Last updated 27 September 2026 · Applies to dinecheck.in (including /request and /check), portal.dinecheck.in (including the kitchen app at /kitchen and restaurants' public pages at /open and /verify), kit.dinecheck.in and api.dinecheck.in
In short
You can browse dinecheck.in and a restaurant's menu or kitchen page without an account. We don't use advertising or tracking cookies, and we never sell personal data.
Our main database and all uploaded files are kept in India (Mumbai). Emails are sent through a provider in Japan, and a few features use providers abroad — each is listed in section 5, with what it receives.
If you ask us to audit a restaurant, only our admins can see who asked; we never tell the restaurant.
If you sign in with Google to ask for an audit, we receive only your name, email address and Google account ID, use them only for your requests, and never sell or share them — details.
If you rate a restaurant, your stars, comment and any first name you give are public on its page. We store a scrambled code for your phone, not who you are.
Restaurants that use our portal decide what they record about their own staff; we process it for them and keep it only as long as needed.
You can reach us at privacy@dinecheck.in for any question or request about your data.
1. Who we are
Dine Check ("we", "us") is an independent food-safety audit bureau based in Hyderabad, Telangana, India. We run the public food-safety directory at dinecheck.in, the audit request page at dinecheck.in/request, the owners' self-check at dinecheck.in/check, the client portal at portal.dinecheck.in (with its kitchen app and the public menu and kitchen pages restaurants choose to publish), the field kit our auditors use at kit.dinecheck.in, and a partner API at api.dinecheck.in.
For people who ask for audits, rate restaurants, use our self-check, and our own staff and partners, we are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023. For the records a restaurant keeps about its own staff in our portal and kitchen app (section 2), the restaurant decides what is recorded and why; we process that data on its behalf and under its instructions. Contact us at privacy@dinecheck.in.
2. What we collect
When you browse dinecheck.in
Nothing that identifies you. There is no account. Your saved places, theme and chosen city are kept in your own browser and are never sent to us.
"Near me" asks your browser for your location. It is used on your device to sort places by distance and is never sent to us.
Visit counts. We use Cloudflare Web Analytics, which counts page views without cookies and without identifying you.
How pages are used. We use Microsoft Clarity to see how people use dinecheck.in — where they click, how far they scroll, and replays of individual page visits — so we can make the site easier to use. We run it without cookies, so it cannot recognise you from one page or visit to the next. Anything you type into a box is never sent, and the audit-request and kitchen self-check pages are hidden from it entirely. Clarity also receives your IP address and browser details. Microsoft keeps replays for 30 days and summary data for up to 9 months.
Technical logs. Our hosting and network providers record technical information (such as IP address, browser type and the page requested) to keep the service running and secure.
When you ask us to audit a restaurant (dinecheck.in/request)
From Google Sign-In: your name, email address and your Google account ID (a number that identifies your account to us). We do not receive your Google password, and we do not store your profile picture.
Your requests: the restaurant you chose, its area and city, its Google Maps place ID, when you asked, and each restaurant you added your voice to.
Your email choice: whether you want updates, and when you stopped them.
What you type in the search box is sent through our server to Google Maps to find the restaurant. We do not keep your searches.
Daily usage counts tied to your account, to stop abuse and runaway costs. These are deleted after 30 days.
Google user data (Sign in with Google)
The only part of Dine Check that uses a Google account is the audit request page, dinecheck.in/request. There you can choose to sign in with Google. We ask Google only for the basic sign-in permissions — openid, email and profile — and nothing else. We cannot see your Gmail, Drive, contacts, calendar or any other Google data, we never see your password, and we never post or act on your behalf.
What we receive from Google: your name, your email address, whether Google has verified that email, and your Google account ID (a number that identifies your account to us). Google's sign-in token also carries a link to your profile picture; we do not store it.
How we use it: to confirm that a real person with a verified email is asking; to record the restaurants you ask us to audit and the requests you add your voice to, so that each person counts once; to show you your own requests; to email you about them only if you tick the box for updates; and to answer requests about your data. We use it for nothing else.
