Terms and conditionsCookie policyIntegration policySvenska

Integration policy

Updated 2026-10-05

This policy describes how Menytorget integrates with other services, which sub-processors handle data, and what applies to anyone building against our API. Draft – to be reviewed before general availability.

Our sub-processors

The list is updated as sub-processors are added; customers are informed of material changes in advance.

Integrations the Customer enables

POS systems, delivery services (e.g. Foodora, Wolt), booking systems and ticket printers are connected by the Customer and governed by each provider's terms. Menytorget shares only the data the integration needs – the menu, orders and status – and never more than the Customer approved by enabling the integration. The Customer can switch an integration off in the portal at any time; the data flow stops immediately.

Online payments

Card payments are processed by Stripe Payments Europe Ltd through a Stripe account in the Customer's name; Swish payments through the Customer's own Swish Handel agreement. The Customer is the seller and payee towards the guest and is responsible for receipts, VAT, refunds and complaints. Menytorget charges a platform fee per completed online payment per the current price list, deducted by Stripe at payout or invoiced for Swish. Stripe's and the bank's fees apply in addition. Menytorget stores no card data; Swish certificates are stored encrypted and used only for the Customer's payment requests.

API keys and the public API

The Customer can create API keys with limited scopes (e.g. read menu, write orders). Keys are stored hashed, shown once and can be revoked. A key gives access only to that restaurant's data; row-level security in the database prevents leakage between restaurants. Calls are rate limited. Abuse, resale of data or attempts to bypass permissions lead to the key being blocked.

Webhooks

Events (new order, menu change) can be sent to an address the Customer provides. Each delivery is signed with a secret so the receiver can verify the sender. We retry a limited number of times on failure.

Security and incidents

We apply encryption in transit (TLS), hashed passwords and keys, two-step verification for administrators and row-level security in the database (see our security description). In the event of a personal data breach affecting the Customer's data we notify the Customer without undue delay, at the latest within 72 hours.

Contact

Integration questions and partnerships: support@menytorget.se, Area81 Solutions AB.

Integration policy – Menytorget – Menytorget