DineKeeper
FeaturesGuest appRatingsHow it worksPricing
Sign inStart for free

Privacy Policy

How we collect, use and protect personal data.

Last updated: 2026-07-28

Operational draft for counsel review — not yet signed off. Provider is Orderking GmbH (Austria). Firmenbuch, VAT ID (UID), and managing director(s) are still marked TODO.

1.Controller and roles

The controller for personal data processed in connection with the dinekeeper.app website (marketing, signup, contact) and for operating the DineKeeper platform as software-as-a-service is Orderking GmbH (see imprint; email: help@orderking.at).

Where guests order via tablets or the Guest app or pay in-venue, the restaurant (our customer / “tenant”) is typically the controller of guest order data. DineKeeper then acts as a processor under Art. 28 GDPR based on a data processing agreement (DPA).

Online payments via Stripe Connect involve Stripe as payment service provider; see Stripe’s terms and privacy notices and the connected restaurant account settings.

2.What data we collect

Website and account: form data (e.g. name, email, restaurant/location details), credentials (password hashed only), contact-message content, and technical logs (IP address, timestamp, user agent) as needed for operations and security.

Platform (dashboard, devices, orders): user roles, table and device identifiers, pairing/access codes, session and order data (items, status, amounts), optional in-session guest profiles, and payment metadata (amounts, tips, Stripe references — no full card numbers stored by DineKeeper).

Cookies and similar technologies: necessary storage for security, language and session; after consent, analytics and marketing tools (Google Tag Manager, Google Analytics 4; Meta Pixel 1705787850725013 after marketing consent). See “Cookies & tracking” and our cookie banner.

3.Purposes and legal bases

Contract performance and pre-contractual steps (Art. 6(1)(b) GDPR): accounts, dashboard, ordering and payment features, POS connectivity.

Legitimate interests (Art. 6(1)(f) GDPR): secure operation, abuse/fraud prevention, and necessary technical diagnostics — balanced against your interests.

Consent (Art. 6(1)(a) GDPR; where applicable ePrivacy / TTDSG): optional analytics and marketing cookies/tags. Withdraw anytime by changing cookie choices (localStorage key dk_cookie_consent) or browser settings.

Legal obligations (Art. 6(1)(c) GDPR): e.g. commercial and tax retention where applicable.

4.Sharing and processors

We use processors that handle data on our behalf (hosting/infrastructure, databases, object storage, realtime messaging, email if used, OrderKing POS connectivity, Stripe payments, and analytics/marketing tools after consent).

Transfers outside the EEA occur only when necessary and with appropriate safeguards (e.g. adequacy decision or standard contractual clauses), where required.

Restaurants may view and further process order data in their operations (kitchen/POS); their own guest-facing privacy notices apply in addition.

5.Retention

We keep personal data only as long as needed for the purposes above or as required by law. Accounts and contract data: for the relationship and statutory periods thereafter. Order and payment data: per tax/commercial rules and the restaurant’s and our processor role. Cookie consent and attribution: in the browser until cleared or changed. Server logs: typically short-term unless needed longer for security.

6.Your rights

Under the GDPR you may have rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. You may withdraw consent at any time with effect for the future.

Contact help@orderking.at to exercise rights. You may also lodge a complaint with a supervisory authority (in Austria, typically the Data Protection Authority (dsb.gv.at) or the authority at the controller’s seat).

Guests whose data is controlled by the restaurant should contact the restaurant first; we assist the controller under the DPA.

7.Cookies and tracking

We use Google Tag Manager (container GTM-5SNB2KW2). Google Analytics 4 (measurement ID G-06JPVX6WW5) loads via GTM only. Meta Pixel (ID 1705787850725013) loads from the site after marketing consent — not as a second GTM Facebook tag. Marketing tags fire only with marketing consent.

Before your choice we set Consent Mode v2 defaults to denied. After Accept all, Necessary only, or a custom choice we update consent and load GTM. The Guest app uses the same model; its privacy link points to this marketing site.

Pay flows (/pay, success, cancel) are noindex. We do not send card data, pay URL tokens, or unnecessary guest PII to analytics/ads tools.

8.Privacy contact

Orderking GmbH — privacy requests: help@orderking.at. Postal address and legal representation: see imprint (once complete).

A data protection officer will be named here if and when legally required or appointed.

Questions? Get in touch.

© 2026 DineKeeper · OrderKing · Live in 48h