DineBuddy Logo

Privacy Policy

Last Updated: January 2025

1. Introduction

Welcome to DineBuddy ("we," "our," or "us"). DineBuddy is a comprehensive restaurant management and dining experience platform that bridges the gap between restaurants and customers through innovative AI-powered technology. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services, including our website, mobile applications, QR-based ordering system, AI waiter assistant, and related services (collectively, the "Services").

We are committed to protecting your privacy and maintaining the security of your personal information. We respect your privacy rights and recognize the importance of secure transactions and information privacy. This policy describes the types of information we may collect from you or that you may provide when you visit our platform and our practices for collecting, using, maintaining, protecting, and disclosing that information.

By accessing or using our Services, you agree to this Privacy Policy. If you do not agree with our policies and practices, please do not use our Services. This policy may change from time to time, and your continued use of the Services after we make changes is deemed to be acceptance of those changes.

2. Information We Collect

A. Information You Provide Directly

We collect information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and services, participate in activities on the Services, or otherwise contact us. The personal information we collect may include:

  • Account Information: Name, email address, phone number, username, password, and other registration information.
  • Restaurant Partner Information: For restaurant owners and managers, we collect business name, restaurant address, business registration details, tax identification numbers, banking information for payments, authorized representative details, and business contact information.
  • Profile Information: Dietary preferences, food allergies, favorite cuisines, spice tolerance levels, and other taste preferences you choose to share.
  • Communication Data: Feedback, ratings, reviews, support messages, survey responses, and any other information you provide when communicating with us or through our Services.
  • Payment Information: While we do not directly store complete credit card numbers or banking details, we collect billing address, payment method preferences, and transaction history. Payment processing is handled by secure third-party payment processors.

B. Information Collected Automatically

When you access our Services, we automatically collect certain information about your device and usage patterns, including:

  • Device Information: Device type, operating system, browser type and version, unique device identifiers, mobile network information, and device settings.
  • Usage Data: IP address, access times, pages viewed, page interaction information, links clicked, search queries, referring/exit pages, and other usage statistics.
  • Location Data: With your permission, we may collect precise location data to verify you are within a restaurant's service area for QR-based ordering and to provide location-based features.
  • Cookies and Tracking Technologies: We use cookies, web beacons, pixel tags, and similar tracking technologies to collect information about your browsing activities and to remember your preferences.

C. Information From QR-Based Ordering

Our QR code ordering system collects specific information to facilitate seamless dining experiences:

  • Table Information: Table number, seating area, and restaurant location automatically captured from QR code parameters.
  • Order Data: Items added to cart, order modifications, special instructions, order timestamps, order status, and order history.
  • Session Data: Duration of dining session, menu browsing patterns, items viewed, and interaction with menu categories.
  • Payment Preferences: Preferred payment methods and split payment preferences (we never store complete card details).

D. AI Waiter & Personalization Data

Our AI-powered recommendation system collects and processes data to provide personalized dining experiences:

  • Order History: Complete history of past orders, frequency of orders, favorite dishes, and ordering patterns across different restaurants and times.
  • Preference Data: Explicitly stated likes and dislikes, cuisine preferences, dietary restrictions, spice level preferences, and ingredient preferences or aversions.
  • Behavioral Patterns: Frequently ordered categories, typical order times, average order values, and seasonal ordering trends.
  • Interaction Data: Conversations with AI waiter, questions asked, recommendations accepted or declined, and feedback on suggestions.
  • Restaurant Popularity Data: Aggregated and anonymized data about popular items, trending dishes, and customer satisfaction metrics.
Important: All AI personalization features are completely optional. You can disable personalized recommendations at any time in your account settings without affecting your ability to use our core ordering services.

