredients, menus, uploaded files and activity to provide the service. The hosted service at dishcard.app uses Cloudflare for hosting, data storage, file processing and email delivery.
Account information
Dishcard uses your email address to sign you in and invite teammates. Signed-in pages use an essential session cookie. When you use an enabled sign-in or billing provider, the relevant account and transaction information is sent to that provider for the action you request. Stripe handles payment details on its hosted checkout and billing pages; Dishcard does not receive your full card number.
Guest menus
Public menus load no third-party scripts or tracking cookies. Dishcard scan reports use daily totals. A rotating one-day hash estimates unique visits; the application does not store raw IP addresses in those reports. Expired visit hashes are removed by scheduled maintenance. Cloudflare also processes request information to deliver and protect the service.
Your recipes and control
Dishcard does not use your restaurant data to train models. Menu photo recognition runs in Dishcard's processing service, without sending the document to an external AI model. You can export your data even when editing access ends. Scheduling account deletion takes public menus offline immediately and starts a 30-day restoration window. After that window, scheduled maintenance purges active account records and removes unreferenced uploaded images. Cached PDFs expire seven days after storage; stored email attachments and backups expire after 30 days. Copies already in those storage areas may remain until their own expiry dates. Printed copies, downloaded exports and messages already delivered are not removed by account deletion.
Service providers
Provider handling is described in the Cloudflare privacy policy and Stripe privacy policy. Payment providers may retain records for their own legal and operational obligations.