How we store and protect it: in our database in India (Mumbai), over encrypted connections, readable only by our own administrators. Your sign-in stays in the current browser tab and is cleared when you close it.
Sharing: we do not sell, rent or trade Google user data, we do not use it for advertising or to build profiles, and we do not use it to train AI models. The restaurants you ask about never learn who asked. It is handled only by the service providers that run the request page for us — Supabase (our database) and, if you asked for updates, Resend (which sends our emails) — or disclosed if the law requires it.
Keeping and deleting it: we keep it until you delete it, or for two years after you last used the request page. You can delete it at any time with Delete my details on the request page, or by writing to privacy@dinecheck.in. You can also remove Dine Check's access to your Google account at myaccount.google.com/permissions.
Dine Check's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you use the owners' self-check (dinecheck.in/check)
Your answers are scored in your browser and are not sent to us. Only if you ask us to contact you do we receive your name, phone or email, your establishment's name and city, and your score.
When you open a restaurant's menu or kitchen page, or rate it
Reading the page needs no account and we collect nothing about you beyond technical logs.
If you rate the restaurant: your stars (overall and, if you choose, cleanliness), your comment and any first name you give. These are public on the restaurant's page. Please do not include other people's names or personal details.
A code for your phone: the page keeps a random code in your browser so that you have one rating per restaurant and can change it. We store only a scrambled (hashed) form of that code — not your name, number, account or location.
When you send a rating, a contact request or an audit request
An "are you a person?" check. Before any of these is accepted, Cloudflare Turnstile checks that a person, not a program, is sending it. It usually runs unseen; sometimes it asks you to tick a box. Cloudflare receives technical details of your browser and your IP address for this, under its own Turnstile privacy terms, and tells us only whether the check passed.
Your IP address, to count. We use it to limit how many ratings or requests arrive from one connection. We never store the address itself — only a scrambled code made from it with a key that changes every day — and we delete that code after two days.
Security records
To protect accounts and data, we keep a security log: sign-ins to the portal, kitchen app and kit; changes to staff, client access, two-factor and plans; public pages switched on or off; deletions; and attempts our public forms refused. It records the account involved, the establishment if there is one, and — for sign-ins and the public forms — a scrambled code made from the IP address with a key that changes every day, never the address itself.
Nobody can edit it. It is kept for 180 days in our database in India (Mumbai), and only our administrators can read it.
If your establishment uses our client portal or kitchen app
Portal users: the name, email address and role of each person invited, when they signed in, and what they do in the portal (recorded for accountability).
What the establishment records: licences, permits and certificates and their copies; corrective-action plans and photographs (we re-encode photographs, which removes location and camera data); appeals and requests; menus, dishes, allergens and prices.
About its staff, as the establishment chooses: name, job, training certificates, whether a medical fitness certificate is current (not the medical details), induction, kitchen-app sign-in and PIN (stored only in scrambled form), the kitchen records each person makes, rota, leave, and attendance. Attendance records the time and the distance from the premises when someone clocks in or out — we do not store their location.
POSH annual report: if the establishment prepares its Internal Committee's report in the portal, the committee members' names and roles and the yearly counts. We never ask for, and the report does not contain, details of any complaint.
Kitchen incidents: if the establishment records a guest complaint, the guest's contact details may be included; they are removed after one year.
When we audit an establishment
Our auditors' observations, photographs of premises and practices (we avoid photographing faces), and the names of people present at the opening and closing meetings.
Contact details of the establishment's staff that the establishment gives us.
Our staff and partners
For our auditors and reviewers: account, role, qualifications and a record of actions in the kit.
For partners using the API: the partner's contact name and email, and a log of API requests (time, request and IP address).
3. Why we use it
To count and act on requests — one voice per person, so the counts are honest — and to decide which restaurants to approach. Based on your consent, given when you sign in and send a request.
To send you updates about restaurants you asked for, only if you tick the box. Based on your consent, which you can withdraw at any time.
