Legal

Privacy Policy

Last Updated: 31 August 2026

DineMagik (Pvt) Ltd (“DineMagik”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you access our websites, applications, point-of-sale systems, online ordering solutions, restaurant management platforms, mobile applications, support services, and other products and services operated by DineMagik.

By using DineMagik’s website or services, you acknowledge the practices described in this Privacy Policy.

1. Who We Are

DineMagik provides technology solutions for restaurants, cafés, hotels, food-service businesses, and other hospitality operators.

Our services may include:

  • Point-of-Sale (POS) systems
  • Restaurant management software
  • Online and QR ordering
  • Kitchen Order Ticket (KOT) and Kitchen Display Systems (KDS)
  • Inventory and recipe management
  • Customer relationship management
  • Loyalty and promotional services
  • Reservations and table management
  • Reporting and business analytics
  • Payment-related integrations
  • Customer display systems
  • Mobile and tablet applications
  • Cloud-based management platforms
  • Technical support and implementation services

Depending on the service being provided, DineMagik may act as a data controller, data processor, or service provider processing information on behalf of a DineMagik customer.

2. Information We Collect

We may collect different categories of information depending on how you interact with DineMagik.

2.1 Information You Provide Directly

This may include:

  • Full name
  • Business or restaurant name
  • Email address
  • Telephone or mobile number
  • Job title
  • Billing information
  • Business address
  • Support requests
  • Messages and communications
  • Account registration information
  • Login credentials
  • Information submitted through contact forms
  • Product enquiries
  • Demo requests
  • Feedback

2.2 Restaurant Customer Information

Restaurants and businesses using DineMagik may choose to collect or process information concerning their own customers through our platform.

Depending on how a restaurant configures DineMagik, this may include:

  • Customer name
  • Telephone number
  • Email address
  • Delivery or contact address
  • Birthday
  • Title
  • Country or country code
  • Order history
  • Dining preferences
  • Loyalty information
  • Reservation history
  • Purchase history
  • Customer notes
  • Voucher or promotion usage
  • Transaction references

Where DineMagik processes this information solely on behalf of a restaurant or business, that restaurant or business is generally responsible for determining why the information is collected and how it is used.

2.3 Transaction and Order Information

Our systems may process information relating to restaurant transactions, including:

  • Order number
  • Bill number
  • Ordered items
  • Modifiers and portions
  • Order notes
  • Table number
  • Order type
  • Transaction amount
  • Discounts
  • Taxes
  • Service charges
  • Payment type
  • Transaction date and time
  • Refund and cancellation information
  • Loyalty points
  • Employee or operator associated with a transaction

2.4 Payment Information

DineMagik may integrate with third-party payment processors, banks, card terminals, payment gateways, or other financial technology providers.

Where payments are processed by a third-party provider, payment card information may be transmitted directly to that provider and may not be stored by DineMagik.

We generally do not require or intend to store complete payment card numbers, CVV security codes, or similar sensitive card-authentication data within DineMagik’s standard systems unless specifically required for an authorised payment solution and handled through an appropriately secured payment provider.

2.5 Technical Information

When you use our website, applications, or cloud services, we may automatically collect certain technical information, including:

  • IP address
  • Device type
  • Operating system
  • Browser type
  • Application version
  • Device identifiers
  • Login timestamps
  • Activity logs
  • Error and crash logs
  • Network information
  • Approximate geographic region derived from an IP address
  • Pages or features accessed
  • Security and authentication events

We use this information primarily to operate, secure, maintain, troubleshoot, and improve DineMagik.

3. How We Use Information

We may use information for purposes including:

Providing Our Services

To:

  • Create and maintain accounts
  • Process restaurant orders
  • Manage transactions
  • Operate POS functionality
  • Manage tables and reservations
  • Process online orders
  • Provide inventory and costing functions
  • Provide reports and analytics
  • Synchronise restaurant devices
  • Deliver cloud services
  • Manage loyalty programmes
  • Provide customer management functionality

Customer Support

To:

  • Respond to support requests
  • Diagnose software issues
  • Investigate errors
  • Provide remote assistance
  • Resolve account or configuration issues
  • Communicate service updates

Security

To:

  • Prevent unauthorised access
  • Detect suspicious activity
  • Investigate security incidents
  • Protect accounts and systems
  • Maintain audit logs
  • Prevent misuse or fraud

Product Improvement

We may analyse usage information to:

  • Improve system performance
  • Identify software defects
  • Understand feature usage
  • Improve user experience
  • Develop new functionality
  • Improve reliability and scalability

Where practical, information used for broader statistical analysis may be aggregated or de-identified.

