- Document
- Privacy Policy
- Version
- 1.1 (pending final legal review before public launch)
- Effective Date
- 2026-07-22
- Last Updated
- 2026-07-22
- Operator
- Vallabh Sakhare, trading as ScatterBrain (“we”, “our”, “us”)
- Privacy contact
- legal@pipchat.in · Support: support@pipchat.in Grievance Officer: Vallabh Sakhare — legal@pipchat.in (acknowledged within 24 hours, resolved within 15 days)
1. Introduction
Welcome to Dinner Date (“we”, “our”, or “us”). Dinner Date is a platform designed to help adults discover, arrange, and participate in food-centered social and dating experiences through participating restaurants, cafés, and other approved public venues. The platform includes user profiles, restaurant discovery, date invitations, messaging, optional safety features, payment functionality, and related services (collectively, the “Services”). Your privacy is important to us. We recognize that using a dating and social platform requires a high degree of trust. This Privacy Policy explains how we collect, use, disclose, store, protect, and otherwise process personal information when you use the Dinner Date mobile applications, websites, and related services. We have designed this Privacy Policy to provide clear and transparent information about our data handling practices while supporting applicable privacy and data protection laws in the jurisdictions where Dinner Date operates. This Privacy Policy should be read together with our: Terms of Service Community Guidelines Safety Guidelines Content Moderation Policy CSAM Policy Reporting and Enforcement Policy Payment Terms Refund and Deposit Policy Location and Geofence Policy Account Deletion and Data Retention Policy AI Usage Disclosure Cookie and Tracking Policy (where applicable) Each of these documents forms part of the overall governance framework for the Dinner Date platform.
1.1 Our Commitment to Privacy
Dinner Date is built around facilitating in-person meetings between users in approved public venues. Because our Services involve user profiles, communications, optional location-based functionality, payment processing, safety features, and user-generated content, protecting personal information is a fundamental part of our platform design. Our privacy principles include:
- collecting only information that is reasonably necessary to provide and improve the Services;
- providing users with meaningful transparency regarding how their information is used;
- giving users reasonable control over their personal information where applicable;
- implementing appropriate technical and organizational safeguards designed to protect personal information;
- supporting applicable legal rights relating to privacy and data protection;
continuously reviewing our privacy practices as the platform evolves. No technology or online service can guarantee absolute security. However, we are committed to maintaining reasonable administrative, technical, and organizational safeguards appropriate to the nature of the information we process.
1.2 Scope of this Privacy Policy
This Privacy Policy applies to personal information processed in connection with the Dinner Date Services, including:
- the Dinner Date mobile applications;
- the Dinner Date website;
- user registration and account management;
- profile creation;
- identity and eligibility verification;
- messaging functionality;
- restaurant and venue interactions;
- payment-related processes;
- safety and trust features;
- customer support communications;
- moderation and enforcement activities;
- marketing communications where permitted by law;
any other services that expressly reference this Privacy Policy. Unless expressly stated otherwise, this Privacy Policy applies regardless of the device you use to access the Services.
1.3 Information Covered by this Policy
This Privacy Policy explains our practices regarding information relating to identifiable individuals, including information that may directly or indirectly identify a person. Depending on applicable law, this information may be referred to as: Personal Information Personal Data Personally Identifiable Information (PII) Protected Personal Information Throughout this Privacy Policy, we generally use the term “Personal Information.” Information that has been irreversibly anonymized so that it can no longer reasonably identify an individual is generally not considered Personal Information under this Privacy Policy.
1.4 Geographic Scope
Dinner Date is intended to support users in multiple countries and regions. Privacy laws differ between jurisdictions. Depending on where you reside, additional legal rights or disclosures may apply to you. Nothing in this Privacy Policy is intended to reduce or limit any rights that you may have under applicable privacy or consumer protection laws. Where local law provides stronger protections than those described in this Privacy Policy, the applicable law will prevail to the extent required. Additional regional disclosures may be provided for users located in jurisdictions such as: European Economic Area (EEA) United Kingdom Switzerland United States Canada Australia New Zealand Singapore Other jurisdictions where Dinner Date makes its Services available
1.5 Eligibility
Dinner Date is intended exclusively for adults who satisfy the minimum age requirements established in our Age and Eligibility Policy and Terms of Service. The Services are not directed toward children. Individuals who do not meet the minimum eligibility requirements must not create an account or use the Services. Where we become aware that an account was created in violation of applicable age requirements or our policies, we may suspend or terminate the account and take appropriate steps consistent with our legal obligations. Additional information regarding age verification, eligibility requirements, and age-related account enforcement is available in the Age and Eligibility Policy.
1.6 Relationship to Other Agreements
This Privacy Policy forms part of the legal framework governing your use of Dinner Date. Where another policy specifically addresses a subject in greater detail, that policy supplements this Privacy Policy. Examples include:
| Subject | Primary Policy |
|---|---|
| Platform rules | Terms of Service |
| Acceptable behavior | Community Guidelines |
| User safety | Safety Guidelines |
| User reports | Reporting and Enforcement Policy |
| Content review | Content Moderation Policy |
| Illegal content | CSAM Policy |
| Payment processing | Payment Terms |
| Deposits and refunds | Refund and Deposit Policy |
| Location processing | Location and Geofence Policy |
| Cookies | Cookie and Tracking Policy |
| Data deletion | Account Deletion and Data Retention Policy |
| Artificial Intelligence | AI Usage Disclosure |
If a conflict exists between this Privacy Policy and another policy regarding a specialized subject, the more specific policy governs that subject to the extent of the inconsistency.
1.7 Future Platform Features
Dinner Date may introduce new products, features, or functionality over time. Where a new feature results in a material change to how Personal Information is collected, used, disclosed, or otherwise processed, we may update this Privacy Policy and, where required by applicable law, provide additional notice or obtain additional consent before the new processing occurs. The publication of future feature descriptions in product roadmaps, public documentation, marketing materials, or other informational resources does not necessarily mean those features are currently available or actively processing Personal Information.
1.8 Acceptance of this Privacy Policy
By creating an account or otherwise using the Services, you acknowledge that you have been provided access to this Privacy Policy. Where consent is required by applicable law for specific processing activities, we will request such consent separately. Your continued use of the Services following updates to this Privacy Policy constitutes acceptance of those updates only to the extent permitted by applicable law.
1.9 Contact Regarding Privacy
Questions, requests, or concerns relating to this Privacy Policy or our privacy practices may be submitted using the contact information published in the Contact Information section of this Privacy Policy. Where applicable law requires the appointment of a Data Protection Officer or similar representative, the relevant contact details will also be provided in that section.
2. Definitions
For purposes of this Privacy Policy, the following terms have the meanings set out below. These definitions apply unless the context requires otherwise or another policy expressly defines a term differently for a specific purpose.
2.1 “Account”
An “Account” means a registered Dinner Date user account that enables an individual to access some or all features of the Services. An Account may include authentication credentials, profile information, preferences, messaging history, safety settings, payment relationships, and other information associated with a registered user.
2.2 “Applicable Law”
“Applicable Law” means all laws, regulations, statutory requirements, governmental orders, regulatory guidance, court decisions, and legally binding obligations that apply to Dinner Date or to a user’s use of the Services in the relevant jurisdiction. Applicable Law may include privacy, consumer protection, payment, intellectual property, child protection, anti-discrimination, telecommunications, and law enforcement requirements.
2.3 “Approved Venue”
An “Approved Venue” means a restaurant, café, coffee shop, tea house, bakery, or other commercial public establishment that is eligible to be selected within the Dinner Date platform. Private residences, undisclosed locations, and other venue types prohibited under the Terms of Service are not Approved Venues.
2.4 “Artificial Intelligence” or “AI”
“Artificial Intelligence” or “AI” refers to automated technologies that may assist with certain platform functions, including but not limited to recommendations, ranking, fraud detection, trust and safety operations, moderation assistance, spam detection, abuse prevention, and customer support. The use of AI within the Services is further described in the AI Usage Disclosure.
2.5 “Business Partner”
A “Business Partner” means an organization with which Dinner Date collaborates in connection with the Services, including restaurants, payment providers, verification providers, cloud service providers, analytics providers, customer support vendors, and other authorized service providers.
2.6 “Content”
“Content” means any information, material, communication, media, or data available through the Services. Content includes, without limitation:
- profile information;
- photographs;
- messages;
- reviews;
- reports;
- comments;
- text;
- audio;
- video;
- metadata;
- uploaded documents;
- other user-generated material.
2.7 “Controller”
Where applicable privacy law distinguishes between data controllers and processors, “Controller” refers to the legal entity that determines the purposes and means of processing Personal Information. Depending on applicable law and the specific processing activity, Dinner Date may act as a Controller or, where appropriate, as a Processor.
2.8 “Cookies”
“Cookies” are small data files stored on a device or browser that enable websites and related services to remember information between visits. Information regarding cookies and similar technologies is provided in the Cookie and Tracking Policy.
2.9 “Device Information”
“Device Information” includes technical information relating to a user’s device, operating system, browser, application version, language settings, unique device identifiers where permitted by law, crash diagnostics, and similar technical information.
2.10 “Dinner Date”
“Dinner Date,” “we,” “our,” and “us” refer to the legal entity operating the Dinner Date platform. The specific legal entity responsible for the Services may vary depending on jurisdiction and will be identified in the Contact Information section of this Privacy Policy or within the Terms of Service.
2.11 “Emergency Contact”
An “Emergency Contact” means an individual designated by a user to receive communications initiated through safety-related features of the Services (for example, SOS, drift, or check-in notifications). At least one Emergency Contact is required in order to publish a date invitation or apply to one — these are safety-critical (“duty of care”) features, not optional preferences. You cannot remove your last remaining Emergency Contact while you have an open invitation or an active match. Emergency Contact details (a name and phone number) are stored so that the app can notify that person if you trigger a safety feature; the contact is not themselves a Dinner Date user and is contacted only in connection with the relevant safety function. Users are responsible for ensuring they have permission to provide Emergency Contact information where required by Applicable Law.
2.12 “Geofence”
A “Geofence” means a virtual geographic boundary established around an Approved Venue for the purpose of enabling location-dependent platform features. A Geofence is intended to support certain platform functions such as attendance verification and optional safety features. The existence of a Geofence does not imply continuous location monitoring.
2.13 “Geofence Verification”
“Geofence Verification” means the process by which the Services determine whether a user’s device is located within the permitted geographic boundary surrounding an Approved Venue for a specific platform function. Unless otherwise disclosed, Geofence Verification is intended to verify a user’s presence within an approved area and should not be interpreted as continuous location tracking. Additional information is available in the Location and Geofence Policy.
2.14 “Legal Basis”
“Legal Basis” means a lawful ground for processing Personal Information under Applicable Law, including consent, contractual necessity, legal obligation, legitimate interests, protection of vital interests, or other lawful grounds recognized by applicable privacy legislation.
2.15 “Personal Information”
“Personal Information” means information relating to an identified or identifiable individual. Depending on Applicable Law, Personal Information may include Personal Data, Personally Identifiable Information (PII), or equivalent legal concepts. Examples include:
- name;
- telephone number;
- email address;
- photographs;
- profile information;
- payment-related identifiers;
- device identifiers;
- location-related information;
- communications;
- account information;
any information that can reasonably identify an individual directly or indirectly. Information that has been irreversibly anonymized so that it can no longer reasonably identify an individual is generally not considered Personal Information.
2.16 “Processing”
“Processing” means any operation performed on Personal Information, whether by automated or manual means. Processing includes collecting, recording, organizing, storing, using, analyzing, combining, transmitting, sharing, updating, deleting, restricting, anonymizing, or otherwise handling Personal Information.
2.17 “Processor”
Where Applicable Law distinguishes between Controllers and Processors, a “Processor” means an entity that processes Personal Information on behalf of a Controller.
2.18 “Profile”
A “Profile” means the information a user chooses or is required to associate with an Account, including photographs, biography, preferences, interests, dining preferences, dating preferences, profile settings, and similar information. Certain Profile information may be visible to other users depending on platform settings.
2.19 “Public Profile Information”
“Public Profile Information” means information that a user intentionally makes available to other users through the Services. Public Profile Information may include, depending on platform functionality:
- first name or display name;
- age;
- photographs;
- biography;
- interests;
- food preferences;
- dining preferences;
- dating preferences;
- profile badges;
- other information intentionally displayed by the user.
2.20 “Safety Features”
“Safety Features” means tools intended to assist users before, during, or after in-person meetings. Examples may include:
- Emergency Contacts;
- reporting tools;
- emergency assistance features;
- geofence verification;
- optional safety monitoring;
- user blocking;
- identity verification;
trust and safety mechanisms. Safety Features are designed to support users but do not guarantee personal safety or emergency intervention.
2.21 “Sensitive Personal Information”
“Sensitive Personal Information” means categories of Personal Information that receive enhanced protection under Applicable Law. Depending on jurisdiction, this may include information relating to:
- precise location;
- biometric information;
- health information;
- racial or ethnic origin;
- religious beliefs;
- sexual orientation;
- government-issued identifiers;
- financial account information;
other specially protected categories recognized by law. Dinner Date seeks to minimize the collection of Sensitive Personal Information except where reasonably necessary for the Services or where voluntarily provided by users.
2.22 “Services”
“Services” means all products, applications, websites, software, communications, APIs, customer support, features, functionality, and related offerings made available by Dinner Date.
2.23 “Third Party”
A “Third Party” means any individual or entity other than:
- the user;
Dinner Date; or an authorized service provider acting on behalf of Dinner Date within the scope of a contractual relationship.
2.24 “User”
“User” means any individual who accesses or uses the Services, whether or not that individual has created an Account. Where context requires, “User” includes registered members, applicants, hosts, guests, and prospective users.
2.25 “User Content”
“User Content” means any Content submitted, uploaded, transmitted, published, or otherwise made available by a User through the Services. Examples include:
- profile photographs;
- profile descriptions;
- messages;
- reports;
- reviews;
- feedback;
- venue preferences;
- dining preferences;
- uploaded media;
communications with support. Ownership and licensing of User Content are governed by the Terms of Service.
2.26 Interpretation
Unless the context requires otherwise:
- singular words include the plural and vice versa;
- references to one gender include all genders;
- headings are provided for convenience only and do not affect interpretation;
- references to policies include future amendments or replacements;
examples introduced by terms such as “including,” “for example,” or similar expressions are illustrative and not exhaustive. These definitions are intended to promote consistency across the Dinner Date legal documentation and should be interpreted together with the Terms of Service and other applicable platform policies.
3. Information We Collect
Dinner Date collects information in several ways depending on how you interact with the Services. Some information is provided directly by you, some is collected automatically through your use of the Services, some is generated as part of operating the platform, and some may be received from authorized third parties. The specific information collected depends on the features you use, your device settings, your permissions, and applicable law. We do not intentionally collect more Personal Information than is reasonably necessary to provide, secure, improve, and operate the Services.
3.1 Categories of Information We Collect
Depending on your use of the Services, we may collect the following categories of information:
| Category | Examples |
|---|---|
| Account Information | Name, phone number, email address (if provided), authentication credentials |
| Profile Information | Biography, photographs, interests, food preferences, dating preferences |
| Identity & Eligibility Information | Date of birth, age confirmation, verification status |
| Communications | Messages, support requests, reports, appeals |
| Venue & Activity Information | Date invitations, applications, bookings, attendance records |
| Payment Information | Deposit transactions, payment status, billing records |
| Location Information | Geofence verification, approximate location where permitted |
| Device Information | Device type, operating system, application version |
| Usage Information | Feature interactions, navigation, preferences |
| Safety Information | Emergency contacts, safety reports, moderation records |
| Technical Information | Logs, diagnostics, crash reports, security events |
The following sections describe each category in greater detail.
3.2 Information You Provide Directly
You may provide Personal Information when creating an Account, completing your Profile, communicating with other users, contacting support, or using various platform features. The categories below describe the types of information you may choose or be required to provide.
3.2.1 Account Registration Information
When creating an Account, we may collect information such as:
- first name or preferred display name;
- mobile telephone number;
- email address (where requested or voluntarily provided);
- date of birth;
- age confirmation;
- authentication credentials;
- country or region;
- preferred language;
- account preferences;
account settings. Certain registration information may be required in order to create and maintain an Account.
3.2.2 Profile Information
Your Profile allows other users to understand your interests and determine whether they wish to interact with you. Profile information may include:
- profile photographs;
- biography;
- interests;
- favorite cuisines;
- dietary preferences;
- dietary restrictions;
- food allergies voluntarily disclosed by you;
- restaurant preferences;
- preferred dining atmosphere;
- preferred budget range;
- dating intentions;
- preferred age range;
- gender identity where voluntarily provided;
- sexual orientation where voluntarily provided;
- languages spoken;
- lifestyle preferences;
- profile badges;
other profile information you choose to share. Some Profile information is visible to other users according to your profile settings and the design of the Services.
3.2.3 Verification Information
To help maintain trust and safety within the platform, we may collect information necessary to verify eligibility or account authenticity. Depending on available platform features, this may include:
- age confirmation;
- phone verification;
- email verification;
- identity verification status;
- verification tokens;
- verification timestamps;
other information reasonably required to confirm account authenticity. Where third-party verification providers are used, additional information may be processed as described in this Privacy Policy and the provider’s applicable privacy documentation.
3.2.4 User Generated Content
You may voluntarily create, upload, publish, or transmit User Content through the Services. Examples include:
- photographs;
- profile descriptions;
- date invitations;
- comments;
- reviews;
- messages;
- restaurant recommendations;
- feedback;
- reports;
- survey responses;
- customer support communications;
other content submitted through the Services. You are responsible for the Personal Information you choose to include within User Content.
3.2.5 Communications
When communicating through the Services or with Dinner Date, we may process information including:
- in-app messages;
- customer support requests;
- moderation appeals;
- abuse reports;
- safety reports;
- responses to platform notifications;
- survey responses;
communications with our support team. Communications may be processed for operational, safety, legal, fraud prevention, customer support, and quality assurance purposes.
3.2.6 Payment and Date Credits Information
Dinner Date’s in-app economy is built primarily on Date Credits — a closed-loop, in-app unit you purchase through the Apple App Store or Google Play in-app purchase (IAP) system, using a subscription/entitlement provider (RevenueCat). The date “bond” (deposit) required to post or apply to a date is held from your Date Credits balance; Dinner Date also offers optional plan passes (Plus / Pro) that may be purchased with Date Credits or through Google Play billing. When payment, credits, or purchase functionality is used, we may process information relating to those transactions, which may include:
- credit balance and credit-ledger entries (purchases, holds, releases, forfeitures, refunds);
- store transaction identifiers and purchase tokens;
- non-refundability acknowledgement records (the version and time you accepted the credits terms), stored against your account and against each purchase and hold;
- plan-grant and entitlement records;
- deposit / bond status (held, released, forfeited);
payment status, confirmations, refund and chargeback information, currency, billing country, and timestamps. Because Date Credits are purchased through Apple or Google, the underlying card/wallet payment is processed by the store, and Dinner Date does not receive or store your card number, card security code (CVV), UPI PIN, or similar payment credentials for those purchases. Where the optional real-money payment gateway (Razorpay) is enabled for a market instead of Date Credits, card and payment-instrument data is handled directly by that PCI-DSS-compliant provider, and Dinner Date receives only transaction metadata (status, identifiers, amounts), never full card credentials. See the Refund and Deposit Policy and Payment Terms for how bonds are held, released, and forfeited.
3.2.7 Restaurant and Date Information
When you organize or participate in dining experiences through the Services, we may collect information relating to those activities. Examples include:
- selected venue;
- reservation preferences;
- proposed date and time;
- meal type;
- party size;
- bill preference;
- dining preferences;
- attendance confirmations;
- applications to join a date;
- invitations;
- negotiation status;
- booking information;
- cancellation information;
- completion status.
3.2.8 Safety Information
To support trust and safety features, you provide information including:
- emergency contact information (a name and phone number for at least one Emergency Contact — required before you can post or apply to a date; see §2.11);
- safety preferences (for example, whether drift monitoring auto-starts at check-in);
- reports regarding other users;
- blocking preferences;
- moderation appeals;
- incident descriptions;
- evidence voluntarily submitted;
responses during safety-related interactions. Safety information is processed only for purposes consistent with maintaining platform integrity, user safety, legal compliance, and enforcement of our policies.
3.3 Information Collected Automatically
When you access or use the Services, certain information may be collected automatically by our systems or by authorized service providers acting on our behalf. This information helps us operate, secure, improve, troubleshoot, and maintain the Services. Automatically collected information may include:
- device identifiers where permitted by law;
- application version;
- operating system;
- browser type (web);
- language settings;
- time zone;
- IP address;
- approximate location derived from IP where applicable;
- network information;
- crash reports;
- diagnostics;
- feature usage;
- interaction events;
- session information;
- referral information;
- security events;
fraud detection indicators. The exact information collected depends on your device, operating system, permissions, and the features you use.
3.4 Information Generated Through Your Use of the Services
Some information is created automatically as a consequence of your interactions with the platform. Examples include:
- account creation date;
- login history;
- verification history;
- profile completion status;
- matching history;
- invitation history;
- messaging activity;
- moderation history;
- reporting history;
- payment history;
- attendance history;
- reputation indicators;
- trust and safety records;
- system-generated identifiers;
platform preferences. This information helps us operate and improve the Services, maintain security, investigate misuse, and comply with legal obligations.
3.5 Information Received from Third Parties
We may receive information from authorized third parties where reasonably necessary to provide the Services. Examples include:
- payment processors;
- identity verification providers;
- authentication providers;
- analytics providers;
- cloud hosting providers;
- fraud prevention providers;
- customer support providers;
- restaurant partners;
- government authorities where legally required;
- law enforcement agencies where legally required;
other service providers acting on our behalf. The specific categories of information received depend on the third-party service involved and the feature you use.
3.6 Information We Do Not Intentionally Collect
Unless specifically required for a feature you choose to use or required by Applicable Law, Dinner Date does not intentionally request or require users to provide:
- government-issued identity numbers;
- passport numbers;
- driver’s licence numbers;
- complete payment card information;
- banking passwords;
- biometric identifiers;
- health records;
- medical diagnoses;
- employment records;
- tax information;
- political opinions;
- religious beliefs;
- criminal history;
- genetic information;
information unrelated to the operation of the Services. If you voluntarily include such information in messages, profile fields, reports, or other User Content, we may process that information only as necessary to provide the Services, investigate reports, comply with legal obligations, or enforce our policies.
3.7 Accuracy of Information
You are responsible for ensuring that the information you provide through the Services is accurate, current, and does not infringe the rights or privacy of others. Providing false, misleading, or fraudulent information may violate our Terms of Service or Community Guidelines and may result in restrictions on your Account.
3.8 Information Relating to Other Individuals
Some platform features may permit you to provide information relating to another person, such as an Emergency Contact or information included within a safety report. By submitting such information, you represent that you have any permissions required by Applicable Law to provide that information for the relevant purpose. We may process such information solely for purposes consistent with the relevant feature, applicable law, and this Privacy Policy.
4. How We Collect Information
Dinner Date collects Personal Information through several methods depending on how you interact with the Services, the permissions you grant, the features you use, your device settings, and applicable law. Some information is collected directly from you, while other information is generated automatically through your use of the Services or received from authorized third parties. We do not intentionally collect Personal Information through undisclosed or deceptive means.
4.1 Information You Provide Directly
You provide information directly to Dinner Date whenever you voluntarily enter, upload, submit, or otherwise communicate information through the Services. Examples include when you:
- create an Account;
- verify your telephone number or email address;
- complete your Profile;
- upload profile photographs;
- provide food preferences;
- provide dating preferences;
- specify dietary requirements;
- create date invitations;
- apply to join another user’s invitation;
- negotiate venue details;
- send messages;
- contact customer support;
- submit reports;
- submit appeals;
- complete surveys;
- participate in promotions;
- update account settings;
- provide payment information through our payment providers;
- designate Emergency Contacts;
voluntarily provide other information while using the Services. Providing certain information may be necessary to access specific features of the Services.
