Privacy policy

Last updated 14 September 2026 · Terms of service
1. What we collect from guests

A first name, a party size, and — only if the guest opts in to texts — a phone number. No account is required to wait. Guests who choose to sign in additionally get their wait history kept in one place; that is the feature, not a byproduct.

2. What we do with it

Run tonight's waitlist. Numbers are used to send messages about the guest's visit and nothing else — not by us, and per the terms, not by the restaurant through us. We do not sell data, we do not build advertising profiles, and we never message a guest after their visit ends.

3. Retention

Guest phone numbers are removed from the live system 48 hours after the visit. Restaurants keep anonymized wait history (times, party sizes, outcomes) for their own analytics. Signed-in guests keep their history until they delete it, which they can do from their own page in one tap.

4. Where it lives

Data is stored in Canada and handled under PIPEDA. Texts are delivered by our carrier partner under the same one-purpose restriction. AI-drafted replies are processed to draft the reply and are not used to train models.

5. Keeping bots off the list

The screens where somebody joins a list or signs in run Cloudflare Turnstile, so a script cannot fill a restaurant's evening with parties that will never arrive. There is nothing to click and no puzzle to solve. Cloudflare reads signals the browser sends anyway — IP address, TLS fingerprint, user agent, and which site asked — solely to tell a person from a bot, and not to identify, profile or target anyone. Their handling of it is covered by the Turnstile Privacy Addendum.

6. Questions

Write to privacy@dineq.app. A person answers.