Last updated: 5 September 2026
YDine is a software platform that lets independent restaurants run digital menus and QR-code table ordering. This policy explains what information YDine collects, why, and how it's protected — for both restaurant accounts (owners, managers, staff) and, once ordering is live, the customers who order through a restaurant's menu.
YDine is in early development. Some of the data-handling described below (customer accounts, online payments) refers to features that are architected but not yet live — this policy will be updated as each one actually ships, not before.
YDine is a multi-tenant platform: each restaurant that signs up is a separate, isolated account (a "tenant"). Restaurant staff accounts and any customer data collected through a given restaurant's menu belong to that restaurant alone — YDine enforces this separation at the database and application level, and one restaurant can never see another's data.
When you or your restaurant sign up, we collect:
Customers ordering through a restaurant's digital menu are not required to create an account for a simple dine-in or collection order. If a restaurant offers customer accounts, or a customer chooses to provide contact details for order updates, we collect only what's needed to fulfil and communicate about that order — typically a name, and a phone number or email address.
YDine does not store full payment card details. Online payments, once enabled, are processed by a third-party payment provider (Stripe) — card details go directly to them, never through YDine's own servers. We store only the resulting payment status and a transaction reference.
Like most web services, our servers automatically log basic technical information for security and debugging — IP address, browser/device type, and the pages or API requests made. These logs are used to keep the service secure and reliable, not for advertising or profiling.
YDine uses a single essential cookie to keep you signed in (a random session identifier — not a tracking identifier, and not shared with any third party). We do not currently use advertising or analytics cookies.
We do not sell personal information. We share it only with:
We keep account and order data for as long as the associated restaurant account is active, plus a reasonable period afterward for legal, tax, and dispute-resolution purposes. You can request deletion of your restaurant account and its data at any time (see "Your rights" below) — this doesn't affect records a restaurant is separately required to keep for its own tax/accounting obligations.
Passwords are hashed with bcrypt, never stored or logged in plain text. All traffic to YDine is encrypted with HTTPS. Every restaurant-scoped action is authorised server-side against the signed-in user's actual role and restaurant membership — a restaurant's data is never exposed based on a value the browser could simply claim. No security system is perfect, but this is treated as a first-class requirement, not an afterthought.
YDine's restaurant accounts are intended for business owners and staff, not children. We don't knowingly collect personal information from children beyond what a customer might submit as part of an ordinary food order (e.g. a family placing a collection order at a restaurant).
Depending on where you're located, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise any of these, contact us at hello@ydine.dalim.dev. If your request concerns an order placed with a specific restaurant, we may need to involve that restaurant, since they are the data controller for their own customers' order records.
We'll update this page as YDine's features change — in particular as online payments, customer accounts, and notifications go from "architected" to "live." The "Last updated" date at the top always reflects the most recent revision.
Questions about this policy or your data: hello@ydine.dalim.dev.