Legal
Privacy policy
Last updated 3 October 2026
This policy explains what personal data Dinery handles, why, and the choices you have. It covers restaurants and their staff who use Dinery, guests who order through a restaurant's Dinery page, and visitors to this website.
1. Who is responsible for what
Guest data. When a guest orders at a restaurant through Dinery, the restaurant decides why and how that guest's data is used. Under the Digital Personal Data Protection Act, 2023, the restaurant is the data fiduciary and Dinery acts as its data processor, handling the data only on the restaurant's instructions and to provide the service.
Restaurant and staff data. For the accounts restaurants and their staff use to run Dinery, and for enquiries made on this website, Dinery is responsible for the data.
2. What we collect
From guests
- Mobile number, used to sign in with a one-time code
- Name, email and date of birth, only if the guest chooses to provide them
- Orders, visits, table, payments made, points earned and reviews left
- Consent choices for messages, with the date they were given or withdrawn
From restaurants and staff
- Names, email addresses, phone numbers and roles of people with access
- Shift times, attendance and, where the owner records them, pay details
- Business details needed for invoices and GST, such as GSTIN and address
From website visitors
- Details you send us through the contact form, email or WhatsApp
- Basic technical information such as browser type, used to keep the site working
Card and UPI details are entered on Razorpay's secure payment pages. Dinery does not receive or store full card numbers or UPI PINs.
3. How the data is used
- To take orders, send them to the kitchen, process payments and show order status
- To award and redeem loyalty points, gift cards and wallet credit
- To send order updates, and marketing messages only to guests who agreed to receive them
- To give restaurants reports on their own sales, guests and staff
- To provide support, prevent fraud and keep the service secure
- To meet legal duties, such as tax records
5. How long it is kept
Guest and order data is kept for as long as the restaurant uses Dinery, and then deleted or returned to the restaurant within 90 days of the account closing, except where we must keep records for longer by law, such as tax and accounting records.
6. Your choices and rights
- Guests can stop marketing messages at any time from their profile on the restaurant's page, or by asking the restaurant
- You can ask to see, correct or delete your personal data
- You can withdraw consent you gave earlier; this does not affect what was done before
- You can nominate someone to exercise these rights on your behalf
Guests should usually contact the restaurant first, since the restaurant controls their data. You can also write to us and we will help, or pass your request to the restaurant.
7. Security
Data is sent over encrypted connections. Staff access is limited by role, passwords are stored only as salted hashes, sessions expire, and changes such as refunds and cancellations are logged. No system is perfectly secure, and we will tell affected restaurants and the authorities of a personal data breach as the law requires.
9. Grievance officer
For any question or complaint about personal data, write to our grievance officer at dinery616@gmail.com. We acknowledge complaints within 48 hours and aim to resolve them within 30 days. If you are not satisfied, you may approach the Data Protection Board of India.
10. Changes to this policy
If we change this policy in a way that matters, we will tell restaurants by email before the change takes effect.
Contact
Dinery
Email: dinery616@gmail.com