Legal

Privacy Policy

Last updated: July 5, 2026

DinePilot ("we", "us", "our") operates the DinePilot restaurant management platform, including the staff mobile app (iOS and Android), the web API, and customer QR ordering pages. This policy explains what information we collect, how we use it, and the choices you have.

Who this applies to

  • Restaurant staff and owners who sign in to the DinePilot staff app or admin features.
  • Customers who scan a table QR code and place orders without creating an account.
  • Prospective customers who submit a demo or contact request on our website.

Information we collect

Staff accounts

When a restaurant owner creates staff accounts, we store name, email address, role, restaurant membership, and a hashed password. We also store authentication tokens used to keep you signed in to the app.

Restaurant and operational data

Restaurants provide business details (name, address, tax identifiers where applicable), menu items, table layout, orders, payments, and analytics derived from those orders. Order line items store item names and prices at the time of ordering.

Customer QR ordering

Customers ordering via QR code do not create a DinePilot account. We process order contents, table association, optional per-item notes, and a temporary public token so the customer can view order status. We do not require customer name, phone, or email for QR ordering unless the restaurant collects it separately.

Device and usage data

Our servers receive standard request logs (IP address, user agent, timestamps) and app version information when the staff app checks for updates or maintenance status. We use this to secure the service, diagnose errors, and enforce minimum supported app versions.

Website and demo requests

If you book a demo or contact us, we collect the information you submit (such as name, email, phone, restaurant name, and message).

How we use information

  • Provide and operate the DinePilot platform (ordering, kitchen board, billing, analytics).
  • Authenticate staff and enforce role-based access within each restaurant.
  • Send real-time updates to connected clients via WebSockets.
  • Respond to support requests, demo inquiries, and account deletion requests.
  • Improve reliability, security, and product performance.
  • Comply with legal obligations.

How we share information

We do not sell personal information. We share data only:

  • Within a restaurant's authorized staff according to their role.
  • With infrastructure providers that host or deliver the service (for example, hosting, email, or push notification providers), under appropriate safeguards.
  • When required by law or to protect rights, safety, and security.

Data retention

We retain restaurant and order data while the restaurant's account is active and as needed for billing, tax, and legal compliance. When an account is deleted, we remove or anonymize associated personal data within a reasonable period, except where retention is required by law.

Security

We use industry-standard measures including encrypted transport (HTTPS), hashed passwords, tenant isolation by restaurant, and access controls. No method of transmission or storage is completely secure; please use a strong password and keep your device secure.

Your choices and rights

  • Staff accounts: ask your restaurant owner to update or remove your staff profile, or follow our account deletion process.
  • Restaurant owners: contact us to export, correct, or delete restaurant data.
  • Marketing: you may opt out of non-essential communications by replying to any message or emailing us.

Children

DinePilot is a business service for restaurants and is not directed at children under 13. We do not knowingly collect personal information from children.

Changes

We may update this policy from time to time. We will post the revised version on this page and update the "Last updated" date.

Contact

Questions about this policy? Email mail@truelytech.com or visit our contact page.