Security and compliance at Popmenu.

Restaurants trust Popmenu with their menus, their guests, and their revenue. This page explains how we protect that data, which standards we hold ourselves to, and how to request the documentation your team needs to review us.

Standards we meet.

  • SOC 2 Type II

    Independent audit of our security controls against the AICPA Trust Services Criteria for Security.

    Audited annually
  • PCI DSS

    Card payments are processed by PCI DSS compliant providers. Popmenu never stores full card numbers.

    Validated annually
  • CCPA / CPRA

    California privacy rights, including Do Not Sell or Share requests, are honoured for every guest.

    Ongoing
  • WCAG 2.1 AA

    Client websites are designed to the Web Content Accessibility Guidelines, level AA.

    Design standard
  • TCPA & CAN-SPAM

    Guest text and email marketing tools are built around consent, opt-out, and sender identification rules.

    Ongoing

Compliance documentation.

Most documents are shared with clients and prospective clients on request. Select a document to see how to request it.

Reports and attestations

Policies

  • Privacy PolicyHow Popmenu collects, uses, and protects personal information.Link
  • DMCA PolicyHow to report copyright infringement on content hosted by Popmenu.Link

How we protect your data.

  • Data security

    • Data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256.
    • Backups are encrypted, stored separately from production, and tested for restore.
    • Full payment card numbers are never stored on Popmenu systems.
  • Application security

    • Every code change is peer reviewed before it reaches production.
    • Dependencies and code are scanned for known vulnerabilities on every build.
    • A third party performs penetration testing at least annually, with findings tracked to closure.
  • Infrastructure and network

    • Hosted on major cloud infrastructure with production separated from development and testing.
    • Centralized logging and alerting for security events across the platform.
    • Edge protection against DDoS and common web attacks on every request.
  • Access control

    • Single sign-on and multi-factor authentication are required for all employees.
    • Access follows least privilege and is reviewed on a regular schedule.
    • Access is revoked the same day an employee leaves or changes roles.
  • People and endpoints

    • Background checks before hire, where permitted by law.
    • Security awareness training at onboarding and every year after.
    • Company devices are centrally managed with disk encryption and endpoint protection.
  • Governance and risk

    • A named security lead owns the program and reports to executive leadership.
    • Formal risk assessments and policy reviews happen at least annually.
    • Vendors with access to client data go through a security review before onboarding.

Guest data stays in your restaurant's hands.

Popmenu processes the information restaurants need to run their business: operator accounts, menus, and the guest details that power online ordering, reservations, waitlists, and marketing. We use that data only to deliver those services, and we never sell it.

Guests can exercise their privacy rights, including Do Not Sell or Share requests under California law, at any time. Full details are in our Privacy Policy.

What we collect
Operator account details, menu content, and guest contact and order information provided through your restaurant's website, ordering, reservations, and marketing tools.
What we don't
Full payment card numbers. Cards are tokenized by our payment providers and never stored on Popmenu systems.
Retention
Data is kept for as long as your account is active or as needed to meet legal obligations, then securely deleted under our retention policy.
Your control
You decide who on your team can access your dashboard, and you can export your guest and order data at any time.

Report a vulnerability.

If you believe you have found a security issue in a Popmenu product or website, we want to hear from you. Emailsecurity@popmenu.comwith a description of the issue, steps to reproduce it, and any affected URLs.

  • Please allow us time to review and respond to your report.
  • We will not pursue action against researchers who act in good faith and avoid privacy violations, data destruction, and service disruption.
  • We ask that you give us reasonable time to fix an issue before disclosing it publicly.

Built to stay up, and to tell you when it doesn't.

The platform is monitored around the clock, with redundancy across our infrastructure and tested backups. Current uptime and incident history are published on our status page. Recovery time and recovery point objectives are available on request.

If a security incident affects your data, we notify you without undue delay as required by your agreement and applicable law, and we share what you need to inform your guests.

FAQ

Frequently asked questions.

Popmenu completes a SOC 2 Type II audit each year with an independent auditor. The report is confidential. Clients and prospective clients can request it by emailing security@popmenu.com.

Questions about security or compliance?

Our security team answers questionnaires, documentation requests, and general questions from clients and prospective clients.

Email security@popmenu.com