GDPR & Data Protection
Last updated: 23 July 2026
1. Our commitment
DineSpot is built in the EU, for EU restaurants, and is designed to operate in line with the General Data Protection Regulation (GDPR). This page summarizes how responsibility for personal data is divided and what that means for restaurants and their guests. The full details are in our Privacy Policy.
2. Who is responsible for what
2.1 Restaurant accounts
For the data of restaurant owners and staff who use DineSpot, DineSpot is the data controller.
2.2 Guest reservations
For reservation data collected through a restaurant's booking page, the restaurant is the data controller and DineSpot acts as its data processor. We process guest data only to provide the reservation service — taking bookings, sending confirmations and reminders — and never for our own purposes.
3. Sub-processors
To provide the service we rely on the following sub-processors, each bound by a data processing agreement:
- Supabase — database, authentication and realtime infrastructure
- Stripe — payment processing and card guarantees
- Resend — transactional email delivery
- Twilio — SMS delivery
- Amazon Web Services — file storage
- OpenAI — AI-assisted reservation entry
Where a sub-processor operates outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses or an adequacy decision.
4. Data subject rights
Guests can exercise their GDPR rights — access, rectification, erasure, restriction, objection and portability — by contacting the restaurant they booked with; we assist restaurants in fulfilling such requests. Restaurant users can exercise their rights directly with us at contact@dinespot.com. Complaints can be lodged with the Slovenian Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si) or your local supervisory authority.
5. Security measures
Personal data is protected with encrypted connections (TLS), encryption at rest, per-restaurant tenant isolation enforced with row-level security, and access controls limiting data access to authorized personnel. Card details are handled exclusively by Stripe and never stored on DineSpot's servers.
6. Data processing agreement
Restaurants that need a signed data processing agreement (DPA) covering DineSpot's processing of their guest data can request one at contact@dinespot.com.
7. Contact
For any data protection question, write to us at contact@dinespot.com.