Early Access
XposeGo is in Early Access, and this is a live document. It describes what we actually collect today. §4 is where that is easiest to check: it lists what a venue page keeps on your phone, item by item, instead of summarising it away.
It is also under external legal review, and the wording may be refined before general availability. The date and version above always identify the text in force, and a change that affects what we collect or who sees it is published here before it takes effect (§15).
If you think this page is wrong about us, tell us —
privacy@menuxpose.com. That is a correction we want.
Most people who read this page gave us nothing at all, and this policy exists to say exactly that, verifiably. If you opened a menu, looked at it and closed the tab, we do not know who you are, we did not put anything on your phone that identifies you, and there is nothing here for you to opt out of.
Three things change that, and only three: you pay for an order, you book a table, or you order through a delivery platform — and none of the three is live yet. Each has its own section, each says who will hold what from the day it is, and today all three hold nothing.
1. Who you are dealing with
Two different companies are involved in almost everything on these pages, and knowing which is which is the whole map.
| The venue | The restaurant, café or bar whose page you are on. They are a business in their own right. They set the menu and the prices, they cook the food, they take the booking, they take the money for the order, and they decide what happens to the details you give them |
| Us — WayExpose, LLC | We make the software the venue publishes its page with (MenuXpose), and the service you may have found them through (XposeGo) |
What follows from that split, and it is the most important sentence on this page: for the details you hand a venue — your name on a booking, your email on a receipt — the venue decides what is done with them and we act on the venue's instructions. In the language United States privacy laws use, the venue is the business and we are its service provider (elsewhere the same split is called controller and processor).
Two exceptions, where there is no venue and it is simply us:
- What you do on
xposego.comitself — Radar and the running total on your phone (§9) - The security and reliability of the software — keeping it up, keeping it safe, and stopping abuse
This does not mean nobody is responsible. It means you may get a faster answer from the venue on their records, and a faster answer from us on ours — and §16 says how to reach either. If you write to us about something a venue holds, we will route it rather than send you away.
2. The short version
| If you… | We hold |
|---|---|
| Looked at a menu | Nothing that identifies you. No account, no cookie — §3 |
| Built an order and sent it as a message | Nothing. The message goes from your phone to the venue and never touches us — §5 |
| Paid for an order on the page | Nothing yet — no venue can take payments on its page yet. From the day one does: your email, if the venue asks for one, plus the order and the payment result — §6 |
| Booked a table | Nothing yet — reservations are not live. From the day they are: your name, and usually a phone number and email — §7 |
| Ordered on DoorDash, Uber Eats or Grubhub | Nothing yet — the connection is not live. §8 says what it holds from the day it is |
| Used Radar | A point to measure from, used once and not kept — §9 |
We never sell any of it. We never share it for advertising. We do not build a profile of you across venues, and there is nowhere in the product where one could be assembled — see xposego.com/do-not-sell.
3. If you are only looking
We do not:
- Create an account for you — there are no buyer accounts on XposeGo, by design
- Set a cookie on a venue page. A venue's page sets none at all — see the Cookie Notice at
xposego.com/cookies - Track you between websites
- Connect what you do at one venue to what you do at another
- Fingerprint your device
- Use any advertising identifier, tag, pixel or SDK
- Use any third-party analytics service
- Know your name, phone number or email address — unless §6, §7 or §8 applies
We do record, for the venue whose page you opened:
- That the page was viewed
- Which items were looked at or tapped
- Which buttons were tapped
- Whether the order button was used
- Whether you arrived from a QR code, a link, or a shared post
That is grouped into a session that exists only while the page is open. The session's number is made up in your browser, is never stored on your device, and is gone the moment you navigate away. Two visits to two different venues are two unrelated sessions, and there is no key that would let us join them.
One thing this page does not claim
Ordering software has to know that this phone is the one holding seat 3, so the venue page keeps a few things in your own browser's storage — including one random number that identifies this browser to this venue and lasts between visits. It is not a cookie, no other venue can read it, and it says nothing about who you are — but it is not nothing either, and §4 lists all of it rather than leaving you to find it.
Each operator's pages are their own website. Their address is on xposego.app, separate from every address of ours that anyone signs in to — so your browser treats two different operators as two unrelated sites, and enforces that separation rather than us merely promising it. Outlets that belong to one operator share one address, and share what it stores.
What the venue sees
Numbers. How many people opened the menu, which items were popular, which printed code brought people in. They never see you. Nothing we give a venue shows who viewed its page, and we will not build it.