Business Administration

We may process information for:

  • Billing
  • Subscription management
  • Contract administration
  • Customer relationship management
  • Accounting
  • Internal audits
  • Business operations
  • Legal and regulatory requirements

Communications and Marketing

Where permitted, we may use business contact information to communicate:

  • Product updates
  • New features
  • Service announcements
  • Offers
  • Events
  • DineMagik news
  • Other relevant business communications

You may opt out of promotional communications at any time using an unsubscribe option provided in the communication or by contacting us.

Operational, security, billing, and service-related communications may still be sent where necessary.

4. Legal Basis and Principles for Processing

Where applicable, we process personal information based on appropriate legal grounds, which may include:

  • Performance of a contract
  • Taking steps requested before entering into a contract
  • Compliance with a legal obligation
  • Legitimate business interests
  • Consent
  • Protection of legal rights
  • Other grounds permitted under applicable data protection legislation

DineMagik aims to process personal information in a manner that is lawful, fair, transparent, and proportionate to the purpose for which it was collected.

5. DineMagik as a Service Provider or Data Processor

An important distinction applies when restaurants use DineMagik.

Restaurants using DineMagik may enter and manage information relating to their own customers, employees, orders, reservations, and business activities.

In many such situations:

The restaurant is responsible for deciding why and how the information is used, while DineMagik provides the technology used to process the information.

DineMagik will process such information according to:

  • Our agreement with the restaurant
  • The restaurant’s authorised instructions
  • Applicable law
  • Appropriate security and confidentiality requirements

Customers wishing to exercise privacy rights concerning information collected directly by a restaurant may therefore need to contact that restaurant first.

DineMagik will reasonably assist its business customers with applicable data protection responsibilities where required.

6. How We Share Information

We do not sell personal information to advertisers or data brokers.

We may disclose information to trusted third parties where reasonably necessary to operate our services.

These may include:

Technology and Hosting Providers

Providers supporting:

  • Cloud infrastructure
  • Data hosting
  • Database services
  • Communications
  • Monitoring
  • Security
  • Backup
  • Analytics
  • Software development infrastructure

Payment Providers

Payment processors, banks, card-terminal operators, or payment gateways where necessary to complete transactions.

Communications Providers

Providers used for:

  • Email
  • SMS
  • WhatsApp or messaging integrations
  • Push notifications
  • Customer notifications

Professional Advisers

Information may be disclosed when reasonably necessary to:

  • Accountants
  • Auditors
  • Lawyers
  • Insurance providers
  • Business advisers

Legal and Regulatory Requirements

We may disclose information where required to:

  • Comply with applicable law
  • Respond to a lawful court order
  • Cooperate with regulatory authorities
  • Investigate fraud
  • Protect DineMagik, our customers, or other individuals
  • Establish, exercise, or defend legal claims

7. International Data Processing

DineMagik or our technology providers may process or store information using infrastructure located outside the country in which the information was originally collected.

Where personal information is transferred internationally, we aim to use appropriate safeguards consistent with applicable data protection requirements.

These may include contractual protections, security controls, data-processing agreements, or other legally recognised mechanisms.

8. Data Security

We take reasonable technical and organisational measures designed to protect personal information.

Depending on the relevant system, these measures may include:

  • Encryption during data transmission
  • Secure authentication
  • Role-based access controls
  • Controlled administrator access
  • System activity logging
  • Database security controls
  • Network security measures
  • Backup and recovery procedures
  • Software security updates
  • Access monitoring
  • Security testing
  • Employee and contractor confidentiality controls

No electronic system can guarantee absolute security. However, DineMagik continuously works to maintain safeguards appropriate to the nature of the information being processed.

9. Data Retention

We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing our services and satisfying legal, accounting, contractual, operational, and security requirements.

Retention periods may differ depending on:

  • Type of information
  • Customer contract
  • Restaurant configuration
  • Legal obligations
  • Accounting requirements
  • Security requirements
  • Backup schedules
  • Dispute or investigation requirements

When information is no longer required, we may delete, anonymise, or securely dispose of it according to our applicable data-retention procedures.

10. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Keep users signed in
  • Remember preferences
  • Maintain security
  • Understand website usage
  • Improve website performance
  • Analyse traffic
  • Measure marketing effectiveness

Cookies may be:

Essential Cookies

Necessary for the operation, authentication, and security of the website.

Functional Cookies

Used to remember preferences and improve functionality.

Analytics Cookies

Used to understand how visitors interact with the website.

Marketing Cookies

Where used, these may help measure advertising campaigns or provide more relevant communications.

You may control certain cookies through your browser settings or any cookie preference controls made available on our website.

Disabling some cookies may affect website functionality.

11. Analytics

We may use analytics tools to understand how visitors and authorised users interact with our services.

These tools may collect information such as:

  • Pages visited
  • Features used
  • Session duration
  • Device characteristics
  • General location
  • Referral source
  • Error events

Where appropriate, we seek to minimise or aggregate information used for analytics.

12. Your Privacy Rights

Depending on the laws applicable to you, you may have rights concerning your personal information.

