GDPR & Data Protection

Last updated: 23 July 2026

1. Our commitment

DineSpot is built in the EU, for EU restaurants, and is designed to operate in line with the General Data Protection Regulation (GDPR). This page summarizes how responsibility for personal data is divided and what that means for restaurants and their guests. The full details are in our Privacy Policy.

2. Who is responsible for what

2.1 Restaurant accounts

For the data of restaurant owners and staff who use DineSpot, DineSpot is the data controller.

2.2 Guest reservations

For reservation data collected through a restaurant's booking page, the restaurant is the data controller and DineSpot acts as its data processor. We process guest data only to provide the reservation service — taking bookings, sending confirmations and reminders — and never for our own purposes.

3. Sub-processors

To provide the service we rely on the following sub-processors, each bound by a data processing agreement:

  • Supabase — database, authentication and realtime infrastructure
  • Stripe — payment processing and card guarantees
  • Resend — transactional email delivery
  • Twilio — SMS delivery
  • Amazon Web Services — file storage
  • OpenAI — AI-assisted reservation entry

Where a sub-processor operates outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.

4. Data subject rights

Guests can exercise their GDPR rights — access, rectification, erasure, restriction, objection and portability — by contacting the restaurant they booked with; we assist restaurants in fulfilling such requests. Restaurant users can exercise their rights directly with us at contact@dinespot.com. Complaints can be lodged with the Slovenian Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si) or your local supervisory authority.

5. Security measures

Personal data is protected with encrypted connections (TLS), encryption at rest, per-restaurant tenant isolation enforced with row-level security, and access controls limiting data access to authorized personnel. Card details are handled exclusively by Stripe and never stored on DineSpot's servers.

6. Data processing agreement

Restaurants that need a signed data processing agreement (DPA) covering DineSpot's processing of their guest data can request one at contact@dinespot.com.

7. Contact

For any data protection question, write to us at contact@dinespot.com.