Privacy Policy

Last updated: April 2026

Who We Are

DineCard is a digital menu platform that helps restaurants create, manage, and share beautiful online menus. Our website is dinecard.in. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our platform, whether as a restaurant owner, a visitor scanning a QR menu, or a visitor to our website.

Information We Collect

Account Information

When you sign up via Google OAuth, we receive your name, email address, and profile picture from your Google account. This is used to create and authenticate your DineCard account.

Restaurant Information

You provide your restaurant name, URL slug, city, phone number, and optionally a logo. This information powers your public menu page and your dashboard.

Menu Content

You create and manage menu categories, items, prices, descriptions, and item photos. This content is displayed publicly on your menu page.

Payment Information

Subscription payments are processed by Razorpay (for India) or Dodo Payments (for all other regions). We store only the subscription ID and customer ID needed to manage your subscription. We never store your card number, CVV, or full payment details — those are handled entirely by our PCI-compliant payment processors.

Usage Data

We collect event data to understand how the platform is used and to improve it. This includes onboarding steps, subscription events, the event name, associated metadata, page URL, and user agent string. We also collect page views via Vercel Analytics (which does not use cookies). IP addresses are used for rate limiting only and are stored in-memory — they are never persisted to a database.

Menu Visitor Data

When someone scans a QR code and views a restaurant's menu, we collect only the user agent and referrer headers along with a timestamp for the restaurant's analytics dashboard. Menu visitors are completely anonymous — no login, no cookies, and no personal identification.

Support Chat Data

If you use our support chat, your messages are processed by Anthropic's Claude AI to generate responses. Chat messages are not stored in our database — they are ephemeral and exist only for the duration of the conversation.

How We Use Your Information

  • To provide and maintain the DineCard platform and your digital menu
  • To authenticate your identity and manage your account
  • To process subscription payments through Razorpay or Dodo Payments
  • To send important service-related notifications (e.g., subscription changes, outages)
  • To improve our service through aggregated analytics and performance monitoring
  • To provide AI-powered support chat assistance
  • To detect and prevent abuse, fraud, and security incidents

Cookies & Tracking Technologies

Essential Cookies

  • region — a functional cookie that stores your detected region ("IN" or "GLOBAL"), derived from the x-vercel-ip-country header. Expires after 24 hours.
  • Supabase auth cookies — essential session management cookies for logged-in users. Required for the service to function.

Analytics & Tracking

  • Google Ads — conversion tracking to measure the effectiveness of our advertising. Does not collect data until consent is granted (for non-India users).
  • Vercel Analytics — privacy-focused page view analytics that does not use cookies. Consent-gated for users outside India.
  • Vercel Speed Insights — collects Web Vitals performance metrics to help us monitor and improve page load times.

Consent

Users outside India are presented with a cookie consent banner. Non-essential tracking (Google Ads, Vercel Analytics) is only activated after you provide consent. Your preference is stored locally on your device. For full details, see our Cookie Policy.

Legal Basis for Processing (GDPR)

If you are located in the European Union or European Economic Area, we process your personal data on the following legal bases:

  • Contractual necessity — processing required to provide you with the DineCard service (account management, menu hosting, payment processing).
  • Legitimate interest — analytics to improve the service, security measures to prevent abuse, and performance monitoring.
  • Consent — non-essential cookies and marketing tracking (Google Ads) are only activated with your explicit consent.

Data Sharing & Third Parties

We work with the following trusted sub-processors to operate our service:

  • Supabase — database hosting, user authentication, and file storage
  • Google — OAuth authentication and Google Ads conversion tracking
  • Vercel — application hosting, analytics, and performance monitoring
  • Anthropic — AI processing for support chat (Claude)
  • Razorpay — payment processing for users in India
  • Dodo Payments — payment processing for users outside India

We do not sell your personal data. We do not share your data with third parties for their own advertising purposes. Data shared with sub-processors is limited to what is necessary to provide the service.

International Data Transfers

Your data may be processed in countries other than where you reside, including the United States and India. When we transfer personal data from the EU/EEA, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards as required by applicable law. All our third-party processors maintain appropriate data protection measures and certifications.

Your Rights

GDPR (EU/EEA Residents)

Under the General Data Protection Regulation, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Request erasure of your personal data
  • Restrict processing of your data
  • Data portability — receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interest
  • Withdraw consent at any time (without affecting prior processing)

CCPA (California Residents)

Under the California Consumer Privacy Act, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell your data)
  • Non-discrimination for exercising your privacy rights

India DPDPA (Indian Residents)

Under the Digital Personal Data Protection Act, you have the right to:

  • Access a summary of your personal data and processing activities
  • Correct inaccurate or misleading personal data
  • Request erasure of your personal data
  • Grievance redressal — file a complaint regarding data processing

To exercise any of these rights, contact us at support@dinecard.in. We will respond within 30 days (or sooner where required by law).

Data Retention

  • Account data — retained while your account is active. Deleted upon request or account deletion.
  • Menu view analytics — retained for up to 2 years, then automatically purged.
  • Event logs — retained for up to 1 year for service improvement, then deleted.
  • Support chat messages — not stored. Messages are ephemeral and are not persisted beyond the active conversation.

Children's Privacy

DineCard is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@dinecard.in and we will promptly delete it.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice on the service before the changes take effect. We encourage you to review this page periodically for the latest information.

Contact

If you have any questions about this Privacy Policy, your data, or wish to exercise your rights, contact us at support@dinecard.in.