This Privacy Policy explains what data Dine. collects, why we collect it, how we use it, who we share it with, and the choices you have. We follow the principle of collecting only what we need to make the Service work.
1. Data we collect
You give us:
- Account info — email address and/or phone number (used to send you the one-time login code), and optionally your full name, profile picture, city, and area.
- Booking info — restaurant, date, time, party size, special notes, and your contact name and phone for the restaurant.
- Reviews and ratings — anything you publish about a restaurant.
- Messages — content of survey responses and support requests you send us.
We collect automatically:
- IP address, device and browser type, and approximate region (used for security, rate-limiting, and fraud prevention).
- Usage events — pages you view, restaurants you tap into, search terms — to improve the recommendations and the product.
- Login session metadata (last login time, refresh-token family) for security.
We do not collect precise location unless you grant it (used only for "restaurants near me"), and we do not store payment-card numbers — payment for in-restaurant bills is settled directly with the restaurant.
2. How we use your data
- To create and operate your account.
- To deliver bookings and tell the restaurant you're coming.
- To send transactional messages — booking confirmations, reminders, cancellations, post-visit surveys.
- To improve recommendations and the product.
- To detect fraud, abuse, or breach of our Terms.
- To meet legal and tax obligations in Pakistan.
We do not sell your personal data, and we do not share it with advertisers for behavioural targeting.
3. Who sees your data
- Restaurants you book with see your name, contact phone, party size, time, and any note you add to the booking. They do not see your other bookings or your account history.
- Other users see only what is public on your profile — your name, avatar, public ratings and reviews. Phone and email are never shown to other users.
- Service providers we use to operate the Service: cloud hosting (Cloudflare, AWS-equivalent in Bahrain), SMS & WhatsApp (Twilio, 360dialog), email (SMTP / SendGrid / equivalent), error monitoring (Sentry). They process data on our behalf under written contracts.
- Legal requirements — we may disclose data when required by Pakistani law, valid court order, or to protect our rights, our users, or the public.
4. Where data is stored
Dine.'s primary servers are hosted in the Bahrain region (~50 ms from Islamabad). Backups are encrypted at rest. Some providers we rely on (e.g. SMS gateways) may process data in other countries to deliver the message; we use providers that are contractually bound to security and data-protection standards.
5. How long we keep data
- Account & profile — for as long as your account is open.
- Bookings — kept for 24 months for dispute resolution and analytics, then anonymised.
- OTP codes — hashed; deleted automatically when consumed or expired.
- Login sessions / refresh tokens — rotated continuously; old tokens revoked.
- Reviews — kept while your account is open; on account deletion, the rating is retained as anonymous after 30 days so the restaurant's aggregate score stays accurate.
- Logs — application logs kept for 30 days; longer only for security investigations.
6. Security
- All traffic between you and Dine. is encrypted with TLS.
- OTP codes and refresh-token secrets are hashed (Argon2id / SHA-256) before storage; we never store them in plaintext.
- We rotate refresh tokens on every use and revoke an entire token family if we detect reuse (a sign of theft).
- Access to production data is limited and audit-logged.
- No system is perfectly secure. If we discover a breach affecting your data we will notify you in line with applicable law.
7. Your choices & rights
- See & edit your profile from the Profile page.
- Mute notification channels (WhatsApp, SMS, email, in-app) from Profile.
- Export a copy of your data — in the app, Profile → Account → Download my data, or email privacy@dinepk.com.
- Deactivate (a reversible pause) — Profile → Account in the app.
- Delete your account permanently — in the app (Profile → Account → Delete account) or online without the app at dinepk.com/account/delete. We re-authenticate you first. Deletion is immediate and irreversible: your personal data, ratings and photos are erased right away, legally required records (if any) are kept only in a segregated archive, and reservations are anonymised (venue, date and party size only) so restaurant statistics stay accurate. Backups age out on their normal rotation.
8. Children
The Service is not directed to children under 13. We do not knowingly collect data from children under 13; if we learn we have, we will delete it.
9. Cookies & local storage
We use browser local storage to keep you signed in (your access and refresh tokens) and to remember small UI preferences. We do not use third-party advertising cookies.
10. Pakistan regulatory compliance
Dine. operates in compliance with Pakistani law, including the Prevention of Electronic Crimes Act 2016 (PECA) and applicable Pakistan Telecommunication Authority (PTA) regulations.
- We do not facilitate the transmission of unlawful content as defined by PECA.
- We cooperate with lawful requests from Pakistani authorities pursuant to valid legal orders.
- OTP and transactional SMS/WhatsApp messages are sent in compliance with PTA guidelines for bulk messaging.
- In the event of a data breach affecting your personal information, we will notify affected users and, where required, relevant Pakistani authorities as soon as reasonably practicable.
Pakistan's Personal Data Protection Bill has not yet been enacted into law as of the date of this policy. Once enacted, we will update our practices accordingly and notify you of any material changes.
11. Changes to this policy
If we change this policy in a material way, we will notify you by email or in-app at least 14 days before it takes effect. The "Last updated" date at the top of this page always reflects the current version.
12. Contact
Questions or requests about your data? Email privacy@dinepk.com.