Skip to content
DDineXpro
Product How it works Pricing Support RO Contact us
Product How it works Pricing Support Română Contact us
← Back to home

Privacy Policy

How we collect, use, and protect your information when you use DineXpro.

Version: v6 · Last updated: August 23, 2026
Contents
  1. Introduction
  2. Who we are
  3. Data we collect
  4. How we use data
  5. Legal bases
  6. Data sharing & processors
  7. Data retention
  8. Security
  9. International transfers
  10. Your rights
  11. Children's privacy
  12. This website and the web app
  13. Changes to this policy
  14. Contact

1. Introduction

This Privacy Policy explains how DineXpro (operated by ANNATECH SRL) collects, uses, stores, and shares information when you interact with our platform — the DineXpro mobile applications, the web application at app.dinexpro.app, this website, and related services (together, the "Services").

We wrote this policy to be specific about what actually happens in the product. If anything is unclear, contact us at privacy@dinexpro.app.

2. Who we are

The data controller for the Services is ANNATECH SRL, a company registered in Romania — B-dul 1 Mai nr. 45, Municipiul Craiova, jud. Dolj, 200355, Romania; CUI 52437424; Reg. Com. J2025066494002; EUID ROONRC.J2025066494002.

Privacy contact: privacy@dinexpro.app. General contact: contact@dinexpro.app.

3. Data we collect

Account & profile

Using DineXpro requires an account. You can register with an email address and password, or sign in with Google or Apple. We collect your name or display name, email address, and optional profile photo and phone number. Authentication is handled by Firebase Authentication (Google).

You may also provide an optional date of birth — either on your profile, or when you enable an age-restricted feature such as Social Mode (18+). We use it solely to verify age eligibility: the minimum age required to hold a DineXpro account, and the 18+ threshold that applies to Social Mode and adults-only loyalty rewards. Your exact date of birth is never shown to other users and is never shared with venues; while you are visible in Social Mode, other participants see only a coarse age band derived from it (for example, "20s"). It is stored with the rest of your profile data and deleted when you delete your account.

Orders, table sessions & activity

When you use the Services as a guest, we collect the activity needed to run the experience: table-session participation and timestamps, QR-scan events and check-ins, order contents and history, bill-splitting choices and payment confirmations, reservation details (party size, time, and any deposit status), pickup and delivery orders (including the delivery address you provide), waiter calls, and feedback you submit.

Location

With your permission, the app uses your device's precise location (GPS) while you are using it, for specific features: showing nearby venues, selecting an address or a business location on the map, and delivery-related flows. The app does not track your location in the background and never requests "always-on" location. You can revoke location access at any time in your device settings; the related features will simply stop working. Independently of GPS, we may derive an approximate, city-level location from your IP address.

Camera & QR scanning

The app uses your camera, with your permission, to scan table and venue QR codes and to take photos you choose to upload. Camera frames used for QR scanning are processed on your device and are not stored or transmitted; the resulting scan event (which code was scanned, and when) is recorded.

Photos & media

If you choose to upload images — a profile photo, or menu and venue photos for business accounts — those images are stored on our infrastructure (Firebase Storage).

Push notifications & device tokens

To deliver order updates, session events, and service notifications, we store a per-device push token issued by Firebase Cloud Messaging, together with your notification settings. Deleting your account deletes your device tokens.

Device & technical data

We automatically collect device type, operating system, and app version; IP address; crash reports and diagnostic logs (via Firebase Crashlytics); and usage analytics (via Firebase Analytics). Analytics and crash data are keyed to pseudonymous identifiers (such as an app-instance ID), not to your name; we use them in aggregate to understand usage and fix problems.

Device integrity

To protect the platform from abuse, requests from the app carry an attestation issued by Firebase App Check (using Google Play Integrity on Android and Apple's attestation services on iOS). These signals help us tell requests coming from a genuine app on a genuine device apart from automated abuse. Attestation is a signal, not an absolute guarantee about a device or the person using it, and the level at which we enforce it on our servers can differ between our environments.

Business & staff data

If you use DineXpro as a business owner or staff member, we collect your business name, address and contact details, menu content and pricing, table configuration and operational settings, staff names, roles and permissions, and operational logs of staff actions (for accountability and audit).

Social & community features

If you opt in to social features, we collect the profile information you choose to make visible, your check-ins and interactions, content you share, reports you submit about other users or content, and related moderation records. Social features are optional; if you never enable them, none of this is collected.