To show guest ratings on the restaurant's page, keep them to one per phone, and stop abuse. Based on your choice to rate.
To carry out audits and run our portal and kitchen app for establishments: reports, corrective actions, compliance reminders, kitchen records, rota and attendance, regulatory updates. Based on our agreement with the establishment, and for its staff on the establishment's instructions.
To keep the services secure, prevent abuse and fix problems, and to meet legal obligations.
We do not use personal data for advertising, we do not build profiles of you, and we do not sell or rent personal data to anyone.
4. Who we share it with
We use a small number of service providers who process data on our behalf, under their own security and privacy commitments. Section 5 says where each one keeps it.
Supabase — our database, sign-in, file storage and server functions.
Cloudflare — network and security, hosting of the portal, kitchen app and kit, visit counts, and the "are you a person?" check on our forms (Turnstile).
GitHub — hosting of the public website (no personal data is stored there).
Microsoft (Clarity) — how visitors use dinecheck.in, without cookies (section 2).
Google — Sign-In, and restaurant search and details (Google Maps Platform). Google's own privacy policy applies to your use of Google Sign-In.
Resend — sending emails.
Anthropic — the AI behind two optional features (section 8). It receives no personal data.
Dropbox — storing our encrypted backups. Backups are encrypted before they leave our system; Dropbox cannot read them.
Meta (WhatsApp) — only if an establishment turns on WhatsApp reminders, which are off today: the phone number and the reminder text.
Restaurants never learn who asked for them. We may tell a restaurant how many people asked, and when.
Guest ratings are public on the restaurant's page. The restaurant can hide a comment that is abusive or off-topic (its stars still count, and the page says how many were hidden); it never sees who wrote it.
Audit results are published on dinecheck.in, or shared with partners such as delivery platforms, only with the audited establishment's written agreement. These results do not contain personal data.
We may disclose data if required by law, a court order or a lawful request from a government authority, or to protect the rights and safety of people or our services.
5. Where it is kept
Our database and all uploaded files — audit records and photographs, licences and certificates, kitchen records, staff records, ratings and requests — are stored in India, in our Supabase project in the Mumbai (ap-south-1) region. Some providers process limited data elsewhere:
Provider
What it handles
Where
Supabase
Database, sign-in, files, server functions and scheduled jobs
India — Mumbai (ap-south-1)
Cloudflare
Delivers our pages and passes requests to our database; stores no personal data, only page files. Its Turnstile check on our forms receives browser details and your IP address
Its global network — requests are handled at the nearest location
Resend
Email address, name and the text of emails we send
Japan — Tokyo (ap-northeast-1)
Google
Sign-In for audit requests; restaurant searches
Google's global infrastructure
Anthropic
Dish names, ingredients and menu sections; public regulation text — never personal data
United States
Dropbox
Backups, encrypted before upload (Dropbox cannot read them)
United States
GitHub
The public website's files; no personal data
United States
Microsoft (Clarity)
How dinecheck.in pages are used — clicks, scrolling and page replays, with typed text and the request and self-check pages hidden; IP address and browser details
Microsoft's cloud (Azure), outside India
Meta (only if WhatsApp is turned on)
Phone number and reminder text
Meta's global infrastructure
Where data leaves India, we use providers that protect it with strong security and we transfer it only as permitted under Indian law, including any restrictions the Government of India notifies under the Digital Personal Data Protection Act, 2023.
6. How long we keep it
Data
Kept for
Your request account (name, email)
Until you delete it, or two years after you last used the request page. Your votes then stay counted without your name.
