Privacy Policy

Last updated: June 4, 2026

Welcome to dinr.pt. The privacy and security of your personal data are of utmost importance to us. This Privacy Policy describes how we collect, use, share, retain, and protect personal information collected through our SaaS platform, our website, and reservation widgets integrated into our partner restaurants' websites. This document was prepared in strict compliance with the General Data Protection Regulation (GDPR) - Regulation (EU) 2016/679 of the European Parliament and of the Council - and applicable Portuguese legislation, namely Law no. 58/2019, of August 8, which ensures the execution of the GDPR in Portugal.

1. Important Definitions under GDPR

To facilitate the reading of this policy, we adopt the following definitions:

  • "Personal Data": Any information relating to an identified or identifiable natural person ("Data Subject").
  • "Data Subject": Any user accessing our website, any professional customer/partner (restaurant manager) contracting our SaaS, or any end customer (diner) making a reservation through our system.
  • "Data Controller": The entity that determines the purposes and means of processing personal data.
  • "Data Processor": The entity that processes personal data on behalf of and under the instructions of the Data Controller.

2. The Two Roles of Dinr under GDPR

Due to the B2B2C nature of our SaaS service, dinr.pt acts under two distinct legal entities, depending on the category of the data subject:

A. Dinr as Data Controller

We act as Data Controller with respect to the data of:

  • Visitors to our main website (dinr.pt).
  • Professional clients (owners, managers, and F&B directors) who create an account, start a trial period, or subscribe to one of our SaaS software plans.

B. Dinr as Data Processor

We act strictly as a Data Processor with respect to the data of:

  • End customers (diners) who use our widget or booking page (dinr.pt/[restaurant-slug]) to book a table at a partner restaurant.

In this specific scenario, the partner restaurant is the sole Data Controller. dinr.pt only provides the technical infrastructure and processes data in accordance with the documented instructions of the restaurant, through a Data Processing Agreement (DPA) signed between the parties. Diners should consult the respective restaurant's privacy policy to understand how their data is managed by it.

3. Identity of the Data Controller

If you are a website user or a professional customer of our SaaS, the entity responsible for processing your data is:

  • Company Name (Placeholder): [Nome da sua Empresa, Lda. ou Unipessoal, Lda.]
  • Commercial Brand: dinr.pt
  • Tax ID (NIPC / NIF) (Placeholder): [500000000]
  • Registered Office (Placeholder): [Morada Completa, Portugal]
  • Contact Email: suporte@dinr.pt / privacidade@dinr.pt

4. What Data We Collect, for What Purposes, and on What Legal Basis?

The collection of personal data is limited to what is strictly necessary for each purpose. The detailed mapping under GDPR is presented below:

A. Website Visitors and Contact/Demo Requests

  • Data Collected: Name, corporate email address, phone number, restaurant name, browsing data (cookies and IP address).
  • Purposes: Respond to requests for information, schedule SaaS demonstration meetings, provide preliminary sales support, and optimize website performance.
  • Legal Basis: User consent (Art. 6(1)(a) GDPR) when submitting forms, or Legitimate Interest (Art. 6(1)(f) GDPR) for website security and technical improvement.

B. SaaS Users (Professional Clients / Restaurateurs)

  • Data Collected: Account username, restaurant email, phone number, billing data (NIF, billing address, payment details securely processed and encrypted by Stripe), operational data (room layouts, staff shifts entered).
  • Purposes: Management and maintenance of the SaaS subscription, account security validation, billing and payment processing, technical support, and sending operational and system information communications (including security, maintenance, critical updates, and billing alerts).
  • SMS and Email Communications: dinr.pt will send notifications directly to the registered email and phone number of the SaaS client regarding any relevant event related to system administration, reservation limit alerts, payment failures, or security updates.
  • Legal Basis: Performance of a Contract (Art. 6(1)(b) GDPR) for service provision and compliance with Legal and fiscal obligations (Art. 6(1)(c) GDPR).

C. End Customers (Diners Booking Tables) — Processed on behalf of the Restaurant

  • Data Collected: Name, mobile number, email, reservation date and time, number of people, reservation occasion (e.g., birthday, business), and observations/allergies voluntarily entered.
  • Purposes: Process and confirm the online booking, manage the digital waitlist, and the customer's preference history at the restaurant.
  • SMS and Email Communications (Booking Notifications): The contact details collected (email and mobile number) are used exclusively to contact you directly about your bookings. This includes automated booking confirmations, reconfirmation reminders to reduce no-shows, change or cancellation notifications, and table availability alerts on the digital waitlist. These communications are purely transactional and operational and will not be used for marketing without the diner's prior consent obtained by the restaurant.
  • Legal Basis: The partner restaurant (as Controller) relies on the performance of pre-contractual/contractual measures (Art. 6(1)(b) GDPR) at the request of the data subject to make the booking, and explicit Consent (Art. 6(1)(a) GDPR) for the collection of sensitive health data (e.g., indicating food allergies).

