DineMagik (Pvt) Ltd (“DineMagik”, “we”, “us”, or “our”) respects your privacy and is committed to protecting the personal information entrusted to us.
This Privacy Policy explains how we collect, use, store, disclose, and protect personal information when you access our websites, applications, point-of-sale systems, online ordering solutions, restaurant management platforms, mobile applications, support services, and other products and services operated by DineMagik.
By using DineMagik’s website or services, you acknowledge the practices described in this Privacy Policy.
1. Who We Are
DineMagik provides technology solutions for restaurants, cafés, hotels, food-service businesses, and other hospitality operators.
Our services may include:
- Point-of-Sale (POS) systems
- Restaurant management software
- Online and QR ordering
- Kitchen Order Ticket (KOT) and Kitchen Display Systems (KDS)
- Inventory and recipe management
- Customer relationship management
- Loyalty and promotional services
- Reservations and table management
- Reporting and business analytics
- Payment-related integrations
- Customer display systems
- Mobile and tablet applications
- Cloud-based management platforms
- Technical support and implementation services
Depending on the service being provided, DineMagik may act as a data controller, data processor, or service provider processing information on behalf of a DineMagik customer.
2. Information We Collect
We may collect different categories of information depending on how you interact with DineMagik.
2.1 Information You Provide Directly
This may include:
- Full name
- Business or restaurant name
- Email address
- Telephone or mobile number
- Job title
- Billing information
- Business address
- Support requests
- Messages and communications
- Account registration information
- Login credentials
- Information submitted through contact forms
- Product enquiries
- Demo requests
- Feedback
2.2 Restaurant Customer Information
Restaurants and businesses using DineMagik may choose to collect or process information concerning their own customers through our platform.
Depending on how a restaurant configures DineMagik, this may include:
- Customer name
- Telephone number
- Email address
- Delivery or contact address
- Birthday
- Title
- Country or country code
- Order history
- Dining preferences
- Loyalty information
- Reservation history
- Purchase history
- Customer notes
- Voucher or promotion usage
- Transaction references
Where DineMagik processes this information solely on behalf of a restaurant or business, that restaurant or business is generally responsible for determining why the information is collected and how it is used.
2.3 Transaction and Order Information
Our systems may process information relating to restaurant transactions, including:
- Order number
- Bill number
- Ordered items
- Modifiers and portions
- Order notes
- Table number
- Order type
- Transaction amount
- Discounts
- Taxes
- Service charges
- Payment type
- Transaction date and time
- Refund and cancellation information
- Loyalty points
- Employee or operator associated with a transaction
2.4 Payment Information
DineMagik may integrate with third-party payment processors, banks, card terminals, payment gateways, or other financial technology providers.
Where payments are processed by a third-party provider, payment card information may be transmitted directly to that provider and may not be stored by DineMagik.
We generally do not require or intend to store complete payment card numbers, CVV security codes, or similar sensitive card-authentication data within DineMagik’s standard systems unless specifically required for an authorised payment solution and handled through an appropriately secured payment provider.
2.5 Technical Information
When you use our website, applications, or cloud services, we may automatically collect certain technical information, including:
- IP address
- Device type
- Operating system
- Browser type
- Application version
- Device identifiers
- Login timestamps
- Activity logs
- Error and crash logs
- Network information
- Approximate geographic region derived from an IP address
- Pages or features accessed
- Security and authentication events
We use this information primarily to operate, secure, maintain, troubleshoot, and improve DineMagik.
3. How We Use Information
We may use information for purposes including:
Providing Our Services
To:
- Create and maintain accounts
- Process restaurant orders
- Manage transactions
- Operate POS functionality
- Manage tables and reservations
- Process online orders
- Provide inventory and costing functions
- Provide reports and analytics
- Synchronise restaurant devices
- Deliver cloud services
- Manage loyalty programmes
- Provide customer management functionality
Customer Support
To:
- Respond to support requests
- Diagnose software issues
- Investigate errors
- Provide remote assistance
- Resolve account or configuration issues
- Communicate service updates
Security
To:
- Prevent unauthorised access
- Detect suspicious activity
- Investigate security incidents
- Protect accounts and systems
- Maintain audit logs
- Prevent misuse or fraud
Product Improvement
We may analyse usage information to:
- Improve system performance
- Identify software defects
- Understand feature usage
- Improve user experience
- Develop new functionality
- Improve reliability and scalability
Where practical, information used for broader statistical analysis may be aggregated or de-identified.