These may include rights to:

  • Request information about how your data is processed
  • Request access to your personal data
  • Request correction of inaccurate information
  • Request deletion where legally applicable
  • Object to or restrict certain processing
  • Withdraw consent where processing relies on consent
  • Request information regarding certain automated processing
  • Submit a complaint to an applicable data protection authority
  • Exercise other rights provided under applicable legislation

These rights may be subject to legal limitations and exceptions.

Where information is held by DineMagik on behalf of a restaurant, we may direct your request to the relevant restaurant or assist that restaurant in responding to your request.

13. Children’s Privacy

DineMagik’s business services are not designed to be independently used by children.

We do not knowingly seek to collect personal information directly from children through our corporate website without an appropriate lawful basis.

Restaurants using DineMagik remain responsible for ensuring that any information they collect relating to children is processed in accordance with applicable laws.

14. Employee Access

Only authorised DineMagik personnel, contractors, or service providers who require access for legitimate business purposes should be permitted to access personal information.

Such access may be necessary for:

  • Customer support
  • Technical maintenance
  • Security investigations
  • System administration
  • Software development and troubleshooting

Personnel with such access are expected to comply with appropriate confidentiality and security obligations.

15. Restaurant Responsibility

Restaurants and businesses using DineMagik are responsible for configuring and using DineMagik appropriately.

Customers are responsible for matters including:

  • Informing their customers about data collection where required
  • Obtaining any required consent
  • Maintaining appropriate employee permissions
  • Protecting usernames and passwords
  • Ensuring authorised use of customer information
  • Maintaining appropriate privacy notices
  • Using marketing information lawfully
  • Complying with laws applying to their own organisation

DineMagik customers should not enter information into the platform that they are not authorised to collect or process.

16. Third-Party Integrations

DineMagik may integrate with services operated by third parties, including:

  • Payment providers
  • Accounting platforms
  • Delivery platforms
  • Messaging providers
  • Reservation platforms
  • Cloud providers
  • Analytics services
  • Customer engagement tools
  • Other restaurant technology systems

When information is transmitted to a third-party service at the request of a restaurant or user, that provider’s privacy policy and contractual terms may also apply.

DineMagik is not responsible for the independent privacy practices of third-party services.

17. Links to Other Websites

Our website may contain links to websites operated by third parties.

DineMagik does not control and is not responsible for the privacy practices or content of third-party websites.

We recommend reviewing the privacy policy of any external website before providing personal information.

18. Business Transfers

If DineMagik undergoes a merger, restructuring, acquisition, financing transaction, sale of assets, or other corporate transaction, information may be transferred as part of that transaction where permitted by applicable law.

Any party receiving such information would remain subject to applicable privacy and data protection obligations.

19. Personal Data Breaches

DineMagik maintains processes intended to identify, assess, manage, and respond to information-security incidents.

Where an incident constitutes a reportable personal data breach, DineMagik will take appropriate action consistent with applicable legal and contractual requirements, including providing required notifications where applicable.

20. Sri Lanka Data Protection

DineMagik is based in Sri Lanka and is preparing its data governance practices with reference to Sri Lanka’s Personal Data Protection Act, No. 9 of 2022, as amended, together with applicable regulations, directives, and guidance.

Where the Act applies to DineMagik or our customers, we intend to maintain appropriate processes concerning matters such as:

  • Lawful processing
  • Transparency
  • Purpose limitation
  • Data minimisation
  • Data accuracy
  • Retention
  • Security
  • Controller and processor responsibilities
  • Data protection impact assessments where applicable
  • Personal data breach management
  • Cross-border processing
  • Data subject rights as they become applicable

Nothing in this Privacy Policy limits any mandatory rights available to an individual under applicable law.

21. International Privacy Requirements

Where DineMagik provides services to customers outside Sri Lanka, other privacy legislation may apply. Depending on the circumstances, this may include laws such as the European Union General Data Protection Regulation (GDPR), UK GDPR, or other applicable national or regional privacy legislation. DineMagik will seek to address applicable requirements based on the services being provided, the location of the relevant individuals, and our role in processing the information.

22. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our products
  • Changes to our technology
  • New services
  • Changes in legal requirements
  • Security practices
  • Changes in our business operations

The latest version will be published on our website with an updated “Last Updated” date. Where an update materially affects how we process personal information, we may provide additional notification where appropriate.

23. Contact Us

If you have questions, concerns, or requests relating to this Privacy Policy or DineMagik’s handling of personal information, please contact:

DineMagik (Pvt) Ltd

Sri Lanka

Privacy / Data Protection Enquiries: info@dinemagik.net

Telephone: +94 71 462 2771

Website: dinemagik.net

For requests concerning personal information collected by a restaurant using DineMagik, we recommend contacting the relevant restaurant directly in the first instance.

© 2026 DineMagik (Pvt) Ltd. All Rights Reserved.