4. What you carry instead of an account
Because there is no account, the software has to know that this phone is the one holding seat 3 at table 6. It does that with a handful of small notes kept in your own browser's storage. None of them is a login and none of them says who you are — and one of them does last between visits, which is the part worth reading rather than skipping. They are listed in full here, because "no account" should be checkable rather than reassuring.
| What | What it is | When it dies |
|---|---|---|
| The code in the QR | An address for a table, printed on a card. Possession of the card is the access control — it says nothing about you | It belongs to the table, not to you. Your phone keeps it only inside the seat note it stores for that table, and it identifies the table, not you |
| A device key | A random number your browser makes the first time you use a table here. It binds this phone to Guest 3 and grants nothing on its own — and it is kept, so that re-scanning mid-meal or reloading the page keeps your seat instead of making you a new guest. It therefore lasts between visits to this operator, and it is sent to us when you join a table or answer a presence check | When you clear this site's data. It is the one thing in this list that outlasts a visit. It is stored for this operator's address only — another operator's page cannot read it, and neither can we from anywhere else. Outlets of the same operator share it |
| A presence code | Four digits, read out to whoever is serving you, to prove the phone ordering is in the room | Five minutes, five attempts. Used by some venues above a certain amount |
| Your basket, and your language | So a half-built order and a language you picked survive a scroll | When you close the tab |
| Your details, if you asked us to keep them | An email or a name, so you do not retype it. Off unless you tick the box. Untick it and it is not used again; the saved copy is erased the next time you send an order | When you next send an order after unticking, or clear this site's data. It stays on your phone — it is not sent anywhere it was not already going |
| A note that a table asked your name | So the "what should we call you?" question is asked once a sitting, not on every reload | When you clear this site's data |
| Your order link | In your receipt. The one thing that outlives the evening, so you can check what you paid for and cancel before the kitchen starts | 24 hours — a shared table phone must not offer a stranger's order to the next person |
Never, anywhere in this list: a buyer account, a cookie, a device fingerprint, or anything that connects you across two different venues. Each venue page is its own website to your browser, so what one keeps is unreadable to the next.
Clearing this site's data in your browser removes every row above. We have no copy of any of it.
5. If you send your order as a message
On venues that do not take payment on the page, "send order" opens your own messaging app or dialer, addressed to the venue.
It goes from your phone to the venue. It never reaches us. We do not receive, store or transmit what you ordered or anything you wrote in it. We record only that the button was used.
That is true of a message. It is not true if you pay on the page — that is a different route with a different answer, and §6 is it. We would rather write two sections than one sentence that covers both badly.
6. If you pay for an order
This is the moment a visitor becomes someone we know, and the screen says so at the time rather than leaving it to a footer. No venue can take payments on its page yet — this is the flow from the day one does.
| We collect | Why |
|---|---|
| Your email address | Your receipt, and telling you what happened to your order. Asked for only where the venue turned it on — and you can still send the order without it. The screen tells you once what you give up by skipping it: no receipt, and no second way back to the order |
| Your name, and sometimes a phone number | Only where the venue needs to call the order out or reach you about it. Same rule: only if that venue asks |
| What you ordered, and any note you added | It is the order. The venue has to see it |
| Whether the payment succeeded, and for how much | Reconciliation and refunds |
We hold nothing about your card. Not the number, not the last four digits, not the brand, not the expiry. The card details go from your browser to Stripe, our payment processor, and what comes back to us is a payment reference and whether it worked.
| Who sees it | The venue you ordered from — it is their sale — and Stripe, who processes the payment |
| Whose sale is it? | The venue's. They are the seller; we provide the software. If something is wrong with the order, the venue is who can fix it |
| Do we sell it? | No. Never, to anyone |
| Do we market to you? | No. You get a receipt and updates about that order. Nothing else, ever |
| Can two venues connect your orders? | No. There is no shared buyer record, and nothing to join one on |
| How long | Seven years. An order is a financial record and the law requires it to be kept — longer than the venue's own account, and we cannot delete it earlier on request. Anything held beyond that minimum, you can ask us to remove |
On the payment page only, Stripe sets cookies to detect fraud on the payment you just asked to make. The menu page still sets none — Cookie Notice §2.
Tax on your order
The sales tax on your order is the venue's tax on the venue's sale. It is charged by the venue into the venue's own payment account and handed to the tax authority by the venue. It is charged once, and the amount is shown on your receipt. We collect none of it.
