PREEA

Privacy Policy

Last updated: August 3, 2026

Effective date: March 29, 2026

This document is provided in English, which is the authoritative and legally binding version. Any translation into another language, where available, is provided for your convenience only; in the event of any conflict or ambiguity, the English version prevails.

1. Introduction

PREEA ("we", "our", or "us") operates the PREEA QR Menu Platform, including the mobile application (PREEA Manager), the website at preea.com, and all related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our Service, regardless of where you are located.

We are committed to protecting your privacy and processing your personal data in compliance with applicable data protection laws in the regions we serve, principally the Singapore Personal Data Protection Act (Singapore PDPA) and the Thailand Personal Data Protection Act (Thailand PDPA), together with the data protection laws of the other ASEAN member states in which our users are located (Malaysia, the Philippines, Indonesia, and Vietnam).

We also apply the core privacy principles in this Policy -- lawful basis, transparency, data minimization, security, and your rights of access, correction, and deletion -- to everyone who uses the Service, wherever they are located.

By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices, please discontinue use of the Service.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to name, email address, phone number, IP address, device identifiers, and usage data.
  • "Processing" means any operation performed on personal data, such as collection, recording, storage, retrieval, use, disclosure, or erasure.
  • "Data Controller" means the entity that determines the purposes and means of processing personal data.
  • "Data Processor" means an entity that processes personal data on behalf of the Data Controller.
  • "Data Subject" means the individual whose personal data is being processed.
  • "Business User" means a business owner or manager who uses PREEA to manage their establishment.
  • "End User" means a customer who views a business menu through the PREEA platform (e.g., by scanning a QR code).

3. Data Controller

PREEA acts as the Data Controller for personal data it collects and uses for its own purposes -- for example, account and business registration data, authentication data, billing data, security and infrastructure logs, and anonymized analytics, including technical data (such as IP address and approximate location) automatically collected when a menu page is loaded. For any questions regarding these processing activities, you may contact us at the details provided in Section 19.

When a Business User uses PREEA to manage their establishment, PREEA acts as a Data Processor on behalf of that Business User (the Data Controller) for any customer data the Business User chooses to collect through the platform. Where PREEA and a Business User each determine the purposes and means of processing the same data, they act as independent or joint controllers for that data, as applicable.

4. Information We Collect

4.1 Information You Provide Directly

  • Account registration: Name, email address, profile photo (via Google Sign-In, Apple Sign-In, or email magic-link sign-in)
  • Business information: Business name, address, contact phone number, category, operating hours, menu items, pricing, and descriptions
  • Payment information: Billing details processed through our third-party payment providers (we do not store full payment card numbers)
  • Communications: Messages, feedback, and support requests you send to us -- including in-app support chat messages and any images you attach, an app rating you submit together with the comment you write, and the email address and display name on your account at the time you write to us
  • Media uploads: Images of menu items, business logos, and other media you upload to the Service

4.2 Information Collected Automatically

  • Device information: Device type, operating system, browser type and version, screen resolution, and language preferences
  • Usage data: Pages visited, features used, actions taken, time spent on pages, and interaction patterns
  • Network information: IP address, approximate geolocation (city/country level only), and internet service provider
  • Diagnostic data: Crash reports, error logs, and performance metrics (collected by PREEA into our own error inbox and by our third-party error-monitoring provider)
  • Cookies and similar technologies: Session identifiers, preferences, and analytics data (see Section 14)

4.3 Information We Do Not Collect

We do not knowingly collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, genetic or biometric data, health information, or sexual orientation. We do not collect precise GPS location data unless you explicitly grant permission in the mobile application.

4.4 Information We Collect from End Users (Menu Viewers)

Most diners view a restaurant menu by scanning a QR code without creating an account. When you view a menu as an End User, we do not require or collect your name, email address, phone number, or any account information. We collect only the limited technical data described in Section 4.2 -- your device and browser information, IP address and approximate (city/country-level) location, and anonymized usage and analytics data -- which we use to display the menu correctly, keep the Service secure, and improve it. Any preferences you set while viewing a menu (such as language, currency, or favorites) are stored locally on your device. For the technical data described here, PREEA acts as the controller (see Section 3).

Menu interaction analytics (collected by PREEA, not a third party). When you view a menu we record aggregate, non-identifying counters -- menu views, the language and currency you selected, items and links you interacted with, favorites you added or removed, and the fact that a search was performed (the search text itself is not stored) -- per restaurant, per day. No IP address, device identifier, session identifier or search text is stored with these counters, and they cannot be traced back to you. We share these aggregate counts with the restaurant whose menu you viewed. We keep them for 180 days.

