Skip to content
Legal

Privacy policy

What DinePilot collects, why, and what we never do with it.

Last updated: 16 July 2026

DinePilot is a restaurant management platform. This policy covers two different groups of people, and it matters which one you are: the restaurants that use DinePilot, and the guests who order from a table QR code.

What we collect from restaurants

  • Account details — name, email, phone and a hashed password for each staff member, plus the role they hold.
  • Restaurant details — name, address, contact number, logo, currency, timezone and tax settings.
  • Operational data — your menu, tables, orders, payments and the analytics derived from them.

What we collect from guests

Guests do not create an account and are not asked to sign in. When someone scans a table QR code we work from a per-table session token. At checkout a guest may optionally give a name and phone number so staff can match the order to the table — both are optional, and an order works without them.

We do not track guests across restaurants, build advertising profiles, or sell any guest data. Ever.

What we collect from this website

  • Contact form — the name, email and any other details you type in, plus your IP address and browser user-agent, used to answer you and to block spam.
  • Newsletter — your email address and where you signed up from. Unsubscribe any time.

How we use it

  • To run the service: showing orders to your kitchen, bills to your cashier and analytics to you.
  • To reply to you when you contact us.
  • To keep the service secure, including rate limiting and spam prevention.
  • To fix problems and improve the product.

We do not sell personal data, and we do not share it with advertisers.

Keeping restaurants separate

Every record belongs to exactly one restaurant. That boundary is enforced at the database query level and checked again on every request, so one restaurant cannot read or change another's menu, orders or sales figures.

Security

  • Passwords are hashed, never stored in readable form.
  • Staff access is token-based and scoped to the person's role.
  • Input is validated on the server, not just in the app.
  • Public order placement is rate limited.

No system is perfectly secure. If you believe you have found a vulnerability, please tell us before disclosing it publicly.

How long we keep things

Operational data is kept while your restaurant's account is active, because you need your own order history and analytics. Ask us to delete your account and we will remove or anonymise your data, except where we are required to retain records — for example tax and accounting obligations.

Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. Write to mail@truelytech.com and we will respond.

Changes

If we change this policy in a way that materially affects you, we will update the date above and let restaurants on our list know rather than changing it quietly.

Contact

Questions about privacy go to mail@truelytech.com.

Free during early access

No card. Nothing for guests to install.

Get started