← All policies

Sub-processors

The providers that process data on our behalf to run Dinebase.

Version 1.0 · Last updated 2026-07-27

Draft: the bracketed company details must be filled in before these documents are relied on.

We use the providers below to operate Dinebase. Each is bound by a data processing agreement and may only process data to deliver the service. We give at least 30 days' notice before adding or replacing a sub-processor.

Current sub-processors

ProviderPurposeData processedHosting region
Lovable Cloud (application platform)Application hosting, managed database, file storage, authenticationAll account, workspace and reservation dataEU, with edge delivery worldwide
ResendTransactional email deliveryRecipient name and email address, message content, delivery statusEU / US, Standard Contractual Clauses
TwilioSMS delivery, where the restaurant enables SMSRecipient phone number, message content, delivery statusEU / US, Standard Contractual Clauses
StripeSubscription billing, and card holds where a restaurant enables themBilling contact, card details (held by Stripe, never by us), payment and payout statusEU / US, Standard Contractual Clauses
Google Maps PlatformAddress autocomplete and map display on booking pagesSearch text entered by a restaurant user, and technical data when a map loadsUS, Standard Contractual Clauses
Lovable AI GatewayOptional assistant features inside the applicationOnly the text a user submits to the assistantEU / US, Standard Contractual Clauses
Guest data is never sold and is not used to train third-party AI models.

Changes

Restaurant customers can object to a new sub-processor on reasonable data protection grounds within the notice period, as set out in section 4 of the Data Processing Agreement. Write to [PRIVACY EMAIL].