Feedback you send to a restaurant.If you choose to send feedback from a restaurant's menu, we store the message you write, the menu language you were reading in, and any photos you attach (up to three), and we make them available to that restaurant. We do not ask for or store your name, email address, phone number, IP address or device identifier alongside the message. Attached photos are automatically screened for unsafe content before they are stored.

If you sign in to the PREEA app. Signing in is optional for diners. If you do, your recently viewed menus are stored on our servers -- the restaurants you scanned, a snapshot of their name and logo, and when you viewed them -- so the list follows you across your devices. You can clear it in the app, and it is deleted when you delete your account.

6. How We Use Your Information

  • Service delivery: To provide, operate, and maintain the QR menu platform, including generating QR codes, displaying menus, and managing business profiles
  • Account management: To create, manage, and authenticate your account
  • Transaction processing: To process payments and manage billing for paid features
  • Communications: To send service-related notifications, security alerts, and support responses
  • Service improvement: To analyze usage patterns, diagnose technical issues, and develop new features
  • Security: To detect, prevent, and respond to fraud, abuse, security incidents, and technical issues
  • Legal compliance: To comply with applicable laws, regulations, and legal processes
  • Marketing: We do not currently send marketing communications. If we introduce them, we will obtain your opt-in consent first and you may opt out at any time.

7. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We may share your data only in the following circumstances:

7.1 Service Providers (Data Processors)

We engage trusted third-party service providers who process data on our behalf. Where a provider processes personal data for us, we rely on that provider's data-processing terms, which require them to protect your data and limit its use to the services they provide to us:

  • Cloud hosting and infrastructure providers
  • Payment processing services
  • Analytics and monitoring services
  • Email delivery services
  • Error tracking and diagnostic services
  • AI service providers (translation, menu photo scanning, and image generation)
  • Automated image content-moderation services

7.2 Legal Requirements

We may disclose your personal data if required by law, court order, or governmental regulation, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.

7.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.

7.4 With Your Consent

We may share your data with third parties when you have given us explicit consent to do so.

8. Third-Party Services

We engage service providers in the categories below. Each processes data only on our instructions, under data-processing terms, and only for the purpose shown. We describe them by category rather than by name so that we can change or add a provider without weakening these commitments; the current list of named providers is available on request (see Section 19).

CategoryPurposeData Shared
Sign-in providers (Google, Apple)Authentication, when you choose to sign in with themThe email address and name on the account you sign in with. Named here because you choose the provider yourself.
Email deliveryPasswordless sign-in (magic link), account-deletion confirmation and notification, and service emailsYour email address and the content of the message
Cloud hosting, database, CDN and media storageRunning the Service and delivering menus. Our primary region is Singapore; we may also process data in European (Frankfurt) and United States (Ashburn / Washington) regionsAll application data, encrypted in transit and at rest, including restaurant menu images (business content)
Payment processingSubscriptions and billingBilling details and subscription status. We do not store full payment card numbers.
AI service providers (translation, menu photo scanning, image generation)Translating menu and interface text, reading menu photos to create menus automatically, and generating menu-item images. We use more than one provider for each task, so a given request may go to a primary provider or to a fallback.Menu content text (item names, descriptions, options), interface text, and menu photos uploaded by a restaurant. This is business menu content and is not intended to contain personal data; we do not send diner personal data.
Automated image content moderationScreening uploaded images for unsafe content before they are published (see Section 15)Images uploaded to the Service (business content)
Analytics (website and mobile app)Understanding aggregate usage so we can improve the ServiceAnonymized usage events, page views and device/browser information. This is separate from the aggregate menu analytics we collect ourselves (see Section 4.4).
Error monitoring and diagnosticsDetecting and fixing crashes and failuresCrash reports, error data and device/browser information, with personal data scrubbed

We select providers that offer appropriate data-protection commitments, and we put data-processing terms in place with them where they process personal data on our behalf. If you would like the current list of named providers -- for example to complete your own vendor assessment -- contact us at the address in Section 19 and we will provide it.

9. International Data Transfers

As a globally operating platform, your personal data may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.

When we transfer personal data outside of the European Economic Area (EEA), United Kingdom, Thailand, or other jurisdictions with data transfer restrictions, we ensure appropriate safeguards are in place, including:

  • Comparable protection: We take reasonable steps to ensure that any recipient provides a standard of protection comparable to that required under the Singapore and Thailand Personal Data Protection Acts, including through data-processing terms with our providers and by using reputable providers that maintain recognized security and privacy standards
  • Provider data-processing terms: Where our providers offer data-processing terms (which for some providers incorporate the EU Standard Contractual Clauses), we rely on those terms to require them to protect personal data
  • Technical safeguards: Encryption in transit (TLS 1.2+) and at rest for all transferred data

Restaurant menu images are stored on our primary media host and may be replicated to a secondary content delivery network with a storage location in the Asia-Pacific region (currently Singapore), so this business content may be stored outside your home region under the safeguards described above.

