Compliance & Safety

Compliance Standards

Detailed overview of our regulatory compliance posture across GDPR, India DPDP Act, PCI-DSS scope, and food industry regulations.

Our Compliance Overview

DineFlow is designed as a privacy-first product that deliberately minimizes data collection at every layer. Our compliance posture reflects both the legal requirements of our operating jurisdictions and our own ethical commitments around responsible data handling. This page provides a transparent, detailed breakdown of each compliance framework we address.

GDPR-aligned practices

Active

India IT Act 2000 compliant

Active

DPDP Act 2023 aligned

Active

PCI-DSS out of scope

Verified

FSSAI display support

Supported

ISO 27001 (via GCP)

Inherited

Regulatory Frameworks

GDPR (General Data Protection Regulation)

European Union — applicable to all EU-resident users

Aligned

Although DineFlow primarily serves Indian restaurants, we implement GDPR-aligned practices across all our data handling operations. Our guest QR menu interface collects zero PII from diners — no email, name, or phone is required to browse or order, which means the majority of our guest-facing interactions fall entirely outside GDPR's scope. For merchant accounts where EU-based individuals may submit enquiries, we process their data lawfully under the "legitimate interest" and "contractual necessity" bases.

  • Zero PII collected from dining guests at the menu level
  • Merchant data processed under contractual necessity basis
  • Data Subject Access Requests (DSARs) honored within 30 days
  • Right to erasure requests processed within 72 hours
  • Data Processing Agreements (DPAs) available for EU enterprise clients
  • Privacy by design principles applied across all new features

India IT Act 2000 & DPDP Act 2023

Republic of India — primary regulatory framework

Compliant

DineFlow complies with the Information Technology Act, 2000 and its associated rules, and has aligned our data practices with India's Digital Personal Data Protection (DPDP) Act, 2023. All Indian restaurant account data is processed and stored within India. We maintain a legally registered entity in India (DineFlow Technologies Pvt. Ltd.) and appoint a Data Protection Officer (DPO) as required under applicable regulations.

  • All Indian merchant data stored within India (GCP Mumbai)
  • Registered as an Indian company under Companies Act
  • Designated Data Protection Officer (DPO) appointed
  • Data localization requirements satisfied
  • Merchant data portability provided via CSV export
  • DPDP Act consent mechanisms implemented for data processing

PCI-DSS (Payment Card Industry Data Security Standard)

International — applicable to payment data handling

Scoped Out

DineFlow is a menu presentation and ordering platform. We do not process, store, or transmit payment card data. Our system submits orders to the merchant dashboard — billing is handled offline at the restaurant's existing cash/card counter. This design means DineFlow is entirely out-of-scope for PCI-DSS compliance obligations. Merchants using third-party payment integrations connect their own PCI-DSS compliant payment processors independently.

  • No payment card data processed, stored, or transmitted
  • Orders are submitted without any payment step in DineFlow
  • PCI-DSS scope analysis confirmed with third-party assessor
  • Merchants retain full control over their payment processors
  • Razorpay / PayU integration guidelines provided for merchants who opt-in
  • Out-of-scope declaration available for merchant compliance reviews

Restaurant Industry-specific Compliance

India (FSSAI, GST, State regulations)

Supportive

DineFlow supports restaurants in displaying FSSAI license information on their menu interfaces as required under food safety regulations. Merchants can add allergen disclosures, caloric information, and certification numbers to individual menu items. We generate GST-inclusive price display options and support proper menu categorization for businesses operating under FSSAI's food business operator license requirements.

  • FSSAI license number display on menu interface (optional)
  • Allergen disclosure fields on each menu item
  • GST-inclusive price display options in menu settings
  • Vegetarian/Non-vegetarian FSSAI color coding supported
  • Caloric / nutritional info fields available per item
  • Halal and Kosher certification display options available

Data Governance Principles

Beyond specific regulatory frameworks, DineFlow applies these overarching data governance principles across all product decisions and system designs.

Data Minimization

We only collect data that is strictly necessary for the functioning of the service. Guest-facing menu experiences require zero data from diners. Merchant accounts collect only the information needed to configure and operate the restaurant profile.

Purpose Limitation

Data collected during enquiry submission (restaurant name, POC details, WhatsApp) is used solely for account setup and support communication. We do not use this data for marketing to third parties or sell it to data brokers.

Storage Limitation

Menu data, order records, and account configuration are retained for the duration of an active subscription plus 6 months post-cancellation. After this period, all data is permanently deleted unless the merchant requests earlier deletion.

Accuracy & Rectification

Merchants can update all account information, menu data, and settings directly from their dashboard at any time. Incorrect data submitted during onboarding can be corrected by contacting support@dineflow.in.

Accountability & Governance

DineFlow maintains an internal data governance register documenting all data categories processed, their purposes, retention periods, and the legal basis for processing. This register is available to enterprise clients for audit purposes under NDA.

Third-party Processor Standards

We use only vetted third-party infrastructure providers (Google Cloud Platform, Supabase) who maintain their own comprehensive compliance certifications including SOC 2 Type II, ISO 27001, and relevant regional standards. Full sub-processor list available on request.

Compliance & DPO Contact

For compliance enquiries, data subject access requests, data processing agreements, or third-party audit facilitation, contact our compliance team directly. We respond to all compliance-related enquiries within 5 business days.

Data Protection Officer

dpo@dineflow.in

DSAR, GDPR, and DPDP Act requests

Legal & Compliance Team

legal@dineflow.in

DPAs, audits, and regulatory enquiries

Ready to deploy digital QR menus?

Request a demo setup, we will configure the tables for you.

Submit Custom Request