/ Legal

Privacy Policy and Data Security

Effective Date: August 18, 2026
Last Updated: August 18, 2026

Dine OS (“Dine OS”, “we”, “us”, or “our”) operates the restaurant management platform at dineos.co. We provide digital menus, POS, ordering, delivery, staff management, payroll, loyalty and membership, CRM, WhatsApp ordering, analytics, and other restaurant-management services.

We are committed to protecting the privacy, confidentiality, and security of information handled through our platform.

Dine OS is operated from Savar, Dhaka, Bangladesh, and this policy is governed by the laws of Bangladesh.


1. Our Role in Data Processing

Dine OS may act in two different roles.

As a Controller

We act as the controller of information relating to our own customers and users, including restaurant account information, owner and staff accounts, subscription and billing records, and platform usage and security information.

As a Processor

Restaurants using Dine OS may collect information about their own customers through our platform. In these situations, the restaurant determines what information it collects and why, while Dine OS processes that information to provide the requested services.

If you are a restaurant customer and have a request concerning your personal information, please contact the restaurant you interacted with first. We will assist the restaurant and respond directly where required by applicable law.


2. Information We Collect

Depending on the services used, Dine OS may collect or process the following categories of information.

Account & Business Information

  • Name
  • Email address
  • Phone number
  • Restaurant or business name
  • Branch addresses
  • Business information
  • Subscription plan and status
  • Chosen subdomain or custom domain
  • Logo and other brand assets
  • Account credentials and security information

Staff & Employment Information

Restaurants may enter information about their employees and staff, including:

  1. Names and contact details
  2. Roles and permissions
  3. Attendance records
  4. Salary and payroll information
  5. Employment information
  6. Identity or employment documents uploaded by the restaurant

Identity documents are stored privately and are accessible through protected, short-lived signed links rather than public folders.

Customer & Guest Information

Depending on the features enabled by a restaurant, we may process:

  • Customer name
  • Phone number
  • Delivery address
  • Approximate location coordinates
  • Order history and order totals
  • Membership number
  • Loyalty points
  • Membership or wallet balance
  • Wallet top-up information
  • Sending mobile number
  • Transaction references
  • Feedback and ratings
  • Song or music requests
  • Waiter-call requests
  • Lost-and-found reports

Rider Information

For restaurants using local delivery services, Dine OS may process:

  • Rider identity
  • Assigned delivery zone
  • Live delivery location while a delivery is active

Live rider location tracking is limited to the active delivery and does not continue in the background after the delivery has ended.

Payment & Financial Information

We may process:

  • Subscription invoices
  • Payment amounts
  • Currency
  • Payment status
  • Mobile financial service references
  • Bank transaction references
  • Wallet and membership transaction records

Dine OS does not collect or store card numbers, CVV codes, PINs, or bank login credentials.

Payments are processed through the applicable payment provider. We may retain transaction references necessary to match payments with invoices or transactions.

Technical & Security Information

We may collect:

  • IP address
  • Device information
  • Browser type
  • Login timestamps
  • Device fingerprints used for session management
  • New-device registrations
  • Login attempts
  • Pages and API endpoints accessed
  • Error diagnostics
  • Security and audit information

Communications

We may process communications sent to us or through our platform, including:

  • Support emails
  • Facebook messages
  • WhatsApp messages
  • SMS messages
  • Transactional communications
  • Delivery notifications
  • Message delivery results

3. How We Use Information

We use information to:

  • Provide and operate Dine OS services.
  • Create and manage accounts.
  • Manage restaurants, branches, menus, staff, and orders.
  • Process subscriptions and payments.
  • Maintain membership and wallet services.
  • Send order updates, receipts, verification codes, password resets, and other service notifications.
  • Enable restaurant-configured SMS, WhatsApp, and email communications.
  • Support delivery and live order tracking.
  • Provide customer support.
  • Detect fraud, abuse, suspicious activity, and unauthorized access.
  • Enforce account and subscription limits.
  • Diagnose technical problems.
  • Improve platform performance, reliability, and functionality.
  • Maintain financial and transaction records.
  • Meet applicable legal, tax, accounting, and regulatory requirements.

We do not sell personal data and do not share restaurant customer data with advertisers.

We also do not use one restaurant's customer data to benefit another restaurant.


4. Marketing Communications

Restaurants may use Dine OS to send promotional or marketing messages to their own customers.

The restaurant is responsible for ensuring that it has the appropriate permission or legal basis to send such communications.

Dine OS respects customer opt-out preferences. Where a customer has opted out of marketing communications, the applicable number will be excluded from future campaigns.


5. Third-Party Service Providers

Dine OS uses selected third-party providers to operate specific parts of the platform.

These may include providers for:

  • Cloud hosting and infrastructure
  • Backup storage
  • Payment processing
  • SMS delivery
  • Email delivery
  • WhatsApp messaging
  • Error monitoring
  • Security services
  • Optional AI features

Only information reasonably necessary for the relevant service is shared with the applicable provider.

