Your data,
handled with
care.
Two roles.
Stated plainly.
DineSights is a platform used by independent restaurants. That means we handle information in two distinct capacities, and it matters which one applies.
On behalf of restaurants
When a diner joins a specific restaurant’s guest list — visits, loved dishes, reward progress — we process that information as a service provider (processor) for that restaurant. The restaurant decides how to use its own guest list; we act on its instructions and on these terms.
On our own behalf
For our website, owner accounts, security, billing, support, and the platform-level diner profile that verifies phone numbers, we act as the business (controller) — the decisions and the responsibility are ours.
Restaurants on DineSights are independent businesses with their own practices. When you share information with a restaurant — on paper, in person, or through DineSights — that restaurant also holds it under its own policies, which we don’t control.
The information
that lives in DineSights.
We collect only what the product visibly uses. There are no hidden profiles: what you see below is the inventory.
If you view a menu
- No name, no phone number, no account.
- Standard technical logs: IP address, browser type, pages requested — kept for security and to run the service.
- Anonymous menu interactions (e.g., which dishes are viewed), tied to a session rather than to you, unless you sign in.
If you join as a diner
- First name and mobile phone number, which you enter yourself.
- Records that your number was verified by one-time code.
- Per restaurant you join: visit history, loved dishes, menu interactions, and reward progress.
- Your text-message opt-in and opt-out status.
If you run a restaurant
- Owner name and mobile number; restaurant name, city, and details.
- Your menu — sections, dishes, prices, photos you upload.
- Billing email and subscription state. Card details go directly to Stripe; we never see or store card numbers.
- Support conversations you have with us.
Viewing a menu is anonymous. Joining shares a first name and phone number — that’s the whole identity. Owners add their menu and billing email. Nothing is collected that the product doesn’t visibly use.
Cookies: essential
only. Literally.
DineSights sets first-party cookies that sign you in and remember setup progress. There are no advertising cookies, no third-party analytics, and no cross-site tracking pixels — on any surface.
- Diner session cookies (
dinesights_diner_session, and one per restaurant you join) — keep you signed in on a menu for up to 90 days. - Owner session cookie (
dinesights_owner_session) — keeps restaurant owners signed in to the dashboard. - Admin session cookie (
dinesights_admin_session) — staff access to internal tools. - Onboarding draft cookie (
dinesights_onboarding_draft) — remembers in-progress restaurant setup.
All are httpOnly, first-party, and used solely to operate the service. Because none are used for advertising or analytics, there’s no cookie banner to click — there’s nothing to opt out of that wouldn’t break sign-in itself. Blocking cookies in your browser prevents signing in but doesn’t affect viewing menus.
The reasons
each piece exists.
Every use ties to running the product you can see. We do not sell personal information, and we do not use it for third-party advertising.
To run menus & the QR experience.
Serving the right restaurant’s menu when a code is scanned, with the dishes, prices, and photos its owner published.
To recognize returning diners.
If you joined a restaurant, your verified phone number is how that restaurant’s menu recognizes you across visits and tracks your rewards there.
To give each owner a view of their own diners.
Visit counts, segments (new, regular, quiet), and reward progress — computed only from that restaurant’s own guest list.
To send the texts you asked for.
One-time security codes when you request them; a restaurant’s texts only if you separately opted in. Details in the SMS & Diner Terms.
To secure and operate the service.
Verifying phone ownership, rate-limiting abuse, keeping request logs, and debugging real problems.
To bill restaurants and provide support.
Subscription state from Stripe tells us whether a menu stays live; support threads let us follow up on your questions.
For people in the United Kingdom, we rely on contract to provide accounts, menus, rewards, and billing; legitimate interests to secure, support, and improve the service; consent for restaurant marketing texts; and legal obligation where we must keep tax, accounting, or regulatory records. A restaurant is responsible for choosing and documenting the lawful basis for its own guest-list activity when it acts as controller. You may withdraw consent at any time without affecting processing that was lawful beforehand.
How your profile works
across restaurants.
This part is easy to get wrong, so here it is exactly.
When you first verify your phone number, DineSights creates a single platform-level diner profile keyed to that number — your name and the fact that the number is verified. If you later join a second DineSights restaurant, you won’t re-enter your name: the platform recognizes the verified number and asks whether you want to join that restaurant too.
Your history at each restaurant — visits, loved dishes, rewards — is kept separately per restaurant. Each restaurant sees only its own guest list: your visits there, your rewards there. No restaurant can see which other restaurants you’ve joined, what you ordered elsewhere, or that you exist anywhere else at all. The platform-level profile exists to verify your number once and to let you manage your data in one place — DineSights operates it as a controller, and never uses it to market one restaurant to another restaurant’s diners.
One verified phone number, one DineSights profile — but every restaurant relationship is its own sealed room. Restaurants never see through the walls.
Who else sees
what.
We share personal information only with the restaurant you chose to join, the service providers below, and — where the law genuinely requires — authorities.
Supabase
Hosts our database and uploaded menu images, on infrastructure in the United States (AWS). This is where the data described above lives.
