Early Access
XposeGo is in Early Access, and this is a live document. The tables below list everything these pages keep on your device — eight items on a venue page, one on ours — rather than a summary of them.
It is also under external legal review, and the wording may be refined. The rule in §7 is the part that matters: if we ever add something that is not strictly necessary, this notice changes before the product does.
This notice is short because we use almost no cookies, and it exists because "almost" is not "none" and the difference is worth writing down.
The one-line version: nothing anywhere in the product sets a cookie except our payment processor, on the payment page, if you choose to pay. What both kinds of page do use is your browser's own storage — which is not the same thing, is never sent to us on its own, and is listed in full below rather than summarised away.
1. What "cookies" covers here
We use browser storage rather than cookies on a venue's page. Both are ways of keeping something on your device, and US privacy law treats them the same — what is regulated is that something is stored on your equipment, not which technology stores it. So this notice covers both, and calling one of them "not a cookie" would not change a single obligation we have.
The difference that matters is not the name. A cookie is sent back to the site on every later request. Browser storage is not sent anywhere unless the page deliberately sends it, and most of what is listed below is never sent at all. Where something is sent to us, the table says so.
We treat both in this notice, because the difference that matters to you is not what the technology is called. It is whether something about you leaves your device.
2. A venue's page
A venue's public page sets no cookies at all.
No analytics cookies. No advertising cookies. No third-party script, font, tag or pixel of any kind. This is why you do not see a cookie banner when you scan a QR code — there is nothing to consent to.
We do measure how a page is used — how many people opened it, which items they looked at, which buttons they tapped — and the number that groups those into one visit is made up in your browser, kept in memory, and never written to your device. It is gone when you navigate away.
Every operator is its own website, and nothing crosses between operators
An operator's pages have their own web address on xposego.app, separate from every address of ours that anyone signs in to. Outlets that belong to one operator share that address, and share what it stores.
Anything set for one operator's address is set for that exact address and no other — never for the domain as a whole — so one operator can never see anything of another's. That rule is the one this whole section rests on, and it holds everywhere the page reaches — including the addresses it loads its photographs and sends its orders to.
The one exception: the payment page
If a venue takes payments and you choose to pay, checkout runs on a separate payment route where Stripe, our payment processor, sets cookies to detect fraud on the payment you just asked to make. Stripe acts as our service provider for that check. Those cookies are strictly necessary for security and fraud prevention, they are not used for cross-context behavioral advertising or any other advertising, and they exist only on that route. The payment cannot safely run without them.
The menu page itself still sets none.
What a venue page does keep on your device — all of it
None of these is a cookie, none is sent to us on its own, and each is readable only by that one operator's pages — your browser treats every operator as a separate website, so nothing here crosses between operators.
| What, and its name on your device | Why | Gone when |
|---|---|---|
Your language · mx-lang | So switching language does not reset while you scroll | You close the tab |
Your basket · mx-cart-<venue> | So a half-built order survives a scroll or a stumble | You close the tab |
A device key · mx-device | One random number naming this browser to this operator, so re-scanning the table or reloading mid-meal keeps your seat instead of making you a new guest. It is kept between visits, and it is sent to us when you join a table or answer a presence check. It is a persistent identifier and US privacy law counts that as personal information, so we do not claim otherwise — we keep it because it is strictly necessary to hold your seat, and for nothing else. It is not used to profile you, not used for advertising, and no other operator can read it | You clear this site's data |
Your table session · mx-ts-<code> | Which seat you are in | Your seat expires after about four hours. The note itself stays until you clear this site's data |
A presence code you were part-way through typing · mx.chal.<venue> | So a closed sheet or a reload does not lose it | When it is used or replaced. A stored code stops being usable five minutes after it was issued |
Links to orders you placed here · mx.orders | The receipt link is your only way back to an order | 24 hours — a shared table phone must not offer a stranger's lunch to the next person |
A note that a table asked your name · mx.named.<session> | So the "what should we call you?" question is asked once a sitting, not on every reload | You clear this site's data |
Your email or name, only if you ticked the box · mx.me | So you do not retype them. Off by default, because a pre-ticked box is not consent. Untick it and it is not used again | The saved copy is erased the next time you send an order after unticking, or when you clear this site's data |
The venue page also keeps a copy of itself on your device so it still opens on a bad connection. It stores the page, not you.
Clearing this site's data in your browser removes every row above, and there is nothing for us to delete on your behalf because we never had any of it.
3. XposeGo's own pages — what stays on your phone
XposeGo has no accounts. The way it remembers anything is to write it into your own browser's storage, on your device — where it stays.
| What | Why it exists | Where it is |
|---|---|---|
| What Flash offers have saved you | A running total, because it is more interesting than a number we could tell you | Your device only. Never sent to us |
The difference between this and §2's list is worth one sentence: the venue page's storage exists so ordering works; this exists so you do not need an account. Neither is sent to us on its own.
It is not a cookie, it is not sent to us with any request, and it does not identify you. It is the alternative to an account, not a quiet version of one.
Because we never had it, we cannot delete it for you — and there is nothing for us to hand over if you ask what we hold. Clearing this site's data in your browser removes it, and that is the only thing that does.
One third party loads on these pages
Our typefaces are served by Google Fonts (fonts.googleapis.com, fonts.gstatic.com) on our own pages — xposego.com, and the directory page on xposego.app. Google sets no cookie for this, but the request tells them your IP address and browser, as any request for a file does. We name it because "no third parties" would not be true, and a notice that overstates is worth less than one that does not. A venue page loads nothing from anyone.
4. What we ask your permission for
Your location is a browser permission, not storage. Your browser asks, you answer, and you can change the answer at any time in its settings.
Radar asks once, so it can measure how far each offer is from you. We never ask twice. If you say no — or never say anything — Radar still works: you pick a neighbourhood and it measures from the middle of it, and the screen says that is what it is doing. We use it for that measurement and we do not build a location history from it.
5. What we never do
- Track you across websites
- Connect you from one operator to another — nothing your browser keeps for one is readable by another
- Fingerprint your device
- Use advertising identifiers
- Load any third-party tag, pixel or SDK
- Sell or share anything — see
xposego.com/do-not-sell
6. Your choices
There is no consent banner because there is nothing here that needs one — no advertising, no analytics cookie, and nothing that follows you.
- Block or delete cookies in your browser settings. Venue pages work perfectly with every cookie blocked, because they use none. The only thing that stops working is paying on the page, which needs Stripe's fraud cookies
- Clear this site's data to remove your saved total (§3)
- Change or withdraw location permission in your browser at any time (§4)
7. If this ever changes
If we ever introduce a cookie that is not strictly necessary — anything for analytics, advertising or measurement across sites — we will update this notice and ask for your consent before setting it, and we will record that consent so you can withdraw it.
The current version is always at xposego.com/cookies.
8. Contact
privacy@menuxpose.com — and the fuller picture of what we hold is the Privacy Policy at xposego.com/privacy.
WayExpose, LLC · 1401 Pennsylvania Ave, STE 105 2394 · Wilmington, DE 19806 · United States