Payment-related information

Card payments you make to a venue are processed by Stripe. We store payment confirmation records — transaction status, amount, timestamps — but we never store full card numbers, CVVs, or other sensitive card credentials on our systems.

Business billing (subscriptions)

DineXpro platform subscriptions are billed by Paddle as merchant of record. Paddle receives the data necessary to process the transaction — typically the business contact email, country, and the items purchased — and issues invoices under its own terms.

4. How we use data

  • Providing the Services — accounts, table sessions, ordering, reservations, pickup/delivery, payments, and the staff dashboard
  • Communication — order confirmations, session and reservation notifications, service announcements, and support
  • Improvement & diagnostics — understanding usage patterns, fixing crashes, and improving reliability and performance
  • Safety & security — fraud and abuse prevention, device attestation, enforcing our Terms, and recording and reviewing the reports users submit about content or about other users
  • Business insights for venues — venues see the operational data needed to serve you (your display name, order and session details) and aggregated analytics about their own operations; venues do not receive your contact details for marketing
  • Legal compliance — meeting bookkeeping, tax, and other regulatory obligations, and responding to lawful requests

5. Legal bases

  • Contract performance — most processing exists to deliver the Services you asked for (account, orders, reservations, payments)
  • Legitimate interests — security, fraud prevention, diagnostics, and product improvement, balanced against your rights
  • Consent — device permissions (location, camera, photos, notifications) and optional social features; you can withdraw consent at any time via device settings or in-app controls
  • Legal obligation — retention of financial and audit records required by law

6. Data sharing & processors

We do not sell your personal data. We share it only as described below.

Infrastructure and service providers

  • Google (Firebase & Google Cloud) — authentication, database, storage, push notifications, analytics, crash reporting, app attestation, and hosting. Google also provides Google Maps and Places for map display and address search. Google may process data in the United States and other countries (see section 9).
  • Stripe — processes guest card payments to venues (via Stripe Connect; the venue is the merchant for those payments).
  • Paddle — merchant of record for business subscriptions.

These providers process data only as necessary to perform their functions and under their own security and compliance obligations.

Venues you interact with

When you join a session, place an order, or make a reservation at a venue, that venue sees the information needed to serve you: your display name, order details, session participation, and reservation details. Venues are required by our Terms to use this data only for serving you. For the data a venue receives about its own guests, the venue acts as an independent data controller under its own privacy obligations — requests concerning a venue's own use of your data can be addressed to that venue, and we will help route them where we can.

Legal and corporate

We may disclose information when required by law or legal process, to protect the rights and safety of users or the public, or — with notice to you — as part of a merger, acquisition, or asset sale involving ANNATECH SRL.

Business accounts — platform tax reporting. Where EU tax-transparency rules for digital platforms apply (Council Directive (EU) 2021/514, "DAC7"), we are required to collect, verify, and report to the competent tax authorities identification and revenue data about businesses that sell through the platform (such as legal name, tax identification number, financial account identifier, and the consideration received through the platform). This applies to business sellers, not to consumer accounts.

7. Data retention

We keep personal data only as long as needed for the purposes above. Records reach the end of their retention window in one of three ways, and the table says which applies to each: they are deleted; they are redacted (the sensitive parts are stripped and a reduced record remains); or they are anonymized (your name and identifying details are replaced with a deletion marker and a non-identifying operational record is kept).

DataWhat happens, and when
Account & profile dataDeleted. Kept while your account is active; deletion starts immediately when you request account deletion
The table-session record and the list of who took partAnonymized, then kept indefinitely as an audit trail. Your name and identifying details are removed when you delete your account; no end date is set for the remaining record
Orders placed in a table session (items, history, related requests)Deleted 30 days after the session closes
In-app payment records (card payments guests make to a venue)Redacted, then deleted. Payment credentials and payer links are removed 30 days after the session closes; the whole record is deleted about 390 days after the session closes, which leaves a reconciliation and chargeback runway
Invoices and accounting recordsKept for as long as accounting and tax law requires — about 7 years. These live in accounting systems, and for business-subscription invoices with Paddle as merchant of record; they are not the in-app payment records described in the row above
Reservations and pickup/delivery ordersAnonymized 180 days after the reservation slot or the order: name replaced with a deletion marker, phone, e-mail, notes and delivery address cleared. The booking or order itself and its amounts are kept
Feedback threads and the messages in themDeleted 180 days after the last message in the thread
Reports you submit about another user or about content, and the evidence attached to themDeleted 180 days after the report is submitted
Direct-message text (social features)Deleted 48 hours after sending — removed shortly after expiry by an automatic sweep
In-app notificationsDeleted 90 days after you read them, or 180 days after they were created if you never read them
Business-subscription checkout requestsDeleted 30 days after the request if the checkout is never completed, or 180 days after it if it is
Push tokens, notification settings, loyalty accounts and pointsDeleted with your account. A device token that stops being used is also removed after 180 days of inactivity
Audit records of staff actions and of manual loyalty-point adjustmentsAnonymized, then kept indefinitely as an accountability record; no end date is set
Crash & analytics dataDeleted by the provider under provider-standard retention windows