7. If you book a table
Reservations are not live yet — this describes them from the day they are. A reservation is the one place we ask for your details before you have bought anything.
We ask the fields the venue chose — always your name, and usually a phone number and email so they can reach you. Some venues also ask about the occasion or where you would like to sit.
| Who holds it | The venue you booked with. Two venues you book with hold two unrelated records, and neither can see the other's |
| No-shows | A venue may record that you did not turn up. Repeated no-shows can lead that venue to require approval, ask for a card hold, or stop taking your bookings |
| If that happened automatically | You can contest it and ask for a person to look at it. Write to privacy@menuxpose.com and say which venue and when |
| Card holds | Some venues authorize a small amount when you book. It is a hold, not a charge, and it is released when you arrive — but the venue sets what happens if you do not. Depending on their policy it can be taken on a no-show, or on a no-show and a late cancellation. The amount and the rule are fixed when you book, and changing the policy afterwards cannot re-price a hold already taken |
We are not a cross-venue reputation service and we will not become one. There is no shared guest history. No venue can see how you behaved at another, and there is no table in the product where such a thing could be written.
8. If you ordered through a delivery platform
If you ordered from this venue on DoorDash, Uber Eats or Grubhub, you are their customer. You never opened our page and you gave us nothing.
No delivery platform is connected yet. No order has ever reached us from one, and none will until the connection ships — this section describes it from the day it does.
From that day, the platform tells the kitchen about your order, so the venue sees a ticket and its daily totals are complete. The platform sends us the order as a single message, and your name, delivery address and phone are removed at the moment the message reaches us — they are never stored, and nothing shows them to anyone, the venue included. What the venue is shown is the order contents, its status, its timestamps, its totals, and the courier's first name.
| Your rights | You can exercise a right with us directly, and you do not have to go to the platform first. Write to privacy@menuxpose.com with the platform, the venue and the date; we will verify it and act on everything we hold, on the terms in §12. Contacting the platform as well will usually still be necessary — they ran the delivery and hold identifying details we never receive — but that is in addition to us, not instead of us |
9. Using XposeGo itself — Radar
This section is the part with no venue in it. Here we are not anyone's processor; it is us, and these are our choices.
Finding what is near you
Radar shows time-boxed offers running around you right now. To measure distance it needs a point to measure from, and it asks:
| If you allow location | Your browser gives the page your coordinates once, for that measurement. We ask once — we never ask twice, and refusing costs you nothing but precision |
| If you decline, or never ask | Radar still works. You pick a neighbourhood instead and we measure from the middle of it. The screen says so plainly, because measuring from a neighbourhood centre is worse than your real location and better than a guess |
| What we do with it | Work out which offers are within your radius, and how far each one is. That is the whole use |
| What we do not do | Build a location history, infer where you live or work, or keep the point after the answer is served |
Your coordinates never reach us at all. The distance is worked out in your browser, on your device — Radar makes no network request while it does it. There is no point for us to discard, because we are never sent one.
The total on your phone
Radar keeps a running total of what its offers have saved you. It is written into your own browser's storage, on your device, and it is never sent to us. Clear your browser's data for the site and it is gone — we have no copy, so there is nothing for us to delete on request.
Telling us something was good
Where a screen asks whether an offer was worth it, the answer is a tap with no identity attached. It is counted; it is not a review, it is not shown to other buyers, and XposeGo carries no reviews and no ratings at all.
10. Who else sees any of this
We do not sell personal data. We do not share it for advertising. We never will — and on XposeGo there is no advertising to share it for: ranking is distance, open-now and relevance, and it cannot be bought.
Companies that can touch something of yours, processing it for us under contract and on our instructions:
| Provider | For |
|---|---|
| Amazon Web Services | Hosting, the database, sending your receipt |
| Stripe | Taking your payment |
| Cloudflare | Storing and delivering the venue's photos and videos |
Google is not on that list, and the distinction is worth a sentence. Get directions is an ordinary link you tap — no map is embedded in the page, nothing of Google's runs on it, and nothing is sent to Google until you choose to go there. At that point you are on Google's site under Google's terms, the same as following any link. Our own typefaces are served by Google Fonts on our own pages — xposego.com, and the directory page on xposego.app — which sets no cookie but does see the request; a venue's own page loads no third-party file of any kind.
