Privacy Policy

Last updated 27 September 2026 · Applies to dinecheck.in (including /request and /check), portal.dinecheck.in (including the kitchen app at /kitchen and restaurants' public pages at /open and /verify), kit.dinecheck.in and api.dinecheck.in

In short

1. Who we are

Dine Check ("we", "us") is an independent food-safety audit bureau based in Hyderabad, Telangana, India. We run the public food-safety directory at dinecheck.in, the audit request page at dinecheck.in/request, the owners' self-check at dinecheck.in/check, the client portal at portal.dinecheck.in (with its kitchen app and the public menu and kitchen pages restaurants choose to publish), the field kit our auditors use at kit.dinecheck.in, and a partner API at api.dinecheck.in.

For people who ask for audits, rate restaurants, use our self-check, and our own staff and partners, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023. For the records a restaurant keeps about its own staff in our portal and kitchen app (section 2), the restaurant decides what is recorded and why; we process that data on its behalf and under its instructions. Contact us at privacy@dinecheck.in.

2. What we collect

When you browse dinecheck.in

When you ask us to audit a restaurant (dinecheck.in/request)

Google user data (Sign in with Google)

The only part of Dine Check that uses a Google account is the audit request page, dinecheck.in/request. There you can choose to sign in with Google. We ask Google only for the basic sign-in permissions — openid, email and profile — and nothing else. We cannot see your Gmail, Drive, contacts, calendar or any other Google data, we never see your password, and we never post or act on your behalf.

Dine Check's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you use the owners' self-check (dinecheck.in/check)

When you open a restaurant's menu or kitchen page, or rate it

When you send a rating, a contact request or an audit request

Security records

If your establishment uses our client portal or kitchen app

When we audit an establishment

Our staff and partners

3. Why we use it

We do not use personal data for advertising, we do not build profiles of you, and we do not sell or rent personal data to anyone.

4. Who we share it with

We use a small number of service providers who process data on our behalf, under their own security and privacy commitments. Section 5 says where each one keeps it.

Restaurants never learn who asked for them. We may tell a restaurant how many people asked, and when.

Guest ratings are public on the restaurant's page. The restaurant can hide a comment that is abusive or off-topic (its stars still count, and the page says how many were hidden); it never sees who wrote it.

Audit results are published on dinecheck.in, or shared with partners such as delivery platforms, only with the audited establishment's written agreement. These results do not contain personal data.

We may disclose data if required by law, a court order or a lawful request from a government authority, or to protect the rights and safety of people or our services.

5. Where it is kept

Our database and all uploaded files — audit records and photographs, licences and certificates, kitchen records, staff records, ratings and requests — are stored in India, in our Supabase project in the Mumbai (ap-south-1) region. Some providers process limited data elsewhere:

ProviderWhat it handlesWhere
SupabaseDatabase, sign-in, files, server functions and scheduled jobsIndia — Mumbai (ap-south-1)
CloudflareDelivers our pages and passes requests to our database; stores no personal data, only page files. Its Turnstile check on our forms receives browser details and your IP addressIts global network — requests are handled at the nearest location
ResendEmail address, name and the text of emails we sendJapan — Tokyo (ap-northeast-1)
GoogleSign-In for audit requests; restaurant searchesGoogle's global infrastructure
AnthropicDish names, ingredients and menu sections; public regulation text — never personal dataUnited States
DropboxBackups, encrypted before upload (Dropbox cannot read them)United States
GitHubThe public website's files; no personal dataUnited States
Microsoft (Clarity)How dinecheck.in pages are used — clicks, scrolling and page replays, with typed text and the request and self-check pages hidden; IP address and browser detailsMicrosoft's cloud (Azure), outside India
Meta (only if WhatsApp is turned on)Phone number and reminder textMeta's global infrastructure

Where data leaves India, we use providers that protect it with strong security and we transfer it only as permitted under Indian law, including any restrictions the Government of India notifies under the Digital Personal Data Protection Act, 2023.

6. How long we keep it

DataKept for
Your request account (name, email)Until you delete it, or two years after you last used the request page. Your votes then stay counted without your name.
Daily usage counts30 days
Scrambled connection codes (to limit repeated ratings and requests)2 days
Security log180 days
Self-check contact requests18 months
Guest ratings and commentsWhile the restaurant's page is published; you can change yours at any time from the same phone, or ask us to remove it
Copies of emails we sent90 days
Audit reports and scoresFive years from the audit
Audit photographsThree years from the audit
Names recorded at audit meetings; establishment staff contactsOne year
Kitchen records and sign-offsTwo years
Guest contact details in a kitchen incidentOne year
Staff who have left an establishmentOne year after they leave, then medical fitness answers are cleared, names anonymised and their documents deleted; kitchen-app PINs and sign-ins end when they leave
Rota, leave and attendanceFor as long as the establishment needs them for its wage and attendance records; deleted at its request
Anything under appeal or disputeUntil two years after it is resolved
Partner API request logs90 days
Encrypted backupsWe keep at most the ten most recent

7. How we protect it

All connections are encrypted (HTTPS). Access to data is limited by role and checked by the database itself on every request; our apps can only call checked functions, never read tables directly. Administrators sign in with two-factor authentication. Kitchen-app PINs and ratings codes are stored only in scrambled form. Photographs are re-encoded to remove location data. Backups are encrypted. People who ask for audits sign in with Google, so we never hold their passwords. No system is perfectly secure; if a breach affects your personal data, we will tell you and the Data Protection Board of India as the law requires.

8. AI features

Two optional features use an AI service from Anthropic:

We do not use AI to make decisions about people. Under Anthropic's commercial terms, data sent to it through its API is not used to train its models.

9. Your rights

Under the Digital Personal Data Protection Act, 2023, you can:

If you work at an establishment that uses our portal, please ask your employer first, as it decides what is recorded; we will help it respond. To exercise any right, email privacy@dinecheck.in from the address we hold, or tell us how to confirm it is you. We aim to reply within 30 days.

10. Children

Our services are not meant for anyone under 18. Please do not sign in, send a request or rate a restaurant if you are under 18. If we learn that we hold a child's data without a parent's consent, we will delete it.

11. Cookies and browser storage

We don't use advertising or tracking cookies. We keep a few things in your own browser, which you can clear at any time:

Microsoft Clarity runs on dinecheck.in with cookies switched off, so it stores nothing in your browser that follows you between pages or visits.

Google Sign-In may set its own cookies on Google's websites, under Google's policies.

12. Public records about businesses

The directory at dinecheck.in republishes food-safety inspection records and hygiene ratings that government food-safety authorities have made public, with a link to each original. These records are about businesses. We do not intend to publish personal data about individuals; if you find any, or believe a record is wrong, write to privacy@dinecheck.in and we will review it promptly.

13. Grievance Officer

Grievance Officer, Dine Check, Hyderabad, Telangana, India
Email: privacy@dinecheck.in

We acknowledge complaints promptly and aim to resolve them within 30 days.

14. Changes to this policy

We will update this page when our practices change and change the date at the top. If a change materially affects how we use data you have given us, we will tell you by email (if we have your email address and you asked for updates) or on the site before it takes effect.

Terms of Use · Home · Ask for an audit