Trust
Where your business data physically lives, who can see it and how that access is revoked. Only what works today — including an honest list of what is not there yet.
The cloud and region are set by the brand you signed up with. It is not an account setting and does not change on the fly.
Brand
cenaly.com, meni.ge
Cloud
AWS
Region
USA (us-east-1)
Account data, files and storefront delivery; site assets are served through a global CDN.
Brand
cenaly.ru
Cloud
Yandex Cloud
Region
Russia
A fully separate stack with its own sign-in: accounts are not created with the US identity provider.
Brand
Turkish brands
Cloud
AWS
Region
Germany (eu-central-1)
A regional copy of the stack closer to the market. To be clear: that is the EU, not hosting inside Turkey.
HTTPS only
The site, the workspace, storefronts and the API run over HTTPS; http addresses redirect to https.
Encrypted storage
Buckets with account data are closed to public access and encrypted at rest by the storage (AES-256).
PINs are stored as hashes
A cashier PIN is stored on the server only as an irreversible hash; passwords are checked by the sign-in service and are not part of account data.
We do not store card numbers
Cards are processed by the payment provider; we only receive the result of the payment.
Two-factor sign-in
A code from an authenticator app when signing in to the web workspace — turn it on in Settings → Access.
By default — only you. Every further level of access is granted by you and revoked by you.
Owner
Sees everything; the account moves to another owner only by an explicit transfer.
Staff by role
A role sets the sections and locations an employee sees; dismissal removes workspace access and revokes their phone extension.
Devices by code
A kitchen display or a monitor signs in with a code to a single page, without full access; the code is removed in one click.
Support — only with your consent
Only while the “Support access” switch is on and within the scope you chose; every session is logged, and revoking ends a session in progress.
Implementation partners — on request
Only on a request you approve, for a limited time and view-only by default; payments, staff permissions and exports are closed in any mode.
AI agents by API key
The key is shown once on creation and is revoked in the access settings.
Full account export
One archive with settings, catalog, orders, customers and reviews. PINs, keys and passwords are deliberately left out.
Change history beta
Editors of key sections show who changed a record and when, what exactly changed, and let you roll a version back.
Account deletion
On request to support after an export; the request is fulfilled within 30 days of confirmation.
Guest data
A cookie banner with a consent log, a legal documents builder and a “My data” screen on the storefront — for your site and menu.
We say it plainly so you can decide whether it fits your business.
A vulnerability in the platform
Write to a dedicated address, not general support. Include the page address and steps to reproduce; please do not publish details before we reply and do not download other people’s data.
security@cenaly.comIllegal content on a client site
A complaint about a page or menu hosted on the platform.
File a report →Suspected leak in your account
Change the password, revoke support access, device codes and API keys, then write to support.
Tell us about your business requirements — we will reply with what the platform covers today.
Contact usSupport: support@cenaly.com