4.2 Information Collected During Account Registration
When you register for the Services, we collect information necessary to establish and maintain your Account. This may include information used to:
- create your user identity;
- authenticate your Account;
- confirm eligibility;
- prevent duplicate accounts;
- detect fraudulent registrations;
- maintain account security;
communicate with you regarding the Services. Some registration information is mandatory because the Services cannot operate without it. Other information is optional and may enhance your experience.
4.3 Information Collected When You Use the Services
As you interact with the Services, certain information is generated automatically. Examples include:
- pages viewed;
- screens visited;
- buttons selected;
- searches performed;
- restaurants viewed;
- invitations created;
- invitations accepted;
- invitations declined;
- profile interactions;
- feature usage;
- session duration;
- application performance information;
- crash diagnostics;
security events. This information helps us understand how the Services are used, improve performance, identify technical issues, prevent abuse, and enhance user experience.
4.4 Information Collected from Your Device
Subject to your device settings and applicable law, Dinner Date may receive information from the device you use to access the Services. Depending on your operating system and permissions, this may include:
- device model;
- operating system;
- application version;
- language settings;
- regional settings;
- device identifiers where permitted;
- IP address;
- network information;
- time zone;
- diagnostic information;
- crash reports;
performance metrics. This information assists us in maintaining compatibility, troubleshooting technical issues, improving application stability, and protecting platform security.
4.5 Location Information
Certain Services rely on location-related functionality. Location information may be collected only when necessary for a feature you choose to use and where permitted by your device settings and applicable law. Examples include:
- approximate location derived from network information;
- location selected by you during profile setup;
- venue selection;
- geofence verification associated with attendance confirmation;
optional safety features that require location access. Dinner Date requests location permissions only when required for relevant platform functionality. Additional information regarding location processing is provided in the Location and Geofence Policy.
4.6 Information Generated Through Communications
When you communicate using the Services, information relating to those communications may be processed. Examples include:
- messages exchanged between users;
- customer support communications;
- moderation appeals;
- reports;
- responses to system notifications;
- safety-related communications;
feedback submissions. Communications may be processed for purposes including:
- delivering messages;
- maintaining platform integrity;
- investigating reports;
- enforcing platform policies;
- preventing fraud;
- complying with legal obligations;
- improving customer support.
4.7 Information Collected During Purchases and Payment Transactions
Purchase and payment-related information is collected when you buy Date Credits, commit or release a date bond, buy a plan pass, complete other eligible purchases, or otherwise use payment functionality available through the Services. Purchases of Date Credits and plan passes are processed by the Apple App Store, Google Play, and our entitlement provider (RevenueCat); optional real-money card/UPI payments, where enabled, are processed by an authorized third-party payment provider (Razorpay). Credit holds, releases, and forfeitures against a date bond are recorded by Dinner Date in an internal credit ledger. Dinner Date typically receives transaction-related information necessary to:
- confirm successful authorization;
- determine payment status;
- process refunds where applicable;
- investigate disputes;
- prevent fraud;
- maintain financial records;
comply with applicable legal obligations. Dinner Date does not intentionally collect complete payment card numbers or card verification codes when payments are processed through PCI-compliant payment providers.
4.8 Information Collected Through Safety Features
Certain optional safety features require additional information to operate. Depending on the feature, this information may include:
- Emergency Contact information;
- attendance confirmation;
- safety reports;
- incident reports;
- geofence verification;
- moderation evidence voluntarily submitted by users;
optional safety preferences. Safety-related information is collected only for purposes consistent with user safety, platform integrity, legal compliance, and enforcement of applicable policies.
4.9 Information Collected from Restaurant Interactions
Where applicable, Dinner Date may collect information relating to restaurant interactions facilitated through the Services. Examples include:
- selected venue;
- reservation details;
- reservation status;
- booking confirmations;
- cancellations;
- attendance confirmation;
- venue preferences;
- restaurant ratings;
dining feedback. This information helps facilitate dining experiences and improve restaurant-related features.
4.10 Information Received from Third Parties
We may receive Personal Information from authorized third parties when necessary to provide or improve the Services. These may include:
- payment providers;
- authentication providers;
- identity verification providers;
- restaurant partners;
- analytics providers;
- fraud prevention providers;
- cloud service providers;
- customer support vendors;
- communication providers;
- government authorities;
- law enforcement agencies where legally required;
other service providers acting on our behalf. Information received from third parties is processed in accordance with this Privacy Policy and Applicable Law.
4.11 Information Collected Through Automated Technologies
Depending on the platform you use, Dinner Date and authorized service providers may collect certain technical information through automated technologies. These technologies may include:
- application telemetry;
- server logs;
- diagnostic tools;
- performance monitoring;
- analytics technologies;
- cookies (website only);
similar technologies permitted by Applicable Law. Additional information regarding cookies and similar technologies is provided in the Cookie and Tracking Policy.
4.12 Information Generated by Platform Operations
Some information is created automatically as a result of operating the Services. Examples include:
- internal identifiers;
- moderation case identifiers;
- security event logs;
- authentication events;
- fraud detection indicators;
- trust and safety records;
- payment reconciliation records;
- system audit logs;
- notification delivery records;
account lifecycle records. These records are necessary for operating, securing, auditing, and improving the Services.
4.13 Information Collected for Security Purposes
Dinner Date processes certain information to help protect users, maintain platform integrity, detect abuse, and comply with legal obligations. This information may include:
- login attempts;
- authentication events;
- suspicious activity indicators;
- abuse reports;
- spam indicators;
- fraud prevention signals;
- compromised account indicators;
- device reputation information where available;
account recovery information. Security-related information helps us investigate unauthorized activity, protect user Accounts, detect violations of our policies, and maintain the security of the Services.
4.14 Information Collected with Your Permission
Certain platform features require your permission before information can be accessed. Examples may include permission to access:
- device location;
- camera;
- photo library;
- microphone;
- notifications;
- contacts, where applicable;
other device capabilities. You may withdraw many permissions through your device settings. Disabling certain permissions may limit the availability or functionality of specific Services.
4.15 Information We Do Not Collect Through Hidden Surveillance
Dinner Date is committed to transparency regarding our data collection practices. Unless expressly disclosed in this Privacy Policy or required by Applicable Law, we do not intentionally:
- activate your camera without your knowledge;
- activate your microphone without your knowledge;
- record private conversations;
- continuously monitor your precise location in the background;
- access unrelated files stored on your device;
- collect keyboard input outside the Services;
- bypass operating system privacy controls;
use hidden tracking mechanisms inconsistent with Applicable Law. If future platform features require additional permissions or processing activities that materially differ from those described in this Privacy Policy, we will update this Privacy Policy and, where required, provide additional notice or obtain additional consent before those activities begin.
4.16 Collection Principles
Our information collection practices are guided by the following principles:
- collect information that is reasonably necessary for legitimate business and operational purposes;
- provide transparency regarding our collection practices;
- respect user choices where consent or permissions are applicable;
- implement safeguards designed to protect Personal Information;
- regularly review collection practices to reduce unnecessary processing;
comply with Applicable Law. The categories and methods of collection described in this section are intended to provide a comprehensive overview of how Dinner Date obtains Personal Information in connection with the Services.
5. Location Information and Geofence Verification
Location-related information is an important component of certain Dinner Date features, including discovering nearby dining opportunities, selecting approved venues, confirming attendance at scheduled dates, and supporting optional safety features. Dinner Date is designed to minimize the collection and use of location information while providing functionality that depends on a user’s geographic proximity to participating venues. This section explains when location information may be processed, how it is used, and the choices available to users. Additional information regarding location processing is available in the Location and Geofence Policy.
5.1 Why We Process Location Information
Depending on the Services you choose to use, location-related information may be processed to:
- identify nearby approved venues;
- display local date invitations and dining opportunities;
- allow users to search within a selected geographic area;
- verify attendance at approved venues;
- support optional safety features;
- reduce fraud and abuse;
- improve location-based recommendations;
- comply with legal obligations;
maintain the integrity and security of the Services. Location information is processed only where reasonably necessary for the relevant feature or where otherwise permitted by Applicable Law.
5.2 Types of Location Information
Depending on your device settings, permissions, and the features you use, Dinner Date may process one or more categories of location-related information. These may include: Approximate Location Approximate location may be derived from information such as:
- IP address;
- network information;
- device regional settings;
user-selected city or locality. Approximate location is generally used for regional content, venue discovery, language preferences, and similar functionality.
User-Selected Location You may choose to specify information such as:
- city;
- metropolitan area;
- neighborhood;
- preferred search area;
search radius. This information is used to personalize your experience and improve relevant recommendations.
Venue Location When creating or participating in a dining invitation, the Services process information relating to the selected Approved Venue, including its geographic location. Venue information allows the platform to:
- display invitations;
- facilitate attendance;
- support reservations;
- enable geofence verification where applicable.
Geofence Verification Information Certain platform features use geofence verification to determine whether a device is located within the vicinity of an Approved Venue at the appropriate time. Geofence verification is intended to support platform integrity, attendance confirmation, and certain safety-related functionality. Geofence verification does not, by itself, imply continuous tracking of a user’s movements.
5.3 When Location Permissions Are Requested
Dinner Date requests access to location services only when required for a feature you choose to use. Examples include:
- discovering nearby venues;
- confirming attendance at an Approved Venue;
- enabling optional safety features;
- improving local recommendations;
other location-dependent Services. You may decline location permissions through your device settings. However, declining permission may prevent certain features from functioning correctly.
5.4 Foreground Location Access
Where location permission is granted, Dinner Date generally requests location information while the application is actively in use and only when necessary for the relevant feature. Examples include:
- viewing nearby venues;
- selecting a dining location;
- confirming attendance;
using certain optional safety tools. Foreground location access occurs while you are actively interacting with the application.
5.5 Background Location
Unless expressly disclosed for a specific feature and authorized by you where required, Dinner Date is not designed to continuously collect precise background location information solely because the application is installed on your device. If future platform features require additional background location processing, we will provide appropriate notice and, where required by Applicable Law, obtain any necessary permissions or consent before such processing occurs.
5.6 Geofence Verification
Certain Services use geofence verification to help confirm that a user has arrived at or is located near an Approved Venue. Geofence verification may support features including:
- attendance confirmation;
- reservation integrity;
- optional safety functionality;
- fraud prevention;
dispute resolution relating to attendance. Geofence verification is intended to verify proximity to an Approved Venue at an appropriate point in time. Unless otherwise disclosed, geofence verification is not intended to create a continuous record of a user’s movements before or after a dining experience.
5.7 Attendance Confirmation
Where attendance confirmation is available, Dinner Date may process information necessary to determine whether a user successfully confirmed their presence at an Approved Venue. Attendance confirmation records may include information such as:
- event identifier;
- venue identifier;
- user identifier;
- confirmation status;
- confirmation timestamp;
related operational metadata. Attendance confirmation is intended to support:
- reservation integrity;
- platform trust;
- dispute handling;
- optional safety features;
- enforcement of applicable platform policies.
5.8 Optional Safety Features
Some optional safety features may rely on location-related information to operate. Examples may include:
- notifying designated Emergency Contacts;
- confirming attendance at an Approved Venue;
- supporting optional safety monitoring features;
facilitating emergency assistance requests initiated by a user. Participation in optional safety features may require additional permissions depending on your device and operating system. Additional information regarding these features is available in the Safety Guidelines and Location and Geofence Policy.
5.9 User Control Over Location Information
Users generally control location permissions through their device operating system. Depending on your device, you may be able to:
- allow location access only while using the application;
- deny location access;
- revoke previously granted permissions;
- manage approximate location settings;
review application permissions. Disabling location permissions may reduce or prevent access to location-dependent features.
5.10 Accuracy of Location Information
Location technologies are not always accurate. Factors that may affect accuracy include:
- GPS availability;
- indoor environments;
- network conditions;
- device configuration;
- operating system limitations;
environmental interference. Accordingly, location-related functionality should not be relied upon as a guarantee of a person’s exact physical location.
5.11 Emergency Situations
Certain optional emergency features may process location-related information to facilitate assistance requested by a user. Dinner Date is not an emergency service, public safety answering point, or law enforcement agency. Users should contact their local emergency services directly whenever immediate emergency assistance is required. Availability of optional safety features may vary depending on jurisdiction, device capabilities, operating system functionality, and feature availability.
5.12 Location Information Shared with Third Parties
Where reasonably necessary to provide the Services, location-related information may be shared with authorized service providers. Examples include:
- mapping providers;
- navigation providers;
- payment providers where location is relevant to a transaction;
- restaurant partners where necessary to facilitate reservations;
- emergency communication providers where initiated by a user;
cloud service providers acting on our behalf. We do not disclose location-related information to third parties for purposes inconsistent with this Privacy Policy except where required or permitted by Applicable Law.
5.13 Data Minimization
Dinner Date seeks to minimize the amount of location-related information processed. Where reasonably possible, we use the least amount of location information necessary to provide the relevant feature. Our design objective is to avoid unnecessary collection, storage, or disclosure of precise location information.
5.14 Retention of Location-Related Information
Location-related information is retained only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by Applicable Law. Retention periods may differ depending on:
- the feature involved;
- legal obligations;
- fraud prevention requirements;
- safety investigations;
- dispute resolution;
security requirements. Additional information regarding retention periods is provided in the Account Deletion and Data Retention Policy and the Data Retention section of this Privacy Policy.
5.15 Future Location-Based Features
Dinner Date may introduce additional location-dependent functionality over time. Examples could include:
- enhanced venue discovery;
- improved recommendation systems;
- additional safety tools;
- restaurant partner services;
optional navigation assistance. If new features materially change how location-related information is processed, we will update this Privacy Policy and, where required by Applicable Law, provide additional notice or obtain any necessary permissions before those features become available.
5.16 Our Location Privacy Principles
Our approach to location processing is guided by the following principles:
- collect only the location information reasonably necessary for the relevant feature;
- provide transparency regarding location processing;
- respect user permissions and device privacy controls;
- implement safeguards designed to protect location-related information;
- support user choice wherever reasonably possible;
comply with Applicable Law. Location information is processed to enable specific platform functionality and is not intended to enable unnecessary surveillance of users.
6. How We Use Personal Information
Dinner Date processes Personal Information only for purposes that are consistent with providing, operating, maintaining, securing, improving, and supporting the Services, complying with Applicable Law, protecting users, and enforcing our legal rights and platform policies. The purposes described below are intended to provide transparency regarding how Personal Information may be used throughout the lifecycle of your interaction with the Services. The specific purposes applicable to you depend on the features you use, your account settings, your permissions, and applicable legal requirements.
6.1 To Provide the Services
We use Personal Information to provide the core functionality of Dinner Date. This includes:
- creating and maintaining user Accounts;
- authenticating users;
- displaying user Profiles;
- enabling profile discovery;
- facilitating date invitations;
- processing applications to join invitations;
- supporting venue selection;
- facilitating reservations where applicable;
- enabling messaging between matched users;
- managing user preferences;
- providing customer support;
delivering platform features requested by users. Without processing certain Personal Information, many core Services cannot function.
6.2 To Verify Eligibility and Maintain Platform Integrity
We process Personal Information to help ensure that users satisfy applicable eligibility requirements and to maintain the integrity of the platform. Examples include:
- verifying minimum age requirements;
- confirming account authenticity;
- reducing duplicate accounts;
- detecting fraudulent registrations;
- preventing impersonation;
- identifying automated or malicious activity;
- protecting users from abuse.
6.3 To Facilitate Dining Experiences
Dinner Date is designed to help users arrange dining experiences at Approved Venues. Accordingly, Personal Information may be processed to:
- publish dining invitations;
- display dining opportunities;
- recommend nearby venues;
- support venue negotiations;
- facilitate booking-related activities;
- manage attendance confirmations;
- support optional reservation features;
- improve restaurant-related experiences.
6.4 To Match Users
Personal Information may be processed to improve compatibility between users and provide relevant recommendations. Examples include information relating to:
- food preferences;
- dietary preferences;
- dining styles;
- location preferences;
- age preferences;
- dating intentions;
- availability;
- previous interactions;
other preferences voluntarily provided by users. Matching functionality may use automated systems to organize or rank information based on user preferences. Additional information regarding automated systems is provided in the AI Usage Disclosure.
6.5 To Enable Communications
We process Personal Information to facilitate communications through the Services. Examples include:
- delivering messages;
- notifying users of invitations;
- reservation updates;
- safety notifications;
- customer support communications;
- account notifications;
- service announcements;
- responses to reports;
moderation decisions. Communication preferences may be managed through available account settings where applicable.
6.6 To Process Payments
Where payment functionality is available, Personal Information may be processed to:
- authorize deposits;
- process eligible payments;
- issue refunds where applicable;
- prevent payment fraud;
- reconcile financial records;
- investigate disputed transactions;
- comply with financial reporting obligations;
support customer inquiries regarding payments. Payment processing is generally performed by authorized payment service providers.
6.7 To Operate Safety Features
Dinner Date includes features intended to support user safety before, during, and after in-person meetings. Personal Information may be processed to:
- facilitate Emergency Contact functionality;
- process safety reports;
- investigate incidents;
- verify attendance where applicable;
- support geofence verification;
- evaluate reports of misconduct;
- assist trust and safety personnel;
- enforce Community Guidelines;
respond to emergencies initiated through the Services. Safety-related processing is intended to support users but does not guarantee prevention of harmful conduct or emergency intervention.
6.8 To Detect, Prevent, and Investigate Abuse
We process Personal Information to help maintain a safe and trustworthy platform. Examples include:
- detecting spam;
- preventing fraud;
- investigating suspicious activity;
- identifying policy violations;
- detecting fake Accounts;
- reducing abusive behavior;
- investigating reports;
protecting users and the Services. Appropriate automated tools and human review may both be used in connection with these activities.
6.9 To Moderate Content
Personal Information and User Content may be processed for trust and safety purposes, including:
- reviewing reported content;
- investigating Community Guideline violations;
- enforcing platform rules;
- restricting prohibited content;
- reviewing appeals;
- protecting users from harmful content;
complying with legal obligations relating to unlawful material. Content moderation practices are described in greater detail within the Content Moderation Policy.
6.10 To Improve the Services
Personal Information may be processed to understand how users interact with the Services and to improve the overall platform. Examples include:
- improving usability;
- identifying technical issues;
- enhancing reliability;
- measuring feature performance;
- improving accessibility;
- optimizing application performance;
- evaluating new functionality;
improving customer support. Where reasonably practicable, aggregated or de-identified information may be used for product improvement activities.
6.11 To Personalize User Experience
Personal Information may be processed to personalize aspects of the Services. Examples include:
- recommended venues;
- suggested dining opportunities;
- localized content;
- preferred language;
- relevant notifications;
- personalized settings;
- saved preferences;
recently viewed content. Personalization is intended to improve the relevance of the Services and may vary depending on user settings.
6.12 To Conduct Analytics
Dinner Date may process Personal Information to better understand the operation of the Services. Examples include:
- application usage;
- feature adoption;
- engagement trends;
- service reliability;
- technical diagnostics;
- error analysis;
- capacity planning;
operational reporting. Analytics help us improve performance, identify problems, and make informed product decisions.
6.13 To Conduct Research and Product Development
Subject to Applicable Law, Personal Information may be used to support research, testing, evaluation, and development activities relating to the Services. Where reasonably appropriate, these activities may rely upon aggregated, anonymized, or de-identified information rather than directly identifiable Personal Information.
6.14 To Communicate with Users
We may process Personal Information to communicate with users regarding:
- account activity;
- platform updates;
- changes to our policies;
- security alerts;
- important operational announcements;
- customer support responses;
- payment-related matters;
- legal notices;
marketing communications where permitted by Applicable Law. Users may have the ability to manage certain communication preferences through available account settings.
6.15 To Comply with Legal Obligations
Personal Information may be processed where reasonably necessary to:
- comply with Applicable Law;
- satisfy regulatory obligations;
- respond to lawful requests;
- maintain financial records;
- comply with tax obligations;
- support legal proceedings;
- preserve evidence;
- cooperate with regulatory authorities;
- protect the rights of users or third parties.
6.16 To Protect Rights and Interests
We may process Personal Information where reasonably necessary to protect:
- users;
- Dinner Date;
- restaurant partners;
- service providers;
- the public;
- property;
- legal rights;
- contractual rights;
intellectual property. Examples include responding to fraud, abuse, security incidents, or legal claims.
6.17 To Enforce Our Agreements
Personal Information may be processed to:
- enforce the Terms of Service;
- enforce Community Guidelines;
- investigate breaches of our policies;
- administer Account restrictions;
- process appeals;
- manage dispute resolution;
- investigate misuse of the Services.
6.18 To Protect Platform Security
Personal Information may be processed to help:
- secure Accounts;
- authenticate users;
- monitor system integrity;
- detect unauthorized access;
- identify cybersecurity threats;
- investigate security incidents;
maintain operational resilience. Security-related processing is an essential component of operating the Services responsibly.
6.19 To Support Artificial Intelligence and Automated Systems
Dinner Date may use automated technologies, including Artificial Intelligence, to assist with certain operational functions. Examples may include:
- ranking recommendations;
- identifying spam;
- detecting suspicious activity;
- assisting content moderation;
- improving search relevance;
- organizing support requests;
improving platform operations. Where AI is used, it is intended to support—not replace—appropriate human oversight for significant trust and safety decisions. Additional information is available in the AI Usage Disclosure.
6.20 Business Operations
Personal Information may also be processed for legitimate business operations, including:
- auditing;
- accounting;
- financial reporting;
- corporate governance;
- internal administration;
- quality assurance;
- insurance;
- risk management;
- business continuity planning;
- disaster recovery;
compliance management. Such processing is limited to purposes reasonably connected with operating the Services.
6.21 Change of Purpose
If Dinner Date intends to process Personal Information for a purpose that is materially different from the purposes described in this Privacy Policy, we will take appropriate steps consistent with Applicable Law. Depending on the circumstances, this may include:
- updating this Privacy Policy;
- providing additional notice;
- obtaining consent where required;
- offering additional choices where required by Applicable Law.
6.22 Our Processing Principles
Whenever Personal Information is processed, Dinner Date seeks to apply the following principles:
- lawfulness;
- fairness;
- transparency;
- purpose limitation;
- data minimization;
- accuracy;
- storage limitation;
- integrity and confidentiality;
accountability. These principles guide the design, operation, and ongoing improvement of the Services and our privacy program.
7. Legal Bases for Processing Personal Information
Where Applicable Law requires a legal basis for processing Personal Information, including under the European Union General Data Protection Regulation (“GDPR”), the United Kingdom GDPR (“UK GDPR”), and similar privacy laws, Dinner Date processes Personal Information only where an appropriate legal basis exists. The legal basis applicable to a particular processing activity depends on the purpose of the processing, the relationship between Dinner Date and the user, the nature of the Personal Information involved, and applicable legal requirements. Where multiple legal bases apply to the same processing activity, Dinner Date may rely on one or more lawful bases as appropriate.
7.1 Performance of a Contract
One of the primary legal bases for processing Personal Information is that the processing is necessary to enter into or perform a contract with you. When you create a Dinner Date Account or use the Services, certain processing activities are necessary in order to provide the functionality you request. Examples include:
- creating and maintaining your Account;
- authenticating your identity;
- managing login sessions;
- displaying your Profile;
- publishing dining invitations;
- allowing you to browse invitations;
- processing applications to join invitations;
- facilitating messaging between matched users;
- managing reservations and attendance;
- processing deposits and eligible payments;
- providing customer support;
- maintaining user preferences;
administering your Account. Without these processing activities, Dinner Date would be unable to provide many of the Services requested by users.
