Privacy Policy
Last updated: July 11, 2026
1. Who we are
EasyDine ("EasyDine", "we", "us") operates the EasyDine restaurant-reservation
platform — the website easydine.pk and the EasyDine (diner) and EasyDine
Partner (restaurant operator) mobile apps. EasyDine is owned and operated by
Sangjani Industries Pvt. Ltd., which is the data controller, of
Sangjani Village, Islamabad, Pakistan.
Contact for privacy matters: privacy@easydine.pk.
This policy explains what we collect, why, how long we keep it, who we share it with, and your rights. It is written to align with Pakistan's Personal Data Protection Bill (PDPPL, draft) and, for users in those regions, the GDPR principles, and to satisfy Apple App Store and Google Play requirements.
2. What we collect
You give us:
- Account & profile: name, email, phone number, and optionally date of birth, anniversary, city/area, dietary tags, and dining preferences.
- Bookings & activity: your reservations, waitlist requests, pickup requests, reviews, referrals, offers, and in-app messages (including any photos you attach).
- Card type / issuing bank (not card numbers): to check your eligibility for card-linked discounts you may tell us your card type or issuing bank. We do not collect or store card numbers, CVV, expiry dates, or any payment credentials — online payments are not enabled in this version.
Collected automatically:
- Approximate location (foreground only, with permission): if you grant the permission, we use your device's approximate location while the app is open to show nearby restaurants and estimate distance. For the in-app Concierge feature, these approximate coordinates are sent to our server to answer your request. We do not collect precise location and we do not track your location in the background. You can decline or revoke the permission at any time in your device settings.
- Device & identifiers: a push notification token (FCM/APNs), a device identifier (IDFV on iOS / ANDROID_ID on Android), your device name and model, app version, and basic diagnostics.
- Usage analytics: in-app events (screens viewed, actions taken) to improve the product and personalize your experience — see §7 and §7a.
- Crash/diagnostics: error reports to keep the apps stable.
We do NOT collect: your precise/GPS location, background location, your contacts, or card numbers / payment credentials. We do not track you across other companies' apps or websites for advertising, and we do not use a cross-app advertising identifier.
3. Why we use it (legal bases)
| Purpose | Data | Basis |
|---|---|---|
| Create your account and log you in (OTP) | name, email, phone | Contract / your request |
| Make and manage reservations | profile + booking data | Contract |
| Notify you about your bookings | push token, contact | Contract / legitimate interest |
| Send transactional email | Contract | |
| Marketing/occasion offers | email, preferences | Consent (opt-in; withdraw any time) |
| Personalize recommendations & offers | profile, preferences, dietary/occasion info, activity | Consent (opt-out any time — see §7a) |
| Show nearby restaurants & answer Concierge queries | approximate location | Consent (device permission; revoke any time) |
| Improve the product | usage analytics | Legitimate interest |
| Keep the service secure, prevent abuse, audit PII access | account + audit logs | Legitimate interest / legal obligation |
4. Restaurants and operators
When you book, the restaurant you booked with receives the booking details and the contact information needed to host you (name, phone, party size, notes). Each restaurant only ever sees its own customers' bookings — access is technically isolated per restaurant. Restaurant staff access to your un-masked contact details is limited to your bookings at that restaurant and is logged. See our internal PII handling summary for how this is enforced.
5. Who else we share with (processors)
We share the minimum necessary with service providers who act on our instructions and may not use your data for their own purposes:
- Hostinger — hosting and transactional email delivery (your email address and message content).
- PostHog (EU region) — product analytics; receives your user id, email, and name. Session replay is disabled.
- Sentry — crash and error diagnostics; receives your user id, email, name, and device model.
- Google Firebase Cloud Messaging (FCM) / Apple Push Notification service (APNs) — to deliver push notifications (push token only).
- Google Maps Platform — to display maps and restaurant locations.
- Twilio Verify — to send one-time login/verification codes (your phone number), where phone-OTP is used.
- Apple / Google sign-in — to authenticate you when you choose social sign-in.
We never sell your personal data. We may disclose data if required by law or to protect rights, safety, and the integrity of the service.
6. International transfers
Some processors may store or process data outside Pakistan (for example, EU or US data centers). Where that happens we rely on the provider's contractual safeguards — including Standard Contractual Clauses (SCCs) or equivalent approved transfer mechanisms where applicable — and choose regional options (for example, EU-region analytics) where practical.
7. Analytics & cookies
The website uses essential cookies for sign-in/session and CSRF protection. We collect in-app and website usage events to understand and improve the product. Our analytics processor (PostHog, EU region) receives your user id, email, and name so we can tie product improvements and personalization to your account; we do not enable session replay and do not use the data for cross-app advertising. See §5 for the full processor list.
7a. Personalized recommendations & marketing
We use your profile, dining preferences, dietary and occasion information (such as birthday and anniversary), and your activity to personalize the restaurants, recommendations, and offers we show you — including launch offers, card-linked bank discounts, and occasion nudges (for example, an anniversary reminder). This is first-party personalization only: we do not sell your data, we do not share it with advertising networks, and we do not use a cross-app advertising identifier.
You can opt out at any time:
- Settings → Privacy — turn off "Share dining preferences" and "Personalized recommendations".
- Settings → Notifications — turn off marketing messages.
Turning these off stops personalized marketing; you will still receive transactional messages about your bookings.
8. How long we keep it
- Account & profile: for the life of your account.
- Bookings & transactional records: retained while your account is active; after account deletion, bookings are anonymized and retained for up to 12 months for legitimate business, accounting, and dispute-resolution records.
- PII-access audit logs: retained for 12 months for security/forensic purposes.
- Account & data deletion: you can delete your account in-app (Settings →
Account → Delete account) or at
easydine.pk/account/delete. On request we deactivate your account immediately and delete or irreversibly anonymize your personal data within 30 days, except for the limited records above that we must retain to meet legal obligations.
9. Your rights
You may access, correct, or delete your personal data, withdraw consent to
marketing, and request a copy of your data. In-app: edit your profile, toggle
marketing preferences, and use Delete my account (also at
easydine.pk/account/delete). For any request, contact privacy@easydine.pk;
we respond within a reasonable period. If you are in a GDPR region you also have the
right to object/restrict processing and to lodge a complaint with your supervisory
authority.
10. Security
We encrypt personal data in transit (HTTPS) and at rest, mask customer PII in our admin tools by default, restrict and audit privileged access to un-masked data, and isolate each restaurant's data. No system is perfectly secure, but we work to protect your information and to respond promptly to any incident.
11. Children
EasyDine is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data; contact us to remove any such data.
12. Changes
We may update this policy. Material changes will be notified in-app or by email, and the "Last updated" date above will change. Continued use after an update means you accept the revised policy.
13. Contact
Privacy: privacy@easydine.pk · Support: support@easydine.pk · Postal: Sangjani Industries Pvt. Ltd., Sangjani Village, Islamabad, Pakistan.