Privacy

Privacy Policy

Last updated: 20 July 2026 · Version 1.2

Your data is yours. This page explains exactly how we handle it, in the same voice we would use if you asked us in person.

1. The short version

This page explains what Dinegram (maintained by Fluidichydra) collects, why we collect it, and what you can do about it. We keep it short because a privacy policy nobody reads protects nobody.

If you are a restaurant owner using Dinegram, this covers your account. If you are a guest who scanned a QR code at a Dinegram-powered restaurant, this covers the small amount we handle on that restaurant's behalf.

2. What we collect

We only collect what we actually need to run the service. Nothing is sold, ever.

  • Account details you give us: name, email, phone, business name, address, currency and language.
  • Menu content you upload: dish names, prices, descriptions, photos, translations and modifiers.
  • Operational data your restaurant generates: orders, order items, tables, staff logins, KOT tickets, printer settings, and invoice numbering.
  • Guest order data your customers submit through your menu: name, phone (if you ask for it), address (for delivery), table or room number, and their order.
  • Anonymous product analytics: which features are used, page performance and error reports — so we can fix what's slow or broken.

3. Why we collect it

Every piece of data has a job:

  • Account details keep your login secure and let us reach you about the service.
  • Menu and operational data are the product — without them, there is nothing to display, print or report on.
  • Guest order data lets your restaurant fulfil the order and, where legal, contact the guest for delivery or follow-up.
  • Analytics tell us where the product needs work. It is aggregated and never tied to an individual guest.

4. Who is responsible for what

For your restaurant's account, Dinegram is the data controller — we decide how the platform data is used.

For guest orders placed through your Dinegram menu, your restaurant is the controller and Dinegram is the processor — we hold that data on your behalf and act on your instructions.

5. Who we share data with

We use a small, deliberate list of infrastructure providers. Each one is chosen for security and reliability, and each one processes your data only as needed to keep Dinegram running:

  • Supabase — our database and authentication backend.
  • Cloudflare — hosting and edge delivery of the platform.
  • Google AI (Gemini via the Lovable AI Gateway) — powering menu translation, image generation and blog assistance, only when you invoke those features.
  • Razorpay — payment processing for subscription billing.

We do not sell your data, we do not rent it, and we do not use it to train third-party advertising models.

6. Where we store it

Data is stored on managed infrastructure in secure data centres. We use encryption in transit (TLS 1.2+) and at rest for all sensitive fields. Passwords are hashed with modern algorithms — we never see them in plain text.

Automated backups run daily and are kept for a rolling 30-day window.

7. How long we keep it

  • Active account data: for as long as your account is open.
  • Guest order data: for as long as your restaurant chooses to keep it — you can delete individual orders from your dashboard at any time.
  • Closed accounts: production data is removed within 30 days of closure. Anonymised aggregates may be retained for analytics.
  • Financial records (invoices, payments): retained for as long as tax law requires (typically up to 7 years).

8. Your rights

Wherever you are, you can:

  • Ask for a copy of the personal data we hold about you.
  • Ask us to correct anything that's wrong.
  • Ask us to delete your account and its data (subject to legal retention).
  • Withdraw consent for anything you previously opted in to.
  • Object to any processing you think is unfair.

To exercise any of these rights, write to privacy@dinegram.com from the email on your account. We respond within 15 working days, usually much faster.

9. Cookies and similar tech

We use a small number of cookies: a session cookie to keep you logged in, and a preference cookie for your language and theme. We do not use third-party advertising cookies.

If we add any additional analytics that identify individuals in future, we will ask for your consent first and update this page.

10. Children

Dinegram is not intended for children under 13. We do not knowingly collect personal data from anyone under 13. If you believe a child has given us data, write to us and we will remove it.

11. Changes to this policy

When we change this policy, we update the 'last updated' date at the top and — for material changes — notify account holders by email or an in-app banner. The current version always lives at this URL.

12. Contact

Data-protection questions: privacy@dinegram.com. General support: support@dinegram.com. We are a small team and read every message.

Want to see our terms too? Read the Terms & Conditions →