§ 01
Introduction
This Privacy Policy explains how DineStack ("DineStack", "we", "us") collects, uses, shares and protects information when you visit our website, request a demo, or use DineStack — our restaurant-management and POS software, including QR ordering pages, kitchen display and dashboards (the "Service").
We handle personal data in line with applicable Indian law, including the Information Technology Act, 2000 and the rules under it, and the Digital Personal Data Protection Act, 2023 as and when its provisions apply.
Two roles, one policy
§ 02
Information We Collect
We collect information you give us, information created when you use the Service, and limited information from third parties such as our Payment Processor. The main categories are explained in the next five sections.
| Category | Examples | Decides how it is used | Status |
|---|---|---|---|
| Account | Names, emails, phone numbers, logins | DineStack | Stored |
| Restaurant | Outlets, menus, prices, tax settings | DineStack | Stored |
| Guests & orders | Orders, bills, guest contact details | Your restaurant | Stored |
| Payments | Payment ID, amount, status, method type | DineStack | Limited |
| Card / UPI credentials | Card number, CVV, UPI PIN, bank passwords | Payment Processor | Never stored |
| Technical | Device, app version, IP address, logs | DineStack | Stored |
We only ask for what we need to provide and improve the Service. If you choose not to provide certain information, some features may not work.
§ 03
Account Information
- Identity & contact
- Name, work email, phone number and role of the account owner and of staff users you add.
- Login & security
- Encrypted passwords, PINs, two-step verification settings and login history.
- Demo & enquiry details
- Information you share when you request a demo or contact us, such as your name, restaurant name, preferred time and message.
- Communications
- Support tickets, emails and feedback you send us.
§ 04
Restaurant / Business Information
Details about your business that you provide to set up and run the Service, such as:
- restaurant or brand name, outlet addresses and number of locations;
- GST or other tax registration details you enter for invoicing;
- menus, item prices, taxes, discounts, table layouts and printer or device settings;
- licence and activation records for each outlet and device;
- billing contact and subscription details.
§ 05
Customer and Order Data
When your restaurant uses DineStack, the Service records orders and may record information about your guests, for example:
- order details — items, quantities, modifiers, table number, order time and status;
- bill and payment status — amount, tax, payment method type and whether it was paid;
- guest details, if your restaurant collects them — such as name, phone number, email or delivery address — for order updates, receipts or loyalty.
Your restaurant controls this data and is responsible for telling guests how it is used. If you are a guest and have questions about your data, please contact the restaurant first; we will help them respond.
§ 06
Payment Information
Payments for DineStack subscriptions are processed by Razorpay or another third-party payment processor we use (a "Payment Processor"). When you pay, you enter your payment details directly with the Payment Processor.
We do not collect or store full card numbers, CVV codes, UPI PINs, net-banking passwords or other payment credentials. We receive limited information from the Payment Processor, such as a transaction or payment ID, amount, date, status, payment method type and, where provided, the last few digits of a card, so we can confirm payments, issue invoices and handle refunds.
The same applies to payments your guests make to your restaurant through a payment provider you have connected — those credentials are handled by that provider, not stored by DineStack.
§ 07
Device and Technical Information
- device type, operating system, app version and browser type;
- IP address and approximate location derived from it;
- log data such as errors, crash reports, timestamps and pages or features used;
- identifiers for devices activated under your licence (for example, POS or kitchen display devices).
We use this to keep the Service secure, troubleshoot problems, manage licences and understand how features are used.
§ 08
How We Use Information
- Provide the Service — create accounts, run POS, ordering, kitchen and reporting features, and sync data across your devices.
- Billing — process subscriptions, issue invoices, and handle failed payments and refunds.
- Support — respond to questions, onboard your team and arrange demos you request.
- Security — detect, prevent and investigate fraud, abuse and unauthorised access.
- Improve DineStack — fix bugs and improve performance using usage and diagnostic data, aggregated or de-identified where possible.