Twilio
Delivers text messages — one-time security codes and, where you opt in, restaurant texts. Phone numbers pass through Twilio for delivery purposes only.
Stripe
Processes restaurant subscription payments. Card details are entered with and held by Stripe; we receive subscription status and a customer reference.
Railway
Hosts the DineSights application itself, with standard server request logging.
No mobile information will be shared with, sold to, or transferred to third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are excluded from any sharing described in this policy, other than to the delivery provider (Twilio) strictly to send the messages you requested — and one restaurant’s opt-ins are never shared with, or usable by, another restaurant.
DineSights is operated from and hosted in the United States, so UK personal data may be transferred outside the United Kingdom. For each US recipient, we use an available UK transfer mechanism: the UK Extension to the EU-US Data Privacy Framework only where the recipient is currently certified for that extension, or contractual safeguards such as the UK International Data Transfer Agreement or UK Addendum together with the required transfer-risk assessment. You can ask us for more information about the safeguard used for a particular provider.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising. There are no ad networks or data brokers in this product.
- Optional integrations: if a restaurant uses an optional feature (for example, AI-assisted menu enrichment or business lookup via Google Places), the specific data needed for that feature flows to that provider — menu text and business details, not diner identities.
- Legal & safety: we may disclose information if required by law, or where necessary to protect the rights, safety, or integrity of DineSights, its users, or the public.
- Business transfers: if DineSights is ever acquired or merged, personal information may transfer with it — under this policy’s commitments, with notice of any material change.
Texts, consent,
and STOP.
Text messaging has its own dedicated terms — the short version lives here.
- Entering your number and selecting Send Code consents to a one-time security code — nothing more.
- Promotional texts from a restaurant are sent only with your separate, explicit opt-in to that restaurant, are identified by restaurant name, and are never a condition of dining or of using a menu.
- Reply STOP to any message to opt out (any reasonable wording works), or email contact@dinesights.com — opt-outs are honored promptly and recorded. Message and data rates may apply.
- Full program terms: SMS & Diner Terms.
Kept while useful.
Guarded while kept.
We keep personal information while it serves the relationship it was collected for, and we delete it on verified request.
- Diner records are kept while your profile exists so your visits and rewards keep working, and are deleted on your verified request (below).
- Owner and billing records are kept for the life of the account and as required for tax, accounting, and legal obligations.
- Security logs and rate-limit records are kept for a limited operational window, then cleared or aggregated. Opt-out records are kept as long as needed to keep honoring the opt-out.
- Security measures include phone-number verification by one-time code, httpOnly session cookies, per-restaurant data isolation enforced at the database layer, encrypted transport (HTTPS), and encryption at rest by our infrastructure providers. No internet service can promise perfect security — we design so that a single mistake doesn’t expose everything.
What you can
ask for.
These apply to everyone, diner or owner. UK data-protection rights and US state rights are described below.
See your data
Ask what’s tied to your phone number and we’ll send a readable summary — visits, rewards, opt-in status — not a database dump.
Fix your data
Wrong name, wrong number, stale details — tell us and we’ll correct them.
Delete your data
We’ll delete your diner profile and its histories, keeping only what the law requires us to keep (like the record of an opt-out).
How to make a request: email contact@dinesights.com with the phone number involved. We’ll verify you control that number — usually with a one-time code — before acting. For requests under the UK GDPR, we respond without undue delay and within one month unless the law permits an extension; elsewhere we respond within the applicable statutory period, generally no later than 45 days. We do not charge except where the law permits it, and we never treat you differently for asking. If your request concerns a specific restaurant’s records, we’ll coordinate with that restaurant, or you can ask them directly.
UK rights: subject to the conditions and exceptions in the UK GDPR and Data Protection Act 2018, you may request access, correction, erasure, restriction, or portability; object to processing, including direct marketing; and withdraw consent. If you are unhappy with our response, you may make a complaint to the Information Commissioner’s Office at ico.org.uk/make-a-complaint. Please contact us first if you are comfortable doing so, so we have a chance to resolve the issue.
US state privacy laws: some states grant these rights formally (with appeal processes if a request is refused); we extend the same treatment to everyone. Because we don’t sell or share personal information for targeted advertising, there’s nothing to opt out of under those laws — but if that ever changed, this policy and a visible control would change first.
Children, changes,
& contact.
- Children. Anyone can view a menu, but DineSights is not directed to children: you must be 13 or older to create a diner profile, and we don’t knowingly collect personal information from children under 13. If we learn we have, we delete it — parents and guardians can write to us at any time.
- Changes to this policy. When this policy changes meaningfully, we’ll update the effective date above and, for significant changes affecting diners or owners, give notice on the surfaces you use before the change takes effect.
- Contact. Privacy questions and requests: contact@dinesights.com. We respond to requests from real humans.
Privacy question? Just ask.
See it, fix it, delete it — or just ask why something is collected. Write in with the phone number involved and we'll take it from there.
Send a privacy request