7.2 Compliance with Legal Obligations
Dinner Date may process Personal Information where necessary to comply with Applicable Law or a legally binding obligation. Examples include processing necessary to:
- comply with court orders;
- respond to lawful requests from public authorities;
- comply with financial reporting obligations;
- maintain accounting records;
- comply with taxation requirements;
- satisfy anti-fraud obligations;
- investigate unlawful activity;
- preserve evidence where legally required;
- comply with consumer protection laws;
- comply with payment-related regulations;
- comply with child protection obligations;
satisfy other applicable regulatory requirements. Where legally required, Dinner Date may retain or disclose Personal Information in accordance with Applicable Law.
7.3 Legitimate Interests
Dinner Date may process Personal Information where doing so is reasonably necessary for our legitimate interests or the legitimate interests of users or third parties, provided that those interests are not overridden by your fundamental rights and freedoms. Examples of legitimate interests include: Operating the Platform
- maintaining platform functionality;
- improving reliability;
- monitoring service availability;
- administering Accounts;
responding to customer inquiries. Platform Security
- detecting unauthorized access;
- protecting Accounts;
- preventing abuse;
- identifying spam;
- preventing fraud;
- investigating suspicious activity;
monitoring system integrity. Trust and Safety
- investigating reports;
- enforcing Community Guidelines;
- preventing harmful conduct;
- reviewing moderation decisions;
- protecting users from abuse;
maintaining platform integrity. Product Improvement
- improving application performance;
- evaluating feature effectiveness;
- conducting internal analytics;
- identifying usability issues;
developing new platform features. Business Operations
- auditing;
- financial administration;
- internal reporting;
- quality assurance;
- operational planning;
risk management. Whenever Dinner Date relies upon legitimate interests, we seek to ensure that the processing is proportionate, reasonably necessary, and balanced against the privacy rights of affected individuals.
7.4 Consent
Certain processing activities are based upon your consent where required by Applicable Law. Where processing relies upon consent, you may withdraw your consent at any time, subject to legal or contractual limitations. Examples may include:
- enabling optional location permissions;
- enabling optional safety features;
- receiving certain marketing communications;
- participating in optional surveys;
- permitting push notifications where required by law;
- allowing access to device capabilities such as the camera or photo library;
participating in optional research activities. Withdrawal of consent does not affect the lawfulness of processing that occurred before consent was withdrawn. Where consent is withdrawn, certain optional features may no longer function.
7.5 Protection of Vital Interests
In limited circumstances, Dinner Date may process Personal Information where reasonably necessary to protect the vital interests of a user or another individual. Examples may include:
- facilitating user-initiated emergency assistance features;
- responding to imminent threats involving health or safety;
- supporting emergency communications initiated by a user;
protecting individuals from serious harm where permitted by Applicable Law. Processing based on vital interests is expected to occur only in exceptional circumstances.
7.6 Public Interest
Where permitted or required by Applicable Law, Dinner Date may process Personal Information in connection with activities carried out in the public interest or pursuant to official legal authority. Examples may include responding to lawful governmental requests or cooperating with competent authorities where legally required.
7.7 Multiple Legal Bases
Some processing activities may rely upon more than one legal basis. For example:
- payment processing may involve contractual necessity, legal obligations, and fraud prevention;
- moderation activities may involve legitimate interests, legal obligations, and protection of vital interests in exceptional cases;
safety-related processing may involve contractual necessity, legitimate interests, consent, or vital interests depending on the circumstances. Where multiple lawful bases are available, Dinner Date may rely on one or more of those bases as appropriate.
7.8 Special Categories of Personal Information
Certain jurisdictions provide additional protection for specific categories of Personal Information, sometimes referred to as “special categories of personal data” or “sensitive personal information.” Dinner Date seeks to minimize the collection and processing of such information. Where processing of these categories is necessary, Dinner Date will seek to ensure that an appropriate legal basis and any additional conditions required by Applicable Law are satisfied. Depending on applicable law, sensitive information may include:
- precise location information;
- biometric information;
- health-related information;
- information concerning sexual orientation;
- information revealing racial or ethnic origin;
- religious or philosophical beliefs;
other specially protected categories recognized by law. Users are encouraged not to disclose unnecessary sensitive information through public Profile fields, messages, or other User Content.
7.9 Automated Processing and Profiling
Certain platform functions may involve automated processing, including algorithms that organize, rank, recommend, or prioritize information. Examples include:
- recommending dining opportunities;
- organizing search results;
- suggesting nearby venues;
- identifying potentially fraudulent activity;
- prioritizing reports for review;
assisting moderation workflows. Automated systems are intended to improve the efficiency and operation of the Services. Where legally required, Dinner Date will provide additional information regarding automated decision-making and any applicable rights under Applicable Law. The use of Artificial Intelligence and automated technologies is described further in the AI Usage Disclosure.
7.10 Legitimate Interests Assessment
Where Dinner Date relies on legitimate interests as a legal basis, we seek to evaluate:
- the purpose of the processing;
- whether the processing is reasonably necessary;
- the potential impact on individuals;
- available safeguards;
- user expectations;
proportionality of the processing. Where appropriate, technical, contractual, organizational, and administrative safeguards are implemented to reduce privacy risks.
7.11 Changes to Legal Bases
As the Services evolve, the legal basis supporting particular processing activities may also evolve. Where a material change affects how Personal Information is processed, Dinner Date will update this Privacy Policy and, where required by Applicable Law, provide additional notice or obtain additional consent before the new processing begins.
7.12 Summary of Legal Bases
The table below provides a high-level overview of common processing activities and the legal bases that may apply.
| Processing Activity | Possible Legal Basis |
|---|---|
| Account registration | Performance of a contract |
| User authentication | Performance of a contract; Legitimate interests |
| Profile management | Performance of a contract |
| Messaging | Performance of a contract |
| Dining invitations | Performance of a contract |
| Reservation management | Performance of a contract |
| Deposit processing | Performance of a contract; Legal obligation |
| Fraud prevention | Legitimate interests; Legal obligation |
| Security monitoring | Legitimate interests |
| Customer support | Performance of a contract; Legitimate interests |
| Safety features | Performance of a contract; Consent; Vital interests (where applicable) |
| Geofence verification | Performance of a contract; Legitimate interests; Consent (where required) |
| Content moderation | Legitimate interests; Legal obligation (where applicable) |
| Abuse investigations | Legitimate interests; Legal obligation |
| Compliance activities | Legal obligation |
| Product improvement | Legitimate interests |
| Analytics | Legitimate interests; Consent (where required) |
| Marketing communications | Consent or Legitimate interests, depending on Applicable Law |
| Research and testing | Legitimate interests; Consent where required |
This table is illustrative and intended to improve transparency. Depending on the specific circumstances and applicable law, more than one legal basis may apply to a particular processing activity.
8. When and How We Share Personal Information
Dinner Date may disclose or make Personal Information available to other users, service providers, business partners, regulatory authorities, or other recipients where reasonably necessary to provide the Services, comply with Applicable Law, protect users, operate the platform, or enforce our legal rights. We do not disclose Personal Information except as described in this Privacy Policy, as required or permitted by Applicable Law, or with your consent where required. The categories of information shared depend on the Services you use, your account settings, your permissions, and applicable legal requirements.
8.1 Sharing with Other Users
Because Dinner Date is a social and dating platform, certain Personal Information is intentionally shared with other users as part of the Services. Depending on platform functionality and your settings, other users may be able to view information such as:
- your display name;
- age;
- profile photographs;
- biography;
- food preferences;
- dining preferences;
- dietary preferences;
- dating intentions;
- languages spoken;
- profile badges;
- information relating to invitations you create;
- restaurant selections associated with your invitations;
other information you intentionally choose to make visible. Only information intended for user-facing features is shared with other users. Information that supports account security, payment processing, fraud prevention, moderation, or internal operations is not displayed to other users unless expressly disclosed elsewhere in this Privacy Policy.
8.2 Sharing During Dining Invitations
When you create, apply for, or participate in a dining invitation, certain information may be shared with the other participants as necessary to facilitate that experience. Depending on the feature, this may include:
- profile information;
- invitation details;
- selected venue;
- proposed date and time;
- dining preferences;
- attendance status where applicable;
- messaging;
reservation-related information. Only information reasonably necessary to facilitate the relevant dining experience is shared.
8.3 Sharing with Service Providers
Dinner Date works with carefully selected third-party service providers that perform services on our behalf. These providers may assist with functions including:
- cloud hosting;
- infrastructure services;
- payment processing;
- customer support;
- analytics;
- application monitoring;
- authentication;
- identity verification;
- fraud prevention;
- communications;
- push notifications;
- email delivery;
- mapping and location services;
- security monitoring;
- data storage;
software development tools. Service providers are authorized to process Personal Information only to the extent reasonably necessary to perform the services requested by Dinner Date and are expected to protect Personal Information through appropriate contractual, technical, and organizational safeguards.
8.4 Sharing with Stores and Payment Service Providers
Because Date Credits and plan passes are sold as in-app purchases, purchase and entitlement information is shared with the Apple App Store, Google Play, and our entitlement provider (RevenueCat) to validate purchases, reconcile entitlements, and honour store-side refunds. Where the optional real-money gateway (Razorpay) is enabled, payment-related information is shared with that provider to facilitate:
- payment authorization;
- deposit processing;
- refunds;
- fraud prevention;
- financial reconciliation;
- regulatory compliance;
dispute resolution. Payment service providers operate under their own privacy notices and may process Personal Information independently in accordance with Applicable Law. Dinner Date does not intentionally disclose complete payment card numbers or payment security codes to restaurant partners or other users.
8.5 Sharing with Restaurant Partners
Where reasonably necessary to facilitate reservations or dining experiences, limited information may be shared with participating restaurant partners. Depending on the feature, this may include:
- reservation details;
- reservation time;
- party size;
- dining preferences where relevant;
- special requests voluntarily submitted by you;
reservation confirmation status. Restaurant partners are not authorized to use Personal Information received from Dinner Date for purposes unrelated to the dining experience unless they have an independent lawful basis to do so.
8.6 Sharing with Emergency Contacts
Where you choose to use optional safety features, Dinner Date may share limited information with the Emergency Contact(s) you designate. Depending on the feature, this may include:
- your name;
- emergency notification;
- information necessary to support the selected safety feature;
information relating to an emergency assistance request initiated through the Services. Emergency Contact information is used only in connection with the relevant safety functionality or where otherwise permitted or required by Applicable Law.
8.7 Sharing with Identity Verification Providers
Where identity verification features are available, Personal Information may be shared with authorized verification providers to assist in confirming eligibility, reducing fraud, preventing impersonation, and maintaining platform integrity. Verification providers process Personal Information in accordance with their contractual obligations and Applicable Law.
8.8 Sharing with Analytics and Technology Providers
Dinner Date may share limited information with analytics, diagnostics, and technology providers to help us:
- understand application performance;
- monitor reliability;
- identify technical issues;
- improve usability;
- evaluate new features;
maintain service quality. Where reasonably practicable, aggregated, anonymized, or de-identified information may be used for these purposes.
8.9 Sharing for Trust and Safety
Personal Information may be shared internally or with authorized service providers where reasonably necessary to:
- investigate reports;
- review moderation decisions;
- detect fraud;
- identify abuse;
- investigate impersonation;
- prevent spam;
- enforce Community Guidelines;
- protect users;
preserve evidence where appropriate. Such sharing is limited to the extent reasonably necessary for trust and safety purposes.
8.10 Sharing for Legal Compliance
Dinner Date may disclose Personal Information where reasonably necessary to:
- comply with Applicable Law;
- respond to lawful court orders;
- comply with legally valid warrants or subpoenas;
- satisfy regulatory obligations;
- cooperate with governmental authorities;
- respond to lawful requests from competent public authorities;
- protect legal rights;
- prevent fraud;
investigate unlawful conduct. Where legally permitted and appropriate, Dinner Date may seek to limit the scope of disclosures and may challenge requests that appear overly broad or otherwise inconsistent with Applicable Law. Additional information is available in the Law Enforcement Request Policy.
8.11 Protection of Rights and Safety
We may disclose Personal Information where reasonably necessary to:
- protect users;
- protect Dinner Date;
- protect restaurant partners;
- protect service providers;
- protect the public;
- investigate threats;
- prevent serious harm;
- respond to emergencies;
- protect property;
establish or defend legal claims. Such disclosures are made only where reasonably necessary and consistent with Applicable Law.
8.12 Corporate Transactions
If Dinner Date becomes involved in a merger, acquisition, investment, financing, corporate restructuring, bankruptcy, sale of assets, or similar corporate transaction, Personal Information may be disclosed to prospective or actual counterparties and their professional advisers as reasonably necessary to evaluate or complete the transaction. Where required by Applicable Law, affected users will be notified of material changes affecting their Personal Information.
8.13 Professional Advisers
Dinner Date may disclose Personal Information to professional advisers where reasonably necessary for legitimate business purposes. These advisers may include:
- legal counsel;
- auditors;
- accountants;
- insurers;
- compliance consultants;
- cybersecurity consultants;
- other professional advisers engaged under appropriate confidentiality obligations.
8.14 Business Transfers
Where permitted by Applicable Law, Personal Information may be transferred as part of:
- sale of business assets;
- transfer of operations;
- corporate restructuring;
- insolvency proceedings;
- business succession;
other lawful business transactions. Recipients of such information will generally be expected to honor existing privacy commitments or provide appropriate notice of any material changes where required by Applicable Law.
8.15 Aggregated and De-Identified Information
Dinner Date may use or disclose information that has been aggregated, anonymized, or de-identified so that it no longer reasonably identifies an individual. Such information may be used for purposes including:
- research;
- analytics;
- reporting;
- product development;
- operational planning;
- business intelligence;
statistical analysis. Where information has been irreversibly anonymized, it is generally no longer considered Personal Information under this Privacy Policy.
8.16 International Sharing
Because Dinner Date may operate across multiple countries, Personal Information may be processed or made available to authorized recipients located in jurisdictions other than the country in which the information was originally collected. International transfers are discussed in greater detail in the International Data Transfers section of this Privacy Policy.
8.17 We Do Not Sell Personal Information
Dinner Date does not sell Personal Information in exchange for monetary consideration as those concepts are commonly defined under applicable privacy legislation. Certain jurisdictions define “sale,” “sharing,” or “targeted advertising” differently. Where Applicable Law requires additional disclosures regarding these concepts, those disclosures will be provided within this Privacy Policy or in jurisdiction-specific privacy notices.
8.18 Your Choices Regarding Information Sharing
Depending on the Services you use and Applicable Law, you may be able to:
- manage Profile visibility;
- control information shared with other users;
- manage communication preferences;
- manage location permissions;
- control optional safety features;
- withdraw consent where processing relies upon consent;
exercise applicable privacy rights. Some information sharing is necessary for the operation of the Services and cannot be disabled without limiting or preventing access to certain platform functionality.
8.19 Our Disclosure Principles
Whenever Personal Information is disclosed, Dinner Date seeks to apply the following principles:
- disclose only what is reasonably necessary for the relevant purpose;
- disclose information only to authorized recipients;
- apply contractual, technical, and organizational safeguards where appropriate;
- respect user privacy expectations;
- comply with Applicable Law;
- regularly review disclosure practices to support data minimization and accountability.
9. International Data Transfers
Dinner Date is intended to support users in multiple countries and regions. As a result, Personal Information may be processed, stored, accessed, or transferred across national borders in connection with the operation of the Services. Because data protection laws vary between jurisdictions, Dinner Date seeks to implement appropriate safeguards designed to protect Personal Information when it is transferred internationally. This section explains how international transfers may occur, the safeguards we seek to apply, and the rights available to users under Applicable Law.
9.1 Global Nature of the Services
Dinner Date is a global platform that may operate through employees, contractors, affiliates, service providers, infrastructure providers, payment providers, restaurant partners, and other authorized recipients located in different countries. As a result, Personal Information may be processed in jurisdictions other than the country in which it was originally collected. Examples include:
- cloud infrastructure;
- data storage;
- customer support;
- payment processing;
- fraud prevention;
- identity verification;
- analytics;
- communications;
- security monitoring;
- disaster recovery;
software maintenance. The countries involved may change as our business, infrastructure, and service providers evolve.
9.2 Circumstances in Which International Transfers May Occur
International transfers may occur where reasonably necessary to:
- provide the Services;
- authenticate users;
- process payments;
- facilitate communications;
- provide customer support;
- investigate abuse;
- maintain platform security;
- detect fraud;
- support trust and safety operations;
- improve application performance;
- comply with Applicable Law;
protect users and the public. Not every user will experience every category of international transfer.
9.3 Countries of Processing
Depending on the Services used, Personal Information may be processed in:
- the country where you reside;
- the country where an Approved Venue is located;
- countries in which our service providers operate;
- countries where authorized support personnel are located;
- jurisdictions where legal obligations require processing;
other locations reasonably necessary for operation of the Services. Dinner Date does not guarantee that all Personal Information will remain exclusively within a user’s country of residence.
9.4 Transfer Safeguards
Where Personal Information is transferred internationally, Dinner Date seeks to implement safeguards appropriate to the nature of the transfer and Applicable Law. Depending on the circumstances, these safeguards may include:
- contractual obligations with service providers;
- confidentiality obligations;
- technical and organizational security measures;
- encryption during transmission where appropriate;
- access controls;
- role-based permissions;
- security monitoring;
- vendor due diligence;
transfer mechanisms recognized by Applicable Law. The safeguards used may vary depending on the jurisdiction involved and the nature of the processing.
9.5 European Economic Area, United Kingdom, and Switzerland
Where Personal Information is subject to the GDPR, UK GDPR, or similar laws governing international transfers, Dinner Date seeks to rely on an appropriate legal transfer mechanism before transferring Personal Information outside the relevant jurisdiction. Depending on the circumstances, this may include:
- an adequacy decision recognized by the relevant authority;
- Standard Contractual Clauses (SCCs) or their approved successor mechanisms;
- the United Kingdom International Data Transfer Agreement (IDTA) or approved UK transfer mechanisms;
- Binding Corporate Rules where applicable;
another lawful transfer mechanism recognized by Applicable Law. Where required, Dinner Date also seeks to implement supplementary technical, contractual, or organizational safeguards designed to protect Personal Information.
9.6 Transfers to Service Providers
Many international transfers occur because Dinner Date uses specialized service providers. Before authorizing a provider to process Personal Information on our behalf, we seek to evaluate factors including:
- the provider’s security practices;
- contractual confidentiality obligations;
- compliance commitments;
- ability to safeguard Personal Information;
- operational reliability;
applicable legal requirements. Service providers are generally authorized to process Personal Information only for the purposes specified in our agreements with them.
9.7 Transfers Related to Payments
Payment processing may involve international transfers performed by authorized payment service providers. Such transfers may be necessary to:
- authorize transactions;
- prevent fraud;
- process refunds;
- comply with financial regulations;
- investigate disputed transactions;
satisfy payment network requirements. Payment providers process Personal Information under their own legal and regulatory obligations in addition to their contractual obligations with Dinner Date.
9.8 Transfers Related to Safety and Security
International transfers may occur where reasonably necessary to:
- investigate abuse;
- detect fraud;
- review safety reports;
- investigate policy violations;
- preserve evidence;
- protect users;
- respond to emergencies initiated by users;
comply with legal obligations. Such transfers are limited to the extent reasonably necessary for the relevant purpose.
9.9 Legal Requests Across Borders
In some circumstances, Personal Information may be disclosed in response to lawful requests originating from governmental authorities located in another jurisdiction. Dinner Date evaluates such requests in accordance with Applicable Law and our Law Enforcement Request Policy. Where legally permitted and appropriate, we may:
- seek clarification regarding the request;
- challenge requests that appear overly broad or inconsistent with Applicable Law;
- limit disclosures to information reasonably required;
- notify affected users where legally permitted.
9.10 Security of International Transfers
International transfers do not reduce Dinner Date’s commitment to protecting Personal Information. Regardless of where Personal Information is processed, we seek to implement safeguards including:
- encryption where appropriate;
- authentication controls;
- access restrictions;
- logging and monitoring;
- vendor oversight;
- security reviews;
- incident response procedures;
confidentiality obligations. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
9.11 Your Rights Regarding International Transfers
Depending on your jurisdiction and Applicable Law, you may have rights relating to international transfers of your Personal Information. These rights may include the ability to:
- request additional information regarding transfer safeguards;
- request access to information about transfers;
- exercise applicable privacy rights;
- lodge complaints with a competent supervisory authority;
seek additional information regarding cross-border processing. The availability of these rights depends on Applicable Law.
9.12 Future Changes to International Transfers
As Dinner Date grows, our infrastructure, service providers, operational footprint, and technology stack may evolve. Accordingly, the countries in which Personal Information is processed may change over time. Where changes materially affect international processing practices, Dinner Date will update this Privacy Policy and, where required by Applicable Law, provide appropriate notice or obtain additional consent before the new processing activities begin.
9.13 Data Localization
Certain jurisdictions may require some categories of Personal Information to be stored, processed, or otherwise handled within a particular country or region. Where such legal requirements apply, Dinner Date seeks to comply with applicable data localization obligations while continuing to provide the Services. Compliance measures may vary depending on the jurisdiction, the nature of the information, and the applicable legal requirements.
9.14 Government Access Risks
Privacy laws and governmental access powers differ between countries. Where Personal Information is transferred internationally, it may become subject to the laws of the destination jurisdiction. Dinner Date seeks to evaluate these risks when selecting service providers and implementing transfer safeguards. Where required by Applicable Law, we conduct assessments intended to determine whether additional technical, contractual, or organizational measures are appropriate.
9.15 International Cooperation
Operating a global platform may require cooperation between different teams, service providers, and authorized recipients located in multiple jurisdictions. Dinner Date seeks to ensure that such cooperation occurs in accordance with:
- Applicable Law;
- contractual obligations;
- confidentiality requirements;
- security standards;
- internal privacy policies;
applicable transfer safeguards. International cooperation is limited to purposes reasonably connected with operating, securing, improving, and supporting the Services.
9.16 Our Principles for International Transfers
Dinner Date seeks to conduct international transfers in accordance with the following principles:
- transparency regarding cross-border processing;
- compliance with Applicable Law;
- implementation of appropriate safeguards;
- data minimization;
- vendor accountability;
- protection of user rights;
- security by design;
ongoing review of transfer practices. International transfers are undertaken only where reasonably necessary for the operation of the Services or otherwise permitted or required by Applicable Law.
10. Data Retention
Dinner Date retains Personal Information only for as long as reasonably necessary to fulfill the purposes described in this Privacy Policy, comply with Applicable Law, resolve disputes, enforce our agreements, maintain platform integrity, protect users, and support legitimate business operations. Retention periods vary depending on the type of information involved, the feature through which it was collected, the legal obligations applicable to Dinner Date, and the operational requirements of the Services. When Personal Information is no longer required for the purposes for which it was collected and no legal or operational obligation requires continued retention, Dinner Date seeks to securely delete, anonymize, or otherwise de-identify the information in accordance with applicable retention procedures.
10.1 Our Data Retention Principles
Dinner Date’s approach to data retention is guided by the following principles:
- retain information only for as long as reasonably necessary;
- comply with Applicable Law;
- support user safety;
- preserve information required for legitimate dispute resolution;
- maintain the integrity of the Services;
- protect against fraud and abuse;
- minimize unnecessary long-term storage of Personal Information;
securely dispose of information that is no longer required. Retention decisions are based upon the purpose for which information was collected rather than applying a single retention period to all categories of information.
10.2 Factors We Consider
When determining how long to retain Personal Information, Dinner Date may consider factors including:
- the purpose of the processing;
- the nature of the information;
- user expectations;
- contractual obligations;
- legal requirements;
- regulatory requirements;
- accounting obligations;
- tax obligations;
- dispute resolution requirements;
- security requirements;
- fraud prevention;
- trust and safety considerations;
- technical limitations;
operational necessity. Retention periods may therefore differ significantly between categories of information.