5. Data Recipients and Processors

To operate our platform and ensure premium quality service delivery, dinr.pt relies on trusted external technological partners acting as processors under GDPR-compliant contracts:

  1. Database Hosting and Backend: Supabase / PostgreSQL (with servers located in the European Union, ensuring strict logical isolation of data through RLS - Row Level Security).
  2. Payment Processing (B2B): Stripe Inc. (credit card details are never stored on dinr.pt servers).
  3. SMS Notifications (Transactional): Twilio Inc. (used for instant alerts of available tables and operational reconfirmations).
  4. Email Notifications: Resend (for operational and transactional emails).

International Data Transfers

Whenever we use service providers based outside the European Economic Area (EEA), such as in the United States (e.g., Twilio, Stripe), we ensure these transfers are safeguarded by using Standard Contractual Clauses (SCCs) approved by the European Commission or under adequacy decisions in force (such as the EU-U.S. Data Privacy Framework).

6. Security and Data Isolation

Our platform's security is based on Security by Design and Security by Default principles:

  • Logical Isolation (Row Level Security - RLS): The multi-tenant architecture of dinr.pt uses PostgreSQL RLS to ensure that each restaurant's data (customer data, booking history, and billing) is logically isolated using a unique tenant identifier. It is impossible for one restaurant to access, modify, or delete another's data.
  • Data Encryption: All communications between the user's browser, the database, and our servers are protected with state-of-the-art HTTPS/TLS encryption.
  • Access Auditing: We monitor and record all administrative access to our databases to mitigate intrusion or data leak risks.

7. Data Retention Period

We retain data only for the period strictly necessary to fulfill the purposes for which it was collected:

  • SaaS Customer Data: Retained while the subscription remains active. After cancellation, data is anonymized or securely deleted within 30 days, except for billing and accounting data, which must be kept for 10 years due to legal fiscal obligations in Portugal.
  • End Customer Data (Bookings): Since dinr.pt is a processor, the retention period for this data is defined by the respective restaurant's privacy policy. dinr.pt will delete or anonymize this data as soon as the contract with the restaurant ends or upon formal request from the Controller restaurant.
  • Demo Requests / Commercial Leads: Retained for a maximum period of 2 years after the last active contact, if it does not convert into an active SaaS subscription.

8. Data Subject Rights

Under the GDPR, all data subjects are guaranteed the following rights by law:

  • Right of Access: To know if their data is being processed and obtain a copy.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of their data when it is no longer necessary for the initial purposes.
  • Right to Restriction of Processing: Temporarily suspend data processing under certain circumstances.
  • Right to Object: Object to data processing for reasons related to their particular situation or for direct marketing purposes.
  • Right to Data Portability: Receive their data in a structured, commonly used digital format to transfer it to another entity.
  • Right to Withdraw Consent: Withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).

How to exercise your rights?

To exercise any of these rights, the data subject must contact us in writing via email: privacidade@dinr.pt.

  • Note: If the requester is a diner who booked a table at one of our partner restaurants, the request must be addressed directly to the restaurant (Data Controller). If you send the request to us directly, we will forward it to the respective partner restaurant for direct processing.

Supervisory Authority

Users and data subjects have the right to lodge a complaint with the national supervisory authority in Portugal if they consider that the processing of their data violates applicable data protection laws:

  • National Data Protection Commission (CNPD)
  • Address: Av. D. Carlos I, 134 - 1.º, 1200-651 Lisbon, Portugal
  • Website: https://www.cnpd.pt/

9. Use of Cookies

The dinr.pt website uses cookies to improve user experience and analyze browsing traffic in an aggregated manner. We provide a cookie consent banner that allows users to choose which categories of cookies to enable (except for strictly necessary cookies for the technical operation of the platform, detailed in our Cookie Policy).

10. Changes to this Privacy Policy

dinr.pt reserves the right to update this Privacy Policy at any time to reflect product improvements, technical changes, or new regulatory guidelines in Portugal. We recommend checking this page periodically. Whenever there are substantial changes, we will notify our registered customers via email or a prominent notice on the SaaS administration screen.