DineOS is restaurant software: QR menus, table ordering, kitchen displays, recipes and stock, guest offers, WhatsApp messages and Google review management. It is built and run by Remon Ramy in Egypt ("DineOS", "we", "us"). This policy covers the DineOS app and this website, howtools.online. If anything here is unclear, write to [email protected] and you'll get an answer from a person.
Who is responsible for what
When a restaurant uses DineOS, the restaurant decides what it collects from its guests and why. For that guest data the restaurant is the controller and DineOS processes it on the restaurant's behalf. For restaurant accounts, the Google account DineOS connects to, and visitors to this website, DineOS is responsible.
What we collect
Restaurant staff and owners
- Name, username, role, branch and a hashed password (we never store the password itself).
- A log of sign-ins and changes, with the time, IP address and device, kept so a restaurant can see who did what.
- If you turn on notifications, the push subscription your browser gives us, so we can reach that device.
- Support tickets and the messages in them.
Guests using a restaurant's menu
- Anonymous use of the menu: which sections and dishes were on screen and for how long, searches, the language, the type of device, the approximate country and city of the connection, and how the menu was opened (QR code, link or social network). A random identifier stored on the device tells a returning guest from a new one. It contains nothing personal.
- Orders placed from the menu: the dishes, the table and the times.
- Only if the guest chooses to share them: mobile number, gender and date of birth (for offers), name and party size (for a waiting list), and a rating and comment about the visit.
- For WhatsApp messages, the restaurant keeps the wording the guest agreed to, when they said yes or stop, and the messages sent to them.
We never record a guest's IP address in the menu statistics, their precise location, or anything from other websites or apps. Each restaurant's menu has its own privacy page that guests can open from the menu.
Visitors to this website
We use Google Analytics 4 with Consent Mode, and a self-hosted, cookieless Umami counter, to see which pages are read and roughly where visitors come from. In the EEA, the UK and Switzerland, Google Analytics stores nothing on your device unless you allow it. There are no ads on this site.
Data from Google (Google Business Profile)
DineOS can connect to Google Business Profile so a restaurant can see and answer its Google reviews inside DineOS. This is how it works and exactly what we do with the data.
Which Google account and what access
DineOS uses one Google account of its own. A DineOS developer signs in with it once and grants these permissions:
| Permission (scope) | Why we need it |
|---|---|
openid, userinfo.email | To show which Google account is connected, so the right one stays linked. |
business.manage | To list the Business Profile locations that restaurants have shared with that account, read their reviews, rating and performance numbers, and post or remove the replies a restaurant's staff write. |
Restaurants never sign in to Google through DineOS. A restaurant gives access by adding DineOS's Google account as a manager of its own Business Profile, and can remove it there at any time. Only DineOS developers link a branch to a listing, so no restaurant can reach another's.
What we read and keep
- The list of locations shared with DineOS's account, with each one's name and address, so a developer can link it to the right branch.
- Reviews on linked listings: the reviewer's display name as Google shows it (nothing for anonymous reviews), the star rating, the text, the date, and any reply.
- The listing's average rating and review count.
- Performance numbers (people who saw the listing on Search and Maps, calls, direction requests, website and menu clicks). These are read when a page asks for them and kept briefly in memory only, never written to a database.
How we use it
- To show a restaurant the reviews and numbers of its own listings in its dashboard.
- To alert that restaurant's managers when a low rating arrives.
- To post a reply that a person on the restaurant's staff wrote and sent. DineOS never writes or posts replies on its own.
Who sees it
Only the restaurant that owns the listing (its accounts with permission to see reviews) and the DineOS team running the service. We don't sell Google data, share it with other restaurants, use it for advertising, or use it to train AI or machine learning models. Humans at DineOS look at it only when the restaurant asks for support, for security reasons, to comply with the law, or when it's part of the service working.
How long we keep it
- Reviews are checked against Google every day. A review Google no longer shows is deleted from DineOS.
- Unlinking a branch from its listing deletes that branch's Google reviews and rating from DineOS straight away.
- Disconnecting the Google account deletes our stored tokens and revokes them with Google.
- When a restaurant leaves DineOS, its database, including any Google data, is deleted as described below.
A restaurant can message guests from its own WhatsApp Business number through Meta's WhatsApp Business Platform. Messages only go to guests who asked for them on the menu and then confirmed on WhatsApp. Replying STOP ends them. The phone number and message content pass through Meta to be delivered, under Meta's own terms.
Where data is stored and who helps us
DineOS runs on a server we rent and manage ourselves. Traffic is encrypted (HTTPS) and passes through Cloudflare. We use a small number of providers, only for what they do:
- Cloudflare: network protection, and R2 storage for uploaded pictures and database backups.
- Our hosting provider: the server itself, and a second machine that keeps an hourly copy of it.
- Meta: WhatsApp messages, for restaurants that use them.
- Google: Business Profile, for restaurants that use it, and Analytics on this website.
- Browser push services (from Google, Apple or Mozilla, depending on the device): delivering notifications to staff devices.
How long we keep data
- Menu statistics: up to 400 days, then deleted. Daily totals without any guest details are kept longer.
- Waiting list names and numbers: erased after 30 days.
- Guest profiles and WhatsApp consent: until the guest asks to be removed or the restaurant deletes them.
- Backups: rolling copies kept for up to 30 days.
- When a restaurant leaves, its database is deleted within 30 days, and its backups age out after that.
Your choices and rights
Guests can use every menu without sharing a phone number (unless a restaurant requires one to order), clear the device identifier by deleting the site's data in their browser, and stop WhatsApp messages at any time. To see, correct or delete data a restaurant holds about you, contact the restaurant or write to us and we'll pass it on and help them do it. You can also ask us directly about any data DineOS is responsible for. Depending on where you live, you may have further rights under laws such as Egypt's Personal Data Protection Law or the GDPR.
Children
DineOS isn't aimed at children. The offers form doesn't accept anyone younger than ten, and we don't knowingly collect data about children beyond the anonymous menu statistics.
Security
Passwords are hashed, accounts lock after ten wrong attempts, sensitive changes ask for the password again, and every change is logged. Each restaurant has its own database, and staff only see the branches and pages their role allows.
Changes to this policy
If we change how we handle data, we'll update this page and the date at the top. Restaurants using DineOS will hear about important changes inside the dashboard.
Contact
DineOS, run by Remon Ramy, Egypt. Email [email protected].