3. How We Use Your Information

We use the information we collect for various purposes, including:

  • Service Delivery: To display digital menus, process QR-based orders, manage table assignments, facilitate order fulfillment, and enable seamless dining experiences.
  • Restaurant Operations: To provide restaurant partners with order management dashboards, kitchen display systems, real-time order notifications, and operational analytics.
  • Personalization: To provide AI-powered personalized menu recommendations, suggest dishes based on your preferences and history, remember your favorite items, and tailor the user experience to your tastes.
  • AI Enhancement: To train and improve our AI waiter's conversational abilities, enhance recommendation algorithms, and develop new AI-powered features.
  • Analytics: To generate insights for restaurants about popular items, peak hours, customer satisfaction, and operational efficiency (without revealing individual customer identities).
  • Communication: To send order confirmations, status updates, account notifications, respond to customer support inquiries, and provide important service announcements.
  • Marketing: With your consent, to send promotional offers, new feature announcements, and restaurant partner updates (you can opt out at any time).
  • Security: To detect and prevent fraud, unauthorized access, security breaches, and other malicious activities.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests.
  • Business Operations: To maintain and improve our Services, develop new features, conduct research and analysis, and ensure platform stability and performance.

4. How We Share Your Information

We may share your information in the following circumstances:

With Restaurant Partners

We share necessary order information with restaurants to fulfill your orders, including your order details, table number, special instructions, and contact information (only when required for order delivery or clarification). We do not share your complete order history or personal preferences with restaurants unless you explicitly consent.

With Service Providers

We engage trusted third-party service providers to perform functions on our behalf, including:

  • Payment Processors: Secure payment gateways that handle transaction processing (they receive only information necessary to process payments).
  • Cloud Hosting: Infrastructure providers that host our databases and applications.
  • Analytics Services: Tools that help us understand usage patterns and improve our Services (using aggregated, non-personally identifiable data).
  • Communication Services: Email and SMS providers for sending notifications and updates.
  • Customer Support: Help desk and support ticket management systems.

For Legal Reasons

We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to government requests.

Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.

What We DO NOT Do

  • We DO NOT sell your personal information to third parties for their marketing purposes.
  • We DO NOT share your individual identity with restaurants beyond what is necessary for order fulfillment.
  • We DO NOT provide your personal data to advertisers or marketing companies without your explicit consent.
  • We DO NOT share your AI interaction data or personalization preferences with external parties.

5. Data Security Measures

We implement comprehensive security measures to protect your personal information from unauthorized access, alteration, disclosure, or destruction:

  • Encryption: All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols. Sensitive data at rest is encrypted using AES-256 encryption.
  • Secure Infrastructure: Our servers are hosted in secure, certified data centers with physical security controls, redundant systems, and regular backups.
  • Access Controls: We implement strict access controls ensuring that only authorized personnel with legitimate business needs can access personal information. All access is logged and monitored.
  • Authentication: We use secure authentication mechanisms including password hashing, multi-factor authentication for administrative access, and session management protocols.
  • Regular Audits: We conduct regular security audits, vulnerability assessments, and penetration testing to identify and address potential security risks.
  • Employee Training: Our team members receive regular training on data protection, privacy practices, and security protocols.
  • Incident Response: We maintain an incident response plan to quickly address any security breaches and notify affected users as required by law.
Important: While we implement robust security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we continuously work to protect your information using industry best practices.

6. Your Privacy Rights

You have several rights regarding your personal information:

  • Right to Access: You can request a copy of the personal information we hold about you, including order history, preferences, and account details.
  • Right to Rectification: You can request correction of inaccurate or incomplete personal information.
  • Right to Deletion: You can request deletion of your personal information, subject to certain legal exceptions (e.g., transaction records required for accounting purposes).
  • Right to Restriction: You can request that we limit how we use your personal information in certain circumstances.
  • Right to Data Portability: You can request a copy of your data in a structured, machine-readable format to transfer to another service.
  • Right to Object: You can object to our processing of your personal information for direct marketing or other purposes based on legitimate interests.
  • Right to Opt-Out: You can disable personalized recommendations, opt out of marketing communications, and withdraw consent for optional data processing at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have violated your privacy rights.

