Draft policy
Privacy
Effective date, controller/legal entity, contact details, retention periods, and jurisdiction-specific disclosures remain to be supplied.
Information GoDine handles
GoDine stores account and profile details such as email address, password hash, name, phone number, verification state, and an optional profile image. It also stores browser sessions, rotating mobile refresh sessions, security and recovery records, membership state, Stripe identifiers, billing transaction records, credit grants and ledger entries, redemptions, notification preferences, and registered mobile push endpoints.
Dining and location information
GoDine uses restaurant addresses and Google Maps for discovery, maps, distance context, and directions. When a customer permits location access during redemption, GoDine may record the submitted coordinates, calculated distance, and whether the configurable distance warning was shown. Location permission is contextual and a missing location does not by itself block redemption.
How information is used
- Authenticate customers and protect sessions.
- Operate memberships, credits, redemptions, waiter-verifiable receipts, restaurant reporting, and payouts.
- Send transactional email and opted-in push notifications.
- Prevent duplicate or fraudulent activity, diagnose failures, and preserve authoritative accounting and audit records.
Implemented providers
Stripe handles hosted membership payment and billing-management flows. SendGrid delivers transactional email. Railway hosts the web/API application and PostgreSQL/PostGIS database. AWS S3 and CloudFront store and deliver managed images. The notification backend integrates with Amazon SNS and the applicable Apple or Google push service when provider resources and credentials are configured. Google Maps supports mapping, geocoding, and directions. GoDine does not collect membership payment details inside the native app.
Account deletion and retention
After all consequences are acknowledged and the current password is verified, deletion immediately cancels future subscription billing without an automatic refund or prorated invoice, ends membership access, and forfeits every unused membership and promotional credit. GoDine revokes sessions and push delivery, removes or irreversibly anonymizes profile and authentication data, and retains opaque relationships and records required for financial accounting, redemption and payout integrity, fraud prevention, legal obligations, and audit. Retained redemption evidence can include restaurant, time, exact submitted location, calculated distance, and Stripe identifiers where required for those purposes. A reviewed retention schedule and specific durations remain to be supplied.
Diagnostics and access
Ordinary logs are designed to exclude passwords, tokens, payment data, exact location, and customer profile fields. Support IDs correlate safe error details without exposing internal billing or deletion state. Requests concerning account information should use the currently configured path on the Support page.