Privacy Policy
How we collect, use, and protect your information when you use DineXpro.
1. Introduction
This Privacy Policy explains how DineXpro (operated by ANNATECH SRL) collects, uses, stores, and shares information when you interact with our platform — the DineXpro mobile applications, the web application at app.dinexpro.app, this website, and related services (together, the "Services").
We wrote this policy to be specific about what actually happens in the product. If anything is unclear, contact us at privacy@dinexpro.app.
2. Who we are
The data controller for the Services is ANNATECH SRL, a company registered in Romania — str. 1 Mai nr. 45, Municipiul Craiova, jud. Dolj, 200355, Romania; CUI 52437424; Reg. Com. J2025066494002; EUID ROONRC.J2025066494002.
Privacy contact: privacy@dinexpro.app. General contact: contact@dinexpro.app.
3. Data we collect
Account & profile
Using DineXpro requires an account. You can register with an email address and password, or sign in with Google or Apple. We collect your name or display name, email address, and optional profile photo and phone number. Authentication is handled by Firebase Authentication (Google).
Orders, table sessions & activity
When you use the Services as a guest, we collect the activity needed to run the experience: table-session participation and timestamps, QR-scan events and check-ins, order contents and history, bill-splitting choices and payment confirmations, reservation details (party size, time, and any deposit status), pickup and delivery orders (including the delivery address you provide), waiter calls, and feedback you submit.
Location
With your permission, the app uses your device's precise location (GPS) while you are using it, for specific features: showing nearby venues, selecting an address or a business location on the map, and delivery-related flows. The app does not track your location in the background and never requests "always-on" location. You can revoke location access at any time in your device settings; the related features will simply stop working. Independently of GPS, we may derive an approximate, city-level location from your IP address.
Camera & QR scanning
The app uses your camera, with your permission, to scan table and venue QR codes and to take photos you choose to upload. Camera frames used for QR scanning are processed on your device and are not stored or transmitted; the resulting scan event (which code was scanned, and when) is recorded.
Photos & media
If you choose to upload images — a profile photo, or menu and venue photos for business accounts — those images are stored on our infrastructure (Firebase Storage).
Push notifications & device tokens
To deliver order updates, session events, and service notifications, we store a per-device push token issued by Firebase Cloud Messaging, together with your notification settings. Deleting your account deletes your device tokens.
Device & technical data
We automatically collect device type, operating system, and app version; IP address; crash reports and diagnostic logs (via Firebase Crashlytics); and usage analytics (via Firebase Analytics). Analytics and crash data are keyed to pseudonymous identifiers (such as an app-instance ID), not to your name; we use them in aggregate to understand usage and fix problems.
Device integrity
To protect the platform from abuse, requests from the app carry an attestation issued by Firebase App Check (using Google Play Integrity on Android and Apple's attestation services on iOS). This verifies the request comes from a genuine app on a genuine device.
Business & staff data
If you use DineXpro as a business owner or staff member, we collect your business name, address and contact details, menu content and pricing, table configuration and operational settings, staff names, roles and permissions, and operational logs of staff actions (for accountability and audit).
Social & community features
If you opt in to social features, we collect the profile information you choose to make visible, your check-ins and interactions, content you share, reports you submit about other users or content, and related moderation records. Social features are optional; if you never enable them, none of this is collected.
Payment-related information
Card payments you make to a venue are processed by Stripe. We store payment confirmation records — transaction status, amount, timestamps — but we never store full card numbers, CVVs, or other sensitive card credentials on our systems.
Business billing (subscriptions)
DineXpro platform subscriptions are billed by Paddle as merchant of record. Paddle receives the data necessary to process the transaction — typically the business contact email, country, and the items purchased — and issues invoices under its own terms.
4. How we use data
- Providing the Services — accounts, table sessions, ordering, reservations, pickup/delivery, payments, and the staff dashboard
- Communication — order confirmations, session and reservation notifications, service announcements, and support
- Improvement & diagnostics — understanding usage patterns, fixing crashes, and improving reliability and performance
- Safety & security — fraud and abuse prevention, device attestation, enforcing our Terms, and moderating reported content
- Business insights for venues — venues see the operational data needed to serve you (your display name, order and session details) and aggregated analytics about their own operations; venues do not receive your contact details for marketing
- Legal compliance — meeting bookkeeping, tax, and other regulatory obligations, and responding to lawful requests
5. Legal bases
- Contract performance — most processing exists to deliver the Services you asked for (account, orders, reservations, payments)
- Legitimate interests — security, fraud prevention, diagnostics, and product improvement, balanced against your rights
- Consent — device permissions (location, camera, photos, notifications) and optional social features; you can withdraw consent at any time via device settings or in-app controls
- Legal obligation — retention of financial and audit records required by law
6. Data sharing & processors
We do not sell your personal data. We share it only as described below.
