Terms and conditionsCookie policyIntegration policySvenska
Integration policy
Updated 2026-10-05
This policy describes how Menytorget integrates with other services, which sub-processors handle data, and what applies to anyone building against our API. Draft – to be reviewed before general availability.
Our sub-processors
- Render (Frankfurt, EU) – hosting of servers and database. All customer data is stored here.
- Brevo (EU) – transactional email: sign-in links, invitations, password resets, order confirmations. Recipient address, name and email content are sent to Brevo.
- Anthropic – AI features such as menu scanning, proofreading and design template generation. Images and texts the Customer submits for scanning are processed by the model; we never send guests' personal data to the AI service. Anthropic does not train models on API data.
- Google – optional sign-in with a Google account (we receive email address, name and an account id) and Google Fonts on restaurant sites.
The list is updated as sub-processors are added; customers are informed of material changes in advance.
Integrations the Customer enables
POS systems, delivery services (e.g. Foodora, Wolt), booking systems and ticket printers are connected by the Customer and governed by each provider's terms. Menytorget shares only the data the integration needs – the menu, orders and status – and never more than the Customer approved by enabling the integration. The Customer can switch an integration off in the portal at any time; the data flow stops immediately.
Online payments
Card payments are processed by Stripe Payments Europe Ltd through a Stripe account in the Customer's name; Swish payments through the Customer's own Swish Handel agreement. The Customer is the seller and payee towards the guest and is responsible for receipts, VAT, refunds and complaints. Menytorget charges a platform fee per completed online payment per the current price list, deducted by Stripe at payout or invoiced for Swish. Stripe's and the bank's fees apply in addition. Menytorget stores no card data; Swish certificates are stored encrypted and used only for the Customer's payment requests.
API keys and the public API
The Customer can create API keys with limited scopes (e.g. read menu, write orders). Keys are stored hashed, shown once and can be revoked. A key gives access only to that restaurant's data; row-level security in the database prevents leakage between restaurants. Calls are rate limited. Abuse, resale of data or attempts to bypass permissions lead to the key being blocked.
Webhooks
Events (new order, menu change) can be sent to an address the Customer provides. Each delivery is signed with a secret so the receiver can verify the sender. We retry a limited number of times on failure.
Security and incidents
We apply encryption in transit (TLS), hashed passwords and keys, two-step verification for administrators and row-level security in the database (see our security description). In the event of a personal data breach affecting the Customer's data we notify the Customer without undue delay, at the latest within 72 hours.
Contact
Integration questions and partnerships: support@menytorget.se, Area81 Solutions AB.