Privacy Policy
How [LEGAL ENTITY NAME] handles personal data about restaurant users of Dinebase.
Version 1.0 · Last updated 2026-07-27
This policy explains how [LEGAL ENTITY NAME] (org. no. [ORG. NUMBER]), [REGISTERED ADDRESS], handles personal data when you use Dinebase as a restaurant user. Guest data is covered separately in the Guest Privacy Notice and the Data Processing Agreement.
1. Controller
[LEGAL ENTITY NAME] is the controller for personal data about account holders, restaurant staff and website visitors. For reservation data about Guests, the restaurant is the controller and [LEGAL ENTITY NAME] acts as processor.
Contact for privacy matters: [PRIVACY EMAIL].
2. What we collect
| Category | Examples |
|---|---|
| Account data | Name, email address, optional phone number, password hash, email verification status |
| Workspace data | Restaurant name, role, invitations, permissions |
| Usage and technical data | IP address, browser and device information, session and login records, device identifiers used for shared-device mode |
| Support and communications | Messages you send us, emails we send you and their delivery status |
| Billing data | Subscription tier, invoices, payment status, usage counts. Card details are handled by our payment provider and never stored by us |
| Content you enter | Settings, notes, templates, floor plans and other information you add to your workspace |
3. Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing the service and your account | Performance of a contract |
| Billing, invoicing and collection | Performance of a contract; legal obligation |
| Security, abuse prevention and audit logs | Legitimate interest in protecting the service |
| Service emails, verification and important notices | Performance of a contract |
| Support and troubleshooting | Performance of a contract; legitimate interest |
| Product improvement and aggregated statistics | Legitimate interest |
| Accounting records | Legal obligation |
We do not sell personal data and we do not use your data or your Guests' data to train third-party AI models.
4. Who we share it with
We share personal data with the providers listed in the Sub-processor List — hosting and database, email delivery, SMS delivery, payment processing, maps and AI features — strictly to run the service. We may also share data where required by law or to establish or defend legal claims.
5. International transfers
Some providers may process data outside the EU/EEA. Where that happens we rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism. Details for each provider are in the Sub-processor List.
6. Retention
- Account data: for as long as the account exists, then deleted or anonymised within 90 days of account closure.
- Workspace content: for the subscription term plus a 30-day export window, unless a longer period is agreed.
- Email delivery logs and audit logs: up to 12 months.
- Accounting and invoicing records: seven years, as required by Swedish bookkeeping law.
7. Your rights
You have the right to access your personal data, to have inaccurate data corrected, to erasure, to restriction of processing, to data portability, and to object to processing based on legitimate interest. Contact [PRIVACY EMAIL] to exercise a right; we respond within one month.
You also have the right to lodge a complaint with your supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY).
8. Security
We use encryption in transit, access control scoped to your workspace at the database level, role-based permissions, audit logging of sensitive actions and email verification for account changes. No service can guarantee absolute security; see the Trust page for what is actually in place today.
9. Cookies
See the Cookie Policy for the cookies and browser storage the service uses.
10. Changes
We update this policy when our processing changes. The version and date at the top of the page always reflect the current version, and material changes are notified in the application or by email.