Legal

Privacy Policy

Last updated: July 30, 2026

This policy explains what personal information DirectDine collects, why, who we share it with, and the rights you have under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL).

Showing the privacy rights that apply in the United Arab Emirates. Somewhere else? Choose your region:

1. Who this covers and who is responsible

This policy applies to personal information handled by DirectDine, operated by Manvion Inc., based in Montréal, Quebec, Canada. It covers two groups: restaurant staff who hold accounts, and diners who place orders through a restaurant’s DirectDine pages, wherever in the world they are.

For diner order information, the restaurant is the business the diner is buying from and decides how to use its own customer data; DirectDine processes that information on the restaurant’s behalf to run the service, and also uses limited data as an independent business for security, billing and improving the Platform.

2. Our Privacy Officer

DirectDine has designated a person responsible for the protection of personal information. Contact them at directdine@manvion.ca with any question, request, or complaint.

3. What we collect

From restaurant staff: name, email, phone, role, and account authentication details (managed by our sign-in provider), plus business details you enter (restaurant name, address, tax numbers, and payout details held by our payment processor).

From diners: name, email, phone, delivery address (for delivery orders), order contents and history, tips, and payment confirmation details. We do not store full card numbers — card payments are handled directly by our payment processor.

Automatically: device and log data (IP address, approximate location, browser type, pages and actions), and cookies or similar technologies needed to keep you signed in, remember your cart, secure the service, and understand basic usage.

4. Why we use it

  • to take, process and fulfil orders, and to process payments and payouts;
  • to send order updates and receipts by email and SMS (transactional messages);
  • to send marketing messages only where you have consented — you can withdraw consent at any time (see “Your choices”);
  • to provide restaurant dashboards, analytics, and tax/accounting summaries;
  • to bill restaurant subscriptions and commission;
  • to secure the Platform, prevent fraud and abuse, and meet legal obligations.

We rely on your consent, the performance of a contract, and our legitimate business interests as our bases for these uses, as Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) allows.

5. Who we share it with

We share personal information with service providers who help us run the Platform, under contracts that limit them to our instructions:

  • Stripe — payment processing and restaurant payouts;
  • Clerk — staff account sign-in and authentication;
  • Twilio — SMS notifications; Resend — email;
  • Uber Direct / DoorDash — delivery dispatch (name, phone and address are shared with the courier so they can deliver the order);
  • Cloud infrastructure — hosting, database, cache and file storage providers, and map/routing providers;

We also share a restaurant’s diner data with that restaurant, which is who the order was placed with. We do not sell personal information. We may disclose information if required by law or to protect rights and safety.

6. Storage and international transfers

DirectDine operates across several countries, and some of our providers process data outside your country — including in Canada, the United States, and the European Union. When personal information crosses borders we take reasonable steps, and assess the protection provided, before the transfer, as Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) requires. By using the Platform you understand your information may be processed in these locations.

7. How long we keep it

We keep personal information only as long as needed for the purposes above and to meet legal, tax and accounting obligations. Transaction records are retained for the period required by the tax law that applies to the restaurant. When information is no longer needed we delete or anonymise it. Suspending or closing an account does not immediately erase records we must keep for legal reasons.

8. Your rights in the United Arab Emirates

You may request access to, correction of, and deletion of your personal information, and object to or restrict its processing.

To exercise a right, email directdine@manvion.ca. For diner data held by a restaurant, we may direct your request to that restaurant, or handle it together with them. We respond within the timeframes Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) requires. If you are not satisfied, you can complain to the UAE Data Office.

9. Your choices

Marketing emails include an unsubscribe link; texting STOP ends marketing SMS. You will still receive transactional messages about orders you place, because those are part of the service, not marketing. You can control cookies through your browser, though disabling essential cookies may break sign-in and checkout.

10. How we protect it

We use technical and organisational safeguards appropriate to the sensitivity of the information — encryption in transit, access controls, audit logging of staff actions, and reputable infrastructure providers. No system is perfectly secure, but if a confidentiality incident creates a risk of serious harm we will notify affected individuals and the relevant authority as the law requires.

11. Children

The Platform is intended for businesses and adult diners. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

12. Changes to this policy

We may update this policy as our service or the law changes. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified to account holders. Please review it periodically.