10.3 Account Information
Account-related information may be retained for as long as reasonably necessary to:
- maintain your Account;
- authenticate future access;
- provide the Services;
- comply with Applicable Law;
- investigate fraud or abuse;
- maintain security;
- respond to lawful requests;
- resolve disputes;
enforce our Terms of Service. Following account closure or deletion, certain account information may be retained where continued retention is reasonably necessary for legal, security, fraud prevention, or legitimate operational purposes.
10.4 Profile Information
Profile information may be retained while your Account remains active. Following account deletion or profile removal:
- publicly visible Profile information will generally no longer be displayed through the Services;
- certain records may remain in backups, archives, security logs, or internal systems for limited periods where reasonably necessary;
information may be retained where required by Applicable Law or to protect the rights of Dinner Date, users, or third parties. Where reasonably practicable, obsolete Profile information will be removed or anonymized in accordance with our retention procedures.
10.5 User Content
User Content may be retained for purposes including:
- operating the Services;
- maintaining conversation history;
- resolving disputes;
- investigating reports;
- enforcing platform policies;
- complying with Applicable Law;
protecting users. Deletion of an Account does not necessarily require immediate removal of all User Content where continued retention is reasonably necessary for these purposes. Where appropriate, User Content may instead be anonymized or dissociated from a deleted Account.
10.6 Messages and Communications
Messages exchanged through the Services may be retained for a limited period to:
- deliver communications;
- support user access;
- investigate abuse;
- respond to reports;
- detect fraud;
- enforce Community Guidelines;
- comply with Applicable Law;
resolve disputes. Dinner Date may establish different retention periods for different categories of communications depending on operational, legal, and safety considerations. Deleted messages may continue to exist temporarily within backup systems until those backups expire in accordance with normal operational processes.
10.7 Safety Reports and Moderation Records
Information relating to trust and safety may require longer retention than ordinary user activity because it may be necessary to:
- investigate abuse;
- identify repeat offenders;
- protect users;
- preserve evidence;
- respond to legal requests;
- enforce Community Guidelines;
comply with legal obligations. Examples include:
- user reports;
- moderation decisions;
- appeals;
- account restrictions;
- safety investigations;
evidence voluntarily submitted by users. Where appropriate, certain moderation records may continue to be retained after an Account has been deleted.
10.8 Attendance and Geofence Verification Records
Dinner Date may retain records relating to attendance confirmation and geofence verification where reasonably necessary to:
- support trust and safety;
- investigate disputes;
- enforce platform policies;
- prevent fraud;
- maintain platform integrity;
comply with Applicable Law. Attendance records generally relate to confirmation that a user attended an Approved Venue rather than creating a continuous record of the user’s movements. Dinner Date seeks to minimize retention of precise location-related information where it is no longer required for the relevant purpose.
10.9 Payment Records
Payment-related information may be retained as reasonably necessary to:
- comply with financial regulations;
- maintain accounting records;
- satisfy tax obligations;
- process refunds;
- investigate disputes;
- detect fraud;
- support audits;
comply with Applicable Law. Certain payment records may be retained for periods required by financial, taxation, or consumer protection legislation. Dinner Date does not intentionally retain complete payment card numbers or payment security codes where payment processing is performed by authorized PCI-compliant payment providers.
10.10 Customer Support Records
Communications with customer support may be retained for purposes including:
- responding to inquiries;
- improving customer service;
- training;
- quality assurance;
- investigating complaints;
- resolving disputes;
complying with legal obligations. Retention periods may vary depending on the nature of the support request.
10.11 Technical Logs
Technical logs may be retained to:
- monitor system health;
- investigate incidents;
- diagnose technical issues;
- improve reliability;
- detect security threats;
maintain operational continuity. Examples include:
- authentication logs;
- server logs;
- application diagnostics;
- error reports;
- system performance records;
audit logs. Technical logs are generally retained only for as long as reasonably necessary for operational and security purposes.
10.12 Security Records
Information relating to cybersecurity and fraud prevention may be retained where reasonably necessary to:
- investigate security incidents;
- prevent repeated attacks;
- identify compromised Accounts;
- detect fraudulent activity;
- protect platform infrastructure;
comply with Applicable Law. Security-related records may be retained for longer than ordinary operational records where justified by legitimate security requirements.
10.13 Legal Holds
Dinner Date may suspend ordinary deletion procedures where information is subject to:
- litigation;
- anticipated litigation;
- regulatory investigations;
- law enforcement requests;
- internal investigations;
- legal preservation requirements;
contractual obligations. Information subject to a legal hold may be retained until the relevant matter has been resolved or until continued retention is no longer reasonably necessary.
10.14 Account Deletion
Users may request deletion of their Account in accordance with available platform functionality and Applicable Law. Deletion requests are processed in accordance with the Account Deletion and Data Retention Policy. Account deletion generally results in the removal or anonymization of Personal Information that is no longer required. However, deletion does not necessarily require immediate destruction of all information where continued retention is reasonably necessary for:
- legal compliance;
- fraud prevention;
- security;
- dispute resolution;
- financial reporting;
- enforcement of platform policies;
- protection of users.
10.15 Backup Systems
To support business continuity, disaster recovery, and operational resilience, Dinner Date may maintain encrypted backup copies of certain information. Backup systems are not intended to create independently accessible user records. Information contained within backups is generally removed through normal backup lifecycle processes rather than immediate modification of historical backup media.
10.16 Aggregated and Anonymized Information
Dinner Date may retain aggregated, anonymized, or de-identified information after identifiable Personal Information has been removed. Where information has been irreversibly anonymized so that it can no longer reasonably identify an individual, it is generally no longer treated as Personal Information under this Privacy Policy. Such information may be used for purposes including:
- analytics;
- research;
- product development;
- statistical reporting;
- operational planning;
- business intelligence.
10.17 Storage Limitation
Dinner Date seeks to periodically review stored information to determine whether continued retention remains reasonably necessary. Where information is no longer required for its original purpose and no legal, contractual, or operational justification exists for continued retention, we seek to securely delete, anonymize, or otherwise de-identify the information.
10.18 Future Changes to Retention Practices
As Dinner Date evolves, new platform features, legal obligations, operational requirements, or regulatory developments may require adjustments to our retention practices. Where changes materially affect how Personal Information is retained, we will update this Privacy Policy and, where required by Applicable Law, provide additional notice.
10.19 Additional Information
Further information regarding:
- account deletion procedures;
- retention schedules;
- deletion requests;
- legal holds;
- safety-related retention;
- backup handling;
- operational retention practices;
is provided in the Account Deletion and Data Retention Policy. That policy supplements this Privacy Policy and should be read together with this section.
10.20 Our Retention Commitment
Dinner Date seeks to retain Personal Information responsibly by:
- limiting retention to legitimate purposes;
- protecting retained information through appropriate safeguards;
- reviewing retention practices periodically;
- supporting user privacy rights;
- complying with Applicable Law;
minimizing unnecessary long-term storage of Personal Information. Retention practices are designed to balance user privacy, operational requirements, trust and safety, legal compliance, and the reliable operation of the Services.
11. Security Measures
Dinner Date recognizes that users entrust us with Personal Information in connection with dating, communications, dining activities, payments, and safety-related features. Protecting that information is an important responsibility. Accordingly, Dinner Date seeks to implement and maintain administrative, technical, physical, and organizational safeguards that are designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, misuse, or other unlawful processing. The safeguards described in this section are intended to support the confidentiality, integrity, availability, and resilience of the Services. No security program, technology, network, device, or transmission method can guarantee absolute security. While Dinner Date strives to maintain appropriate safeguards, users should understand that no online service can eliminate every security risk.
11.1 Our Security Principles
Dinner Date’s information security program is guided by the following principles:
- privacy by design;
- security by design;
- least-privilege access;
- defense in depth;
- data minimization;
- secure system administration;
- continuous improvement;
- risk-based decision making;
- accountability;
compliance with Applicable Law. These principles influence the design, development, operation, and ongoing maintenance of the Services.
11.2 Administrative Safeguards
Dinner Date seeks to implement administrative controls appropriate to the nature of the Services. These may include:
- documented internal security policies;
- role-based responsibilities;
- employee and contractor confidentiality obligations;
- security awareness activities;
- internal access management procedures;
- vendor management procedures;
- incident response procedures;
- business continuity planning;
- disaster recovery planning;
- periodic policy reviews;
governance processes designed to support information security. Access to Personal Information is intended to be limited to individuals who require such access to perform authorized duties.
11.3 Technical Safeguards
Dinner Date seeks to implement technical safeguards designed to reduce security risks. Depending on the Services and technical environment, these safeguards may include:
- encryption of data in transit using industry-standard protocols;
- encryption of sensitive information at rest where appropriate;
- secure authentication mechanisms;
- session management controls;
- role-based access controls;
- multi-factor authentication for administrative access where appropriate;
- logging and monitoring of security-relevant events;
- network security controls;
- application security controls;
- secure backup procedures;
- infrastructure monitoring;
- malware protection;
- vulnerability management processes;
software update procedures. Specific technical controls may evolve over time as technology, threats, and operational requirements change.
11.4 Organizational Safeguards
Dinner Date seeks to maintain organizational practices intended to support responsible handling of Personal Information. Examples include:
- limiting access based on business need;
- maintaining confidentiality obligations;
- restricting administrative privileges;
- separating operational responsibilities where appropriate;
- reviewing access permissions periodically;
- maintaining internal approval processes for sensitive operations;
documenting security-related responsibilities. These organizational controls are intended to reduce the risk of unauthorized processing.
11.5 Secure Development Practices
Dinner Date seeks to incorporate security considerations throughout the software development lifecycle. Depending on the Services, this may include:
- secure design practices;
- code review processes;
- dependency management;
- vulnerability remediation;
- security testing;
- configuration management;
- environment separation;
- change management;
- release management;
post-deployment monitoring. Security considerations are intended to form part of ongoing product development rather than being limited to production deployment.
11.6 Access Controls
Access to Personal Information is intended to be restricted to authorized personnel who require access for legitimate operational purposes. Access controls may include:
- individual user accounts;
- authentication requirements;
- authorization controls;
- role-based permissions;
- least-privilege principles;
- administrative approval processes;
- audit logging;
periodic access reviews. Access permissions may be modified or revoked whenever operational or security requirements change.
11.7 Authentication and Account Security
Dinner Date seeks to protect user Accounts through appropriate authentication mechanisms. Depending on available platform features, this may include:
- telephone or email verification;
- secure credential management;
- authentication tokens;
- session expiration;
- account recovery procedures;
- login monitoring;
- suspicious activity detection;
account protection measures. Users are responsible for maintaining the confidentiality of their authentication credentials and should not share account access with others.
11.8 Payment Security
Dinner Date seeks to minimize direct handling of payment credentials. Where payment functionality is available:
- payment processing is generally performed by authorized payment service providers;
- Dinner Date does not intentionally store complete payment card numbers or card security codes processed by PCI-compliant providers;
- payment transactions may be subject to fraud detection measures;
payment providers maintain their own security controls and regulatory obligations. Additional information is available in the Payment Terms and Refund and Deposit Policy.
11.9 Infrastructure Security
Dinner Date seeks to maintain infrastructure appropriate to the operation of the Services. Depending on the technical environment, infrastructure protections may include:
- secure hosting environments;
- network segmentation where appropriate;
- encrypted communications;
- redundancy measures;
- monitoring systems;
- disaster recovery capabilities;
- backup systems;
- security logging;
infrastructure maintenance. Infrastructure architecture may evolve as the Services develop.
11.10 Vendor Security
Dinner Date works with third-party service providers to support operation of the Services. Where reasonably appropriate, we seek to evaluate providers based on factors including:
- security practices;
- contractual obligations;
- privacy commitments;
- operational reliability;
- regulatory compliance where applicable;
ability to protect Personal Information. Providers are expected to process Personal Information only in accordance with applicable agreements and Applicable Law.
11.11 Monitoring and Threat Detection
Dinner Date seeks to monitor the security of the Services to identify and respond to potential threats. Monitoring activities may include:
- authentication monitoring;
- anomaly detection;
- fraud detection;
- infrastructure monitoring;
- performance monitoring;
- security logging;
- abuse detection;
- automated alerting;
operational diagnostics. Monitoring is intended to protect users, maintain platform integrity, and improve operational resilience.
11.12 Security Incident Response
Despite appropriate safeguards, security incidents may still occur. Dinner Date seeks to maintain procedures designed to:
- identify potential incidents;
- investigate reported events;
- contain security issues;
- reduce operational impact;
- restore affected systems;
- preserve relevant evidence;
- document incident response activities;
comply with legal notification obligations where applicable. Where required by Applicable Law, affected individuals and competent authorities may be notified of certain security incidents.
11.13 Data Integrity
Dinner Date seeks to protect Personal Information against unauthorized alteration or corruption. Measures supporting data integrity may include:
- validation procedures;
- audit logging;
- version control;
- backup systems;
- access restrictions;
- integrity monitoring;
operational controls. Maintaining accurate and reliable information supports both user experience and platform security.
11.14 Data Availability
Security includes maintaining the availability of the Services. Dinner Date seeks to implement measures intended to support:
- operational continuity;
- backup systems;
- disaster recovery;
- fault tolerance where appropriate;
- infrastructure resilience;
service restoration procedures. Unexpected outages, technical failures, or external events may nevertheless affect availability.
11.15 User Responsibilities
Users also play an important role in protecting Personal Information. Users should:
- maintain the confidentiality of login credentials;
- use strong and unique passwords where applicable;
- secure their devices;
- promptly install operating system and application updates;
- avoid sharing verification codes;
- report suspected unauthorized access;
- review account activity regularly;
exercise caution when communicating with other users. Dinner Date cannot protect information that users voluntarily disclose publicly or share directly with others outside the intended functionality of the Services.
11.16 Security of Communications
Dinner Date seeks to protect communications transmitted through the Services using appropriate technical safeguards. However:
- electronic communications may be affected by third-party networks;
- internet communications cannot be guaranteed to be completely secure;
users should avoid transmitting unnecessary sensitive information through messaging features unless reasonably required. Communications may also be subject to lawful access or disclosure where required by Applicable Law.
11.17 Children’s Information
Dinner Date is intended only for eligible adults. Where we become aware that Personal Information relating to an individual who is not eligible to use the Services has been collected contrary to our policies or Applicable Law, we seek to take appropriate steps consistent with our legal obligations. Additional information is provided in the Children’s Privacy section of this Privacy Policy and the Age and Eligibility Policy.
11.18 Security Reviews
Dinner Date seeks to periodically review and improve its security program. Reviews may include:
- internal assessments;
- operational reviews;
- vulnerability remediation;
- software maintenance;
- infrastructure improvements;
- policy updates;
- vendor evaluations;
lessons learned from operational experience. Security practices are expected to evolve over time in response to changing risks and technologies.
11.19 Reporting Security Concerns
Users who believe they have identified a potential security issue relating to the Services are encouraged to notify Dinner Date promptly using the contact information provided in this Privacy Policy. Examples include:
- suspected unauthorized account access;
- phishing attempts;
- security vulnerabilities;
- suspected data exposure;
- fraudulent activity;
impersonation. Reports should include sufficient information to assist with investigation where reasonably possible.
11.20 Our Security Commitment
Dinner Date is committed to protecting Personal Information through a combination of administrative, technical, physical, and organizational safeguards appropriate to the nature of the Services. While no security measures can guarantee absolute protection, we seek to:
- continuously improve our security practices;
- protect users from reasonably foreseeable risks;
- respond appropriately to security incidents;
- support responsible disclosure of security concerns;
- comply with Applicable Law;
integrate privacy and security into the ongoing development and operation of the Services. Protecting Personal Information is an ongoing process that requires continual evaluation, improvement, and adaptation as technology, threats, legal requirements, and the Services evolve.
12. Your Privacy Rights
Dinner Date respects the privacy rights of its users and seeks to provide reasonable mechanisms that allow individuals to exercise rights available under Applicable Law. Privacy rights differ between jurisdictions. Depending on where you reside and the laws that apply to your Personal Information, you may have some or all of the rights described in this section. Nothing in this Privacy Policy is intended to limit any rights that you may have under Applicable Law.
12.1 Right to Access
Subject to Applicable Law, you may have the right to request confirmation regarding whether Dinner Date processes your Personal Information. Where required by Applicable Law, you may also request access to Personal Information relating to you. Depending on the circumstances, this may include information regarding:
- categories of Personal Information processed;
- purposes of processing;
- categories of recipients;
- retention practices;
- sources of Personal Information where not collected directly from you;
- information relating to international transfers;
other information required by Applicable Law. Dinner Date may request information reasonably necessary to verify your identity before responding to an access request.
12.2 Right to Correct or Update Information
You may request correction of inaccurate or incomplete Personal Information where permitted by Applicable Law. Many categories of Profile information can also be updated directly through your Account settings. Maintaining accurate information helps us provide the Services and maintain platform integrity. Dinner Date may request additional information where reasonably necessary to verify requested corrections.
12.3 Right to Delete Personal Information
Depending on Applicable Law, you may request deletion of some or all of your Personal Information. Deletion requests are evaluated in accordance with:
- Applicable Law;
- contractual obligations;
- legal obligations;
- fraud prevention requirements;
- trust and safety requirements;
- financial recordkeeping obligations;
- dispute resolution needs;
legitimate business purposes. Certain information may continue to be retained where continued retention is reasonably necessary for purposes described in this Privacy Policy. Additional information is available in the Account Deletion and Data Retention Policy.
12.4 Right to Restrict Processing
Where recognized by Applicable Law, you may request that Dinner Date temporarily restrict certain processing activities involving your Personal Information. Restriction may be available in circumstances including:
- disputes regarding data accuracy;
- pending verification requests;
- legal claims;
situations recognized by Applicable Law. Where processing is restricted, some Services or platform functionality may become unavailable.
12.5 Right to Object
Depending on Applicable Law, you may have the right to object to certain processing activities. Examples may include processing based upon:
- legitimate interests;
- certain direct marketing activities;
profiling in circumstances recognized by Applicable Law. Dinner Date will evaluate objections in accordance with Applicable Law and may continue processing where lawful grounds exist.
12.6 Right to Withdraw Consent
Where processing is based upon your consent, you may withdraw that consent at any time. Withdrawal of consent does not affect:
- processing performed before consent was withdrawn;
- processing supported by another lawful basis;
processing required by Applicable Law. Withdrawal of consent may affect the availability of certain optional platform features. Examples may include:
- optional location permissions;
- optional safety features;
- certain marketing communications;
- optional notifications;
optional research participation. Device permissions may also be managed through your device operating system.
12.7 Right to Data Portability
Where recognized by Applicable Law, you may request a copy of certain Personal Information in a structured, commonly used, and machine-readable format. Where technically feasible and legally required, you may also request transmission of such information to another organization. The right to data portability applies only in circumstances recognized by Applicable Law.
12.8 Right Not to Be Subject to Certain Automated Decisions
Depending on Applicable Law, you may have rights relating to certain decisions based solely on automated processing where those decisions produce legal or similarly significant effects. Dinner Date may use automated technologies to assist with:
- recommendations;
- fraud detection;
- spam prevention;
- trust and safety operations;
- content prioritization;
operational efficiency. Where Applicable Law provides additional rights relating to automated decision-making, Dinner Date seeks to respect those rights. Additional information is available in the AI Usage Disclosure.
12.9 Right to Lodge a Complaint
If you believe that Dinner Date has processed your Personal Information in violation of Applicable Law, you may have the right to submit a complaint to a competent supervisory authority, privacy regulator, or other authority responsible for enforcing applicable privacy legislation. Where appropriate, we encourage users to contact Dinner Date first so that we have an opportunity to understand and address concerns directly. Nothing in this Privacy Policy limits any rights you may have to contact an appropriate regulatory authority.
12.10 Right to Non-Discrimination
Where Applicable Law prohibits discrimination for exercising privacy rights, Dinner Date will not discriminate against individuals for exercising those rights. However, exercising certain rights may affect our ability to provide particular Services where Personal Information is reasonably necessary for those Services to function. Examples include:
- account authentication;
- messaging;
- payment processing;
- dining invitations;
- safety features;
- reservation functionality.
12.11 Right to Know
Depending on Applicable Law, you may have the right to request additional information regarding our processing activities. This may include information concerning:
- categories of Personal Information collected;
- purposes of processing;
- categories of recipients;
- categories of third parties receiving information;
- retention practices;
- international transfers;
- automated processing;
other information required by Applicable Law. Relevant information is also provided throughout this Privacy Policy.
12.12 Right to Opt Out of Certain Processing
Depending on Applicable Law, you may have the right to opt out of certain processing activities. Examples may include:
- direct marketing communications;
- certain analytics technologies where consent is required;
- certain targeted advertising activities where applicable;
optional processing activities based upon consent. Where Dinner Date introduces new processing activities requiring additional choices, appropriate controls will be provided where required by Applicable Law.
12.13 Exercising Your Rights
Requests relating to Personal Information may generally be submitted through:
- account settings where available;
- customer support;
- privacy contact channels identified in this Privacy Policy;
other methods made available by Dinner Date. To protect users, Dinner Date may require information reasonably necessary to verify the identity of the requesting individual before processing a request. Where permitted by Applicable Law, requests submitted by authorized representatives may require additional verification.
12.14 Verification of Requests
Before fulfilling certain requests, Dinner Date may request additional information reasonably necessary to verify:
- identity;
- authority to act on behalf of another individual;
- ownership of an Account;
authenticity of the request. Verification procedures are intended to protect users from unauthorized disclosure or alteration of Personal Information. If verification cannot reasonably be completed, Dinner Date may decline the request to the extent permitted by Applicable Law.
12.15 Response Time
Dinner Date seeks to respond to privacy requests within the time periods required by Applicable Law. Response times may vary depending upon:
- the complexity of the request;
- the volume of requests received;
- verification requirements;
applicable legal obligations. Where permitted by Applicable Law, response periods may be extended if reasonably necessary, and users will be informed where required.
12.16 Limitations
Privacy rights are not absolute. Applicable Law may permit or require Dinner Date to decline, limit, or defer certain requests in circumstances including:
- legal obligations;
- fraud prevention;
- security investigations;
- protection of other individuals;
- protection of confidential information;
- intellectual property;
- legal privilege;
- public safety;
- ongoing litigation;
regulatory investigations. Where required by Applicable Law, Dinner Date will explain the basis for declining a request unless prohibited by law.
12.17 Authorized Representatives
Where recognized by Applicable Law, users may authorize another person to submit certain privacy requests on their behalf. Dinner Date may require documentation reasonably necessary to verify:
- the authority of the representative;
- the identity of the requesting individual;
the authenticity of the request. Additional verification may be required before disclosing Personal Information.
12.18 No Fee for Ordinary Requests
Dinner Date generally does not charge a fee for reasonable privacy requests. However, where permitted by Applicable Law, a reasonable administrative fee may be charged or a request may be declined if it is:
- manifestly unfounded;
- repetitive;
- excessive;
- abusive;
otherwise permitted to be declined under Applicable Law. Any applicable fee will be communicated before processing the request where required by law.
12.19 Our Commitment to Privacy Rights
Dinner Date seeks to respect privacy rights through:
- transparency;
- fairness;
- accountability;
- accessible request procedures;
- identity verification safeguards;
- timely responses;
- lawful processing;
ongoing review of privacy practices. As privacy laws evolve, Dinner Date may update its procedures and this Privacy Policy to reflect new legal requirements and industry best practices.
13. Children’s Privacy
Dinner Date is designed exclusively for adults who satisfy the minimum eligibility requirements established in our Terms of Service and Age and Eligibility Policy. Protecting children and preventing underage access to the Services are important components of our trust and safety program. The Services are not directed toward children, are not intended for use by children, and are not designed to attract individuals who do not satisfy the minimum age requirements applicable to the Services.
