Privacy Policy

Last updated: 23 July 2026

1. Who we are

DineSpot ("DineSpot", "we", "us") operates the website www.dinespot.si, the DineSpot restaurant dashboard and the public booking pages hosted for our restaurant customers. Our registered address is Kumrovškova ulica 11, 1000 Ljubljana, Slovenia. For any privacy matter you can reach us at contact@dinespot.com.

2. Our two roles

2.1 DineSpot as a controller

For data about our own users — restaurant owners and staff who create a DineSpot account, visitors of our marketing website, and people who contact us — we decide how and why the data is processed and act as a data controller.

2.2 DineSpot as a processor

When a guest books a table through a restaurant's booking page, the reservation data belongs to that restaurant. The restaurant is the controller of its guests' data and DineSpot processes it on the restaurant's behalf. If you are a guest and want your reservation data corrected or deleted, please contact the restaurant you booked with; we will assist them in fulfilling your request.

3. What data we process

3.1 Account data

Name, email address, password (stored as a cryptographic hash), language and appearance preferences.

3.2 Restaurant data

Restaurant name, address, VAT number, contact details, logo, opening hours, tables and floorplan, and subscription/billing status.

3.3 Reservation and guest data

Guest name, email address, phone number, party size, reservation date and time, preferred language, and any notes or cancellation reasons attached to a reservation.

3.4 Payment data

Where a restaurant requires a card guarantee, the guest's card details are collected and stored directly by our payment provider Stripe. Card numbers never touch or reside on DineSpot's servers.

3.5 Support and communication data

Messages you send us through contact forms, support tickets or email.

3.6 Technical data

Log data and cookies as described in our Cookie Policy.

4. Why we process it and on what legal basis

We process personal data to provide the DineSpot service, including taking, confirming and reminding about reservations (performance of a contract); to send transactional emails and SMS related to reservations (performance of a contract); to bill subscriptions and process card guarantees (performance of a contract and legal obligations); to respond to inquiries and provide support (legitimate interest); to secure and improve the service (legitimate interest); and to comply with tax and accounting law (legal obligation). Where we rely on consent — for example optional cookies — you can withdraw it at any time.

5. Who we share data with

We never sell personal data. We share it only with service providers who process it for us under data processing agreements:

  • Supabase — database, authentication and realtime infrastructure
  • Stripe — payment processing and card guarantees
  • Resend — transactional email delivery
  • Twilio — SMS delivery
  • Amazon Web Services — file storage (e.g. restaurant logos)
  • OpenAI — processing of free-text reservation details when a restaurant uses the AI autocomplete feature

Some providers may process data outside the European Economic Area; where they do, transfers are safeguarded by the European Commission's Standard Contractual Clauses or an adequacy decision.

6. How long we keep data

Account and restaurant data is kept for as long as the account exists and deleted or anonymized after termination, except where retention is required by law (e.g. invoices). Reservation data is kept for as long as the restaurant that owns it keeps it in the service. Support communication is kept for as long as needed to resolve the matter and for a reasonable period thereafter.

7. Your rights

Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. To exercise these rights, contact us at contact@dinespot.com. You also have the right to lodge a complaint with your supervisory authority — in Slovenia, the Information Commissioner (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si.

8. Security

We protect personal data with industry-standard measures, including encrypted connections (TLS), encryption at rest, tenant isolation with row-level security, and access controls limiting data access to authorized personnel.

9. Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.

10. Contact

Questions about this policy or your data? Write to us at contact@dinespot.com.