- Communicate — send service, security and billing messages; with your permission, send product updates you can opt out of at any time.
- Legal — comply with laws, tax rules, lawful requests and to protect our rights.
We do not sell personal data, and we do not use your guests' data to market our own products to them.
§ 09
Payment Processors / Third-Party Services
We rely on trusted service providers to run DineStack. They may process personal data on our behalf, only for the purposes we specify and under appropriate confidentiality and security obligations. These include:
- Payment processing
- Razorpay or another Payment Processor, for subscription payments and refunds.
- Hosting & infrastructure
- Vercel — servers, databases and backups.
- Communications
- Resend — service emails, OTPs and notifications.
If you connect third-party integrations to your restaurant (for example, a delivery platform or accounting tool), data you choose to share with them is governed by their own privacy policies.
§ 11
Data Security
We use reasonable technical and organisational safeguards to protect information, such as encryption in transit, access controls based on roles, password hashing, monitoring and regular backups. Access to personal data within our team is limited to people who need it to do their job.
No system is completely secure. You can help by using strong passwords, giving each staff member their own login and removing access for staff who leave. If we become aware of a personal-data breach affecting you, we will notify you and the relevant authorities as required by law.
§ 12
Data Retention
We keep personal data only for as long as needed for the purposes in this policy:
- account and Restaurant Data — for as long as your account is active, and for a limited period afterwards so you can export it;
- billing and invoice records — for as long as required by tax and accounting laws;
- logs and diagnostic data — for a limited period, after which they are deleted or anonymised.
§ 13
Data Sharing
We share personal data only:
- with service providers who help us run the Service, as described above;
- with your restaurant, for data relating to that restaurant (for example, staff activity logs);
- with third-party integrations you choose to connect;
- when required by law, court order or a lawful request from a government authority;
- to protect the rights, safety and security of DineStack, our users or the public;
- in connection with a merger, acquisition or sale of assets, subject to this policy continuing to protect your data.
§ 14
User Rights
Subject to applicable law, you may have the right to:
- access the personal data we hold about you and get a summary of how it is processed;
- correct inaccurate or incomplete data, or update it;
- request erasure of data that is no longer needed;
- withdraw consent where processing is based on consent (this does not affect processing that already happened);
- nominate another person to exercise your rights in the event of death or incapacity;
- raise a grievance with us, and escalate it to the Data Protection Board of India where applicable.
To make a request, email official.dinestack@gmail.com. We may need to verify your identity before acting on it. If you are a restaurant guest, requests about data a restaurant collected should be sent to that restaurant.
§ 15
Account / Data Deletion
Account owners can ask us to close their DineStack account and delete associated data by writing to official.dinestack@gmail.com from the registered email address. Before closing, we recommend exporting any menus, order history and reports you need.
Once the request is confirmed, we will delete or anonymise your account and Restaurant Data within a reasonable time, except for information we must keep by law (such as invoices) or to resolve disputes. Copies in backups are overwritten over time as part of our normal backup cycle.
§ 16
Children's Privacy
DineStack is a business tool and is not directed at children. Account holders must be at least 18. We do not knowingly collect personal data from children through our website or account sign-up. If you believe a child has provided us personal data, contact us and we will delete it.
Restaurants using guest-facing features are responsible for complying with applicable rules if they knowingly collect data relating to children.
§ 17
Policy Updates
We may update this Privacy Policy to reflect changes in the Service or the law. If changes are material, we will notify you by email or in the Service before they take effect. The "Last Updated" date at the top shows the latest version.
§ 18
Contact / Grievance Information
For privacy questions or requests, contact us at official.dinestack@gmail.com.
—Grievance Officer
If you have a complaint about how your personal data is handled, you can contact our Grievance Officer:
- Name: Navdeepak
- Email: official.dinestack@gmail.com
We will acknowledge and resolve grievances within the time required by applicable law. You can also read our Terms of Service and Refund & Cancellation Policy.