Privacy Policy
Last updated: 17 September 2026 · Effective: 17 September 2026
1. Who we are
DinePluz is operated by Softwarepluz, a company registered in India (Karnataka), GSTIN 29ADQFS4753D1ZM. For any privacy or data-protection matter, contact us at info@dinepluz.com.
We provide a cloud-based point-of-sale and restaurant management platform (“the Service”) for restaurants, cafés, bakeries, and food businesses in India. This policy explains how we collect, use, store, and protect personal data in connection with the Service.
Grievance Officer: Udaya Kumar C, info@dinepluz.com — for complaints regarding the handling of your personal data under the Digital Personal Data Protection Act, 2023.
2. Data we collect
2.1 Restaurant owners and staff
- Account registration data (name, email, phone number, password hash)
- Business details provided during onboarding (restaurant name, address, GSTIN, branch information)
- Staff and captain login credentials (PIN-based access)
- Usage logs, session data, and platform activity
2.2 Order and billing data
As part of providing the Service, we process:
- Menu items, pricing, and category configuration you set up
- Order and billing data generated through your use of the POS (items ordered, quantities, totals, payment method, GST breakdown)
- Invoice records, required to be retained for tax compliance
- Table/QR-menu orders placed by your customers, where enabled
2.3 End customers (via QR Menu)
Where you enable QR-based ordering, we may process:
- Table/session identifiers
- Order selections and any special requests entered
- We do not require end-customer accounts, names, or contact details to place a QR-menu order unless you separately configure such collection
2.4 Website visitors
- Contact form submissions (name, email, business name, message)
- Standard server logs (IP address, browser, referrer)
- Anonymised campaign tracking (see Section 8, Cookies)
3. Legal basis for processing
We rely on the following legal bases under India’s Digital Personal Data Protection Act, 2023:
- Contract: to deliver the Service you have subscribed to
- Legitimate interests: to improve the platform, prevent fraud, and maintain security
- Legal obligation: where required by law (e.g., GST invoice retention, tax records, regulatory requests)
4. How we use your data
- Providing, maintaining, and improving the Service
- Generating GST-compliant invoices and reports on your behalf
- Processing subscription payments
- Sending service updates, security notices, and support responses
- Analysing platform usage to identify and fix issues
- Complying with legal and regulatory requirements (including tax law)
We do not sell personal data to third parties. We do not use your business or customer order data for advertising purposes.
5. Data sharing and sub-processors
We share personal data only where necessary to deliver the Service:
- Cloud infrastructure: application and database servers hosted on DigitalOcean
- File and asset storage: Amazon Web Services S3 (for app installers, uploaded images, and generated documents)
- Transactional email: Brevo, for account notifications and receipts
- Payment processing: Razorpay Software Private Limited, for subscription billing. Razorpay is PCI-DSS compliant; we do not store your full card details
- Delivery platform integrations: where you enable third-party delivery aggregators (e.g., for order aggregation), order data necessary to fulfil that integration is shared with the enabled platform only
All sub-processors are engaged under appropriate data-protection terms. A full, current list of sub-processors is available on request.
6. Data retention
- Account data: retained for the duration of your subscription plus 90 days after termination
- Invoice and billing records: retained for the period required under applicable Indian tax law (currently a minimum of 6 years under GST regulations)
- Order/menu data: retained for the duration of your subscription
- Contact enquiries: retained for 2 years
- Server logs: retained for 30 days
7. Your rights
Under the DPDP Act, you have the right to:
- Access: request a copy of personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion of your data where no legal basis for retention exists (subject to statutory invoice-retention requirements described in Section 6)
- Grievance redressal: raise a complaint about how we’ve handled your data
To exercise any of these rights, email info@dinepluz.com. We will respond within 30 days. End customers of a restaurant using DinePluz’s QR Menu should contact that restaurant directly for matters relating to their order, as the restaurant is the data controller for that transaction.
8. Cookies and tracking
Our marketing website (dinepluz.com) uses:
- Session cookies: required for authenticated users of the platform (owner dashboard, admin dashboard, POS)
- Analytics: Google Analytics, used to understand website traffic and measure marketing campaigns (including QR code scans from print materials). This is aggregated, non-invasive usage data — it is not used for advertising or shared with advertisers
We do not use third-party advertising cookies on this website.
9. Security
We implement industry-standard security measures including TLS encryption in transit, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we take all reasonable steps to protect your data.
10. International transfers
Data is primarily stored in India-accessible cloud infrastructure. Where a sub-processor operates outside India (e.g., certain AWS S3 regions), we rely on that provider’s standard data-protection safeguards.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or via a prominent notice in the platform. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact and complaints
For privacy-related questions, contact us at info@dinepluz.com.
If you believe we have not handled your personal data correctly, you may lodge a complaint with the Data Protection Board of India.