Legal

Privacy policy

Last updated: 31 August 2026

Who we are

Dineya provides online ordering, point-of-sale and delivery-management software to takeaways and restaurants. This policy covers what personal information we collect and use when you visit dineya.co.uk, enquire about Dineya, book a demo, or hold a Dineya account as a restaurant client.

Controller: Dineya Ltd, a company registered in England and Wales (company number 17349919), registered office 167-169 Great Portland Street, London W1W 5PF, registered with the Information Commissioner's Office under reference ZC208806. Contact us about privacy or your data: support@dineya.co.uk.

Ordering food from a restaurant that uses Dineya? The restaurant you order from is responsible for your information; we process it on their behalf. See the privacy notice on that restaurant's ordering page, and contact the restaurant to exercise your rights. We'll pass any request you send us on to them.

What we collect and why

WhatWhenWhy (lawful basis)
Name, business name, email, phone, message — plus your IP address and browser type (spam prevention) You submit the "register your interest" form To respond to your enquiry and follow up about Dineya (legitimate interests — you asked us to contact you); IP/browser data to prevent abuse of the form
Booking details (name, email, chosen time) You book a demo call via the booking link in our reply email — a third-party scheduling tool (Google Calendar appointments) To hold the appointment (steps prior to a contract)
Account details: name, email, phone, business name and address, login credentials You become a Dineya client To provide the service (contract)
Billing details: subscription plan, payment method reference (held by Stripe — we never see full card numbers) You pay for a subscription Contract; legal obligation (tax/accounting records)
Support correspondence You email or message us To help you (contract / legitimate interests)
Technical data: IP address, browser type, pages visited You browse dineya.co.uk Site security and performance (legitimate interests)

We do not use your information for automated decision-making with legal effects, and we do not sell it.

Cookies and similar technologies

No analytics or advertising cookies are currently set on dineya.co.uk. The site uses only strictly necessary items (e.g. security and load balancing at our hosting provider), which are always on and don't need consent.

If we introduce analytics or advertising tags in future, we'll update this policy first, publish a short cookie policy, and — where the law requires it — ask for your consent via a banner before anything is set.

Who we share it with

Service providers who process data for us:

  • Railway — application hosting (EU West, Amsterdam)
  • MongoDB Atlas — database (AWS Dublin)
  • Resend — email delivery
  • Twilio — SMS delivery
  • Microsoft 365 — business email
  • Cloudflare — this website's hosting and DNS (Cloudflare sees standard visitor request data such as your IP address), and encrypted off-site backups of our database (Cloudflare R2)
  • Sentry — application error monitoring and diagnostics
  • Google — demo-booking scheduling
  • Stripe — client subscription billing

Some providers are US-headquartered; where data leaves the UK/EEA we rely on UK adequacy decisions (including the UK–US Data Bridge) or the ICO-approved International Data Transfer Agreement/Addendum.

We may also share information if required by law, or in a business sale or restructure (we'd tell you first).

How long we keep it

DataRetention
Leads/enquiries that don't become clients 12 months from last contact
Client account data Life of the account + 12 months
Billing/tax records 6 years (HMRC requirement)
Support correspondence 24 months

Your rights

You can ask us to: access the information we hold about you; correct it; delete it; restrict or object to our use of it; or send you a copy in a portable format. You can withdraw consent at any time where we rely on it. Contact support@dineya.co.uk — we'll respond within one month.

If you're unhappy, you can complain to the Information Commissioner's Office (ico.org.uk / 0303 123 1113), but we'd appreciate the chance to fix it first.

Security

Data is encrypted in transit and at rest, hosted in UK/EEA data centres, protected by role-based access controls, and access is limited to those who need it. We notify affected people and the ICO of any breach where the law requires.

Changes

We'll post any changes here and update the date above. Material changes affecting clients are notified by email.