13.1 Adults-Only Platform
Dinner Date is an adults-only platform. Only individuals who satisfy the minimum age requirements established by:
- our Terms of Service;
the Age and Eligibility Policy; and Applicable Law may create an Account or use the Services. Individuals who do not satisfy these requirements must not:
- register for an Account;
- create a Profile;
- upload content;
- communicate with other users;
- arrange dining experiences;
- access restricted platform functionality.
13.2 No Intentional Collection of Children’s Personal Information
Dinner Date does not knowingly solicit, collect, process, or maintain Personal Information from individuals who are not eligible to use the Services. Our Services are designed with the expectation that users are eligible adults. We do not intentionally market the Services to children or encourage children to submit Personal Information.
13.3 Age Verification Measures
Dinner Date may implement measures intended to reduce the likelihood of underage access. Depending on available platform functionality, these measures may include:
- date of birth collection;
- age confirmation;
- telephone verification;
- email verification;
- identity verification where available;
- fraud detection systems;
- moderation reviews;
- user reporting mechanisms;
additional verification where appropriate. These measures are intended to improve platform integrity but do not guarantee that every user accurately represents their age.
13.4 If We Become Aware of an Underage Account
If Dinner Date becomes aware, or has reasonable grounds to believe, that an individual using the Services does not satisfy the applicable minimum age requirements, we may take appropriate action consistent with Applicable Law and our platform policies. Depending on the circumstances, this may include:
- requesting additional age verification;
- restricting Account functionality;
- temporarily suspending the Account;
- permanently terminating the Account;
- removing Profile information;
- removing User Content;
- preserving information where legally required;
notifying competent authorities where required by Applicable Law. The specific action taken will depend upon the circumstances of the case, applicable legal requirements, and the need to protect users and the integrity of the Services.
13.5 Removal of Children’s Personal Information
Where Dinner Date determines that Personal Information relating to an ineligible child has been collected contrary to this Privacy Policy or Applicable Law, we seek to take appropriate steps consistent with our legal obligations. Depending on the circumstances, this may include:
- deleting Personal Information;
- anonymizing information where appropriate;
- restricting further processing;
- preserving limited information where required by law;
documenting actions taken as part of trust and safety procedures. Deletion may not occur immediately where continued retention is reasonably necessary to:
- comply with Applicable Law;
- preserve evidence;
- investigate abuse;
- respond to legal requests;
- protect other users;
- satisfy regulatory obligations.
13.6 Reports of Underage Users
Dinner Date encourages users to report Accounts that appear to belong to individuals who do not satisfy the platform’s minimum age requirements. Reports may be submitted through available reporting features or customer support channels. Reports are reviewed in accordance with our:
- Reporting and Enforcement Policy;
- Content Moderation Policy;
Age and Eligibility Policy. Submitting a report does not guarantee that an Account will be removed. Each report is evaluated based on available information and Applicable Law.
13.7 Misrepresentation of Age
Providing false information regarding age or eligibility may constitute a violation of the Terms of Service. Where Dinner Date determines that a user intentionally misrepresented their age, we may take appropriate enforcement action, including:
- requesting additional verification;
- restricting Account functionality;
- suspending the Account;
- permanently terminating the Account;
- removing User Content;
preserving relevant records where appropriate. Enforcement decisions are made in accordance with our platform policies and applicable legal obligations.
13.8 Parents, Guardians, and Legal Representatives
If a parent, guardian, or legal representative believes that an individual who is not eligible to use the Services has provided Personal Information to Dinner Date, they are encouraged to contact us using the contact information provided in this Privacy Policy. Upon receiving a sufficiently detailed request, Dinner Date may:
- investigate the matter;
- request additional information reasonably necessary to verify the request;
- take appropriate action consistent with Applicable Law;
respond in accordance with applicable legal obligations. Verification procedures are intended to protect the privacy and security of all individuals.
13.9 Child Protection and Safety
Dinner Date maintains a zero-tolerance approach toward content or conduct that exploits, endangers, or sexualizes children. Information relating to suspected child exploitation or child sexual abuse material (“CSAM”) is handled in accordance with our:
- CSAM Policy;
- Content Moderation Policy;
- Reporting and Enforcement Policy;
- Terms of Service;
Applicable Law. Dinner Date may preserve relevant information, restrict access, remove content, terminate Accounts, and cooperate with competent authorities where legally required or otherwise permitted by Applicable Law.
13.10 International Age Requirements
Minimum age requirements may differ between jurisdictions. Where Applicable Law establishes a higher minimum age than Dinner Date’s general eligibility requirements, users must satisfy the higher applicable age requirement. Users are responsible for ensuring that their use of the Services complies with Applicable Law in their jurisdiction.
13.11 Educational Institutions
Dinner Date is not intended for use by:
- primary schools;
- secondary schools;
- children’s organizations;
- youth clubs;
organizations primarily serving minors. The Services are designed exclusively for eligible adult users.
13.12 Marketing to Children
Dinner Date does not intentionally direct advertising or marketing activities toward children. Marketing activities are intended for eligible adults who may lawfully use the Services. If Dinner Date becomes aware that marketing communications have been directed to an ineligible individual due to inaccurate information, we seek to take reasonable steps to correct the issue.
13.13 Changes to Children’s Privacy Practices
As legal requirements, platform functionality, or industry standards evolve, Dinner Date may update its practices relating to children’s privacy. Material changes will be reflected through updates to this Privacy Policy and, where required by Applicable Law, through additional notices.
13.14 Relationship to Other Policies
This section should be read together with:
- Terms of Service;
- Age and Eligibility Policy;
- Community Guidelines;
- Safety Guidelines;
- Content Moderation Policy;
- CSAM Policy;
Reporting and Enforcement Policy. Where those documents address age verification, account eligibility, moderation, or child protection in greater detail, they supplement this Privacy Policy.
13.15 Our Commitment to Child Protection
Dinner Date is committed to maintaining an adults-only platform and supporting the protection of children. Accordingly, we seek to:
- discourage underage access;
- minimize the collection of Personal Information relating to children;
- investigate credible reports of underage Accounts;
- take appropriate enforcement action where warranted;
- comply with Applicable Law;
- cooperate with competent authorities where legally required;
continuously improve age assurance and trust and safety practices as the Services evolve. Protecting children is a shared responsibility involving users, parents or guardians, platform operators, technology providers, and public authorities.
14. Third-Party Services
Dinner Date relies on a variety of carefully selected third-party products, technologies, infrastructure providers, and professional service providers to support the operation, security, reliability, and functionality of the Services. These third parties may process Personal Information on our behalf or, in certain circumstances, independently of Dinner Date. This section explains the role of third-party services, how they may process information, and the responsibilities that apply when users interact with them.
14.1 Categories of Third-Party Services
Depending on the Services you use, Dinner Date may utilize third-party providers that support functions including:
- cloud infrastructure;
- application hosting;
- content delivery;
- authentication;
- identity verification;
- payment processing;
- fraud prevention;
- customer support;
- analytics;
- crash reporting;
- monitoring;
- mapping;
- geolocation services;
- push notifications;
- email delivery;
- SMS communications;
- artificial intelligence services;
- restaurant reservation systems;
- cybersecurity services;
- backup and disaster recovery;
- legal compliance;
auditing. The specific providers used may change over time as the Services evolve.
14.2 Service Providers Acting on Our Behalf
Many third-party providers act solely on behalf of Dinner Date. These providers may receive access to Personal Information only to the extent reasonably necessary to perform contracted services. Examples include providers supporting:
- infrastructure;
- hosting;
- payments;
- customer support;
- communications;
- security;
- analytics;
- monitoring;
software development. Dinner Date seeks to require such providers to process Personal Information only in accordance with:
- applicable contracts;
- confidentiality obligations;
- Applicable Law;
- appropriate security requirements.
14.3 Independent Third-Party Services
Certain third-party organizations operate independently of Dinner Date. Examples may include:
- payment providers;
- restaurant partners;
- identity verification providers;
- mapping providers;
- mobile platform operators;
- internet service providers;
telecommunications providers. Where a third party independently determines the purposes and means of processing Personal Information, that organization may act as an independent controller or equivalent legal entity under Applicable Law. Its processing activities are governed by its own privacy documentation rather than this Privacy Policy.
14.4 Payment Providers
Payment transactions are generally processed through authorized third-party payment service providers. These providers may collect and process information necessary to:
- authorize payments;
- process deposits;
- detect fraud;
- comply with financial regulations;
- process refunds;
- manage chargebacks;
satisfy payment network requirements. Dinner Date generally receives transaction-related information necessary to operate the Services but does not intentionally receive complete payment card numbers or payment security codes processed directly by PCI-compliant payment providers. Users should review the applicable privacy documentation of payment providers for additional information regarding their independent processing activities.
14.5 Restaurant Partners
Dinner Date may interact with participating restaurant partners to facilitate dining experiences. Where reasonably necessary, limited Personal Information may be shared to support:
- reservations;
- attendance;
- booking confirmations;
- dining preferences voluntarily provided by users;
- reservation changes;
operational coordination. Restaurant partners remain responsible for any Personal Information they collect independently from users during visits to their premises. For example, a restaurant may independently collect payment information, loyalty program information, surveillance footage, or reservation information through its own systems. Such processing is governed by the restaurant’s own privacy practices.
14.6 Authentication and Identity Verification Providers
Dinner Date may utilize third-party providers to assist with:
- telephone verification;
- email verification;
- identity verification;
- fraud prevention;
- account integrity;
security monitoring. Verification providers process only the information reasonably necessary to perform their contracted services. Depending on the provider and jurisdiction, some verification activities may also be subject to the provider’s own legal obligations.
14.7 Mapping and Location Services
Certain location-based functionality relies upon third-party mapping, geolocation, or navigation technologies. These services may assist with:
- displaying Approved Venues;
- map visualization;
- routing;
- location search;
- address lookup;
geofence functionality. Location information shared with such providers is limited to what is reasonably necessary for the relevant feature. Additional information regarding location processing is available in the Location and Geofence Policy.
14.8 Communications Providers
Dinner Date may use third-party providers to deliver communications including:
- SMS messages;
- email;
- push notifications;
- authentication codes;
- customer support communications;
operational alerts. These providers process Personal Information only as reasonably necessary to transmit communications requested or authorized by Dinner Date.
14.9 Analytics and Performance Providers
Dinner Date may use analytics and application performance providers to better understand how the Services operate. These providers may assist with:
- application performance monitoring;
- crash reporting;
- diagnostic analysis;
- feature usage;
- service reliability;
- technical troubleshooting;
operational reporting. Where reasonably practicable, aggregated, anonymized, or de-identified information may be used for analytics purposes.
14.10 Artificial Intelligence Providers
Dinner Date may use third-party technologies supporting Artificial Intelligence or machine learning functionality. Depending on platform features, these services may assist with:
- recommendation systems;
- fraud detection;
- spam prevention;
- moderation assistance;
- language processing;
- customer support;
operational efficiency. The use of Artificial Intelligence is further described in the AI Usage Disclosure. Dinner Date seeks to ensure that third-party AI providers process Personal Information only in accordance with applicable contractual and legal obligations.
14.11 Cloud Infrastructure Providers
Dinner Date may use third-party cloud infrastructure providers to support:
- application hosting;
- database services;
- storage;
- networking;
- backup;
- disaster recovery;
- monitoring;
operational resilience. Cloud providers may process Personal Information solely for purposes reasonably necessary to provide contracted infrastructure services.
14.12 Mobile Platform Providers
Users may access Dinner Date through mobile application marketplaces and operating systems operated by independent organizations. Examples include application stores, operating systems, and device manufacturers. These organizations may independently collect information relating to:
- application downloads;
- application updates;
- device identifiers;
- operating system diagnostics;
- purchase records;
platform analytics. Such processing is governed by the privacy documentation of the relevant platform operator rather than this Privacy Policy.
14.13 Links to External Websites
The Services may contain links to external websites, restaurant websites, reservation systems, promotional content, or other third-party resources. Dinner Date does not control the privacy practices of those external services. Users are encouraged to review the privacy documentation of any third-party website before providing Personal Information. The inclusion of a link does not constitute an endorsement of that third party or its privacy practices.
14.14 Third-Party Software Development Kits (SDKs)
The Services may incorporate third-party software development kits (“SDKs”) or application programming interfaces (“APIs”) that provide technical functionality. Examples may include technologies supporting:
- authentication;
- notifications;
- analytics;
- payments;
- mapping;
- communications;
- fraud prevention;
security. Dinner Date seeks to evaluate SDKs before integration and to limit their access to Personal Information to what is reasonably necessary for their intended purpose.
14.15 Changes to Third-Party Providers
Dinner Date may change, replace, add, or discontinue third-party providers as business, technical, operational, or legal requirements evolve. Because providers may change over time, this Privacy Policy describes categories of providers rather than maintaining a complete public list of every individual vendor. Material changes affecting the processing of Personal Information will be reflected through updates to this Privacy Policy where required by Applicable Law.
14.16 International Processing by Third Parties
Some third-party providers may process Personal Information outside the country in which it was originally collected. International processing is subject to the safeguards described in the International Data Transfers section of this Privacy Policy. Where required, Dinner Date seeks to implement appropriate contractual, technical, and organizational safeguards before authorizing such processing.
14.17 Third-Party Security
Dinner Date seeks to work with providers that maintain security measures appropriate to the nature of the services they perform. However, each independent third party remains responsible for maintaining the security of the systems under its own control. Dinner Date cannot guarantee the security practices of organizations that operate independently from our Services.
14.18 Third-Party Privacy Policies
Where third parties independently process Personal Information, their privacy practices are governed by their own policies, notices, and legal obligations. Users are encouraged to review applicable third-party privacy documentation before using third-party services connected with the Dinner Date platform.
14.19 Our Third-Party Governance Principles
Dinner Date seeks to manage relationships with third-party providers in accordance with the following principles:
- use providers only where reasonably necessary;
- conduct appropriate vendor due diligence;
- minimize information shared with providers;
- implement contractual safeguards where appropriate;
- monitor provider performance where reasonably practicable;
- review third-party relationships periodically;
- support transparency regarding third-party processing;
comply with Applicable Law. Third-party providers play an important role in enabling the Services, but Dinner Date seeks to ensure that Personal Information shared with them remains subject to appropriate protections.
15. Changes to this Privacy Policy
Dinner Date may update, revise, supplement, or replace this Privacy Policy from time to time to reflect changes in our Services, technology, legal obligations, operational practices, security measures, or other business requirements. We are committed to providing reasonable transparency regarding material changes that affect how Personal Information is collected, used, disclosed, retained, or otherwise processed. This section explains how updates to this Privacy Policy are communicated and when they become effective.
15.1 Why This Privacy Policy May Change
This Privacy Policy may be updated for reasons including, but not limited to:
- introduction of new platform features;
- changes to the Services;
- changes in technology;
- improvements to trust and safety measures;
- implementation of new security practices;
- operational improvements;
- changes in payment functionality;
- changes relating to restaurant partnerships;
- changes to applicable laws or regulations;
- regulatory guidance;
- court decisions;
- changes to industry standards;
- corporate restructuring;
- clarification of existing practices;
- correction of drafting errors;
improvements to readability. Not every update will materially affect your privacy rights or the way your Personal Information is processed.
15.2 Types of Changes
Changes to this Privacy Policy generally fall into two categories: Administrative or Minor Changes These may include updates such as:
- correcting typographical errors;
- improving wording;
- reorganizing sections;
- updating references to related policies;
- improving readability;
- clarifying existing practices;
updating contact information. Administrative changes generally do not materially affect how Personal Information is processed.
Material Changes Material changes are changes that may significantly affect the processing of Personal Information or users’ privacy rights. Examples may include:
- collecting new categories of Personal Information;
- introducing new purposes for processing;
- changing how Personal Information is shared;
- introducing significant new platform features;
- expanding international processing activities;
- implementing new categories of automated processing;
- changing retention practices in a material way;
modifying users’ privacy rights where permitted by Applicable Law. Material changes may require additional notice or other actions depending on Applicable Law.
15.3 Notification of Changes
Where reasonably appropriate, Dinner Date may notify users of updates to this Privacy Policy using one or more communication methods. Depending on the circumstances, notifications may be provided through:
- in-application notices;
- account notifications;
- email;
- push notifications;
- updates published on our website;
- login notices;
other reasonable communication channels. The method of notification may vary depending on the significance of the changes and applicable legal requirements.
15.4 Effective Date
Each version of this Privacy Policy identifies: the effective date; and the date on which the document was last updated. Unless otherwise stated, revisions become effective on the effective date identified at the beginning of the Privacy Policy. Where Applicable Law requires a different implementation process, Dinner Date will comply with those legal requirements.
15.5 Consent for New Processing Activities
Some updates may involve new processing activities that require consent under Applicable Law. Where consent is legally required, Dinner Date will seek that consent before beginning the relevant processing activity. Examples may include:
- optional features requiring additional permissions;
- new categories of marketing communications where consent is required;
- new optional location-based functionality;
processing activities requiring explicit consent under Applicable Law. If consent is not provided, certain optional features may not be available.
15.6 Continued Use of the Services
Following publication of an updated Privacy Policy, your continued use of the Services may indicate your acknowledgement of the revised Privacy Policy to the extent permitted by Applicable Law. However, where Applicable Law requires additional consent, agreement, or another legal basis before new processing activities may begin, Dinner Date will comply with those legal requirements before undertaking such processing. Nothing in this section is intended to reduce or limit any rights available to users under Applicable Law.
15.7 Historical Versions
Dinner Date may maintain records of previous versions of this Privacy Policy for purposes including:
- legal compliance;
- auditing;
- dispute resolution;
- regulatory inquiries;
- operational reference;
internal governance. Historical versions may not remain publicly available indefinitely. Where required by Applicable Law, Dinner Date may make previous versions available upon request or through other reasonable means.
15.8 Review of Privacy Practices
Dinner Date periodically reviews its privacy practices to help ensure that this Privacy Policy remains accurate and reflects the operation of the Services. Reviews may consider:
- changes in Applicable Law;
- regulatory guidance;
- technological developments;
- platform functionality;
- trust and safety practices;
- operational experience;
- user feedback;
- security developments;
business requirements. Updates may be made whenever reasonably necessary following these reviews.
15.9 Relationship to Other Policies
Updates to this Privacy Policy may occur independently of updates to other Dinner Date policies. Where changes affect related documents, those documents may also be updated. Related documents may include:
- Terms of Service;
- Community Guidelines;
- Safety Guidelines;
- Content Moderation Policy;
- Reporting and Enforcement Policy;
- CSAM Policy;
- Payment Terms;
- Refund and Deposit Policy;
- Location and Geofence Policy;
- Account Deletion and Data Retention Policy;
- AI Usage Disclosure;
Cookie and Tracking Policy. Users are encouraged to review those documents periodically.
15.10 Questions About Changes
Users who have questions regarding updates to this Privacy Policy may contact Dinner Date using the contact information provided in the Contact Information section of this Privacy Policy. Where required by Applicable Law, Dinner Date will provide additional information regarding material changes upon request.
15.11 Our Commitment to Transparency
Dinner Date seeks to communicate changes to this Privacy Policy in a manner that is:
- transparent;
- understandable;
- proportionate to the significance of the changes;
- consistent with Applicable Law;
respectful of user privacy rights. Our objective is to ensure that users remain informed about how Personal Information is processed as the Services continue to evolve.
16. Contact Information
Dinner Date is committed to maintaining open communication regarding privacy, data protection, trust and safety, and the processing of Personal Information. Users, regulators, business partners, and other authorized parties may contact Dinner Date regarding privacy-related matters using the contact channels published in the most current version of this Privacy Policy and on the official Dinner Date website or application. This section explains the types of inquiries that may be directed to Dinner Date and how those inquiries are handled.
16.1 Privacy Inquiries
Questions relating to this Privacy Policy or the processing of Personal Information may include:
- interpretation of this Privacy Policy;
- collection of Personal Information;
- use of Personal Information;
- disclosure of Personal Information;
- international data transfers;
- data retention;
- user privacy rights;
- account deletion;
- correction requests;
- access requests;
- security concerns;
other privacy-related matters. Users are encouraged to include sufficient information to enable Dinner Date to identify the relevant Account and understand the nature of the request.
16.2 Privacy Contact
Dinner Date will publish a dedicated privacy contact before the public launch of the Services. The published contact information may include one or more of the following:
- privacy email address;
- online privacy request form;
- customer support portal;
- postal mailing address;
other communication methods designated for privacy-related inquiries. The most current contact details published by Dinner Date will supersede any previously published contact information.
16.3 Data Protection Officer or Privacy Representative
Where Applicable Law requires the appointment of a Data Protection Officer (“DPO”), privacy representative, or similar individual or organization, Dinner Date will publish the appropriate contact information. Where Applicable Law does not require such an appointment, privacy-related inquiries may instead be directed through the designated privacy contact identified by Dinner Date.
16.4 Exercising Privacy Rights
Requests relating to privacy rights may include:
- access requests;
- correction requests;
- deletion requests;
- restriction requests;
- objection requests;
- portability requests;
- consent withdrawal;
- complaints regarding processing activities;
other requests recognized by Applicable Law. Dinner Date may request additional information reasonably necessary to verify the identity of the requesting individual before responding. Verification procedures are intended to protect users against unauthorized disclosure of Personal Information.
16.5 Account-Related Requests
Requests relating to user Accounts may include:
- account recovery;
- account deletion;
- profile corrections;
- authentication issues;
- communication preferences;
- safety features;
- payment questions;
moderation appeals. Some account-related requests may be handled through customer support rather than the privacy contact.
16.6 Trust and Safety Reports
Reports concerning user safety, harassment, impersonation, fraud, abusive conduct, or other violations of Dinner Date policies should generally be submitted through the reporting tools available within the Services whenever reasonably practicable. Alternative reporting channels may be made available for users who cannot access in-application reporting tools. Trust and safety reports are handled in accordance with the:
- Reporting and Enforcement Policy;
- Community Guidelines;
- Content Moderation Policy;
- Safety Guidelines;
- CSAM Policy;
- Terms of Service.
16.7 Security Reports
Individuals who believe they have identified a potential security issue affecting the Services are encouraged to notify Dinner Date promptly. Security reports may relate to:
- unauthorized account access;
- suspected data exposure;
- phishing attempts;
- security vulnerabilities;
- fraud;
- compromised accounts;
other cybersecurity concerns. Security reports are reviewed in accordance with Dinner Date’s internal security procedures. Where appropriate, Dinner Date may request additional information necessary to investigate reported issues.
16.8 Law Enforcement and Government Requests
Government agencies, courts, regulators, and law enforcement authorities seeking information from Dinner Date should use the procedures described in the Law Enforcement Request Policy. Dinner Date seeks to evaluate such requests in accordance with:
- Applicable Law;
- user privacy rights;
- due process requirements;
internal review procedures. Additional information is available in the Law Enforcement Request Policy.
16.9 Business and Partnership Inquiries
Organizations interested in:
- restaurant partnerships;
- technology partnerships;
- enterprise services;
- compliance matters;
- business development;
- vendor relationships;
should use the business contact information published by Dinner Date through its official communication channels. Business inquiries are handled separately from privacy requests.
16.10 Response Time
Dinner Date seeks to acknowledge and respond to inquiries within reasonable timeframes consistent with:
- the complexity of the request;
- verification requirements;
- operational workload;
Applicable Law. Certain requests may require additional time where:
- identity verification is necessary;
- multiple departments must participate;
- legal review is required;
- external service providers must be consulted;
Applicable Law permits an extension. Where required by Applicable Law, users will be informed if additional time is necessary.
16.11 Identity Verification
To protect user privacy and prevent unauthorized disclosure of Personal Information, Dinner Date may require verification before responding to certain requests. Verification procedures may include confirmation of:
- account ownership;
- contact information;
- authentication credentials;
- identity documentation where legally appropriate;
authority of an authorized representative. Dinner Date seeks to collect only the information reasonably necessary to complete the verification process.
