Dineo

Privacy Policy

Last updated: August 2026

1. Introduction

Dineo ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our AI-powered restaurant reservation platform, including our website, applications, and related services (collectively, the "Service").

By using our Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

2. Data We Collect

2.1 Information You Provide

  • Account information: name, email address, phone number, and password.
  • Restaurant profile data: business name, address, opening hours, and contact details.
  • Reservation details: guest names, party sizes, dates, times, and special requests.
  • Payment information: billing address and payment method details (processed by our payment provider).
  • Communications: messages, feedback, and support requests you send to us.

2.2 Information Collected Automatically

  • Device and browser information: IP address, browser type, operating system, and device identifiers.
  • Usage data: pages visited, features used, actions taken, and timestamps.
  • Cookies and similar technologies: session cookies, preference cookies, and analytics cookies.

3. How We Use Your Data

We use the information we collect for the following purposes:

  • To provide and maintain the Service, including processing reservations and managing restaurant operations.
  • To communicate with you, including sending booking confirmations, reminders, and service updates.
  • To improve and personalise the Service, including AI-powered features and recommendations.
  • To process payments and manage subscriptions.
  • To ensure the security and integrity of the Service.
  • To comply with legal obligations and enforce our terms.

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your information with:

  • Service providers: third-party vendors who assist in operating our Service (e.g., hosting, payment processing, analytics).
  • Restaurant partners: reservation and guest information shared with the restaurant you are booking with.
  • Legal requirements: when required by law, regulation, or legal process.
  • Business transfers: in connection with a merger, acquisition, or sale of assets.

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law. When data is no longer needed, we securely delete or anonymise it.

7. Your Rights

Under the GDPR and applicable data protection laws, you have the following rights:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your personal data ("right to be forgotten").
  • Restriction: request restriction of processing in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Withdraw consent: withdraw consent at any time where processing is based on consent.

To exercise any of these rights, please contact us at privacy@dineo.io.

8. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.

9. Cookies

We use cookies and similar tracking technologies to enhance your experience. You can manage your cookie preferences through your browser settings. For more information, please refer to our cookie settings within the Service.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Dineo
Email: privacy@dineo.io

12. WhatsApp data processing.

When a restaurant connects its WhatsApp Business account to Dineo, Dineo processes the following data on the restaurant’s behalf:

  • WhatsApp account data: WhatsApp Business Account and phone-number identifiers; business display, verification, quality, registration, and connection status; message-template metadata and status; and encrypted access credentials.
  • Contact data: WhatsApp phone number, profile or display name when provided by Meta, and restaurant customer/contact records associated with the conversation.
  • Message data: incoming and outgoing message content; supported media or attachment metadata; message, reply, and conversation identifiers; timestamps; delivery, read, and failure status; and operational logs needed to route, secure, and troubleshoot messages.

Dineo uses this data to connect and operate the restaurant’s WhatsApp channel, receive and route guest requests, create and send replies or templates, support restaurant communications and operations, and secure and troubleshoot the Service. Dineo processes data received through Meta/WhatsApp and shares it only as described in this Privacy Policy, including with Meta/WhatsApp and service providers needed to operate the Service.

Retention and deletion.

Dineo retains WhatsApp-related personal data only for as long as necessary for the purposes described above and to meet applicable contractual, legal, security, and dispute-handling obligations. When data is no longer needed, Dineo deletes or anonymises it. Disconnecting a WhatsApp account stops new Dineo messaging after the disconnect completes, but does not by itself delete data already stored.

To request access to or deletion of WhatsApp-related data, email privacy@dineo.io with the subject “WhatsApp data request”. Include:

  • the restaurant or business name;
  • the email address used for the Dineo account;
  • the WhatsApp Business display phone number, WABA ID, or phone-number ID, if available;
  • if the request concerns a conversation, the contact’s WhatsApp number and enough context or a date range to locate the conversation; and
  • whether the request concerns account, contact, message, or all WhatsApp-related data.

Do not send passwords, access tokens, or message content unless Dineo specifically requests it through a secure channel. Dineo may request additional information to verify the requester’s identity and authority. After verification, Dineo will locate the relevant data and delete or anonymise it where applicable, subject to records that must be retained for legal, security, fraud-prevention, or dispute-handling reasons. Dineo will confirm the outcome or explain why particular data cannot be deleted. If the request concerns data held by a restaurant, Dineo may direct the requester to that restaurant or coordinate with it.