You may request a copy of the safeguards we use for international transfers by contacting us.

10. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Specific retention periods are:

Data TypeRetention Period
Account dataDuration of account + 90-day grace period, counted from the moment you confirm the deletion by email (see Section 12)
Business content (menus, images)Duration of account + 90-day grace period, counted from your email confirmation. Exception: text you send through our translation features may be stored under a content-derived key and re-used to serve identical menu text for other businesses; that translation store is not account-owned and is retained after deletion, in a form that is not linked to you or your business.
Transaction recordsHeld by our payment processor under its retention terms
Menu interaction analytics (aggregate, collected by PREEA)180 days, then automatically purged
Third-party analytics providersAnonymized; per that provider's retention settings
Menu-scan records (the menu photo a restaurant uploaded, the AI's extracted output, and the outcome)Retained for the life of the account and used by our team to audit AI extraction quality; deleted when the account is deleted
Error events (PREEA error inbox)30 days, then automatically purged
Grouped error signatures (PREEA error inbox)90 days after the last occurrence, then automatically purged
Third-party error monitoring providerPer that provider's retention settings
Sign-in sessions and device recordsDevice type, model, operating system, app version and the IP address of the sign-in: kept while the session is valid and for 30 days after it expires, for security review
Support communicationsRetained while your account is active; deleted when your account is deleted
Audit logsRetained while your account is active; deleted when your account is deleted

When data is no longer needed, we securely delete or irreversibly anonymize it. Anonymized data that can no longer identify you may be retained indefinitely for statistical purposes.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption: All data in transit is protected by TLS 1.2 or higher. Data at rest is protected by the encryption provided by our managed database and object-storage providers.
  • Access controls: Strict role-based access controls and multi-tenant isolation ensure that only authorized personnel can access personal data.
  • Authentication: Secure authentication via Google and Apple Sign-In (OAuth 2.0) and passwordless email magic links, with token-based session management.
  • Infrastructure security: Several of our infrastructure providers maintain independent security certifications such as SOC 2 and ISO 27001.
  • Monitoring: Automated static analysis and dependency, secret, and vulnerability scanning run in our continuous-integration pipeline on every code change. Our infrastructure providers perform their own security monitoring.
  • Incident response: Documented incident response procedures to detect, contain, and remediate security incidents.

While we strive to use commercially acceptable means to protect your personal data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

12. Your Rights

Regardless of your location, we respect the following data protection rights for all users:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete personal data.
  • Right to erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to restriction: Request that we limit the processing of your personal data in certain circumstances.
  • Right to data portability: Receive your personal data in a structured, commonly used, and machine-readable format.
  • Right to object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: Withdraw your consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days (or within the timeframe required by your applicable law). We may request verification of your identity before processing your request.

If you are located outside Southeast Asia, we still honor the core rights described in this section and will handle your request in good faith under applicable law.

13. Additional Rights for ASEAN Residents

If you are located in a member state of the Association of Southeast Asian Nations (ASEAN), the following additional provisions apply based on your country of residence:

13.1 Thailand (Personal Data Protection Act, PDPA)

  • We process your personal data in compliance with the Thailand Personal Data Protection Act B.E. 2562 (2019), obtaining opt-in consent before collection and providing clear purpose-based choices.
  • You have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
  • You have the right to access your personal data, request correction, request deletion or anonymization, restrict processing, object to processing, and request data portability in a machine-readable format.
  • You have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) if you believe your data has been mishandled.
  • In the event of a data breach, we will notify the PDPC within 72 hours. Cross-border data transfers from Thailand are conducted only with appropriate safeguards in place.

13.2 Singapore (Personal Data Protection Act)

  • We obtain your consent before collecting, using, or disclosing your personal data, and notify you of the purposes at or before the time of collection.
  • You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice.
  • You have the right to request access to and correction of your personal data held by us.
  • In the event of a data breach that could result in significant harm, we will notify the Personal Data Protection Commission (PDPC) and affected individuals within 3 calendar days of assessing the breach.
  • We implement reasonable security arrangements to protect your personal data against unauthorized access, collection, use, disclosure, or similar risks.
  • We retain your personal data only for as long as necessary for business or legal purposes, and securely dispose of it when no longer needed.

