Draft for legal review. This document is not final. Highlighted
[●] items are still to be completed.
Privacy Policy
Effective date: [●] · Last updated: 4 October 2026
- Who we are and our role
- Personal data we collect
- How we use it
- If you are a diner
- Who we share it with
- Where it is stored
- How long we keep it
- How we protect it
- Your rights
- Cookies and browser storage
- Children
- Changes to this policy
- Contact and Grievance Officer
1. Who we are and our role
DineBlue is restaurant management software operated by OPL Tech Private Limited (CIN [●]), registered office
[●] ("DineBlue", "we", "us"), at dineblue.in,
admin.dineblue.in and each restaurant's own address such as restaurant.dineblue.in.
This policy explains how we handle personal data under:
- the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as their provisions
come into force ("DPDP law");
- the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and
Sensitive Personal Data or Information) Rules, 2011.
We have two roles:
- For restaurant owners, their staff and visitors to dineblue.in, we decide why and how personal data is used. We
are the Data Fiduciary.
- For diners (people who order, book or pay at a restaurant that uses DineBlue), the restaurant is the
Data Fiduciary. We process diners' data on the restaurant's behalf as its Data Processor. See
section 4.
2. Personal data we collect
Restaurant owners and staff
- Account details: name, email address, mobile number (verified by one-time password), role, and your password,
which we store only as a one-way hash and cannot read.
- Business details: restaurant name, address, GSTIN, contact details, logo, menu and photos.
- Connections you set up: credentials for your payment gateway and email (SMTP) accounts, stored encrypted.
- Billing details: plan, invoices, payments and GST details.
- Usage and security data: sign-in times, IP address, browser type, actions recorded in audit logs, and the IP
address used at sign-up.
- Communications: messages you send to our support team.
Diners (processed for the restaurant)
- name, mobile number and, if given, email address, with OTP verification of the mobile number;
- orders: items, amounts, table, time and how the order was placed (counter, QR code at the table, or online);
- payment status and the payment reference returned by the restaurant's payment provider. We never receive card numbers,
UPI PINs or bank passwords;
- if the restaurant collects them: date of birth, anniversary and marketing preferences (with the time consent was given).
We do not knowingly collect sensitive personal data such as health, biometric, financial account or card data, except
restaurant credentials for payment providers, which are encrypted and used only to process the restaurant's payments.
3. How we use personal data
We use the personal data of restaurant owners, staff and visitors to:
- create and verify accounts, sign users in, and keep accounts secure;
- provide the Service, including each restaurant's site, ordering, kitchen display, payments, reports and add-ons;
- bill subscriptions and issue GST tax invoices;
- send service messages, such as one-time passwords, trial-ending and plan-limit reminders, and security alerts;
- prevent fraud and abuse, for example limiting free trials to one per mobile number and email address, and rate-limiting
sign-up attempts;
- provide support and respond to requests;
- comply with law and lawful requests from authorities;
- improve the Service using aggregated statistics that do not identify any individual.
We process this data with your consent, given when you sign up or provide it, or for other legitimate uses permitted under DPDP
law, such as complying with law. We send marketing messages about DineBlue only with your consent, and you can opt out at any
time. We do not sell personal data and do not use it for advertising.
4. If you are a diner
- The restaurant you order from decides what personal data it collects and how it uses it. DineBlue processes that data only
to provide the restaurant's service, on its instructions.
- We do not use diners' data for our own purposes, do not share it with other restaurants, and do not sell it. Each
restaurant's data is kept separate from every other restaurant's.
- Your account at one restaurant is separate from any account at another restaurant using DineBlue.
- For questions, or to access, correct or delete your data, please contact the restaurant. If you contact us instead, we
will pass your request to the restaurant and help it respond.
- Promotional messages from a restaurant are the restaurant's responsibility. It must have your consent, and you can ask it
to stop at any time.
5. Who we share personal data with
We share personal data only as follows.
Service providers (sub-processors) who process it for us under contract and only on our instructions:
| Provider | Purpose | Location |
| Amazon Web Services India | Hosting, database and backups | Mumbai, India |
| [●] | Sending one-time passwords and service SMS | India |
- Providers chosen by the restaurant, under the restaurant's own agreements:
- its payment gateway or card-terminal provider (such as Razorpay, Paytm, Pine Labs or Mswipe), to process
payments;
- its email provider, to send its notifications;
- delivery or accounting platforms it connects.
