← GoPlate

GoPlate · Legal

Privacy policy

Last updated July 26, 2026 | 5 min read

The short version

That is the whole policy in six lines. The full detail — written to be read, not to hide things — follows below.

Who we are

Everyone

GoPlate is a menu platform that lets restaurants present their dishes in 3D and AR, share their menu through a QR code, and take orders from the table. It is operated by the GoPlate team in Colombo, Sri Lanka. This policy covers the GoPlate website, the GoPlate mobile app for restaurant owners, and every public menu page we host.

Three kinds of people interact with GoPlate, and we treat their data differently: restaurant owners who create an account, diners who view a menu or place an order, and visitors to this website. Each section below is tagged with who it applies to.

What we collect from you

Restaurant owners
  • Account details — your name, email address, and a password. Passwords are never stored in plain text, only a bcrypt hash.
  • Menu content — restaurant names and settings, categories, dish names, descriptions, prices, tags, and the photos and videos you upload or film.
  • Plan status — which plan you are on, trial dates, and, when paid checkout is active, a reference to your payment subscription. Card numbers never touch our servers (see Payments).
  • Order records — the orders your customers place, which appear on your Orders screen.

What we collect from diners

Diners

Diners never need an account and never install anything — viewing a menu is like viewing any web page. If a restaurant has table ordering enabled and you place an order, we store exactly what you submit: the items you chose, and optionally a name, table number, and a note (“no onions please”). That information is collected on behalf of the restaurant you ordered from, is visible only to that restaurant, and is used for nothing else.

We do not run advertising or analytics trackers on menu pages, and we do not build profiles of diners.

How we use your data

Restaurant owners
  • To operate your account, publish your menus, and deliver orders to your Orders screen.
  • To generate 3D models — photos and video frames of a dish are sent to our 3D partner solely to produce the model, which is then stored with your menu.
  • To produce menu clips — uploaded videos are processed on our own servers (trimmed, resized, audio removed). The original recording is never published.
  • To reach you about your account — a trial that is ending, or an important service change. We do not send marketing email.

Payments

Restaurant owners

Subscriptions are purchased on this website, not inside the mobile app. When card checkout is active it is handled by Stripe, a PCI-DSS-certified payment processor: your card details go directly to Stripe, and we only receive confirmation that a payment succeeded along with a subscription reference. While we onboard our payment gateway, some plans are activated manually by our team after you contact us — in that case we handle no payment data at all.

Cookies & sessions

Everyone

We use a single kind of cookie: a signed session credential that keeps restaurant owners logged in. There are no advertising cookies, no analytics cookies, and no third-party trackers anywhere on GoPlate. Public menu pages set no cookies at all beyond what is technically required to serve them.

Where data lives & how long

Everyone

GoPlate runs on Railway infrastructure, and all traffic is encrypted in transit with HTTPS. Your data may be stored on servers outside Sri Lanka. We keep content for as long as your account exists: deleting a dish, a restaurant, or your whole account removes the content and media permanently — deletion is not a soft-hide. Order records are kept until the restaurant that owns them deletes them or deletes its account.

What we never do

Everyone
  • Sell your data — not owner data, not diner data.
  • Show third-party advertising.
  • Use your photos, videos, or 3D models for anything other than displaying your own menu — including training AI models.
  • Share data with anyone beyond the service providers that run GoPlate — 3D generation, payment processing, and hosting — and only ever to the extent those jobs require.

Your rights & controls

Everyone

Under Sri Lanka’s Personal Data Protection Act No. 9 of 2022, and comparable laws elsewhere such as the GDPR, you have the right to access, correct, export, and erase your personal data. In practice:

  • Edit or delete any dish, photo, or video at any time from the app.
  • Unpublish a menu instantly — it disappears from its public link.
  • Delete your account from inside the app (Account → Delete account). This permanently removes your restaurants, menus, media, and order history.
  • Email us for anything else — a copy of your data, a correction, or a deletion request if you can no longer access the app. We respond within 30 days.

If you are a diner and want an order record removed, contact the restaurant you ordered from — they own that record — or email us and we will help.

Children

Everyone

GoPlate accounts are a business tool intended for people 18 or older, and we do not knowingly collect personal data from children. Public menu pages can be viewed by anyone, but they collect no personal data from viewers.

Changes to this policy

Everyone

If we change this policy in a way that matters — new data, new processor, new purpose — we will update this page and the date at the top, and for significant changes we will email account holders before the change takes effect.

Contact

Everyone

Questions, access requests, or deletion requests: malikanishnatha4@gmail.com. We are a small team and we read everything.

See also our Terms of service and About us.