Business Administration
We may process information for:
- Billing
- Subscription management
- Contract administration
- Customer relationship management
- Accounting
- Internal audits
- Business operations
- Legal and regulatory requirements
Communications and Marketing
Where permitted, we may use business contact information to communicate:
- Product updates
- New features
- Service announcements
- Offers
- Events
- DineMagik news
- Other relevant business communications
You may opt out of promotional communications at any time using an unsubscribe option provided in the communication or by contacting us.
Operational, security, billing, and service-related communications may still be sent where necessary.
4. Legal Basis and Principles for Processing
Where applicable, we process personal information based on appropriate legal grounds, which may include:
- Performance of a contract
- Taking steps requested before entering into a contract
- Compliance with a legal obligation
- Legitimate business interests
- Consent
- Protection of legal rights
- Other grounds permitted under applicable data protection legislation
DineMagik aims to process personal information in a manner that is lawful, fair, transparent, and proportionate to the purpose for which it was collected.
5. DineMagik as a Service Provider or Data Processor
An important distinction applies when restaurants use DineMagik.
Restaurants using DineMagik may enter and manage information relating to their own customers, employees, orders, reservations, and business activities.
In many such situations:
The restaurant is responsible for deciding why and how the information is used, while DineMagik provides the technology used to process the information.
DineMagik will process such information according to:
- Our agreement with the restaurant
- The restaurant’s authorised instructions
- Applicable law
- Appropriate security and confidentiality requirements
Customers wishing to exercise privacy rights concerning information collected directly by a restaurant may therefore need to contact that restaurant first.
DineMagik will reasonably assist its business customers with applicable data protection responsibilities where required.
6. How We Share Information
We do not sell personal information to advertisers or data brokers.
We may disclose information to trusted third parties where reasonably necessary to operate our services.
These may include:
Technology and Hosting Providers
Providers supporting:
- Cloud infrastructure
- Data hosting
- Database services
- Communications
- Monitoring
- Security
- Backup
- Analytics
- Software development infrastructure
Payment Providers
Payment processors, banks, card-terminal operators, or payment gateways where necessary to complete transactions.
Communications Providers
Providers used for:
- SMS
- WhatsApp or messaging integrations
- Push notifications
- Customer notifications
Professional Advisers
Information may be disclosed when reasonably necessary to:
- Accountants
- Auditors
- Lawyers
- Insurance providers
- Business advisers
Legal and Regulatory Requirements
We may disclose information where required to:
- Comply with applicable law
- Respond to a lawful court order
- Cooperate with regulatory authorities
- Investigate fraud
- Protect DineMagik, our customers, or other individuals
- Establish, exercise, or defend legal claims
7. International Data Processing
DineMagik or our technology providers may process or store information using infrastructure located outside the country in which the information was originally collected.
Where personal information is transferred internationally, we aim to use appropriate safeguards consistent with applicable data protection requirements.
These may include contractual protections, security controls, data-processing agreements, or other legally recognised mechanisms.
8. Data Security
We take reasonable technical and organisational measures designed to protect personal information.
Depending on the relevant system, these measures may include:
- Encryption during data transmission
- Secure authentication
- Role-based access controls
- Controlled administrator access
- System activity logging
- Database security controls
- Network security measures
- Backup and recovery procedures
- Software security updates
- Access monitoring
- Security testing
- Employee and contractor confidentiality controls
No electronic system can guarantee absolute security. However, DineMagik continuously works to maintain safeguards appropriate to the nature of the information being processed.
9. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing our services and satisfying legal, accounting, contractual, operational, and security requirements.
Retention periods may differ depending on:
- Type of information
- Customer contract
- Restaurant configuration
- Legal obligations
- Accounting requirements
- Security requirements
- Backup schedules
- Dispute or investigation requirements
When information is no longer required, we may delete, anonymise, or securely dispose of it according to our applicable data-retention procedures.
10. Cookies and Similar Technologies
Our website may use cookies and similar technologies to:
- Keep users signed in
- Remember preferences
- Maintain security
- Understand website usage
- Improve website performance
- Analyse traffic
- Measure marketing effectiveness
Cookies may be:
Essential Cookies
Necessary for the operation, authentication, and security of the website.
Functional Cookies
Used to remember preferences and improve functionality.
Analytics Cookies
Used to understand how visitors interact with the website.
Marketing Cookies
Where used, these may help measure advertising campaigns or provide more relevant communications.
You may control certain cookies through your browser settings or any cookie preference controls made available on our website.
Disabling some cookies may affect website functionality.
11. Analytics
We may use analytics tools to understand how visitors and authorised users interact with our services.
These tools may collect information such as:
- Pages visited
- Features used
- Session duration
- Device characteristics
- General location
- Referral source
- Error events
Where appropriate, we seek to minimise or aggregate information used for analytics.
12. Your Privacy Rights
Depending on the laws applicable to you, you may have rights concerning your personal information.
