DinePlatform ("we", "us", "our") operates the DinePlatform Client Center (the "Platform"), a software-as-a-service tool that allows restaurants and food businesses to manage and deploy their own branded online ordering apps. This Privacy Policy explains how we collect, use, and protect your information when you use our Platform.
1. Who We Are
DinePlatform is a company incorporated in the State of Delaware, United States. DinePlatform is a platform provider that supplies white-label online ordering technology to food and hospitality businesses. When you create an account on the Client Center, you become an administrator ("Merchant") of your own app instance. Your customers interact with your branded app, not with DinePlatform directly.
2. Information We Collect
When you register and use the Platform, we collect:
- Account information: your name, email address, and password (stored securely via Firebase Authentication).
- App configuration data: settings, themes, logos, menu content, pricing, and any other data you input into the Platform.
- Store and billing data: subscription plan details, billing status, and Stripe customer references. We do not store full payment card details — these are handled directly by Stripe.
- Usage data: actions taken within the Platform such as logins, configuration changes, and feature usage, for operational and security purposes.
- Communications: if you contact us for support, we retain those communications.
3. Information We Do Not Collect
Your end customers' personal data (names, addresses, payment details, order history) is processed by the app instance you operate. DinePlatform does not have direct access to your customers' personal data and is not responsible for how you handle it. You, as the Merchant, are the data controller for your customers and must maintain your own privacy policy within your app.
4. How We Use Your Information
- To provide, maintain, and improve the Platform.
- To manage your subscription and process billing via our payment provider (Stripe).
- To send you service-related communications including account notifications, plan updates, and security alerts.
- To send you marketing communications about DinePlatform products and features, if you have opted in.
- To enforce our Terms & Conditions and protect against abuse or fraud.
5. Legal Basis for Processing
We process your personal data on the following bases under applicable data protection laws in your jurisdiction:
- Contract: processing necessary to provide the Platform under our agreement with you.
- Legitimate interests: platform security, fraud prevention, and improving our services.
- Consent: marketing communications where you have opted in.
6. Data Sharing
We do not sell your personal data. We share data only with:
- Google Cloud: infrastructure, including but not limited to authentication, database, storage, cloud functions, and secret management.
- Stripe: subscription billing and payment processing.
- Uber Direct (where configured): delivery fulfillment credentials stored securely via our secrets manager.
- Cloudflare Workers: app configuration hosting.
All third-party providers are bound by data processing agreements and are required to handle your data securely.
7. Data Retention
We retain your account data for as long as your account is active. If you close your account, we will delete or anonymise your personal data within 90 days, unless we are required to retain it for legal or regulatory reasons. Billing records may be retained for up to 7 years for tax and accounting purposes.
8. Security
We implement industry-standard security measures including encrypted data transmission (TLS), Firebase Authentication with multi-factor OTP verification, and access controls that restrict data access to authorised personnel only. Sensitive credentials (such as Uber Direct API keys) are stored in Google Secret Manager and never exposed in plaintext.
9. Your Rights
Depending on the data protection laws applicable in your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Request deletion of your data (subject to legal obligations).
- Withdraw consent to marketing communications at any time.
- Lodge a complaint with the relevant data protection authority in your jurisdiction.
10. Cookies
The Platform uses only essential session cookies required for authentication. We do not use tracking or advertising cookies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email and/or a prominent notice within the Platform at least 14 days before they take effect. Continued use of the Platform after the effective date constitutes your acceptance of the updated policy.
12. Contact
For privacy-related enquiries, please contact us at privacy@dineplatform.com.
See also our Terms & Conditions.