AI Features

Dine OS may offer optional AI features, including menu assistance and voice-ordering functionality.

AI features are optional and disabled by default.

When an AI feature is used, the information required to process that request, such as menu content or a typed/spoken customer request, may be sent to the relevant AI provider.

Under our agreements, information submitted for these requests is not used to train third-party AI models.

Users may disable optional AI features through the applicable Dine OS settings.


6. Cookies & Browser Storage

Dine OS uses essential cookies and browser storage to:

  • Maintain login sessions
  • Authenticate users
  • Remember selected branches
  • Remember language preferences
  • Remember theme preferences
  • Support platform functionality

We do not operate third-party advertising trackers and do not sell audience data.

Blocking essential cookies may prevent some parts of Dine OS from functioning correctly.


7. Data Security

We use reasonable technical and organizational measures designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction.

Our security measures include:

Encryption

  • TLS/HTTPS encryption for data transmitted between users and our platform.
  • Encryption of sensitive information at rest.
  • AES-256 encryption for applicable sensitive fields.
  • Secure password hashing.
  • Encrypted backup archives.

Passwords are never stored in plain text.

Access Control

  • Role-based permissions.
  • Restaurant-level data isolation.
  • Database-level access restrictions.
  • Optional two-factor authentication.
  • Device and session controls.
  • Remote logout.
  • Account blocking.
  • Protected administrative access.

Our support personnel cannot access a restaurant dashboard without appropriate authorization. Privileged and emergency access is recorded and audited.

Financial & Wallet Security

Membership and wallet transactions use additional integrity controls, including:

  • Append-only transaction records.
  • Reversal entries instead of changing historical transactions.
  • Transaction sequencing.
  • SHA-256 hash chaining.
  • Controls against negative balances.
  • Idempotency controls to help prevent duplicate charges.
  • Automated reconciliation checks.

Application Security

We also use measures such as:

  • Security headers
  • Rate limiting
  • Server-side input validation
  • Parameterized database queries
  • File-upload security controls
  • Private file access
  • Short-lived signed URLs

No online system can guarantee absolute security. However, we continuously work to protect the information entrusted to us.


8. Data Retention

We retain information only for as long as reasonably necessary to:

  • Provide our services.
  • Maintain business and transaction records.
  • Meet legal, tax, and accounting requirements.
  • Resolve disputes.
  • Prevent fraud and abuse.
  • Maintain platform security and integrity.

When information is no longer required, it may be deleted or anonymized, except where retention is required by law or necessary for legitimate business purposes.

Specific retention periods may vary depending on the type of information and applicable legal requirements.


9. Your Rights

Subject to applicable Bangladesh law, you may have the right to request:

  • Access to your personal information.
  • Correction of inaccurate information.
  • Deletion of information where applicable.
  • Export of your information.
  • Restriction of certain processing.
  • Withdrawal of consent where processing is based on consent.

Restaurant owners can manage many types of information directly through the Dine OS dashboard.

For privacy requests that cannot be handled through the dashboard, contact:

dineosofficial@gmail.com

We aim to respond to valid privacy requests within 30 days, subject to identity verification and applicable legal requirements.


10. Data Transfers & Storage

Dine OS and its service providers may process or store information using infrastructure located inside or outside Bangladesh.

Primary server location: [COUNTRY OR REGION]

Where applicable law requires additional safeguards for information processed outside Bangladesh, Dine OS will take appropriate contractual and organizational measures.


11. Security Incident Reporting

If you believe you have discovered a security vulnerability in Dine OS, please report it responsibly.

Email: dineosofficial@gmail.com
Subject: Security

Please provide a description of the issue and reasonable steps to reproduce it.

We will review reported security concerns and take appropriate action.


12. Security Incidents & Data Breaches

If we determine that a security incident has affected personal information, we will take reasonable steps to contain, investigate, and remediate the incident.

Where notification is required by applicable law, we will notify affected parties and/or relevant authorities within the required timeframe.

Where appropriate, notifications may explain:

  • What happened
  • What information was affected
  • What actions we have taken
  • What affected users should do

13. Children's Privacy

Dine OS is a business-focused platform and is not directed toward children under 16.

We do not knowingly collect children's personal information for purposes unrelated to providing our services.

If you believe that information relating to a child has been submitted to Dine OS and should be removed, please contact us.


14. Changes to This Policy

We may update this Privacy Policy & Data Security document when our services, technology, security practices, or applicable laws change.

The latest version will be published on dineos.co.

The effective date and last-updated date will be changed whenever this policy is materially updated.


15. Contact Us

Dine OS
Savar, Dhaka, Bangladesh

Email: dineosofficial@gmail.com
Website: dineos.co
Facebook: facebook.com/dineosbd
Instagram: instagram.com/dineosbd

This Privacy Policy & Data Security document is governed by the laws of Bangladesh.