Security & your data
Your costs are your business.
Marji asks you to hand over the numbers most restaurants show nobody — what you pay, what you charge, and where the gap is closing. This page says what we do with them, what we do not do with them, and what happens to them if you leave. Including the parts we have not built yet.
Never sold
Not to suppliers, brokers, or anyone else.
Yours to take
CSV export any time, on every plan.
Cancel in two clicks
Month to month. No fee, no call.
A person answers
support@marji.co — usually same day.
What we hold, and why
Marji only works if it can see what you buy and what you charge. That means we hold the things you upload: your menu and its prices, your recipes, the supplier invoices you send us, and the ingredient costs read off them. We also hold your account details — name, email, a password hash, never a plaintext password — and, if you subscribe, your Stripe customer and subscription identifiers. We never see or store your card number; Stripe handles that end to end.
We do not ask for anything we do not need to compute a margin. There is no reason for us to have your payroll, your bank details, your guest data, or your POS credentials beyond the Square token you explicitly grant when you link a catalog.
Who can see it
Your data is scoped to your restaurant at the database level, and every query is filtered by that scope before it runs. Another Marji customer cannot see your prices, your suppliers, or that you exist. Anyone you invite to your restaurant can see its data; nobody else can.
Inside our team, access to production data is limited to what is needed to operate the service and answer your support email. Sensitive actions are written to an append-only audit log, and the database itself rejects any attempt to edit or delete an entry — with one deliberate exception, so that erasing an account at your request actually erases it.
We never sell your data
Not to suppliers, not to distributors, not to data brokers, not as an anonymised aggregate product. Your costs are commercially sensitive — knowing what you pay for beef is worth money to the person selling you beef — and that is exactly why the answer is a flat no rather than a policy with exceptions in it.
The one place your numbers can leave your account is when you send them somewhere yourself: a CSV you export, or an approved price you push to your own Square catalog.
Where it lives, and who processes it
Marji runs on Vercel, with a Postgres database at Neon and uploaded files in Vercel Blob storage. Invoice and menu images are read by AI and OCR services — Anthropic, OpenAI and AWS Textract — strictly to extract the lines on them. Stripe handles billing; Resend sends email.
Each of those is a processor acting on our instructions, not a party we share your data with for their own purposes. The current list is maintained in our privacy policy, which is the canonical version and is updated when a processor changes.
How it is protected in transit and in the browser
Every request is HTTPS, with HSTS set to two years and preload-eligible, so a browser will not talk to us over plain HTTP at all. The application ships a strict Content Security Policy, denies framing entirely, blocks MIME sniffing, and disables browser APIs it does not use — camera, microphone, geolocation, payments, USB.
Authentication endpoints are rate-limited per endpoint class, with an additional per-email throttle on password reset, and menu scanning is capped per restaurant per hour. Email addresses must be verified before an account can sign in, so nobody can take an account by signing up with your address.
Your dashboard and your public menu are separate problems
The published QR menu at your own link is designed to be public — that is the point of it. Your dashboard is not: the whole authenticated application is served with instructions to search engines not to index it, and is blocked in robots.txt as well as by response header, because relying on one of those alone is how internal screens end up in search results.
One product rule sits above all of this: no automation, outage or bug can change a menu price you did not approve. Marji recommends; you decide.
Cancellation, stated plainly
Billing is month to month. There is no contract, no minimum term, no cancellation fee, and no requirement to talk to anyone. Cancel from Settings in two clicks. You keep everything you paid for until the end of the current period.
After that you land on the free QR Menu plan rather than a wall. Your published menu keeps serving at the same link, you can keep editing prices and 86ing dishes, your dashboard stays viewable, and your data stays exportable. What pauses is the AI engine — menu scanning, invoice scanning, recipe drafting and new price recommendations wait until you pick a paid plan again.
Getting your data out
Export your menu with its costs, margins, weekly leakage and suggested prices as CSV from the menu screen, whenever you want, on any plan including the free one. No support ticket, no export fee, no waiting period, and no different treatment on the way out than on the way in.
A tool that holds your numbers hostage is a tool you cannot leave, and a tool you cannot leave does not have to keep earning its keep. We would rather keep earning it.
Deleting your account for good
If you want everything gone rather than parked, Settings has a danger zone that does it: any live subscription is cancelled first, then a single transaction removes your restaurants and everything under them — recipes, invoices, menus, audit history — along with your account, which signs you out everywhere. Uploaded files are deleted afterwards.
One record deliberately survives: if you asked us not to email you, that suppression outlives the account. Deleting your data should never quietly re-subscribe you to anything.
What we have not done
We hold no SOC 2, ISO 27001, HIPAA or PCI certification, and we have not begun one. We are not going to imply otherwise with a badge or an “in progress” that means nothing.
Two-factor authentication is not available yet. The server-side support exists but there is no enrolment screen, so no account can turn it on today — we would rather say that than let you assume it is there.
We do not publish an uptime percentage or a contractual SLA. We have not been running long enough for either number to mean anything, and a fabricated one would be worse than none.
Short answers
- Do you sell my data?
- No. We do not sell your restaurant data, your costs, your supplier invoices or your contact details to anyone, and we do not share them with other restaurants or with your vendors. There is no aggregate-data product, no data brokerage, and no arrangement where a supplier pays to see what you pay.
- Can another restaurant see my prices?
- No. Every row of restaurant data is scoped to your restaurant, and queries are filtered by that scope before they run. Your recipes, invoices, costs and margins are visible to you and to anyone you invite to your restaurant. Nobody else.
- How do I cancel?
- Settings, two clicks, no phone call and no retention queue. Billing is month to month with no contract and no cancellation fee. You keep access until the end of the period you already paid for, then you land on the free QR Menu plan — your menu stays live and your data stays exportable.
- What happens to my data if I leave?
- Nothing is deleted when you stop paying. Your dashboard stays viewable, your QR menu keeps serving, and your menu and cost data stays exportable as CSV. If you want everything gone instead, delete your account in Settings and it is removed — restaurants, recipes, invoices, and the account itself — in one transaction.
- Are you SOC 2 certified?
- No. We hold no SOC 2, ISO 27001, HIPAA or PCI attestation, and we have not started one. Saying so is more useful to you than a badge we would have to qualify. If a certification becomes a requirement for you, tell us — that is the kind of thing that moves a roadmap.
- How fast will someone answer my email?
- support@marji.co is read by a person, not a queue robot. We aim to reply within one business day, and same day for anything that stops your published menu from working — put that in the subject line and it jumps the queue. Operator plans get priority. We do not publish a contractual response SLA because we are small enough that we would rather beat an honest expectation than defend a promised one.
Found a vulnerability?
Email sales@marji.co with “SECURITY” in the subject, or read /.well-known/security.txt. We will acknowledge you, fix it, and credit you if you want the credit.
The rest of the paperwork
- Privacy policy — the canonical list of what we collect and who processes it
- Terms of service
- System status — checked live, not a permanently green dashboard
- Changelog — including the fixes that were our fault
- Editorial policy — how we source every number we publish
This page describes how Marji operates today. When something on it changes — a new processor, a gap closed, a certification actually obtained — it changes here and in the changelog, not quietly.