13.3 Malaysia (Personal Data Protection Act 2010)

  • We process your personal data in accordance with the General Principle, Notice and Choice Principle, Disclosure Principle, Security Principle, Retention Principle, Data Integrity Principle, and Access Principle of the Malaysia PDPA.
  • You have the right to access your personal data, request corrections, and withdraw consent for processing.
  • From June 2025, you have the right to data portability, allowing you to request that your personal data be transmitted to another data controller where technically feasible.
  • Cross-border transfers of your data are conducted only to jurisdictions with substantially similar data protection laws or with adequate safeguards in place, following a Transfer Impact Assessment.
  • In the event of a data breach, we will notify the Personal Data Protection Department (PDPD) within 72 hours and affected individuals within 7 days thereafter.

13.4 Philippines (Data Privacy Act of 2012)

  • We process your personal information in compliance with the principles of transparency, legitimate purpose, and proportionality as required by the Data Privacy Act.
  • You have the right to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, and to file a complaint with the National Privacy Commission (NPC).
  • We implement reasonable and appropriate organizational, physical, and technical security measures to protect personal information.
  • Any data breach that may pose risk to the rights and freedoms of data subjects will be reported to the NPC and affected individuals within 72 hours of discovery.

13.5 Indonesia (PDP Law No. 27 of 2022)

  • We process your personal data based on a valid legal basis: consent, contractual necessity, legitimate interest, or legal obligation, in accordance with the PDP Law.
  • You have the right to obtain information about your data processing, access your data, request correction, request deletion, withdraw consent, object to automated decision-making, and request data portability.
  • We distinguish between general personal data and specific (sensitive) personal data, applying enhanced protections to sensitive categories including financial data and children's data.
  • Cross-border transfers are conducted only where the receiving country has an adequate level of data protection or with appropriate contractual safeguards.
  • Data breach notifications will be made to affected individuals within 3 x 24 hours of the breach being discovered, as required by the PDP Law.

13.6 Vietnam (Decree 13/2023/ND-CP and PDP Law)

  • We obtain your explicit, voluntary consent based on a full understanding of the purpose, type of data collected, entities involved, and your rights before processing your personal data.
  • You have the right to access, correct, delete, restrict, and object to the processing of your personal data. We will respond to your requests within 72 hours as required by Decree 13.
  • We classify personal data into basic personal data and sensitive personal data, with enhanced protections applied to sensitive categories.
  • Cross-border transfers of personal data of Vietnamese residents are conducted only with appropriate safeguards, including Data Protection Impact Assessments and Transfer Impact Assessments.

14. Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website. Cookies are small text files stored on your device that help us provide and improve our Service.

Types of Cookies We Use

CategoryPurposeRequired
Strictly NecessarySession management, security, load balancingYes
FunctionalLanguage preferences, user settingsNo
AnalyticsOur analytics providers - usage patterns and performanceNo
DiagnosticError monitoring service - error tracking and performance monitoringNo

Managing Cookies

We do not currently show a cookie banner. Analytics cookies are set when you load our website. You can control cookies through your browser settings -- most browsers allow you to block or delete them -- although blocking strictly necessary cookies may impact the functionality of the Service. You can also opt out of analytics tracking through:

  • Google Analytics opt-out browser add-on (available at tools.google.com/dlpage/gaoptout)
  • You can disable analytics cookies through your browser's cookie settings or the Google Analytics opt-out add-on above
  • Your browser's built-in cookie management settings

15. Automated Decision-Making and Profiling

We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significantly affects you. Our analytics services collect anonymized data for the sole purpose of improving the Service and do not make automated decisions about individual users. Our AI features (menu photo scanning, translation, and image generation) process restaurant and menu content to create or translate menus; they do not make automated decisions about, or profile, individual diners.

Automated content screening. Images uploaded to the Service are automatically screened for unsafe content before publication. An image may be blocked outright, or held back from public display pending review, without a person seeing it first. This decision concerns the image, not you, and you can contact us at the address in Section 19 to ask for a human review.

If we introduce automated decision-making in the future, we will update this policy, provide meaningful information about the logic involved, and ensure you have the right to obtain human intervention.

16. Children's Privacy

Our Service is not directed to children, and accounts are for business users aged 18 or older. We do not knowingly collect personal data from children. Where a minimum age of consent applies under local law (for example, 10 years with parental consent under the Thailand PDPA), we honor it.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected]. We will take immediate steps to delete such information from our systems.

17. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within the period required by applicable law (for example, the Singapore PDPC or the Thailand PDPC, as short as 72 hours) after becoming aware of the breach
  • Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches, including their effects and the remedial actions taken
  • Take immediate steps to contain and mitigate the impact of the breach

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Post the updated policy on this page with a new "Last updated" date
  • Notify you via email or in-app notification at least 30 days before the changes take effect
  • Where required by law, obtain your consent to material changes

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after the effective date of changes constitutes your acceptance of the updated policy.

19. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

We aim to respond to all privacy-related inquiries within 30 days, or within the period required by your applicable law (see the region-specific sections above, which may allow a longer statutory response window).