To exercise any of these rights, please contact us using the information provided in Section 13. We will respond to your request within 30 days and may require verification of your identity before processing your request.

7. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our Services:

Types of Cookies We Use

  • Essential Cookies: Required for basic functionality, including user authentication, session management, security features, and QR code table session tracking. These cannot be disabled without affecting core functionality.
  • Preference Cookies: Remember your settings, language preferences, and customization choices to provide a personalized experience.
  • Analytics Cookies: Help us understand how visitors interact with our Services, which pages are most popular, and how users navigate through the platform. This data is aggregated and anonymized.
  • Marketing Cookies: Used to deliver relevant advertisements and track campaign effectiveness (only with your consent).

Managing Cookies

You can control cookies through your browser settings. Most browsers allow you to refuse cookies or delete existing cookies. However, disabling certain cookies may limit your ability to use some features of our Services, particularly QR-based ordering and personalized recommendations.

8. Children's Privacy

DineBuddy is not intended for use by children under the age of 13 without parental supervision. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information without your consent, please contact us immediately, and we will take steps to delete such information from our systems.

For users between 13 and 18 years of age, we recommend parental guidance when using our Services, particularly when making orders or providing personal information.

9. AI System Transparency

As a platform utilizing artificial intelligence for personalized recommendations and customer service, we believe in transparency about how our AI systems work:

How Our AI Works

  • Automated Responses: Our AI waiter provides automated conversational responses based on natural language processing and machine learning algorithms. While designed to be helpful and accurate, AI responses may occasionally contain errors or misunderstandings.
  • Learning Mechanisms: Our AI uses interaction patterns, order history, and feedback to continuously improve recommendations and responses. The system learns from aggregated user behavior while respecting individual privacy.
  • Data Usage: AI algorithms process your order history, stated preferences, and interaction patterns to generate personalized recommendations. This processing occurs on secure servers and is subject to the same security measures as other personal data.
  • Anonymization: Where possible, data used for AI training and improvement is anonymized and aggregated to protect individual privacy while enhancing system performance.
  • Human Oversight: Our AI systems are regularly monitored and reviewed by human teams to ensure accuracy, fairness, and compliance with our values and policies.

Your Control Over AI Features

  • You can disable AI personalization at any time in your account settings.
  • You can clear your preference data and start fresh.
  • You can provide feedback on AI recommendations to improve accuracy.
  • You can choose to interact with human support instead of AI assistance.

10. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law:

  • Account Data: Retained while your account is active and for a reasonable period afterward to facilitate account reactivation if desired.
  • Order History: Retained for accounting, tax, and legal compliance purposes, typically for 7 years from the transaction date.
  • Communication Records: Customer support interactions retained for quality assurance and dispute resolution, typically for 2-3 years.
  • Analytics Data: Aggregated and anonymized analytics data may be retained indefinitely for business intelligence and service improvement.
  • AI Training Data: Anonymized data used for AI training may be retained to maintain and improve system performance.

You can request deletion of your personal information at any time by contacting us. Upon receiving a valid deletion request, we will delete or anonymize your personal information within 30 days, except where retention is required by law or for legitimate business purposes (such as completing transactions or resolving disputes).

11. International Data Transfers

DineBuddy operates primarily in India, and your information may be transferred to, stored, and processed in India or other countries where our service providers operate. These countries may have data protection laws that differ from those in your country of residence.

When we transfer personal information internationally, we implement appropriate safeguards to ensure your data receives adequate protection, including standard contractual clauses approved by relevant authorities.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Last Updated" date at the top of this policy and provide you with an opportunity to review the updated policy.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

DineBuddy Privacy Team

General Inquiries:

hellodinebuddy@gmail.com

Response Time:

We aim to respond to all privacy-related inquiries within 48 hours.

Effective Date: This Privacy Policy is effective as of January 1, 2025, and applies to all information collected by DineBuddy from that date forward. By using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.