Privacy Policy

La Carta · Last updated: September 21, 2026 · Version 1.0

One-line summary We store the account of the restaurant owner (name, email, hashed password) and the menu they publish on our own server. We never ask a diner for a name, an email, or a phone number, and we sell nothing to anyone.

1. Who we are

La Carta (hereinafter, "the App") is developed and operated by Ingeniería.dev, led by Chris Flores (hereinafter, "we", "the Developer").

2. Two very different kinds of user

Reading this policy is much easier once this distinction is clear, because the two groups are treated differently on purpose.

3. What data we collect

3.1 From the restaurant account

To give you an account that works across your devices, we store on our server:

When you sign up or sign in, we email you a three-digit verification code to confirm the address belongs to you. See Section 6.1 for the service that delivers that email.

3.2 The content you publish

Everything you create in order to run your menu is stored on our server, because that is what the diner's browser has to load when the QR code is scanned:

This content is public by design: any person who scans your QR code can see it. Please do not put anything in a dish name, a description, or a photo that you would not want a stranger at a table to read.

3.3 From diners — deliberately almost nothing

When a guest orders from the web menu, the server stores:

We do not ask for, receive, or store a diner's name, email address, phone number, address, payment details, or any account credential. There is no diner account to create, because there is nothing we want to know about them.

4. What we never collect

The following is true of the App as a whole, for restaurants and diners alike:

We do not sell, rent, or share your data with third parties for their own purposes, and we never will. The only parties that ever receive data are the infrastructure providers listed in Section 6, strictly so the service can function.

5. What is stored on your device

The App keeps very little on the iPhone or iPad itself:

DataPurposeLocation
Your session token Keep you signed in without retyping your password Device — iOS Keychain, encrypted by the system
App preferences (language, onboarding state, selected restaurant) Remember your settings between sessions Device (UserDefaults)
A temporary copy of menu data being displayed Show your menu and incoming orders on screen Device memory, discarded when the App closes

Your password itself is never stored on the device. Signing out removes the session token from the Keychain; deleting the App removes everything in this table with it.

6. External services

La Carta is not an offline app: it has a backend, because your menu has to reach the phone of a guest who never installed anything. These are the only parties involved.

6.1 Our own server

Your account and your menu live on a server operated by the Developer at menu.ingenieria.dev, running a PostgreSQL database on infrastructure rented from Digital Ocean in their SFO3 region (San Francisco, United States). Digital Ocean is our hosting provider: they supply the machine, they do not process your data for any purpose of their own. All traffic between the App and the server travels over HTTPS.

6.2 Resend (email delivery)

The three-digit verification code that confirms your email address is delivered by Resend, an email delivery service. To send it, Resend necessarily receives your email address and the message containing the code. Nothing else is shared with them — not your password, not your menu, not your orders. See Resend's Privacy Policy.

6.3 Apple

Apple distributes the App through the App Store and delivers the notifications described in Section 7 through the Apple Push Notification service. Their handling of that data is governed by Apple's Privacy Policy. The App contains no In-App Purchases, so no purchase data exists.

7. System permissions

La Carta requests only what it actually uses:

Choosing a photo for a dish uses the standard iOS photo picker. The picker runs outside the App and hands over only the single image you selected — the App never receives access to your photo library as a whole, which is why no photo library permission is requested.

The App does not request access to: the camera, your full photo library, location, contacts, calendar, reminders, the microphone, Bluetooth, the local network, health data, or HealthKit.

8. Marketing and advertising

The App displays no ads. We do not collect data for remarketing, profiling, segmentation, behavioral analysis, or any promotional purpose. We do not participate in ad networks. We will not email you marketing messages: the only email we ever send to a restaurant account is the verification code it asked for, and operational notices about the service.

9. Data retention and deletion

10. Minors

The App is a business tool intended for restaurant owners and staff, who are expected to be adults. It contains no content directed at children and no advertising. Diners are never asked for personal data at all, so no data about a minor sitting at a table is ever collected.

11. User rights (GDPR, CCPA, LFPDPPP, LGPD)

If you hold a restaurant account, the following rights apply to the data described in Section 3:

To exercise any of these rights, email [email protected]. We respond within 48 business hours and resolve requests within the period required by applicable law.

12. Security

No system is perfectly secure. If a breach ever affected your personal data, we would notify you by email and, where the law requires it, the competent authority, without undue delay.

13. International transfers

Our server is located in the United States (Digital Ocean, SFO3 region), and our email provider, Resend, also operates from the United States. If you use the App from Mexico, the European Union, Brazil, or elsewhere, your account data is therefore transferred to and stored in the United States. That transfer is necessary to provide the service you requested, and it is the only reason it takes place.

14. Changes to this policy

We may update this Privacy Policy to reflect changes to the App or to applicable law. The current version will always be published at this URL, along with the date of the last update. Material changes will also be announced inside the App.

15. Governing law

This Policy is governed by the laws of the United Mexican States, in particular the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). Any dispute will be submitted to the competent courts of Mexico City.

16. Contact

Privacy Officer: Chris Flores
Email: [email protected]
Postal address: Av. Javier Barros Sierra 495, Santa Fe Lomas de Santa Fe Zedec Santa Fé, Álvaro Obregón 01219, Mexico City, CDMX, Mexico