Two kinds of company are not our service providers and answer to you directly: DoorDash, Uber Eats and Grubhub (§8), and Google, where a venue chooses to show its public Google rating.
We may also disclose data where the law requires it, or to protect someone's safety.
11. Where it is kept, and for how long
Personal data is stored in the United States. We operate in the United States and Canada.
| Your paid order | At least 7 years — a financial record the law requires us to keep, and the reason we cannot delete it on request before then |
| Your reservation | With the venue's records, for as long as the venue's account lasts, then 30 days |
| Analytics sessions | 90 days in detail — removed in monthly sweeps, so a detailed row can live up to about 120 — then counts only |
| Server logs | 30 days |
| Backups | 7 days, then overwritten |
| The saved total on your phone | On your device only. We never had it |
12. Your rights
Wherever you are, you can ask to access, correct, delete or export what we hold about you. Email privacy@menuxpose.com. We answer within 30 days, and we will verify who you are first — that protects you from someone else asking for your data.
We do not treat anyone differently for asking.
Two limits, stated up front rather than discovered later: a paid order cannot be deleted before its retention period ends (§11), and a booking is the venue's record — we will route your request to them and act on their instruction (§1).
If you are in California, or a state with a similar law
- We do not sell your personal information and we do not share it for cross-context behavioral advertising. Not for money, not for anything else of value, not with anyone. Our Do Not Sell or Share My Personal Information page at
xposego.com/do-not-sellcarries the required link and explains why there is nothing to switch off - Your browser's Global Privacy Control signal asks for a state that is the only state our systems have. We honor it by default, for everyone, whether it is sent or not
- The categories we collect are in §3, §6, §7 and §9; the purposes are beside them; the recipients are in §10; the retention periods are in §11
- Precise geolocation is treated as sensitive personal information by California and several other states when a business collects it. If you turn location on for Radar, your browser hands the coordinates to the page and the measurement happens on your device — they are never transmitted to us. We do not collect it, so there is nothing for us to retain and nothing for you to limit the use of. Radar works without it, and says so on the screen
- Do Not Track. Do Not Track is an older browser signal, separate from Global Privacy Control, and no agreed standard for honouring it ever emerged. We do not track you across third-party websites at all, so our pages do not respond to a DNT signal — there is no behaviour it could switch off. The Global Privacy Control answer above is the one that does work
- You may use an authorized agent, whose authority we will verify
If you are in Quebec
Law 25 gives you rights of access, rectification, deletion and portability, and the right to withdraw consent. Our contact for privacy matters is privacy@menuxpose.com. If a decision about you were ever made purely automatically, you can be told about it and ask for a person to review it. Nothing in the product makes such a decision today — a booking restriction is always applied by a person at the venue (§7).
Everywhere else in Canada
PIPEDA gives you access and correction rights. Complaints can go to the Office of the Privacy Commissioner of Canada, or in Quebec to the Commission d'accès à l'information.
13. Children
XposeGo is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If we learn that we have, we delete it. This is the threshold the federal Children's Online Privacy Protection Act sets.
We also do not knowingly sell or share the personal information of anyone under 16, which is the threshold United States state privacy laws set for that. We do not sell or share anyone's personal information, at any age.
We collect nothing at all from someone who is only reading a menu, whatever their age. If you believe we hold a child's personal information, write to privacy@menuxpose.com and we will delete it.
14. Security
We encrypt data in transit and at rest, limit staff access to what is necessary, and keep a record of who reaches the live systems.
No system is perfectly secure. If a breach puts your rights at risk, we will notify you and the relevant authorities as the law where you are requires, and without unreasonable delay. Where the risk to you is high, we will tell you directly rather than waiting to be asked.
15. Changes
We will update this policy when the product changes. The date at the top is always the current version, and a change that affects what we collect or who sees it will be published here before it takes effect.
The current version is always at xposego.com/privacy.
16. Contact
| Privacy | privacy@menuxpose.com |
| A problem with an order or a booking | The venue first — their details are on their page. support@menuxpose.com if you cannot reach them |
| Copyright | copyright@menuxpose.com |
| Anything else that should not be on a page | abuse@menuxpose.com |
| Address | WayExpose, LLC · 1401 Pennsylvania Ave, STE 105 2394 · Wilmington, DE 19806 · United States |
Why the email addresses say
menuxpose.com. WayExpose, LLC runs both products and reads one set of mailboxes. Those are the monitored addresses, and we would rather print an address that is read than one that matches the domain you are on.