These may include rights to:
- Request information about how your data is processed
- Request access to your personal data
- Request correction of inaccurate information
- Request deletion where legally applicable
- Object to or restrict certain processing
- Withdraw consent where processing relies on consent
- Request information regarding certain automated processing
- Submit a complaint to an applicable data protection authority
- Exercise other rights provided under applicable legislation
These rights may be subject to legal limitations and exceptions.
Where information is held by DineMagik on behalf of a restaurant, we may direct your request to the relevant restaurant or assist that restaurant in responding to your request.
13. Children’s Privacy
DineMagik’s business services are not designed to be independently used by children.
We do not knowingly seek to collect personal information directly from children through our corporate website without an appropriate lawful basis.
Restaurants using DineMagik remain responsible for ensuring that any information they collect relating to children is processed in accordance with applicable laws.
14. Employee Access
Only authorised DineMagik personnel, contractors, or service providers who require access for legitimate business purposes should be permitted to access personal information.
Such access may be necessary for:
- Customer support
- Technical maintenance
- Security investigations
- System administration
- Software development and troubleshooting
Personnel with such access are expected to comply with appropriate confidentiality and security obligations.
15. Restaurant Responsibility
Restaurants and businesses using DineMagik are responsible for configuring and using DineMagik appropriately.
Customers are responsible for matters including:
- Informing their customers about data collection where required
- Obtaining any required consent
- Maintaining appropriate employee permissions
- Protecting usernames and passwords
- Ensuring authorised use of customer information
- Maintaining appropriate privacy notices
- Using marketing information lawfully
- Complying with laws applying to their own organisation
DineMagik customers should not enter information into the platform that they are not authorised to collect or process.
16. Third-Party Integrations
DineMagik may integrate with services operated by third parties, including:
- Payment providers
- Accounting platforms
- Delivery platforms
- Messaging providers
- Reservation platforms
- Cloud providers
- Analytics services
- Customer engagement tools
- Other restaurant technology systems
When information is transmitted to a third-party service at the request of a restaurant or user, that provider’s privacy policy and contractual terms may also apply.
DineMagik is not responsible for the independent privacy practices of third-party services.
17. Links to Other Websites
Our website may contain links to websites operated by third parties.
DineMagik does not control and is not responsible for the privacy practices or content of third-party websites.
We recommend reviewing the privacy policy of any external website before providing personal information.
18. Business Transfers
If DineMagik undergoes a merger, restructuring, acquisition, financing transaction, sale of assets, or other corporate transaction, information may be transferred as part of that transaction where permitted by applicable law.
Any party receiving such information would remain subject to applicable privacy and data protection obligations.
19. Personal Data Breaches
DineMagik maintains processes intended to identify, assess, manage, and respond to information-security incidents.
Where an incident constitutes a reportable personal data breach, DineMagik will take appropriate action consistent with applicable legal and contractual requirements, including providing required notifications where applicable.
20. Sri Lanka Data Protection
DineMagik is based in Sri Lanka and is preparing its data governance practices with reference to Sri Lanka’s Personal Data Protection Act, No. 9 of 2022, as amended, together with applicable regulations, directives, and guidance.
Where the Act applies to DineMagik or our customers, we intend to maintain appropriate processes concerning matters such as:
- Lawful processing
- Transparency
- Purpose limitation
- Data minimisation
- Data accuracy
- Retention
- Security
- Controller and processor responsibilities
- Data protection impact assessments where applicable
- Personal data breach management
- Cross-border processing
- Data subject rights as they become applicable
Nothing in this Privacy Policy limits any mandatory rights available to an individual under applicable law.
21. International Privacy Requirements
Where DineMagik provides services to customers outside Sri Lanka, other privacy legislation may apply. Depending on the circumstances, this may include laws such as the European Union General Data Protection Regulation (GDPR), UK GDPR, or other applicable national or regional privacy legislation. DineMagik will seek to address applicable requirements based on the services being provided, the location of the relevant individuals, and our role in processing the information.
22. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes to our products
- Changes to our technology
- New services
- Changes in legal requirements
- Security practices
- Changes in our business operations
The latest version will be published on our website with an updated “Last Updated” date. Where an update materially affects how we process personal information, we may provide additional notification where appropriate.
23. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or DineMagik’s handling of personal information, please contact:
DineMagik (Pvt) Ltd
Sri Lanka
Privacy / Data Protection Enquiries: info@dinemagik.net
Telephone: +94 71 462 2771
Website: dinemagik.net
For requests concerning personal information collected by a restaurant using DineMagik, we recommend contacting the relevant restaurant directly in the first instance.
© 2026 DineMagik (Pvt) Ltd. All Rights Reserved.