16.12 Authorized Representatives
Where recognized by Applicable Law, privacy requests may be submitted by an authorized representative acting on behalf of another individual. Dinner Date may request documentation reasonably necessary to verify:
- the representative’s authority;
- the identity of the individual concerned;
the authenticity of the request. Additional verification may be required before Personal Information is disclosed.
16.13 Regulatory Authorities
Where Applicable Law provides the right to contact a supervisory authority or privacy regulator, nothing in this Privacy Policy limits that right. Users may also choose to contact Dinner Date directly before or after contacting a regulator. Dinner Date seeks to cooperate with competent supervisory authorities in accordance with Applicable Law.
16.14 Updating Contact Information
Dinner Date may update contact details from time to time. Current contact information will be published through:
- the Services;
- the official Dinner Date website;
- updated versions of this Privacy Policy;
other official communication channels. Users are encouraged to use the most recently published contact information.
16.15 Official Communications
To reduce the risk of fraud or phishing, users should communicate with Dinner Date only through official communication channels identified by Dinner Date. Dinner Date cannot guarantee the authenticity of communications originating from unofficial sources. Users are encouraged to exercise caution before disclosing Personal Information in response to unsolicited communications claiming to represent Dinner Date.
16.16 Our Commitment to Communication
Dinner Date seeks to communicate with users in a manner that is:
- respectful;
- transparent;
- accessible;
- secure;
- timely;
consistent with Applicable Law. We are committed to maintaining appropriate channels through which users can exercise their privacy rights, report concerns, request assistance, and obtain additional information regarding the processing of Personal Information.
16.17 Information to Be Published Before Public Launch
Before the public release of the Services, Dinner Date will publish current contact information, including, where applicable:
| Contact Type | Information to be Published |
|---|---|
| Privacy Email | Dedicated privacy contact email |
| General Support | Customer support email or support portal |
| Legal Notices | Legal contact email or postal address |
| Business Contact | Partnership and business inquiries |
| Registered Business Address | Registered office (where applicable) |
| Data Protection Officer | Contact details if required by Applicable Law |
| Privacy Request Portal | URL if available |
| Security Contact | Security reporting channel if available |
Dinner Date may update these details from time to time. The most recently published contact information supersedes any previous versions.
Appendix A – Categories of Personal Information This Appendix supplements the Dinner Date Privacy Policy by providing a detailed overview of the categories of Personal Information that may be processed through the Services. The categories described below are intended to improve transparency regarding the types of information processed throughout the lifecycle of the Services. Not every category of information applies to every user. The Personal Information processed depends upon:
- the Services used;
- account settings;
- permissions granted;
- optional features enabled;
- applicable legal requirements;
interactions with the platform. This Appendix should be read together with:
- Sections 3 through 10 of this Privacy Policy;
- Account Deletion and Data Retention Policy;
- Location and Geofence Policy;
- Payment Terms;
- AI Usage Disclosure.
A.1 Identity Information Identity Information helps establish and maintain user identity. Examples may include:
- first name;
- display name;
- date of birth;
- age confirmation;
- verification status;
- identity verification status;
- country of residence;
- language preference;
- profile identifiers;
account identifiers. Purpose of Processing:
- account creation;
- eligibility verification;
- authentication;
- fraud prevention;
- trust and safety.
A.2 Contact Information Contact Information enables communication between Dinner Date and users. Examples include:
- mobile telephone number;
- email address;
- notification preferences;
communication preferences. Purpose of Processing:
- authentication;
- account recovery;
- customer support;
- security notifications;
- operational communications.
A.3 Account Information Information relating to the administration of user Accounts. Examples include:
- account identifier;
- account status;
- registration date;
- verification history;
- account settings;
- language preferences;
- login preferences;
subscription status (if applicable). Purpose of Processing:
- account management;
- authentication;
- operational administration.
A.4 Profile Information Information voluntarily provided for display within the platform. Examples include:
- biography;
- photographs;
- interests;
- hobbies;
- favorite cuisines;
- dining preferences;
- preferred budget range;
- preferred dining style;
- dating intentions;
- languages spoken;
profile badges. Purpose of Processing:
- profile display;
- matching;
- recommendations;
- user interactions.
A.5 Verification Information Information used to verify eligibility or account authenticity. Examples include:
- telephone verification status;
- email verification status;
- identity verification status;
- verification timestamps;
verification tokens. Purpose of Processing:
- fraud prevention;
- account integrity;
- trust and safety.
A.6 Communications Information Information generated through communications using the Services. Examples include:
- messages;
- customer support communications;
- moderation appeals;
- reports;
- survey responses;
platform feedback. Purpose of Processing:
- communication delivery;
- customer support;
- moderation;
- dispute resolution.
A.7 Restaurant and Reservation Information Information relating to dining experiences. Examples include:
- selected restaurant;
- reservation preferences;
- reservation status;
- booking confirmation;
- invitation information;
- attendance confirmation;
cancellation status. Purpose of Processing:
- reservations;
- venue coordination;
- dining experiences;
- trust and safety.
A.8 Payment Information Information relating to financial transactions. Examples include:
- payment status;
- authorization status;
- deposit information;
- refund status;
- billing country;
- transaction identifiers;
currency. Dinner Date generally does not intentionally store complete payment card numbers processed by PCI-compliant payment providers. Purpose of Processing:
- payment processing;
- fraud prevention;
- financial compliance.
A.9 Device Information Technical information relating to the device used to access the Services. Examples include:
- device model;
- operating system;
- application version;
- browser information;
- device language;
- regional settings;
device identifiers where permitted. Purpose of Processing:
- compatibility;
- diagnostics;
- security;
- application performance.
A.10 Technical Information Technical information generated during operation of the Services. Examples include:
- IP address;
- server logs;
- authentication logs;
- error logs;
- crash diagnostics;
- API logs;
security events. Purpose of Processing:
- security;
- diagnostics;
- platform reliability.
A.11 Usage Information Information describing how users interact with the Services. Examples include:
- screens viewed;
- features used;
- searches;
- invitations created;
- invitations accepted;
- application interactions;
session duration. Purpose of Processing:
- analytics;
- product improvement;
- personalization.
A.12 Location Information Location-related information processed by the Services. Examples include:
- approximate location;
- selected city;
- venue location;
- geofence verification events;
attendance confirmation. Dinner Date seeks to minimize the retention of precise location information where no longer required. Purpose of Processing:
- venue discovery;
- attendance verification;
- optional safety features.
A.13 Trust and Safety Information Information supporting platform integrity. Examples include:
- abuse reports;
- moderation decisions;
- appeals;
- account restrictions;
- trust indicators;
- fraud indicators;
investigation records. Purpose of Processing:
- safety;
- moderation;
- fraud prevention.
A.14 Emergency Contact Information Information voluntarily provided for optional safety features. Examples include:
- contact name;
- relationship;
- contact method;
emergency notification status. Purpose of Processing: optional safety functionality.
A.15 Customer Support Information Information relating to support interactions. Examples include:
- support requests;
- correspondence;
- troubleshooting information;
- attachments;
satisfaction surveys. Purpose of Processing:
- customer support;
- service improvement.
A.16 Marketing and Communication Preferences Information relating to communication choices. Examples include:
- notification preferences;
- email preferences;
- marketing preferences;
consent status. Purpose of Processing:
- communication management;
- consent management.
A.17 Analytics Information Information used to evaluate performance of the Services. Examples include:
- feature adoption;
- aggregated usage statistics;
- engagement metrics;
diagnostic analytics. Purpose of Processing:
- product development;
- service optimization.
A.18 Security Information Information supporting cybersecurity. Examples include:
- authentication events;
- login history;
- suspicious activity indicators;
- fraud detection signals;
audit records. Purpose of Processing:
- security;
- fraud prevention;
- incident response.
A.19 Artificial Intelligence Information Where AI-assisted functionality is available, certain information may be processed to support automated systems. Examples include:
- recommendation inputs;
- moderation signals;
- spam detection indicators;
- fraud detection indicators;
customer support routing information. Dinner Date seeks to ensure appropriate human oversight for significant trust and safety decisions. Purpose of Processing:
- AI-assisted platform functionality;
- operational efficiency;
- trust and safety.
A.20 Legal and Compliance Information Information retained to satisfy legal obligations. Examples include:
- legal hold records;
- regulatory correspondence;
- compliance documentation;
- law enforcement request records;
litigation records. Purpose of Processing:
- legal compliance;
- regulatory obligations;
- dispute resolution.
A.21 Aggregated and De-Identified Information Dinner Date may create information that has been aggregated, anonymized, or de-identified. Examples include:
- statistical reporting;
- anonymous analytics;
- operational metrics;
product performance data. Where information has been irreversibly anonymized such that it no longer reasonably identifies an individual, it is generally no longer treated as Personal Information under this Privacy Policy.
A.22 Special Categories of Personal Information Some jurisdictions provide enhanced protections for certain categories of Personal Information. Depending on the Services used and the information voluntarily provided, these categories may include:
- precise location information;
- information relating to sexual orientation;
- dietary restrictions that may reveal health-related information;
- emergency contact information;
other categories recognized as sensitive under Applicable Law. Dinner Date seeks to minimize the collection and processing of such information and processes it only where reasonably necessary, voluntarily provided, or otherwise permitted by Applicable Law.
A.23 Categories We Generally Do Not Intentionally Collect Unless required for a specific feature or by Applicable Law, Dinner Date does not intentionally request or require users to provide:
- passport numbers;
- national identity numbers;
- driver’s licence numbers;
- complete payment card information;
- payment security codes (CVV/CVC);
- banking passwords;
- tax identification numbers;
- medical records;
- genetic information;
- criminal history;
unrelated employment records. If such information is voluntarily submitted through user-generated content or support communications, Dinner Date may process it only to the extent reasonably necessary for the relevant purpose, legal compliance, or the protection of users.
A.24 Data Inventory Principles Dinner Date seeks to maintain a data inventory that is guided by the following principles:
- transparency;
- data minimization;
- purpose limitation;
- proportionality;
- accountability;
- accuracy;
- security;
- privacy by design;
compliance with Applicable Law. This Appendix is intended to provide a comprehensive overview of the categories of Personal Information processed through the Services. It should be read together with the main body of this Privacy Policy and the related Dinner Date legal documentation.
Appendix B – Data Retention Schedule Part 1 – Retention Governance, Core Account Records and Identity Information
B.1 Purpose of this Appendix This Appendix supplements Section 10 (Data Retention) of the Dinner Date Privacy Policy by providing additional transparency regarding the categories of Personal Information processed by Dinner Date and the principles governing their retention, review, anonymization, archival, and deletion. This Appendix is intended to:
- improve transparency regarding data lifecycle management;
- explain the factors that influence retention periods;
- support user understanding of deletion requests;
- demonstrate compliance with Applicable Law;
- support Dinner Date’s trust and safety program;
provide a framework that may evolve as the Services develop. This Appendix should be read together with:
- Privacy Policy;
- Account Deletion and Data Retention Policy;
- Terms of Service;
- Reporting and Enforcement Policy;
- Content Moderation Policy;
- CSAM Policy;
- Law Enforcement Request Policy.
B.2 Retention Philosophy Dinner Date seeks to retain Personal Information only for as long as reasonably necessary to:
- provide the Services;
- fulfil contractual obligations;
- maintain platform integrity;
- protect users;
- investigate abuse;
- comply with Applicable Law;
- satisfy accounting obligations;
- satisfy taxation obligations;
- preserve evidence where appropriate;
- resolve disputes;
- defend legal claims;
improve platform security. Retention is determined by operational necessity rather than a single fixed period applicable to every category of information. Different categories of information may therefore have different retention lifecycles.
B.3 Retention Lifecycle Personal Information generally progresses through one or more lifecycle stages. These stages may include: Active Processing Information actively used to provide the Services. Examples include:
- active Accounts;
- current Profiles;
- ongoing conversations;
- active reservations;
- current payment transactions.
Restricted Processing Information retained but subject to reduced operational use. Examples include:
- suspended Accounts;
- archived conversations;
- completed reservations;
- historical moderation records.
Archived Storage Information retained primarily for:
- legal compliance;
- accounting;
- dispute resolution;
- fraud prevention;
- trust and safety;
disaster recovery. Archived information is generally subject to stricter access controls.
Anonymization Where reasonably practicable, information may be irreversibly anonymized. Once anonymized so that an individual can no longer reasonably be identified, the information is generally no longer treated as Personal Information under this Privacy Policy.
Secure Deletion When information is no longer required and no legal or operational justification exists for continued retention, Dinner Date seeks to securely delete the information in accordance with internal deletion procedures.
B.4 Factors Used to Determine Retention Retention periods are determined by evaluating factors including:
- purpose of collection;
- sensitivity of the information;
- contractual obligations;
- user expectations;
- fraud prevention requirements;
- security requirements;
- trust and safety considerations;
- accounting requirements;
- taxation obligations;
- legal limitation periods;
- regulatory obligations;
- litigation risks;
- technical feasibility;
operational requirements. These factors may result in different retention periods for different information categories.
B.5 Deletion Requests Deletion requests are evaluated individually. Approval of an Account deletion request does not necessarily require immediate deletion of every category of Personal Information. Some information may continue to be retained where reasonably necessary for:
- fraud prevention;
- abuse investigations;
- legal compliance;
- financial reporting;
- trust and safety;
- dispute resolution;
- legal claims;
regulatory investigations. Additional information is provided in the Account Deletion and Data Retention Policy.
B.6 Account Information Description Account Information identifies and administers a user’s Dinner Date Account. Examples include:
- Account identifier;
- registration timestamp;
- Account status;
- Account settings;
- language preferences;
- profile configuration;
notification settings. Primary Purpose
- account administration;
- authentication;
- customer support;
platform operation. Retention Trigger Retention generally begins when an Account is created. End of Active Retention Active retention generally ends when:
- the Account is deleted;
- the Account is permanently terminated;
applicable legal requirements require continued retention. Post-Deletion Handling Following Account deletion, information may:
- be removed from active systems;
- remain temporarily within backups;
- be archived where legally required;
- be retained to prevent fraudulent re-registration;
- be anonymized where appropriate.
B.7 Identity Information Description Identity Information assists Dinner Date in establishing user identity and eligibility. Examples include:
- first name;
- display name;
- age confirmation;
- country;
- language preference;
identity verification status. Primary Purpose
- user identification;
- eligibility verification;
- fraud prevention;
trust and safety. Retention Trigger Collection begins during Account registration. End of Active Retention Identity Information generally remains active while an Account exists. Post-Deletion Handling Following Account deletion:
- publicly visible identity information is removed from user-facing systems where appropriate;
- internal records may continue to be retained where reasonably necessary;
- anonymization may occur where operationally appropriate.
B.8 Contact Information Description Contact Information enables Dinner Date to communicate with users. Examples include:
- telephone number;
- email address;
communication preferences. Primary Purpose
- authentication;
- customer support;
- security alerts;
operational communications. Retention Trigger Collected during registration or subsequently updated by the user. Post-Deletion Handling Contact Information may continue to be retained where reasonably necessary to:
- prevent duplicate Accounts;
- investigate abuse;
- comply with legal obligations;
- maintain audit records.
B.9 Profile Information Description Profile Information supports user interaction through the platform. Examples include:
- biography;
- photographs;
- interests;
- food preferences;
- dietary preferences;
- preferred dining style;
- dating intentions;
profile badges. Primary Purpose
- profile presentation;
- matching;
- recommendations;
user interaction. Active Retention Profile Information generally remains active while the user maintains an active Account. Users may modify or remove certain Profile Information through available account settings. Post-Deletion Handling Following Account deletion:
- Profile information is generally removed from public visibility;
- cached information may persist temporarily;
- backup copies may remain until normal backup expiration;
- information required for fraud prevention, moderation, or legal compliance may continue to be retained where justified.
B.10 Profile Photographs Description Photographs voluntarily uploaded by users. Primary Purpose
- profile presentation;
- identity consistency;
trust and safety. Active Retention Profile photographs remain associated with the user’s Account until:
- removed by the user;
- replaced;
- Account deletion;
moderation removal. Post-Deletion Handling Photographs may continue to exist temporarily within:
- backup systems;
- security archives;
- moderation evidence repositories where reasonably necessary;
- legal preservation systems.
B.11 Authentication Information Description Information used to authenticate user Accounts. Examples include:
- verification tokens;
- authentication events;
- session identifiers;
- password hashes where applicable;
login timestamps. Primary Purpose
- account security;
- authentication;
fraud prevention. Active Retention Authentication records remain active while necessary to protect Account security. Post-Deletion Handling Authentication logs may continue to be retained where reasonably necessary for:
- security investigations;
- fraud prevention;
- audit requirements;
- legal compliance.
B.12 Verification Information Description Verification Information supports confirmation of eligibility and Account authenticity. Examples include:
- telephone verification;
- email verification;
- identity verification status;
- verification timestamps;
verification provider responses. Primary Purpose
- account integrity;
- eligibility verification;
- prevention of impersonation;
fraud prevention. Active Retention Verification records remain associated with the Account while reasonably necessary. Post-Deletion Handling Verification records may continue to be retained after Account deletion where reasonably necessary to:
- prevent repeated abuse;
- investigate fraud;
- satisfy legal obligations;
- support future dispute resolution.
B.13 User Preferences Description Information describing how users configure the Services. Examples include:
- language preferences;
- notification settings;
- dining preferences;
- visibility settings;
communication preferences. Primary Purpose
- personalization;
service customization. Active Retention Maintained while the Account remains active. Post-Deletion Handling Preferences generally cease to be operational following Account deletion. Residual copies may remain temporarily within system backups until normal backup rotation is complete.
B.14 Data Integrity Reviews Dinner Date seeks to periodically review retained information to determine whether continued retention remains justified. Reviews may consider:
- operational necessity;
- legal obligations;
- fraud prevention;
- security;
- user requests;
applicable retention schedules. Where continued retention is no longer justified, information may be:
- securely deleted;
- anonymized;
- aggregated;
- archived where legally required.
B.15 General Principles Applicable to Part 1 Categories The information categories described in this Part are retained in accordance with the following principles:
- retain only what is reasonably necessary;
- minimize unnecessary duplication;
- protect information through appropriate security safeguards;
- support user privacy rights;
- comply with Applicable Law;
- preserve information where legally required;
securely delete or anonymize information when continued retention is no longer justified. These principles apply throughout the lifecycle of the Personal Information described in this Appendix.
Appendix B – Data Retention Schedule Part 2 – Communications, Dining Activities, Attendance, Location, and Safety Records
B.16 Communications and Messaging Records Description Dinner Date enables eligible users to communicate through messaging and other in-app communication features. Communications may include:
- direct messages;
- invitation discussions;
- reservation-related communications;
- customer support conversations;
- moderation communications;
- automated service notifications;
- safety-related communications.
Primary Purposes Communication records are processed to:
- deliver messages;
- facilitate dining experiences;
- support customer service;
- investigate reports;
- detect fraud;
- enforce Community Guidelines;
- comply with Applicable Law.
Active Retention Communications remain available while reasonably necessary for normal platform operation and user access. Different categories of communications may have different operational retention lifecycles.
Post-Deletion Handling Following deletion of an Account:
- messages may disappear from the deleted user’s account;
- messages previously delivered to another user may remain visible to that recipient unless otherwise removed;
- communication records may continue to be retained for trust and safety, fraud prevention, legal compliance, dispute resolution, or system integrity purposes;
- backup copies may persist until ordinary backup rotation is complete.
B.17 Dining Invitations Description Dinner Date processes information relating to dining invitations created by users. Examples include:
- invitation title;
- proposed venue;
- proposed date and time;
- participant limits;
- dining preferences;
- invitation status;
- invitation history;
- cancellation history.
Primary Purposes Invitation information supports:
- matching;
- reservations;
- attendance;
- user interactions;
- customer support;
- operational reporting.
Retention Invitation information is generally retained while operationally necessary. Historical invitation records may continue to be retained where reasonably necessary for:
- dispute resolution;
- fraud prevention;
- moderation;
- legal compliance;
- analytics using anonymized information.
B.18 Applications to Join Invitations Description Dinner Date records applications submitted by users seeking to join dining invitations. Examples include:
- application status;
- submission timestamp;
- organizer decisions;
- acceptance history;
- withdrawal history.
Primary Purposes Application records support:
- invitation management;
- user communications;
- operational reporting;
- trust and safety;
- dispute resolution.
Post-Deletion Handling Application history may remain associated with historical operational records where reasonably necessary to maintain platform integrity.
B.19 Restaurant Selection Records Description Restaurant-related operational information. Examples include:
- selected venue;
- reservation preferences;
- restaurant identifier;
- booking status;
- seating preferences where voluntarily provided.
Primary Purposes Restaurant records support:
- reservations;
- dining coordination;
- customer support;
- operational analytics.
Retention Restaurant information is generally retained for as long as reasonably necessary to:
- complete reservations;
- support trust and safety;
- resolve disputes;
- satisfy accounting requirements where applicable.
B.20 Reservation Records Description Reservation information relating to dining experiences. Examples include:
- reservation identifier;
- reservation time;
- reservation confirmation;
- reservation modifications;
- cancellation records;
- attendance confirmation.
Primary Purposes Reservation records support:
- venue coordination;
- operational management;
- customer support;
- payment reconciliation;
- trust and safety.
Post-Deletion Handling Historical reservation records may continue to be retained where reasonably necessary for:
- accounting;
- taxation;
- fraud prevention;
- customer support;
- dispute resolution;
- legal compliance.
B.21 Attendance Records Description Attendance records indicate whether a user attended an approved dining experience. Examples include:
- attendance confirmation;
- attendance status;
- attendance timestamp;
event completion status. Attendance records are intended to support platform integrity rather than create a comprehensive record of a user’s movements.
Primary Purposes Attendance records support:
- trust and safety;
- reservation management;
- fraud prevention;
- no-show management;
- platform analytics.
Retention Attendance records may be retained after an event has concluded where reasonably necessary for:
- platform integrity;
- customer support;
- dispute resolution;
- moderation;
- legal obligations.
B.22 Geofence Verification Records Description Where users voluntarily enable applicable permissions, Dinner Date may process limited geofence verification events to confirm attendance at Approved Venues. Examples include:
- verification success;
- verification failure;
- verification timestamp;
- venue identifier;
approximate verification event. Dinner Date seeks to avoid retaining continuous location histories.
Primary Purposes Geofence verification supports:
- attendance confirmation;
- safety features;
- fraud prevention;
- reservation integrity.
Post-Deletion Handling Geofence verification records may continue to be retained where reasonably necessary to:
- investigate abuse;
- resolve disputes;
- maintain platform integrity;
satisfy legal obligations. Where practical, precise location information is minimized, removed, or anonymized once no longer operationally necessary.
B.23 Emergency Contact Information Description Users may voluntarily designate emergency contacts for optional safety features. Examples include:
- emergency contact name;
- relationship;
- communication method;
- notification preferences.
Primary Purposes Emergency Contact information supports:
- optional user safety features;
- emergency notifications initiated by the user;
- trust and safety functionality.
Retention Emergency Contact information generally remains active until:
- removed by the user;
- replaced;
Account deletion. Limited records relating to safety events may continue to be retained where reasonably necessary.
B.24 Safety Check-In Records Description Dinner Date may provide optional safety check-in functionality. Examples include:
- check-in requests;
- completion status;
- missed check-ins;
- user-initiated safety events;
- notification history.
Primary Purposes Safety check-ins support:
- user safety;
- trust and safety operations;
- customer support.
Retention Safety records may be retained longer than ordinary operational records where reasonably necessary to:
- investigate incidents;
- respond to reports;
- preserve evidence;
- comply with Applicable Law.
B.25 Incident Reports Description Incident reports submitted by users or generated through trust and safety operations. Examples include:
- harassment reports;
- impersonation reports;
- inappropriate conduct reports;
- restaurant safety concerns;
- emergency reports.
