Legal
Privacy Policy
Last updated: July 30, 2026
This policy explains what personal information DirectDine collects, why, who we share it with, and the rights you have under the Privacy Act 2020.
Showing the privacy rights that apply in New Zealand. Somewhere else? Choose your region:
1. Who this covers and who is responsible
This policy applies to personal information handled by DirectDine, operated by Manvion Inc., based in Montréal, Quebec, Canada. It covers two groups: restaurant staff who hold accounts, and diners who place orders through a restaurant’s DirectDine pages, wherever in the world they are.
For diner order information, the restaurant is the business the diner is buying from and decides how to use its own customer data; DirectDine processes that information on the restaurant’s behalf to run the service, and also uses limited data as an independent business for security, billing and improving the Platform.
2. Our Privacy Officer
DirectDine has designated a person responsible for the protection of personal information. Contact them at directdine@manvion.ca with any question, request, or complaint.
3. What we collect
From restaurant staff: name, email, phone, role, and account authentication details (managed by our sign-in provider), plus business details you enter (restaurant name, address, tax numbers, and payout details held by our payment processor).
From diners: name, email, phone, delivery address (for delivery orders), order contents and history, tips, and payment confirmation details. We do not store full card numbers — card payments are handled directly by our payment processor.
Automatically: device and log data (IP address, approximate location, browser type, pages and actions), and cookies or similar technologies needed to keep you signed in, remember your cart, secure the service, and understand basic usage.
4. Why we use it
- to take, process and fulfil orders, and to process payments and payouts;
- to send order updates and receipts by email and SMS (transactional messages);
- to send marketing messages only where you have consented — you can withdraw consent at any time (see “Your choices”);
- to provide restaurant dashboards, analytics, and tax/accounting summaries;
- to bill restaurant subscriptions and commission;
- to secure the Platform, prevent fraud and abuse, and meet legal obligations.
We rely on your consent, the performance of a contract, and our legitimate business interests as our bases for these uses, as the Privacy Act 2020 allows.
6. Storage and international transfers
DirectDine operates across several countries, and some of our providers process data outside your country — including in Canada, the United States, and the European Union. When personal information crosses borders we take reasonable steps, and assess the protection provided, before the transfer, as the Privacy Act 2020 requires. By using the Platform you understand your information may be processed in these locations.
7. How long we keep it
We keep personal information only as long as needed for the purposes above and to meet legal, tax and accounting obligations. Transaction records are retained for the period required by the tax law that applies to the restaurant. When information is no longer needed we delete or anonymise it. Suspending or closing an account does not immediately erase records we must keep for legal reasons.
8. Your rights in New Zealand
You may request access to and correction of your personal information, and complain about how it is handled.
To exercise a right, email directdine@manvion.ca. For diner data held by a restaurant, we may direct your request to that restaurant, or handle it together with them. We respond within the timeframes the Privacy Act 2020 requires. If you are not satisfied, you can complain to the Office of the Privacy Commissioner.
9. Your choices
Marketing emails include an unsubscribe link; texting STOP ends marketing SMS. You will still receive transactional messages about orders you place, because those are part of the service, not marketing. You can control cookies through your browser, though disabling essential cookies may break sign-in and checkout.
10. How we protect it
We use technical and organisational safeguards appropriate to the sensitivity of the information — encryption in transit, access controls, audit logging of staff actions, and reputable infrastructure providers. No system is perfectly secure, but if a confidentiality incident creates a risk of serious harm we will notify affected individuals and the relevant authority as the law requires.
11. Children
The Platform is intended for businesses and adult diners. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to this policy
We may update this policy as our service or the law changes. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified to account holders. Please review it periodically.