Privacy Policy
DineBotics™ / DiBi™
What we collect, why we collect it, who sees it, and what we will never do with it, written for restaurant operators, their teams, and their guests.
Beta Program. DineBotics is beta software. Our systems, integrations, retention practices, and sub-processors are still changing, and this policy will change with them. During beta you should not treat the Platform as a system of record, and you should keep your own independent copies of anything you need.
We take security seriously, but no system is perfectly secure and we cannot guarantee that data will never be lost, corrupted, or exposed. Our Terms of Service set out the limits of our responsibility.
1. Scope
This policy explains how DineBotics ("DineBotics," "we," "us") handles information in connection with our website, the DineBotics platform, the DiBi™ assistant, our demos, and our sales and support communications (together, the "Services").
It does not apply to the practices of restaurants that use our Services, or to third-party services you connect. Those are governed by their own policies.
2. Our Two Roles
We handle information in two distinct roles, and your rights differ depending on which applies.
As a controller we decide how information is used. This covers website visitors, prospects, demo requests, and the account and billing contacts at our customers.
As a processor or service provider we handle information on a restaurant's behalf and on its instructions. This covers operational data pulled from a customer's systems, including information about that customer's employees and guests. In that role the restaurant is the controller, it decides what is collected and why, and privacy requests from its staff or guests should go to the restaurant first. We will support our customers in responding.
3. What We Collect
We collect the following categories of information:
- ●Contact and account (Controller): Name, business email, phone, restaurant name, role, number of locations, account credentials. Source: you, directly.
- ●Billing (Controller): Billing contact, address, tax details, subscription tier, invoice history. Card details are handled by our payment processor, not stored by us. Source: you and our payment processor.
- ●Restaurant operational data (Processor): Sales and transaction records, menu and item mix, ticket times, covers, labor hours and schedules, inventory counts and orders, waste logs, temperature and safety checks, reviews and guest feedback. Source: systems you connect and data you upload.
- ●Employee-related (Processor): Names or IDs, roles, shifts, hours, station assignments, certifications, and other data your connected systems supply. Source: your connected systems.
- ●Guest-related (Processor): Reservation and waitlist entries, order history, loyalty identifiers, and feedback your systems supply. Source: your connected systems.
- ●Usage and device (Controller): IP address, browser and device type, pages viewed, features used, timestamps, referring page, error and diagnostic logs. Source: automatic collection.
- ●Communications (Controller): Support tickets, emails, demo notes, feedback, and survey responses. Source: you, directly.
We do not intentionally collect Social Security numbers, government ID numbers, biometric identifiers, precise geolocation, protected health information, or payment card numbers. Do not submit these to the Platform unless we have agreed in writing to receive them.
4. Employee and Guest Data
Restaurant data inherently includes information about people. We treat that seriously.
- ●We do not build individual employee productivity scores. This is a standing product decision, not a setting. The Platform is designed to surface patterns at the level of shifts, stations, and operations, not to rank people.
- ●Employee data is used to produce operational insight for the operator, never sold, never used to build profiles for our own purposes, and never shared with other customers in identifiable form.
- ●Our customers are responsible for giving their staff and guests any required notice, obtaining any required consent, and complying with applicable employment, privacy, and recording laws.
If you are an employee or guest of a restaurant that uses DineBotics and you have a privacy question, contact that restaurant. You may also write to us at support@dinebotics.com and we will route your request to them.
5. How We Use Information
- ●Provide, operate, secure, and support the Services.
- ●Generate insights, trends, forecasts, and recommendations for the customer whose data it is.
- ●Authenticate users, prevent fraud and abuse, and investigate security incidents.
- ●Process payments and manage subscriptions.
- ●Communicate about your account, releases, incidents, and support requests.
- ●Diagnose bugs, monitor performance, and improve reliability and usability.
- ●Send marketing to business contacts, subject to your right to opt out at any time.
- ●Meet legal, tax, and regulatory obligations, and enforce our agreements.
We do not use one customer's identifiable operational data to serve another customer.
6. AI and Model Training
We do not use your identifiable operational data to train foundation models for other customers, and we do not sell your data to model providers.
Where we use third-party AI providers to power DiBi, we send only what is needed to answer the request at hand, under agreements that prohibit the provider from using that content to train its general models. We do not permit vendor training on customer content.
We may use de-identified and aggregated data, stripped of anything identifying a person, a customer, or a location, and combined across many restaurants, to improve model quality, build benchmarks, and develop the Services. We will not attempt to re-identify it or allow others to.