Primary Purposes Incident reports support:
- investigations;
- moderation;
- user protection;
- legal compliance.
Retention Incident reports may continue to be retained following Account deletion where reasonably necessary for:
- repeat offender detection;
- appeals;
- litigation;
- regulatory investigations;
- user protection.
B.26 Trust and Safety Investigation Records Description Internal records generated during trust and safety investigations. Examples include:
- investigator notes;
- review history;
- moderation evidence;
- internal assessments;
- enforcement recommendations.
Primary Purposes These records support:
- Community Guideline enforcement;
- appeals;
- fraud prevention;
- user protection;
- operational consistency.
Retention Investigation records may remain archived after an investigation concludes where reasonably necessary to:
- identify repeat misconduct;
- respond to future complaints;
- defend legal claims;
- comply with legal obligations.
B.27 User Reports Description Reports submitted by users through reporting tools. Examples include:
- spam reports;
- fake profile reports;
- harassment reports;
- safety reports;
- impersonation reports.
Primary Purposes User reports assist Dinner Date in:
- protecting users;
- investigating abuse;
- enforcing platform policies;
- improving trust and safety.
Retention Reports may continue to be retained after resolution to support:
- appeals;
- pattern detection;
- repeat offender identification;
- legal compliance.
B.28 Customer Support Case Records Description Support interactions associated with operational assistance. Examples include:
- support tickets;
- troubleshooting information;
- account recovery requests;
- payment inquiries;
- reservation assistance.
Primary Purposes Support records assist with:
- resolving issues;
- improving services;
- quality assurance;
- operational reporting.
Retention Support records are retained only for as long as reasonably necessary to support customer service, legal compliance, quality assurance, dispute resolution, and fraud prevention.
B.29 Communication Metadata Description Metadata generated through communications. Examples include:
- message timestamps;
- delivery status;
- read status where applicable;
- communication identifiers;
routing information. Communication metadata generally does not include the substantive content of messages.
Primary Purposes Communication metadata supports:
- message delivery;
- diagnostics;
- fraud detection;
- service reliability.
Retention Metadata may be retained independently of message content where reasonably necessary for:
- diagnostics;
- security;
- legal compliance;
- operational reporting.
B.30 General Principles Applicable to Part 2 Categories The categories described in this Part are retained in accordance with the following principles:
- retain operational records only as long as reasonably necessary;
- prioritize user safety and platform integrity;
- preserve evidence where legally required;
- minimize retention of precise location information;
- support dispute resolution and appeals;
- protect the confidentiality of communications;
- comply with Applicable Law;
securely delete, anonymize, or archive information when continued active processing is no longer justified. These principles complement the general retention framework established in Section 10 of the Privacy Policy and Appendix B, Part 1.
Appendix B – Data Retention Schedule Part 3 – Payments, Financial Records, Trust & Safety, Moderation, Legal Preservation, and Compliance Records
B.31 Payment Transaction Records Description Dinner Date processes information relating to payment transactions required to operate the Services. Examples include:
- transaction identifiers;
- payment authorization status;
- payment confirmation;
- settlement status;
- payment timestamps;
- payment currency;
- payment method type;
payment processor reference numbers. Dinner Date generally does not intentionally retain complete payment card numbers or payment security codes processed directly by PCI-compliant payment providers.
Primary Purposes Payment records support:
- payment processing;
- reservation confirmation;
- accounting;
- fraud prevention;
- customer support;
- dispute resolution;
- financial reconciliation.
Active Retention Payment transaction information remains active while reasonably necessary to complete the transaction and associated operational processes.
Post-Transaction Retention Certain financial records may continue to be retained where reasonably necessary to:
- comply with financial regulations;
- satisfy accounting obligations;
- comply with taxation laws;
- investigate fraud;
- defend legal claims;
- resolve payment disputes.
B.32 Deposit Records Description Dinner Date may require reservation deposits for certain dining experiences. Examples include:
- deposit authorization;
- authorization timestamp;
- capture status;
- release status;
- forfeiture status;
- refund status.
Primary Purposes Deposit records support:
- reservation integrity;
- no-show prevention;
- payment reconciliation;
- dispute resolution.
Retention Deposit records may continue to be retained following completion of a dining experience where reasonably necessary for:
- accounting;
- taxation;
- fraud prevention;
- legal compliance;
- chargeback investigations.
B.33 Refund Records Description Information relating to refunds processed through the Services. Examples include:
- refund request;
- refund approval;
- refund amount;
- refund method;
- refund reference;
- processing status.
Primary Purposes Refund information supports:
- customer service;
- accounting;
- financial reporting;
- dispute resolution.
Retention Refund records may be retained for periods reasonably necessary to satisfy:
- financial reporting;
- accounting obligations;
- tax obligations;
- legal compliance;
- payment network requirements.
B.34 Chargeback and Payment Dispute Records Description Records associated with payment disputes initiated by users, payment providers, or financial institutions. Examples include:
- chargeback notifications;
- supporting evidence;
- payment processor communications;
- investigation notes;
- dispute outcomes.
Primary Purposes These records support:
- financial compliance;
- fraud prevention;
- dispute resolution;
- legal defence.
Retention Chargeback documentation may be retained until:
- the dispute is fully resolved;
- applicable legal limitation periods expire;
- continued retention is no longer reasonably necessary.
B.35 Fraud Prevention Records Description Information used to detect, investigate, and prevent fraudulent activity. Examples include:
- fraud indicators;
- suspicious activity scores;
- authentication anomalies;
- unusual transaction patterns;
- account linkage information;
- investigation history.
Primary Purposes Fraud records support:
- user protection;
- financial integrity;
- platform security;
- regulatory compliance.
Retention Fraud-related information may be retained longer than ordinary operational records where reasonably necessary to:
- detect repeat abuse;
- prevent financial loss;
- support investigations;
- comply with Applicable Law.
B.36 Risk Assessment Records Description Operational records generated through internal risk management activities. Examples include:
- account risk indicators;
- fraud review outcomes;
- operational risk assessments;
- payment risk evaluations.
Primary Purposes Risk records support:
- fraud prevention;
- trust and safety;
- financial protection;
- operational resilience.
Retention Risk assessment records may remain archived following resolution of the relevant matter where reasonably necessary to improve future fraud detection and maintain platform integrity.
B.37 Moderation Records Description Records created during content moderation and policy enforcement. Examples include:
- moderation decisions;
- review history;
- removed content references;
- enforcement actions;
- moderator notes;
- appeal outcomes.
Primary Purposes Moderation records support:
- Community Guideline enforcement;
- appeals;
- consistency of moderation decisions;
- user safety.
Retention Moderation records may continue to be retained following:
- Account deletion;
- content removal;
- appeal completion;
enforcement actions. Retention supports repeat offender identification, legal compliance, and operational consistency.
B.38 Removed Content Records Description Information relating to content removed from the Services. Examples include:
- removed photographs;
- removed profile information;
- removed messages;
- removed invitation content;
- moderation evidence.
Primary Purposes Removed content may be retained to:
- investigate abuse;
- support appeals;
- defend legal claims;
- comply with legal obligations;
- identify repeat misconduct.
Retention Removed content is generally not restored to public visibility solely because it remains archived for operational or legal purposes.
B.39 Appeal Records Description Records generated when users appeal moderation decisions. Examples include:
- appeal submissions;
- supporting information;
- reviewer decisions;
- appeal history.
Primary Purposes Appeal records support:
- fairness;
- consistency;
- quality assurance;
- legal compliance.
Retention Appeal records may remain archived after the appeal concludes where reasonably necessary for auditing, legal defence, moderation consistency, or future investigations.
B.40 Abuse Investigation Records Description Internal records relating to investigations of abusive behaviour. Examples include:
- harassment investigations;
- impersonation investigations;
- fraud investigations;
- safety investigations;
- coordinated abuse investigations.
Primary Purposes These records support:
- user protection;
- trust and safety;
- fraud prevention;
- regulatory compliance.
Retention Investigation records may be retained after an investigation concludes where reasonably necessary to:
- identify repeat misconduct;
- preserve evidence;
- support future investigations;
- comply with Applicable Law.
B.41 CSAM Preservation Records Description Dinner Date maintains a zero-tolerance policy toward Child Sexual Abuse Material (“CSAM”). Where content is reasonably suspected or confirmed to constitute CSAM or related child exploitation material, records may be preserved in accordance with Applicable Law and the Dinner Date CSAM Policy. Examples include:
- investigation identifiers;
- preservation records;
- moderation documentation;
- legal reporting records;
- evidence preservation logs.
Primary Purposes CSAM preservation supports:
- child protection;
- compliance with Applicable Law;
- mandatory reporting obligations where applicable;
- cooperation with competent authorities.
Retention Information relating to CSAM investigations may be retained for as long as reasonably necessary to:
- satisfy legal obligations;
- preserve evidence;
- support criminal investigations;
- protect children;
comply with lawful preservation requirements. Ordinary user deletion requests do not override lawful preservation obligations relating to CSAM investigations.
B.42 Law Enforcement Request Records Description Records relating to requests received from competent governmental or law enforcement authorities. Examples include:
- legal requests;
- preservation requests;
- disclosure records;
- correspondence;
- review documentation.
Primary Purposes These records support:
- legal compliance;
- transparency;
- auditing;
- regulatory accountability.
Retention Law enforcement records may be retained where reasonably necessary to:
- document compliance;
- defend legal claims;
- satisfy regulatory requirements;
- maintain audit trails.
B.43 Litigation and Legal Hold Records Description Certain information may become subject to legal hold procedures. Examples include:
- litigation preservation notices;
- legal hold instructions;
- preserved evidence;
- legal correspondence.
Primary Purposes Legal holds ensure that relevant information is preserved while legal or regulatory matters remain active.
Retention Information subject to legal hold may be retained until:
- the legal matter concludes;
- preservation obligations expire;
continued retention is no longer legally required. During an active legal hold, ordinary deletion schedules may be suspended.
B.44 Regulatory Compliance Records Description Records maintained to demonstrate compliance with Applicable Law. Examples include:
- audit documentation;
- compliance reviews;
- privacy assessments;
- regulatory correspondence;
- policy acknowledgements.
Primary Purposes Compliance records support:
- regulatory accountability;
- auditing;
- governance;
- legal compliance.
Retention Compliance documentation may be retained for as long as reasonably necessary to demonstrate regulatory compliance and satisfy applicable legal obligations.
B.45 General Principles Applicable to Part 3 Categories The categories described in this Part are generally retained longer than ordinary operational information because they support:
- financial integrity;
- user protection;
- fraud prevention;
- legal compliance;
- dispute resolution;
- trust and safety;
regulatory accountability. Dinner Date seeks to apply the following principles:
- retain only what is reasonably necessary;
- preserve evidence where legally required;
- protect retained information using appropriate security safeguards;
- restrict access to authorized personnel;
- periodically review continued retention;
securely delete or anonymize information when preservation is no longer justified. Where a conflict exists between an ordinary deletion request and a lawful preservation obligation, Dinner Date will comply with Applicable Law and preserve information to the extent legally required.
Appendix B – Data Retention Schedule Part 4 – Analytics, Technical Records, Artificial Intelligence, Backups, Deletion Procedures, Retention Matrix, and Governance
B.46 Analytics Records Description Dinner Date processes analytics information to understand how the Services operate and how users interact with platform features. Examples include:
- feature usage;
- application interactions;
- engagement metrics;
- navigation patterns;
- aggregated operational statistics;
- diagnostic analytics;
service performance indicators. Where reasonably practicable, analytics are performed using aggregated, pseudonymized, or anonymized information.
Primary Purposes Analytics records support:
- service improvement;
- performance optimization;
- product development;
- operational reporting;
- capacity planning;
- reliability improvements.
Retention Analytics information is retained only for as long as reasonably necessary to support legitimate business purposes, legal obligations, and platform improvement. Where feasible, identifiable information is removed or transformed into aggregated or anonymized datasets.
B.47 Technical Logs Description Dinner Date generates technical logs during operation of the Services. Examples include:
- server logs;
- application logs;
- authentication logs;
- API request logs;
- network logs;
- system diagnostics;
- error reports;
- infrastructure monitoring records.
Primary Purposes Technical logs support:
- cybersecurity;
- diagnostics;
- troubleshooting;
- fraud detection;
- platform stability;
- operational monitoring.
Retention Technical logs are generally retained only for operational, security, compliance, or legal purposes. Certain logs may be retained longer where reasonably necessary for:
- security investigations;
- legal preservation;
- fraud investigations;
- regulatory obligations.
B.48 Device Information Description Technical information relating to devices used to access the Services. Examples include:
- operating system;
- application version;
- browser type;
- device language;
- regional settings;
- device capabilities;
- platform identifiers where permitted.
Primary Purposes Device information supports:
- compatibility;
- diagnostics;
- fraud prevention;
- application optimization;
- security.
Retention Device information is retained only as reasonably necessary for operational, security, analytical, and legal purposes.
B.49 Artificial Intelligence Processing Records Description Dinner Date may maintain operational records relating to AI-assisted platform functionality. Examples include:
- recommendation model inputs;
- moderation assistance indicators;
- spam detection indicators;
- fraud detection signals;
- model evaluation metrics;
- AI confidence scores;
- AI-generated operational recommendations.
Primary Purposes AI processing records support:
- recommendation systems;
- moderation assistance;
- fraud prevention;
- quality assurance;
- operational improvement.
Retention AI processing records are retained only where reasonably necessary to:
- improve model performance;
- investigate platform issues;
- evaluate operational effectiveness;
satisfy legal obligations. Where appropriate, model training and evaluation should preferentially rely upon anonymized or aggregated information.
B.50 Audit Records Description Audit records document significant operational activities affecting the Services. Examples include:
- administrative actions;
- permission changes;
- configuration changes;
- policy acknowledgements;
- security events;
- operational approvals.
Primary Purposes Audit records support:
- accountability;
- governance;
- security;
- compliance;
- investigations.
Retention Audit records may be retained longer than ordinary operational records because they support legal compliance, internal governance, and incident investigations.
B.51 Backup Systems Description Dinner Date maintains backup systems intended to support business continuity and disaster recovery. Backups may contain copies of information processed through the Services.
Primary Purposes Backups support:
- disaster recovery;
- operational resilience;
- restoration following system failure;
- cybersecurity recovery.
Retention Backup copies are retained in accordance with internal backup lifecycle procedures. Deletion of Personal Information from active systems may not immediately remove historical backup copies. Backup information generally becomes unavailable through ordinary operational interfaces and is removed through normal backup rotation or secure destruction procedures.
B.52 Archived Information Description Certain information may be moved from active operational systems into archival storage. Archived information may include:
- historical operational records;
- completed investigations;
- historical payment documentation;
- compliance documentation;
- legal correspondence.
Primary Purposes Archival storage supports:
- regulatory compliance;
- historical reference;
- auditing;
- litigation;
- disaster recovery.
Retention Archived information is retained only where reasonably necessary for legitimate operational or legal purposes. Archived information is generally subject to stricter access controls than active operational data.
B.53 Secure Deletion Procedures When information reaches the end of its retention lifecycle, Dinner Date seeks to apply secure deletion procedures appropriate to the nature of the information and the storage environment. Deletion methods may include:
- logical deletion;
- secure overwriting where appropriate;
- cryptographic erasure where applicable;
- destruction of encryption keys where appropriate;
- secure destruction of physical media;
deletion through managed cloud lifecycle processes. Deletion methods may vary depending on technical architecture and applicable legal requirements.
B.54 Anonymization Where continued operational value exists but identifiable Personal Information is no longer required, Dinner Date may anonymize information. Anonymization seeks to remove or permanently transform identifiers such that an individual can no longer reasonably be identified. Examples include:
- aggregated reporting;
- statistical analysis;
- operational metrics;
- product improvement;
research. Information that has been irreversibly anonymized is generally no longer treated as Personal Information under this Privacy Policy.
B.55 Pseudonymization Where full anonymization is not reasonably practicable, Dinner Date may apply pseudonymization techniques. Examples include:
- replacement of identifiers;
- tokenization;
- internal reference identifiers;
restricted access mapping tables. Pseudonymized information remains Personal Information where it can reasonably be re-associated with an individual.
B.56 Data Minimization Dinner Date seeks to minimize unnecessary retention by:
- collecting only information reasonably necessary;
- limiting duplicate storage;
- periodically reviewing retained information;
- removing obsolete information;
anonymizing historical datasets where appropriate. Data minimization forms part of Dinner Date’s privacy-by-design and security-by-design practices.
B.57 Retention Governance Dinner Date seeks to maintain internal governance procedures relating to data retention. Governance activities may include:
- periodic retention reviews;
- policy updates;
- legal review;
- operational audits;
- security assessments;
- vendor oversight;
documentation of retention decisions. Retention practices may evolve as legal requirements, technology, and the Services develop.
B.58 Consolidated Retention Matrix The table below summarizes the general lifecycle of major categories of information.
| Information Category | Active Use | Possible Archive | Possible Legal Hold | Deletion / Anonymization |
|---|---|---|---|---|
| Account Records | Yes | Yes | Yes | Yes |
| Identity Information | Yes | Yes | Yes | Yes |
| Contact Information | Yes | Yes | Yes | Yes |
| Profile Information | Yes | Limited | Yes (if required) | Yes |
| Messages | Yes | Yes | Yes | Yes |
| Reservations | Yes | Yes | Yes | Yes |
| Attendance Records | Yes | Yes | Yes | Yes |
| Geofence Verification | Limited | Limited | Yes (if required) | Yes |
| Emergency Contacts | Yes | Limited | Yes (if required) | Yes |
| Payment Records | Yes | Yes | Yes | Yes |
| Refund Records | Yes | Yes | Yes | Yes |
| Fraud Records | Yes | Yes | Yes | Yes |
| Moderation Records | Yes | Yes | Yes | Yes |
| Investigation Records | Yes | Yes | Yes | Yes |
| CSAM Preservation Records | No (operational use) | Yes | Yes | Subject to Applicable Law |
| Technical Logs | Yes | Yes | Yes | Yes |
| Audit Records | Yes | Yes | Yes | Yes |
| Analytics Data | Yes | Aggregated | Limited | Yes |
| AI Processing Records | Yes | Limited | Limited | Yes |
| Backup Copies | Disaster Recovery | Yes | Yes | Removed through Backup Lifecycle |
This matrix is illustrative and does not establish fixed retention periods. Actual retention depends upon Applicable Law, operational requirements, legal preservation obligations, and the principles described throughout this Appendix.
B.59 Relationship with Other Policies This Appendix should be read together with:
- Privacy Policy;
- Account Deletion and Data Retention Policy;
- Law Enforcement Request Policy;
- Payment Terms;
- Refund and Deposit Policy;
- Reporting and Enforcement Policy;
- Content Moderation Policy;
- CSAM Policy;
AI Usage Disclosure. Where those documents establish additional operational procedures, they supplement this Appendix.
B.60 Our Retention Commitment Dinner Date is committed to responsible lifecycle management of Personal Information. Our retention program seeks to balance:
- user privacy;
- trust and safety;
- legal compliance;
- operational reliability;
- financial accountability;
- fraud prevention;
- platform integrity;
- security;
transparency. We periodically review our retention practices to ensure they remain appropriate as the Services, technology, legal requirements, and industry standards evolve.
Appendix C – Region-Specific Privacy Rights Part 1 – European Union (GDPR), European Economic Area (EEA), United Kingdom (UK GDPR), and Switzerland
C.1 Purpose of this Appendix This Appendix supplements the Dinner Date Privacy Policy by providing additional information for individuals located in jurisdictions with privacy laws that require jurisdiction-specific disclosures. This Part applies, where applicable, to individuals whose Personal Information is processed under:
- the European Union General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”);
- the UK General Data Protection Regulation (“UK GDPR”);
- the UK Data Protection Act 2018;
the Swiss Federal Act on Data Protection (“FADP”); and other substantially similar privacy legislation where applicable. Nothing in this Appendix limits any rights available under Applicable Law.
C.2 Scope This Part applies only where the above laws govern the processing of Personal Information. Whether these laws apply depends on factors including:
- your place of residence;
- where processing activities occur;
- the establishment of Dinner Date or its service providers;
applicable legal requirements. Where another jurisdiction’s privacy law applies instead, the relevant section of this Appendix should be consulted.
C.3 Controller Information For purposes of the GDPR, UK GDPR, and similar legislation, Dinner Date acts as the controller (or equivalent legal entity) for Personal Information processed in connection with providing the Services, except where another organization independently determines the purposes and means of processing. Where Dinner Date appoints a representative or Data Protection Officer as required by Applicable Law, the relevant contact information will be published in the Contact Information section of the Privacy Policy.
C.4 Categories of Personal Information The categories of Personal Information processed are described in:
- Section 3 (Information We Collect);
Appendix A (Categories of Personal Information). Depending on the Services used, these categories may include:
- identity information;
- contact information;
- account information;
- profile information;
- communications;
- location information;
- reservation information;
- payment-related information;
- technical information;
- device information;
- trust and safety information;
customer support information. Not every category applies to every user.
C.5 Purposes of Processing Dinner Date processes Personal Information for the purposes described throughout this Privacy Policy, including:
- providing the Services;
- authenticating users;
- facilitating dining experiences;
- enabling messaging;
- processing reservations and payments;
- improving platform functionality;
- protecting users;
- preventing fraud;
- enforcing platform policies;
- complying with legal obligations;
maintaining platform security. Additional information is available in Section 6.
C.6 Legal Bases for Processing Where required by GDPR, UK GDPR, or similar legislation, Dinner Date relies on one or more lawful bases for processing Personal Information. Depending on the circumstances, these may include:
- performance of a contract;
- legitimate interests;
- compliance with legal obligations;
- consent;
- protection of vital interests;
public interest where recognized by Applicable Law. Further details are provided in Section 7.
C.7 Legitimate Interests Where Dinner Date relies upon legitimate interests, examples may include:
- operating the Services;
- improving security;
- preventing fraud;
- investigating abuse;
- maintaining platform integrity;
- responding to user inquiries;
- improving product performance;
- conducting internal analytics;
protecting legal rights. Dinner Date seeks to balance these interests against the rights and freedoms of affected individuals.
C.8 Special Categories of Personal Data Certain information may constitute special category personal data under GDPR or similar legislation. Dinner Date seeks to minimize the collection of such information. Where processing of special categories of Personal Information occurs, Dinner Date seeks to ensure that an appropriate lawful basis and any additional legal conditions required by Applicable Law are satisfied. Examples may include:
- precise location information;
- voluntarily disclosed dietary restrictions that may reveal health-related information;
- voluntarily disclosed information relating to sexual orientation;
other specially protected information recognized by law. Users are encouraged not to disclose unnecessary sensitive information through public profiles or messages.
C.9 International Transfers Personal Information may be transferred outside the EEA, United Kingdom, or Switzerland where reasonably necessary to operate the Services. Where required, Dinner Date seeks to implement appropriate safeguards, which may include:
- adequacy decisions;
- Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Agreement (IDTA);
- approved UK Addenda;
- Binding Corporate Rules where applicable;
other transfer mechanisms recognized by Applicable Law. Further information is available in Section 9.
C.10 Data Retention Retention practices are described in:
- Section 10 (Data Retention);
Appendix B (Data Retention Schedule). Retention periods vary depending on:
- operational necessity;
- legal obligations;
- trust and safety requirements;
- accounting requirements;
- fraud prevention;
dispute resolution. Dinner Date seeks to delete, anonymize, or securely archive Personal Information when continued retention is no longer reasonably necessary.
C.11 Your Rights Subject to Applicable Law, you may have some or all of the following rights:
- right of access;
- right to rectification;
- right to erasure (“right to be forgotten”);
- right to restrict processing;
- right to object;
- right to data portability;
- right to withdraw consent;
- rights relating to certain automated decision-making;
right to lodge a complaint with a competent supervisory authority. These rights are described in greater detail in Section 12.