- Authorities: government agencies, courts or law enforcement, where required by law or a lawful order.
- Advisers: professional advisers, such as auditors and lawyers, under confidentiality obligations.
- Business transfers: a buyer or successor in a merger or sale of our business. This policy will continue to
protect your data, and we will notify you.
6. Where personal data is stored
Personal data is stored and backed up in India, on Amazon Web Services' Mumbai region. We do not transfer it outside India,
except where permitted under DPDP law and never to a country the Government of India has restricted.
7. How long we keep personal data
- Active accounts: for as long as the restaurant's account is active.
- After a subscription ends: 90 days, so the restaurant can renew or export its data.
We then delete it, including diners' data, except as below.
- Backups: replaced on a rolling basis and kept for up to 30 days.
- One-time passwords: valid for 10 minutes; removed once used, or replaced by the next code.
- Sign-up records (mobile number, email, date): kept to enforce the one-free-trial rule.
- Invoices and billing records: kept for the period required by tax and company law.
- Security and audit logs: kept for up to [●] to investigate misuse.
We also delete personal data earlier on a valid erasure request, unless the law requires us to keep it.
8. How we protect personal data
We follow reasonable security practices and procedures, including:
- encryption in transit (HTTPS) for every page;
- passwords stored only as hashes;
- payment-provider and email credentials encrypted at rest;
- encrypted disks and backups;
- strict separation of each restaurant's data;
- role-based access within each restaurant;
- verification of mobile numbers by one-time password, with limits on attempts;
- rate limiting of sign-up;
- audit logs of administrative actions;
- regular backups;
- access to production systems limited to authorised personnel.
No system is completely secure. If a personal data breach occurs, we will inform the affected restaurants and individuals,
the Data Protection Board of India and CERT-In as and when required by law. Where we act as a processor, we will also help the
restaurant meet its own obligations.
9. Your rights
Subject to DPDP law, you have the right to:
- obtain a summary of your personal data we process and our processing activities, and the identities of those we have shared
it with;
- have inaccurate or incomplete data corrected, completed or updated;
- have your data erased when it is no longer needed for the purpose it was collected for, unless the law requires us to keep
it;
- withdraw consent at any time, as easily as you gave it. This does not affect processing already done, and some services
may stop working without the data;
- nominate another person to exercise your rights in the event of your death or incapacity;
- have your grievances redressed.
To exercise these rights, write to [●]. Restaurant owners can also update most details in their account. We may
need to verify your identity. We respond within the time limits set by law and aim to do so within 30 days.
If you are not satisfied with our response, you may complain to the Data Protection Board of India after using our grievance
process.
Please also meet your duties under DPDP law: give accurate information, do not impersonate anyone, and do not file false or
frivolous complaints.
10. Cookies and browser storage
We use only cookies that are strictly necessary for the Service to work:
- a sign-in cookie, which keeps you signed in;
- a session cookie, which remembers your table and order while you use QR ordering;
- a security cookie, which protects forms against forgery.
We also store display preferences, such as a collapsed menu, in your browser. We do not use advertising, analytics or
third-party tracking cookies. Staff can choose to allow desktop notifications in their browser, and can turn them off
at any time in the browser's settings.
11. Children
DineBlue is a service for businesses and is not directed at children. Restaurant accounts may be opened only by adults. Under
DPDP law, personal data of a child (under 18) may be processed only with verifiable consent of a parent or lawful guardian,
and must not be used for tracking, behavioural monitoring or targeted advertising. Restaurants must not knowingly collect
children's data for marketing. If we learn that we hold a child's data without the required consent, we will delete it or
ask the restaurant to do so.
12. Changes to this policy
We may update this policy. We will tell restaurant owners about material changes by email or in the Service before they take
effect. The date at the top shows when it was last updated.
For privacy questions and requests, write to [●]. For general support, write to support@dineblue.in.
Grievance Officer, under the Information Technology Act, 2000, the rules made under it and DPDP law:
[●], [●]
OPL Tech Private Limited, [●]
Email: [●] · Phone: [●]
We acknowledge grievances within 24 hours and aim to resolve them within 15 days of receipt.
OPL Tech Private Limited · CIN [●] · Registered office: [●]
DineBlue is operated by OPL Tech Private Limited at dineblue.in and its subdomains.