Cleanup runs on scheduled jobs rather than at the exact second a window expires, so a record can survive a short time past the point shown before the next run removes it.

You can delete your account and its data at any time — see Delete your account for exactly what is deleted and what is retained in anonymized form.

8. Security

We protect your data with encryption in transit and at rest, strict server-side access rules (security rules and server-validated operations for all sensitive actions), role-based access for staff functions, device attestation, and audit logging of sensitive operations. No system is perfectly secure, but security is a design principle of the platform, not an afterthought.

9. International transfers

We operate from Romania and primarily use infrastructure in the European Union. Some of our providers — including Google, Stripe, and Paddle — may process data in the United States and other countries. Where personal data leaves the European Economic Area, transfers rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions covering the receiving country and provider.

10. Your rights

Depending on your jurisdiction (and under the GDPR in the EU/EEA), you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your data (see account deletion)
  • Receive a portable copy of data you provided
  • Restrict or object to certain processing, including processing based on legitimate interests
  • Withdraw consent at any time, where processing is based on consent

To exercise any right, email privacy@dinexpro.app. We respond in accordance with applicable law. You also have the right to lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP) — or with your local data-protection authority.

Automated decision-making. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Automated protections (such as device attestation and abuse rate-limits) only gate platform access for security and are subject to human review on request.

11. Children's privacy

DineXpro is not intended for children under 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children; if you believe a child has provided us data, contact privacy@dinexpro.app and we will delete it promptly.

12. This website and the web app

This website (www.dinexpro.app) sets no cookies, runs no analytics or tracking scripts, and loads no third-party resources — all assets are served from our own domain. Our hosting provider (Google Firebase Hosting) processes standard technical request data, such as your IP address, strictly to deliver the pages.

The web application (app.dinexpro.app) stores only what is strictly necessary to provide the service you request: your sign-in state (Firebase Authentication, kept in browser storage such as IndexedDB and localStorage), local preferences saved on your device (for example, your recently visited venues), security and anti-abuse attestation (Google reCAPTCHA Enterprise, used by Firebase App Check, which may set a Google cookie), fraud-prevention cookies set by Stripe when a payment component loads, and Paddle checkout cookies on the business subscription pages. The web app sets no advertising cookies and no analytics cookies, and for that reason it shows no cookie banner. These strictly-necessary items are provided by the processors listed in section 6 and are covered by the transfer safeguards in section 9.

13. Changes to this policy

When we make material changes, we update the version and "Last updated" date at the top of this page and, where appropriate, notify you in the app or by email. For business accounts, acceptance is recorded with the version number in effect at the time.

14. Contact

  • Privacy: privacy@dinexpro.app
  • General: contact@dinexpro.app
  • Controller: ANNATECH SRL, B-dul 1 Mai nr. 45, Municipiul Craiova, jud. Dolj, 200355, Romania · CUI 52437424 · Reg. Com. J2025066494002 · EUID ROONRC.J2025066494002

See also: Terms of Service · Refund Policy · Delete your account

DDineXpro

The all-in-one platform for restaurants, venues, and their guests.

Product

  • Modules
  • Pricing
  • Web dashboard
  • Support

Legal

  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Account deletion
  • Company info

Contact

  • contact@dinexpro.app
  • support@dinexpro.app
  • privacy@dinexpro.app

ANNATECH SRL · B-dul 1 Mai nr. 45, Municipiul Craiova, jud. Dolj, 200355, Romania · CUI 52437424 · Reg. Com. J2025066494002 · EUID ROONRC.J2025066494002
© 2026 ANNATECH SRL All rights reserved. · English · Română