Privacy Policy
This Privacy Policy explains how DineHopper collects, uses, and protects personal information across the DineHopper platform. It covers two different relationships, which is worth reading carefully: DineHopper's relationship with the venues that subscribe to the Service, and each venue's own relationship with its guests and staff, whose information passes through the Service.
On this page
1. Two roles DineHopper plays
As a subscriber — if you are the owner or a staff member of a venue with a DineHopper account, DineHopper collects and uses your own information (name, email, phone, role, login activity) to run your account, bill your subscription, and provide support. For this information, DineHopper decides how it is used and is directly responsible to you for it.
As a service provider — the venue's own guests, diners, and staff are not DineHopper's customers. When a venue takes a booking, an order, a loyalty sign-up, or logs a staff timesheet through DineHopper, the venue decides what is collected and why; DineHopper simply stores and processes that information on the venue's behalf, inside that venue's own isolated account. If you are a guest or staff member of a DineHopper-powered venue and have a question about your own information, the venue you dealt with — not DineHopper directly — is generally the right first point of contact, since they control what was collected and why. DineHopper will still help where it reasonably can.
2. Information we collect
Directly from a subscribing venue
- Account and owner details: name, email, phone, restaurant name, and password (stored as a salted hash, never in plain text).
- Billing details: handled by Stripe on our behalf — DineHopper stores which plan you're on and billing status, not your full card number.
- Support communications you send us.
Collected by a venue, through the Service, on that venue's behalf
- Guest details entered for a booking, order, waitlist entry, gift card, voucher, loyalty account, or feedback/review: name, contact details, party size, allergy or dietary notes, order and visit history, and loyalty point balances.
- Staff details entered by a venue for rostering, timesheets, and wages: name, contact details, role, PIN (hashed), shift times, and pay figures.
- Where AI Calls is enabled and configured with an OpenAI key, a recording and transcript of the phone call, used to take a booking or answer a menu/hours question, and (if a transfer number is set) to hand the call to a staff member.
- Where a venue connects a third-party order or delivery source (UberEats, DoorDash, a POS system, LunchFox), the order and item details that source sends.
Collected automatically
- Standard technical logs (IP address, browser, timestamps) generated by Cloudflare, our hosting provider, for security and reliability.
- Basic in-app preferences stored in your browser's local storage (for example, your chosen theme or accent colour on the Till) — this stays on your device and is not sent to DineHopper's servers.
3. How we use information
- To provide, maintain, and improve the Service — running bookings, orders, payments, rosters, and every other module a venue has enabled.
- To communicate with subscribers about their account, billing, and material changes to the Service.
- To send guest-facing messages a venue has configured (a booking confirmation, a deposit link, a gift card code, a marketing campaign through Promote) — always on that venue's instruction, through their own connected email (Resend) or SMS (Twilio) setup.
- To detect, investigate, and prevent fraud, abuse, and security incidents.
- To meet legal and tax obligations.
DineHopper does not sell personal information, and does not use a venue's guest data to advertise to those guests on behalf of anyone other than that venue.
5. International data transfers
Cloudflare, Stripe, Resend, Twilio, and OpenAI all operate global infrastructure, so information may be processed outside Australia. Where that happens, we rely on those providers' own security and, where applicable, standard data-protection safeguards. If your business or your guests are based outside Australia, your own local privacy law may also apply to how you use the Service — that responsibility sits with you as the venue, per Section 1.
6. Security
Passwords and staff PINs are stored as salted hashes, never in plain text. Guest-facing payments run through Stripe or a connected EFTPOS terminal, so DineHopper never holds full card numbers. Data is encrypted in transit (HTTPS) and at rest on Cloudflare's infrastructure. No system is perfectly secure, and we can't guarantee against every possible breach, but we take reasonable, industry-standard steps to protect the information in our care.
7. Data retention
We keep account and guest data for as long as a venue's account is active, plus a reasonable period afterwards in case of reactivation, unless a venue deletes specific records earlier through the Service. We may retain some information longer where the law requires it (for example, tax and payroll records) or to resolve disputes.
8. Your rights
Depending on where you're located, you may have rights to access, correct, or request deletion of your personal information, consistent with the Australian Privacy Principles or an equivalent local law. As a subscribing venue, you can access and correct most of your own account information directly in DineHopper, and can contact us for anything else. As a guest or staff member of a DineHopper-powered venue, the venue itself holds and controls that data day to day (Section 1) — contact the venue first; DineHopper will assist where we reasonably can, including on request from the venue.
10. Children's privacy
DineHopper's subscriber accounts are for businesses, not children. A venue's guest-facing booking or ordering flow may occasionally be used on a child's behalf by a parent or guardian placing an order or booking — DineHopper does not knowingly collect personal information directly from children, and relies on each venue to use the Service appropriately for its own guests.
11. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material, we will make reasonable efforts to let subscribers know before it takes effect. The "Last updated" date at the top of this page always reflects the current version.
12. Contact
Questions about this Privacy Policy, or a request about your personal information, can be sent to sales@dinehopper.com.