C.12 Exercising Your Rights Privacy requests may generally be submitted through:
- available account settings;
- customer support;
- the privacy contact identified in this Privacy Policy;
other channels designated by Dinner Date. Dinner Date may request information reasonably necessary to verify identity before responding. Verification procedures are intended to protect the privacy and security of users.
C.13 Automated Processing Dinner Date may use automated technologies to assist with:
- recommendations;
- spam detection;
- fraud detection;
- moderation assistance;
- operational prioritization;
customer support routing. These technologies are intended to support—not replace—appropriate human oversight, particularly for significant trust and safety decisions. Additional information is provided in the AI Usage Disclosure.
C.14 Supervisory Authorities Individuals subject to the GDPR, UK GDPR, or similar legislation may have the right to lodge a complaint with a competent supervisory authority. The appropriate supervisory authority generally depends on factors such as:
- the individual’s place of habitual residence;
- the location of the alleged infringement;
the jurisdiction in which processing occurs. Nothing in this Privacy Policy limits the right to contact a competent supervisory authority where provided by Applicable Law.
C.15 Data Protection Officer or Representative Where Dinner Date is legally required to appoint a Data Protection Officer (“DPO”), UK Representative, EU Representative, or equivalent privacy representative, the relevant contact information will be published in the Contact Information section of the Privacy Policy. Where no such appointment is legally required, privacy inquiries may be directed to the designated privacy contact.
C.16 Cookies and Similar Technologies Where Dinner Date provides web-based Services that use cookies or similar technologies, processing will occur in accordance with:
- this Privacy Policy;
- the Cookie and Tracking Policy;
Applicable Law governing cookies and electronic communications. Where legally required, consent will be obtained before placing non-essential cookies or similar technologies.
C.17 Future Regulatory Developments Privacy and data protection laws continue to evolve. Dinner Date may update this Appendix to reflect:
- legislative changes;
- regulatory guidance;
- judicial decisions;
- industry standards;
operational developments. Material updates will be communicated in accordance with Section 15 of the Privacy Policy.
C.18 Relationship with the Main Privacy Policy This Appendix supplements—but does not replace—the main Privacy Policy. Where a conflict exists between this Appendix and the main Privacy Policy with respect to individuals covered by the GDPR, UK GDPR, or Swiss FADP, Dinner Date will seek to comply with Applicable Law.
Appendix C – Region-Specific Privacy Rights Part 2 – California (CCPA/CPRA) and United States State Privacy Laws
C.19 Purpose This Part supplements the Dinner Date Privacy Policy by providing additional disclosures for residents of California and other U.S. states that have enacted comprehensive consumer privacy legislation. Depending on your place of residence and Applicable Law, you may have additional privacy rights beyond those described in the main Privacy Policy. Nothing in this Appendix limits any rights available under Applicable Law.
C.20 Scope This Part may apply to residents of jurisdictions that have adopted comprehensive privacy legislation, including where applicable:
- California;
- Virginia;
- Colorado;
- Connecticut;
- Utah;
- Oregon;
- Texas;
- Montana;
- Delaware;
- Iowa;
- Nebraska;
- New Hampshire;
- New Jersey;
- Tennessee;
- Minnesota;
- Maryland;
- Kentucky;
- Indiana;
- Rhode Island;
and other U.S. jurisdictions that enact substantially similar legislation. The rights available to an individual depend upon the law applicable to that individual and the processing activities involved.
C.21 Categories of Personal Information Collected During the preceding twelve (12) months, Dinner Date may have collected categories of Personal Information described throughout this Privacy Policy, including:
- identifiers;
- contact information;
- account information;
- profile information;
- communications;
- reservation information;
- payment-related information;
- commercial information;
- device information;
- internet or network activity;
- approximate or precise location information (where enabled);
- geofence verification events;
- customer support records;
- trust and safety records;
- moderation records;
- fraud prevention information;
- AI-assisted operational information;
inferences generated from user preferences or interactions. Not every category is collected for every user.
C.22 Sources of Personal Information Personal Information may be collected from:
- users directly;
- user-generated content;
- communications with Dinner Date;
- devices used to access the Services;
- payment providers;
- restaurant partners;
- authentication providers;
- identity verification providers;
- service providers;
- analytics providers;
- fraud prevention systems;
publicly available sources where permitted by Applicable Law. Additional information is available in Sections 3 and 4 of the Privacy Policy.
C.23 Business and Commercial Purposes Personal Information may be processed for purposes including:
- providing the Services;
- account administration;
- reservations;
- messaging;
- customer support;
- fraud prevention;
- trust and safety;
- content moderation;
- analytics;
- application improvement;
- payment processing;
- legal compliance;
- cybersecurity;
operational administration. Additional information is provided in Section 6.
C.24 Categories of Recipients Dinner Date may disclose Personal Information to categories of recipients including:
- service providers;
- contractors;
- payment processors;
- restaurant partners;
- authentication providers;
- identity verification providers;
- cloud infrastructure providers;
- analytics providers;
- communications providers;
- cybersecurity providers;
- professional advisers;
- regulators;
- law enforcement authorities where legally required;
- other recipients described in Section 8.
C.25 Sale of Personal Information Dinner Date does not sell Personal Information in exchange for monetary consideration as those concepts are commonly understood under applicable U.S. privacy laws. If Dinner Date’s practices change in the future, this Privacy Policy will be updated before any such activity begins where required by Applicable Law.
C.26 Sharing for Cross-Context Behavioral Advertising As of the Effective Date of this Privacy Policy, Dinner Date does not intentionally share Personal Information for cross-context behavioral advertising in the manner contemplated by the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CPRA”), unless such processing is disclosed and users are provided any choices required by Applicable Law. If future platform features involve targeted advertising that is subject to Applicable Law, Dinner Date will provide appropriate notices and controls before such processing begins.
C.27 Sensitive Personal Information Depending on the Services used, Dinner Date may process categories of Sensitive Personal Information as defined by certain privacy laws. Examples may include:
- precise location information;
- account authentication information;
- information relating to sexual orientation voluntarily disclosed by users;
dietary information voluntarily provided by users that could reveal health-related information. Dinner Date seeks to use Sensitive Personal Information only for purposes reasonably necessary to provide the Services, protect users, maintain platform integrity, comply with Applicable Law, or other purposes permitted by applicable privacy legislation. Dinner Date does not use Sensitive Personal Information to infer characteristics beyond those reasonably necessary for providing the Services unless permitted by Applicable Law or with any required consent.
C.28 Your Privacy Rights Depending upon Applicable Law, you may have some or all of the following rights. Right to Know You may request information regarding:
- categories of Personal Information collected;
- categories of sources;
- business purposes;
- categories of recipients;
- retention practices;
- categories of Sensitive Personal Information processed where required.
Right to Access You may request access to Personal Information relating to you.
Right to Correct You may request correction of inaccurate Personal Information.
Right to Delete You may request deletion of Personal Information, subject to exceptions permitted by Applicable Law.
Right to Data Portability You may request certain Personal Information in a portable format where required by Applicable Law.
Right to Opt Out Where Applicable Law provides such rights, you may request to opt out of:
- sale of Personal Information;
- sharing for cross-context behavioral advertising;
- certain profiling activities where applicable.
Right to Limit Use of Sensitive Personal Information Where required by Applicable Law, users may have rights relating to certain uses of Sensitive Personal Information.
Right to Non-Discrimination Dinner Date will not unlawfully discriminate against users for exercising privacy rights recognized by Applicable Law. However, some Services may become unavailable where Personal Information is reasonably necessary for those Services to function.
C.29 Exercising Privacy Rights Privacy requests may generally be submitted through:
- available account settings;
- customer support;
- the designated privacy contact;
other methods identified by Dinner Date. Dinner Date may require verification of identity before responding. Verification procedures are intended to protect users from unauthorized disclosure of Personal Information.
C.30 Authorized Agents Where recognized by Applicable Law, users may designate an authorized agent to submit certain privacy requests. Dinner Date may require documentation reasonably necessary to verify:
- the identity of the requesting individual;
- the authority of the authorized agent;
- the authenticity of the request.
C.31 Verification Procedures Before fulfilling certain requests, Dinner Date may request information reasonably necessary to verify:
- Account ownership;
- identity;
- contact information;
authority of an authorized representative. Verification requirements may vary depending upon:
- the sensitivity of the information requested;
- the nature of the request;
- Applicable Law.
C.32 Retention Retention practices applicable to U.S. residents are described in:
- Section 10;
Appendix B. Retention periods are determined based upon:
- operational necessity;
- legal obligations;
- accounting requirements;
- fraud prevention;
- trust and safety;
- dispute resolution.
C.33 Appeals Where Applicable Law provides a right to appeal the denial of a privacy request, Dinner Date will make reasonable efforts to provide information regarding available appeal procedures. Appeal procedures may vary depending upon the applicable jurisdiction and the nature of the request.
C.34 Future State Privacy Laws Privacy legislation within the United States continues to evolve. Dinner Date may update this Appendix to reflect:
- newly enacted state privacy laws;
- amendments to existing legislation;
- regulatory guidance;
- judicial decisions;
operational developments. Where required by Applicable Law, updates will be reflected in accordance with Section 15 of this Privacy Policy.
C.35 Relationship with the Main Privacy Policy This Part supplements the Dinner Date Privacy Policy. Where Applicable Law provides greater rights than those described elsewhere in the Privacy Policy, Dinner Date seeks to honor those rights to the extent required by law. If a conflict exists between this Appendix and another provision of the Privacy Policy with respect to individuals covered by applicable U.S. privacy legislation, Dinner Date will seek to comply with Applicable Law.
Appendix C – Region-Specific Privacy Rights Part 3 – Canada (PIPEDA), Australia, New Zealand, Brazil (LGPD), Singapore (PDPA), South Africa (POPIA), and Other International Jurisdictions
C.36 Purpose This Part supplements the Dinner Date Privacy Policy by providing additional information for users located in jurisdictions outside the European Union, United Kingdom, Switzerland, and the United States where privacy legislation grants additional rights or imposes additional obligations. This Appendix should be read together with the remainder of the Privacy Policy. Nothing in this Appendix limits any rights available under Applicable Law.
C.37 Canada (PIPEDA) Where the Personal Information of individuals in Canada is processed in a manner subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”) or substantially similar provincial privacy legislation, Dinner Date seeks to process Personal Information in accordance with the principles of:
- accountability;
- identifying purposes;
- informed consent where required;
- limiting collection;
- limiting use, disclosure and retention;
- accuracy;
- safeguards;
- openness;
- individual access;
challenging compliance. Subject to Applicable Law, Canadian users may have rights to:
- request access to Personal Information;
- request correction of inaccurate information;
- withdraw consent where consent is the lawful basis for processing;
submit complaints regarding privacy practices. Dinner Date may transfer Personal Information outside Canada where reasonably necessary to operate the Services, subject to appropriate safeguards consistent with Applicable Law.
C.38 Australia (Privacy Act) Where the Australian Privacy Act 1988 (Cth) applies, Dinner Date seeks to process Personal Information in accordance with the Australian Privacy Principles (“APPs”). Examples include:
- collecting information reasonably necessary for the Services;
- using information for disclosed purposes;
- maintaining appropriate security safeguards;
- providing access and correction mechanisms where required;
implementing reasonable procedures for handling privacy complaints. Where reasonably necessary, Personal Information may be transferred outside Australia subject to applicable legal requirements and appropriate safeguards. Australian users may submit privacy complaints through the contact channels identified in this Privacy Policy.
C.39 New Zealand (Privacy Act) Where New Zealand’s Privacy Act 2020 applies, Dinner Date seeks to process Personal Information consistently with the Information Privacy Principles (“IPPs”). Subject to Applicable Law, New Zealand users may request:
- access to Personal Information;
- correction of inaccurate information;
additional information regarding processing activities where required. Dinner Date seeks to implement reasonable safeguards before transferring Personal Information outside New Zealand where applicable legal requirements apply.
C.40 Brazil (LGPD) Where Brazil’s Lei Geral de Proteção de Dados Pessoais (“LGPD”) applies, Dinner Date seeks to process Personal Information only where an appropriate legal basis exists. Depending upon the circumstances, legal bases may include:
- consent;
- performance of a contract;
- compliance with legal obligations;
- exercise of legal rights;
- protection of life;
- legitimate interests;
other legal bases recognized by the LGPD. Subject to Applicable Law, users may have rights including:
- confirmation of processing;
- access;
- correction;
- anonymization where appropriate;
- portability;
- deletion where applicable;
- information regarding data sharing;
- information regarding consent;
withdrawal of consent. Dinner Date seeks to implement safeguards for international transfers where required by Brazilian law.
C.41 Singapore (PDPA) Where Singapore’s Personal Data Protection Act (“PDPA”) applies, Dinner Date seeks to process Personal Information in accordance with the PDPA and applicable regulatory guidance. Subject to Applicable Law, users may have rights relating to:
- consent;
- withdrawal of consent;
- access;
- correction;
- accuracy;
- protection;
retention limitation. Where Personal Information is transferred outside Singapore, Dinner Date seeks to ensure that comparable protection is provided as required by Applicable Law.
C.42 South Africa (POPIA) Where South Africa’s Protection of Personal Information Act (“POPIA”) applies, Dinner Date seeks to process Personal Information lawfully and reasonably. Processing principles include:
- accountability;
- processing limitation;
- purpose specification;
- further processing limitation;
- information quality;
- openness;
- security safeguards;
data subject participation. Subject to Applicable Law, users may request:
- access;
- correction;
- deletion where appropriate;
- objection to processing;
- information regarding processing activities.
C.43 Other International Jurisdictions Dinner Date may process Personal Information relating to individuals located in jurisdictions not specifically identified in this Appendix. Where local privacy legislation applies, Dinner Date seeks to comply with Applicable Law, including obligations relating to:
- transparency;
- lawful processing;
- security;
- international transfers;
- user rights;
complaint handling. As privacy legislation evolves, Dinner Date may supplement this Appendix with additional jurisdiction-specific disclosures.
C.44 International Transfers Personal Information processed under the jurisdictions described in this Part may be transferred internationally where reasonably necessary to operate the Services. Dinner Date seeks to implement safeguards appropriate to the applicable jurisdiction, which may include:
- contractual protections;
- organizational safeguards;
- technical safeguards;
transfer mechanisms recognized by Applicable Law. Additional information is available in Section 9 of this Privacy Policy.
C.45 Security Dinner Date seeks to protect Personal Information through administrative, technical, physical, and organizational safeguards appropriate to the sensitivity of the information and the nature of the Services. Additional information is provided in Section 11.
C.46 Retention Retention practices applicable to these jurisdictions are described in:
- Section 10;
Appendix B. Retention periods vary according to:
- operational necessity;
- legal obligations;
- trust and safety requirements;
- financial obligations;
- fraud prevention;
- dispute resolution.
C.47 Complaints Users who believe that Dinner Date has processed Personal Information inconsistently with Applicable Law may contact Dinner Date using the contact channels described in Section 16. Where Applicable Law provides the right to submit complaints to a competent supervisory authority, privacy commissioner, or regulatory body, nothing in this Privacy Policy limits that right. Where appropriate, Dinner Date encourages users to contact us first so that we may attempt to resolve concerns directly.
C.48 Updates Privacy legislation continues to evolve globally. Dinner Date may update this Appendix to reflect:
- legislative developments;
- regulatory guidance;
- judicial decisions;
- operational changes;
industry best practices. Material updates will be communicated in accordance with Section 15 of the Privacy Policy.
C.49 Relationship with the Main Privacy Policy This Part supplements the main Privacy Policy. Where Applicable Law grants greater rights than those described elsewhere in the Privacy Policy, Dinner Date seeks to comply with those requirements. If a conflict exists between this Appendix and another provision of the Privacy Policy with respect to individuals covered by the legislation described in this Part, Dinner Date will seek to comply with Applicable Law.
Appendix C – Region-Specific Privacy Rights Part 4 – India, Asia-Pacific Jurisdictions, Interpretation, Governing Principles, and Final Provisions
C.50 India (Digital Personal Data Protection Act, 2023) Where the processing of Personal Information is governed by the Digital Personal Data Protection Act, 2023 (“DPDP Act”) or any successor legislation, Dinner Date seeks to process Digital Personal Data in accordance with Applicable Law. Depending upon the circumstances, processing may occur for purposes including:
- providing the Services;
- creating and administering user Accounts;
- facilitating dining experiences;
- trust and safety;
- fraud prevention;
- customer support;
- payment processing;
- legal compliance;
security. Dinner Date seeks to process Digital Personal Data only where an appropriate legal basis exists under Applicable Law. Where consent is required, Dinner Date seeks to obtain valid consent before processing begins. Where another lawful basis is recognized under Applicable Law, Dinner Date may rely upon that basis where appropriate.
C.51 Rights of Individuals in India Subject to the DPDP Act and Applicable Law, eligible individuals may have rights including:
- the right to obtain information regarding processing activities;
- the right to request correction of inaccurate information;
- the right to request updating of incomplete information;
- the right to request erasure of Personal Information where applicable;
- the right to withdraw consent where consent forms the basis of processing;
- the right to nominate another individual to exercise certain rights where recognized by law;
- the right to seek grievance redressal;
the right to submit complaints to the competent authority where applicable. The availability and scope of these rights depend upon Applicable Law.
C.52 Consent Management Where processing relies upon consent, Dinner Date seeks to provide mechanisms enabling users to:
- provide consent;
- review consent;
- withdraw consent;
- update consent preferences;
manage optional permissions. Withdrawal of consent does not affect processing already lawfully performed before withdrawal. Certain Services may become unavailable if consent necessary for those Services is withdrawn.
C.53 Grievance Redressal Dinner Date seeks to maintain procedures for receiving, reviewing, and responding to privacy-related complaints. Depending upon Applicable Law, users may submit concerns regarding:
- collection of Personal Information;
- processing activities;
- correction requests;
- deletion requests;
- consent;
- security concerns;
- international transfers;
trust and safety matters. Dinner Date has designated a Grievance Officer as required by Rule 3(2) of the Indian Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and by the Digital Personal Data Protection Act, 2023:
Grievance Officer: Vallabh Sakhare Email: legal@pipchat.in Acknowledgement: within 24 hours of receipt Resolution: within 15 days of receipt
Complaints regarding personal data handling, content, conduct, moderation decisions or account actions may be sent to that address. Complaints concerning content that exposes a person's private area, shows nudity or sexual acts, or is impersonation in an electronic form are actioned within 24 hours as required by Rule 3(2)(b).
Dinner Date is not, at present, a Significant Social Media Intermediary as defined by those Rules. Should it cross the applicable user threshold, it will additionally publish a physical contact address and appoint the further officers those Rules require.
C.54 Other Asia-Pacific Jurisdictions Dinner Date may process Personal Information relating to users located in other Asia-Pacific jurisdictions. Examples include:
- Japan;
- South Korea;
- Hong Kong;
- Malaysia;
- Thailand;
- Indonesia;
- Philippines;
- Vietnam;
- Taiwan;
other jurisdictions where the Services become available. Where local privacy legislation applies, Dinner Date seeks to comply with Applicable Law governing:
- transparency;
- lawful processing;
- user rights;
- security;
- international transfers;
complaint handling. Additional jurisdiction-specific disclosures may be published as Dinner Date expands into new markets.
C.55 Conflict of Laws Dinner Date operates internationally. Accordingly, multiple privacy laws may apply simultaneously to the same processing activity. Where multiple legal obligations apply, Dinner Date seeks to comply with the requirements applicable to the relevant processing activity. Where two legal requirements appear inconsistent, Dinner Date seeks to apply the interpretation that:
- best protects user privacy;
- satisfies Applicable Law;
- supports user safety;
maintains operational integrity. Nothing in this Privacy Policy is intended to reduce rights granted by Applicable Law.
C.56 Interpretation of Region-Specific Rights The region-specific provisions contained in this Appendix supplement the main Privacy Policy. They should not be interpreted as limiting any rights otherwise available under Applicable Law. Where a particular jurisdiction provides broader protections than those described elsewhere in this Privacy Policy, Dinner Date seeks to comply with those broader legal requirements.
C.57 Future Privacy Legislation Privacy laws continue to evolve rapidly throughout the world. Dinner Date may update this Privacy Policy to reflect developments including:
- newly enacted legislation;
- amendments to existing privacy laws;
- judicial decisions;
- regulatory guidance;
- enforcement actions;
- industry standards;
technological developments. Examples may include future developments relating to:
- Artificial Intelligence regulation;
- biometric information;
- children’s privacy;
- cross-border transfers;
- digital identity;
- online safety;
- cybersecurity;
consumer protection. Material changes will be communicated in accordance with Section 15 of this Privacy Policy.
C.58 Cross-Reference to Other Dinner Date Policies This Privacy Policy forms part of Dinner Date’s broader privacy, trust and safety, and compliance framework. It should be read together with, where applicable:
- Terms of Service;
- Community Guidelines;
- Safety Guidelines;
- Content Moderation Policy;
- CSAM Policy;
- Reporting and Enforcement Policy;
- Refund and Deposit Policy;
- Payment Terms;
- Location and Geofence Policy;
- Age and Eligibility Policy;
- Photo and Profile Policy;
- Intellectual Property Policy;
- Copyright Policy;
- Cookie and Tracking Policy;
- Law Enforcement Request Policy;
- Account Deletion and Data Retention Policy;
AI Usage Disclosure. These documents complement one another and should be interpreted consistently where reasonably possible.
C.59 Governing Principles Dinner Date seeks to administer its privacy program according to the following principles:
- lawfulness;
- fairness;
- transparency;
- accountability;
- proportionality;
- purpose limitation;
- data minimization;
- privacy by design;
- security by design;
- user safety;
- operational integrity;
continual improvement. These principles guide the ongoing development of the Services and the processing of Personal Information.
C.60 Questions Regarding Jurisdiction-Specific Rights Users who have questions regarding rights applicable within their jurisdiction may contact Dinner Date using the contact information provided in Section 16. Where reasonably necessary, Dinner Date may request additional information to determine:
- the applicable jurisdiction;
- identity;
- eligibility to exercise particular rights;
the scope of the request. Verification procedures are intended to protect users from unauthorized disclosure of Personal Information.
C.61 Severability If any provision of this Privacy Policy or this Appendix is determined to be invalid, unlawful, or unenforceable under Applicable Law, that provision shall be interpreted or modified only to the minimum extent necessary to achieve compliance with Applicable Law. The remaining provisions shall continue in full force and effect to the extent permitted by law.
C.62 No Waiver of Statutory Rights Nothing contained in this Privacy Policy is intended to waive, restrict, or limit any mandatory rights provided to individuals under Applicable Law. Where Applicable Law grants protections that cannot lawfully be limited by contract or policy, those protections shall prevail.
C.63 Prevailing Language If Dinner Date publishes translated versions of this Privacy Policy for convenience, the English-language version shall govern in the event of inconsistency unless Applicable Law requires another version to prevail. Where legally required, Dinner Date will provide localized versions of this Privacy Policy.
C.64 Entire Privacy Policy This Privacy Policy, together with the documents expressly incorporated by reference, constitutes Dinner Date’s complete Privacy Policy regarding the processing of Personal Information through the Services. This Privacy Policy supersedes previous public privacy notices relating to the Services unless expressly stated otherwise.
C.65 Our Privacy Commitment Dinner Date recognizes that privacy is fundamental to user trust. Accordingly, we seek to:
- collect only information reasonably necessary for the Services;
- process Personal Information responsibly;
- protect Personal Information using appropriate safeguards;
- respect user privacy rights;
- support user safety;
- maintain transparency regarding our processing activities;
- comply with Applicable Law;
continuously improve our privacy program as technology, legal requirements, and user expectations evolve. Protecting Personal Information is an ongoing responsibility that forms an integral part of the design, operation, and continuous improvement of the Dinner Date platform.