If you would prefer your de-identified data be excluded from aggregate improvement work, write to support@dinebotics.com and we will honor that.
AI output can be inaccurate or incomplete. Sections 3 through 8 of our Terms of Service explain the limits of what DiBi does and where responsibility for decisions sits.
7. Legal Bases
Where privacy law requires a legal basis, we rely on: performance of a contract (operating the Services); legitimate interests (security, product improvement, business marketing); consent (non-essential cookies, certain marketing, where required); and legal obligation (tax, accounting, lawful requests). You may withdraw consent at any time without affecting prior processing.
8. How We Share Information
- ●Service providers who host, secure, analyze, support, or bill on our behalf, under contract and limited to what they need.
- ●Systems you connect, at your direction, using credentials you authorize.
- ●Within your organization, according to the roles and permissions your administrators configure.
- ●Professional advisors such as lawyers, auditors, and accountants under confidentiality obligations.
- ●Legal and safety, where required by law or legal process, or to protect rights, safety, or the integrity of the Services. We will notify affected customers where lawfully permitted.
- ●Corporate transactions, in a merger, acquisition, financing, or sale of assets, with this policy continuing to apply until replaced with notice.
We do not sell personal information and do not share it for cross-context behavioral advertising.
9. Sub-Processors
We use third parties to run the Services, including cloud hosting, database and storage, AI model providers, email and messaging, payments, analytics, error monitoring, and customer support tooling. A current list is available on request from support@dinebotics.com. We will give notice of material changes to that list so customers can raise concerns.
10. Cookies and Tracking
We use strictly necessary cookies for sign-in, security, and session handling; preference cookies to remember settings; and analytics cookies to understand how the site and product are used. We may use marketing or conversion tracking on our public website.
You can control cookies through your browser and, where offered, through our cookie banner. Blocking strictly necessary cookies will break parts of the Platform. We currently do not respond to Global Privacy Control and Do Not Track signals.
11. Retention
We keep information only as long as needed for the purpose it was collected, or as required by law.
- ●Customer operational data: for the life of your subscription, then deleted or de-identified within 30 days of termination unless you request earlier deletion or the law requires longer.
- ●Account and billing records: up to 7 years for tax and audit purposes.
- ●Support and communications: up to 24 months.
- ●Security and access logs: up to 12 months.
- ●De-identified aggregate data: retained indefinitely, since it no longer identifies anyone.
Backups persist on a rolling cycle and are overwritten in the ordinary course. Export anything you need before your account closes.
12. Security
We use encryption in transit and at rest, role-based access controls, least-privilege access for staff, environment separation, audit logging, vendor review, and routine patching. Access to customer data by our personnel is limited to what support and operations require and is logged.
No method of transmission or storage is completely secure, and during beta our controls are still maturing. We cannot guarantee absolute security. If a breach affects your information, we will notify you as required by law and without undue delay. Report a suspected vulnerability to support@dinebotics.com.
13. Your Privacy Rights
Depending on where you live, you may have the right to know what we hold, access a copy, correct inaccuracies, delete information, obtain a portable copy, opt out of sale or targeted advertising, limit use of sensitive information, and appeal a decision. You will not be discriminated against for exercising these rights.
To make a request, contact support@dinebotics.com. We will verify your identity before acting and respond within the timeframe the applicable law requires. An authorized agent may act for you with proof of authority.
If your information sits inside a restaurant's account, we will refer your request to that restaurant as the controller and assist them in responding. Marketing emails include an unsubscribe link; account and service notices are not optional while you hold an account.
14. Sale and Sharing of Data
We have not sold personal information and have not shared it for cross-context behavioral advertising in the preceding twelve months, and we do not do so now. We do not sell or share the personal information of anyone we know to be under 16.
15. Children
The Services are business tools and are not directed to children. We do not knowingly collect information from anyone under 16. If you believe a child's information has reached us, write to support@dinebotics.com and we will delete it. Restaurants employing minors are responsible for complying with the laws that apply to that employment.
16. International Transfers
We operate in the United States and store and process information there. If you access the Services from elsewhere, your information is transferred to the United States, where privacy laws may differ from those in your country. Where required, we use appropriate safeguards such as standard contractual clauses.
17. Changes
We will update this policy as the Platform develops. The revised version will carry a new effective date, and we will give notice of material changes by email or in-product before they take effect. Continued use after the effective date means you accept the update.
18. Contact
DineBotics
Tampa, FL
Privacy: support@dinebotics.com
Security: support@dinebotics.com