Infrastructure and service providers
- Google (Firebase & Google Cloud) — authentication, database, storage, push notifications, analytics, crash reporting, app attestation, and hosting. Google also provides Google Maps and Places for map display and address search. Google may process data in the United States and other countries (see section 9).
- Stripe — processes guest card payments to venues (via Stripe Connect; the venue is the merchant for those payments).
- Paddle — merchant of record for business subscriptions.
These providers process data only as necessary to perform their functions and under their own security and compliance obligations.
Venues you interact with
When you join a session, place an order, or make a reservation at a venue, that venue sees the information needed to serve you: your display name, order details, session participation, and reservation details. Venues are required by our Terms to use this data only for serving you. For the data a venue receives about its own guests, the venue acts as an independent data controller under its own privacy obligations — requests concerning a venue's own use of your data can be addressed to that venue, and we will help route them where we can.
Legal and corporate
We may disclose information when required by law or legal process, to protect the rights and safety of users or the public, or — with notice to you — as part of a merger, acquisition, or asset sale involving ANNATECH SRL
Business accounts — platform tax reporting. Where EU tax-transparency rules for digital platforms apply (Council Directive (EU) 2021/514, "DAC7"), we are required to collect, verify, and report to the competent tax authorities identification and revenue data about businesses that sell through the platform (such as legal name, tax identification number, financial account identifier, and the consideration received through the platform). This applies to business sellers, not to consumer accounts.
7. Data retention
We keep personal data only as long as needed for the purposes above. In summary:
| Data | Retention |
|---|---|
| Account & profile data | While your account is active; deletion starts immediately when you request account deletion |
| Order, payment & audit records (anonymized after account deletion) | Up to 7 years (accounting, tax, and audit obligations) |
| Closed-session snapshots (anonymized) | Up to 3 years |
| Feedback threads & moderation reports (anonymized) | Up to 180 days |
| Direct-message text (social features) | Expires automatically within 48 hours of sending |
| Push tokens, notification settings, loyalty accounts | Deleted with your account |
| Crash & analytics data | Limited, provider-standard retention windows |
You can delete your account and its data at any time — see Delete your account for exactly what is deleted and what is retained in anonymized form.
8. Security
We protect your data with encryption in transit and at rest, strict server-side access rules (security rules and server-validated operations for all sensitive actions), role-based access for staff functions, device attestation, and audit logging of sensitive operations. No system is perfectly secure, but security is a design principle of the platform, not an afterthought.
9. International transfers
We operate from Romania and primarily use infrastructure in the European Union. Some of our providers — including Google, Stripe, and Paddle — may process data in the United States and other countries. Where personal data leaves the European Economic Area, transfers rely on appropriate safeguards, in particular the European Commission's Standard Contractual Clauses and, where applicable, adequacy decisions covering the receiving country and provider.
10. Your rights
Depending on your jurisdiction (and under the GDPR in the EU/EEA), you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data (see account deletion)
- Receive a portable copy of data you provided
- Restrict or object to certain processing, including processing based on legitimate interests
- Withdraw consent at any time, where processing is based on consent
To exercise any right, email privacy@dinexpro.app. We respond in accordance with applicable law. You also have the right to lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP) — or with your local data-protection authority.
Automated decision-making. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Automated protections (such as device attestation and abuse rate-limits) only gate platform access for security and are subject to human review on request.
11. Children's privacy
DineXpro is not intended for children under 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children; if you believe a child has provided us data, contact privacy@dinexpro.app and we will delete it promptly.
12. This website
This website (www.dinexpro.app) sets no cookies, runs no analytics or tracking scripts, and loads no third-party resources — all assets are served from our own domain. Our hosting provider (Google Firebase Hosting) processes standard technical request data, such as your IP address, strictly to deliver the pages.
13. Changes to this policy
When we make material changes, we update the version and "Last updated" date at the top of this page and, where appropriate, notify you in the app or by email. For business accounts, acceptance is recorded with the version number in effect at the time.
14. Contact
- Privacy: privacy@dinexpro.app
- General: contact@dinexpro.app
- Controller: ANNATECH SRL, str. 1 Mai nr. 45, Municipiul Craiova, jud. Dolj, 200355, Romania · CUI 52437424 · Reg. Com. J2025066494002 · EUID ROONRC.J2025066494002
See also: Terms of Service · Refund Policy · Delete your account