Daily usage counts
30 days
Scrambled connection codes (to limit repeated ratings and requests)
2 days
Security log
180 days
Self-check contact requests
18 months
Guest ratings and comments
While the restaurant's page is published; you can change yours at any time from the same phone, or ask us to remove it
Copies of emails we sent
90 days
Audit reports and scores
Five years from the audit
Audit photographs
Three years from the audit
Names recorded at audit meetings; establishment staff contacts
One year
Kitchen records and sign-offs
Two years
Guest contact details in a kitchen incident
One year
Staff who have left an establishment
One year after they leave, then medical fitness answers are cleared, names anonymised and their documents deleted; kitchen-app PINs and sign-ins end when they leave
Rota, leave and attendance
For as long as the establishment needs them for its wage and attendance records; deleted at its request
Anything under appeal or dispute
Until two years after it is resolved
Partner API request logs
90 days
Encrypted backups
We keep at most the ten most recent
7. How we protect it
All connections are encrypted (HTTPS). Access to data is limited by role and checked by the database itself on every request; our apps can only call checked functions, never read tables directly. Administrators sign in with two-factor authentication. Kitchen-app PINs and ratings codes are stored only in scrambled form. Photographs are re-encoded to remove location data. Backups are encrypted. People who ask for audits sign in with Google, so we never hold their passwords. No system is perfectly secure; if a breach affects your personal data, we will tell you and the Data Protection Board of India as the law requires.
8. AI features
Two optional features use an AI service from Anthropic:
Allergen and calorie suggestions for a restaurant's dishes. Only the dish name, menu section, the diet the kitchen chose and its list of ingredients are sent — no names of people, customers or staff, and no business details. A person at the restaurant checks every suggestion before it is used.
Regulation watch, which reads public government pages and searches the web for new or changed rules. It uses only public information. What it finds is checked by a Dine Check admin before any client sees it.
We do not use AI to make decisions about people. Under Anthropic's commercial terms, data sent to it through its API is not used to train its models.
9. Your rights
Under the Digital Personal Data Protection Act, 2023, you can:
Get a summary of the personal data we hold about you and what we do with it.
Correct or update inaccurate or incomplete data.
Erase your data where we no longer need it. For requests, use Delete my details at dinecheck.in/request after signing in.
Withdraw consent at any time — for emails, use the link in any email or untick updates at dinecheck.in/request. Withdrawing does not affect what we did before.
Nominate someone to exercise your rights if you die or become unable to.
Complain to our Grievance Officer (below), and if you are not satisfied, to the Data Protection Board of India.
If you work at an establishment that uses our portal, please ask your employer first, as it decides what is recorded; we will help it respond. To exercise any right, email privacy@dinecheck.in from the address we hold, or tell us how to confirm it is you. We aim to reply within 30 days.
10. Children
Our services are not meant for anyone under 18. Please do not sign in, send a request or rate a restaurant if you are under 18. If we learn that we hold a child's data without a parent's consent, we will delete it.
11. Cookies and browser storage
We don't use advertising or tracking cookies. We keep a few things in your own browser, which you can clear at any time:
dinecheck.in: saved places, theme, chosen city, and that you have seen our notice.
dinecheck.in/request: your Google sign-in for the current browser tab, cleared when you close it.
A restaurant's public page: the random code that keeps your rating to one per phone.
The portal, kitchen app and kit keep your sign-in on your device so you stay signed in; the kitchen app also keeps its set-up and unsent records on the device so it works without a connection.
Microsoft Clarity runs on dinecheck.in with cookies switched off, so it stores nothing in your browser that follows you between pages or visits.
Google Sign-In may set its own cookies on Google's websites, under Google's policies.
12. Public records about businesses
The directory at dinecheck.in republishes food-safety inspection records and hygiene ratings that government food-safety authorities have made public, with a link to each original. These records are about businesses. We do not intend to publish personal data about individuals; if you find any, or believe a record is wrong, write to privacy@dinecheck.in and we will review it promptly.
13. Grievance Officer
Grievance Officer, Dine Check, Hyderabad, Telangana, India Email: privacy@dinecheck.in
We acknowledge complaints promptly and aim to resolve them within 30 days.
14. Changes to this policy
We will update this page when our practices change and change the date at the top. If a change materially affects how we use data you have given us, we will tell you by email (if we have your email address and you asked for updates) or on the site before it takes effect.