Skip to main content
Dinelytics

Legal

Privacy Policy

Last updated 26 July 2026

Who we are

Dinelytics ("we", "us") is a restaurant feedback service operated by Francesco Vitale, trading as Dinelytics, Via della Repubblica 51, 95040 Ramacca (CT), Italy (P.IVA IT06178100878). When a restaurant uses Dinelytics, we act as the data processor for the guest data that restaurant collects, and as the data controller for the restaurant owner's own account data. You can reach us any time at info@vitalesystems.com.

What we collect

Restaurant accounts. Business name, contact email, restaurant location and Google Business details, and billing information needed to run your subscription.

Guest feedback. When a guest taps a Dinelytics card, we collect their star rating, any written comment they choose to leave, and — optionally — the name and email address they give us if they want the restaurant's reward or news. We also store a one-way keyed hash of their IP address, never the address itself, purely to stop spam and abuse. Guests are never required to create an account, and every field except the star rating is optional.

Usage data. Basic, privacy-respecting analytics about how the service is used, so we can keep it working and improve it.

How we use it

To deliver feedback and reports to the restaurant, to send reward offers to guests who opted in, to route low ratings privately to the owner, to process subscription payments, and to provide support. Our legal bases are: performing our contract with the restaurant (providing the service and processing payments), your consent (for guest marketing emails), our legitimate interests (routing feedback and preventing abuse), and legal obligations (keeping billing records).

Who we share it with

We do not sell personal data. We share it only with the service providers that make Dinelytics run: Stripe (payments), Supabase (secure data storage), Resend (transactional email), OpenAI (guest comments are sent to be summarized into the restaurant's weekly report; OpenAI does not use data submitted through its API to train its models), Google (review and place information), and Vercel (hosting). Each processes data only on our instructions. Some of these providers are based outside the EU/EEA; where that is the case, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.

Data retention

Specifically: written guest comments are deleted after 24 months, keeping only the anonymous star rating; guest contacts are kept while the restaurant's account is active, and are deleted 30 days after a guest unsubscribes; step-by-step funnel analytics are deleted after 90 days; abuse-prevention IP hashes are deleted after 12 months; and the raw IP addresses used for rate limiting are deleted within hours. When a restaurant closes its account we delete it and all of its guest data within 30 days. We delete or anonymise personal data sooner on request. Billing records are kept for as long as Italian tax law requires.

Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and objection, and to withdraw consent at any time (for example via the unsubscribe link in any offer email). To exercise any right, email us at info@vitalesystems.com and we will respond within 30 days. You also have the right to lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).

Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "last updated" date above.