Privacy Policy

Last updated: 10 July 2026

This policy explains what personal data Dinor collects, why it is collected, where it is stored and what rights you have over it. It is written to reflect how the platform actually works — nothing more, nothing less. Dinor is operated by Dinor, an independent software business founded and operated by Joshua Kuriakose, based in Kottayam, Kerala, India("we", "us").

1. Who this policy covers

Dinor is a QR-based table ordering and restaurant management platform. It handles data for three kinds of people:

  • Restaurant owners — the account holders who register a business on Dinor.
  • Restaurant staff — managers and staff added to a restaurant by its owner.
  • Diners — customers who scan a table QR code to order. Diners never create accounts.

2. Data we collect

From restaurant owners: name, email address, phone number (optional), a password (stored only as a bcrypt hash — we cannot read it), business name, branch details (name, address, contact details), optional GST/tax ID, subscription and payment historyand support tickets you raise.

From restaurant staff: name, 10-digit phone number (used to sign in), optional email and a password (bcrypt-hashed). Staff accounts are created by the restaurant owner or manager — if you are staff, your employer added you.

From diners: the name and 10-digit phone number entered when starting a table session, your orders and the resulting bill. That is all. Diners do not create accounts and we do not collect diner emails, addresses or payment card details.

Generated by the platform: order and billing records, receipts, uploaded menu images, minimal audit logs (e.g. session opened/closed, order placed, bill paid) and one-time verification codes (stored only as expiring hashes).

3. What we do NOT collect

  • No analytics, advertising or behavioural tracking of any kind — the platform contains no third-party trackers, pixels or ad SDKs.
  • No tracking cookies — see the Cookie Policy; sessions use your browser's local storage instead.
  • No payment card numbers — card and UPI payments are processed entirely by Razorpay; card data never touches Dinor's servers.
  • No location tracking, contact-list access or device fingerprinting.

4. How we use data

  • Operating the service: signing you in, resolving table QR codes, routing orders to the right restaurant, computing bills and generating receipts.
  • Diner identity at the table: the name/phone a diner enters is shown to that restaurant's staff (as "Table · Name · Phone") so they can verify and serve the order and is used to recover an active session on the same phone.
  • Transactional email: account verification codes and password-reset codes are sent via Resend from noreply@dinor.in. We do not send marketing email.
  • Billing: processing subscription payments through Razorpay and keeping the records the law requires.
  • Support and safety: responding to tickets, preventing abuse (e.g. rate-limiting PIN and code attempts) and maintaining audit logs.

We do not sell personal data, share it with advertisers, or use it to train AI models.

5. Who can see diner data

Order details and the name/phone entered at a table are visible to the restaurant you ordered from (its owner, managers and staff, limited by their roles). Restaurants are independent businesses responsible for how they handle information about their own customers. Dinor's platform administrators can access records only for operating, securing and supporting the service.

6. Where data is stored (including outside India)

Dinor uses established infrastructure providers, each processing data only to provide their service to us:

  • Supabase (PostgreSQL database) — primary data storage, hosted on AWS in the Asia-Pacific (Sydney) region. This means platform data is stored outside India.
  • Render — hosts the application API and uploaded menu images.
  • Vercel — hosts and serves the website and dashboard.
  • Razorpay (India) — processes payments; receives the amount and payment identifiers and handles your payment instrument under its own privacy policy.
  • Resend — delivers verification and password-reset emails; receives the recipient address and email content.

All data in transit is encrypted with HTTPS/TLS. See the Security page for more detail.

7. How long we keep data

  • Account data — for as long as the account exists. Unverified sign-ups that never confirm their email may be replaced or removed.
  • Orders, bills and payment records — retained while the restaurant's account exists and, after deletion requests, for as long as applicable Indian tax and accounting laws require billing records to be kept.
  • Verification codes — hashed and expire within 10 minutes; cleared on use.
  • Diner session data — kept as part of the restaurant's order history.

8. Your rights

You can ask us to access, correct or delete personal data we hold about you. Restaurant owners can edit most business data directly in the dashboard. For anything else — including full account deletion or diner data requests — see the Data Deletion Request page or email hqdinor@gmail.com. We verify requests against the email or phone number on record and respond within 30 days.

9. Children

Dinor accounts are for people 18 or older. Diners of any age may be handed a menu by a restaurant, but the only diner data we take is the name and phone number entered at the table; restaurants remain responsible for their own customer interactions.

10. Grievance & contact

Questions, complaints and data requests are handled by the operator, Joshua Kuriakose, at hqdinor@gmail.com (Kottayam, Kerala, India). If we change this policy in a way that matters, we will update the date at the top and, for significant changes, notify account holders by email or an in-product announcement.