Privacy Policy
Effective September 24, 2026. Diner on Demand is a product of Fourdots Digital Inc.
Diner on Demand runs digital loyalty programs for restaurants and food businesses (“businesses”). This policy explains what we collect, why, and what you can do about it. It covers the Diner on Demand dashboard, the counter scanner, the hosted signup pages, the wallet cards we issue, and the texts we send on a business's behalf.
What we collect
- From guests who join a loyalty program: first name, mobile number, and, if given, last name, email address, date of birth and preferred location. We also record the loyalty card issued to you, whether it was added to a phone wallet, and each visit recorded at the counter, including the ticket total when the business enters it.
- From business users: name, work email, password (stored hashed), the actions taken in the dashboard, and billing details handled by Stripe.
- From connected Meta accounts: when a business connects its Meta ad account, we read advertising spend and performance figures for that account, and the leads submitted through that business's lead ads (the fields the guest filled in). We do not post, message, or change anything on the business's behalf.
- Technical: server logs with IP address, browser type and timestamps, kept for security and troubleshooting.
How we use it
- To issue and update your loyalty card, record stamps, points and rewards, and show them to the business at the counter.
- To text you the card link and a small number of service messages the business has turned on, such as directions after you join or a request for a review after a visit. You can reply STOP at any time.
- To show the business how its program is performing: members, visits, revenue and lifetime value, in aggregate and per member.
- To connect what a business spends on ads with the members those ads bring in, so the business can see what its advertising returns.
- To run the service: security, fraud prevention, support and billing.
Who we share it with
- The business you joined. Your loyalty data belongs to that business's program; its staff can see your name, contact details, visits and balances.
- Service providers that run parts of the product for us: the digital wallet card platform that hosts the cards, Twilio for text messages, Stripe for billing, Vercel and Supabase for hosting and storage, and Meta when a business connects its ad account. Each processes data only to provide its service.
- Tools the business connects, such as its CRM or email platform, when the business sets up an integration to receive its own members' details.
- Nobody else. We do not sell personal information, and we do not share mobile numbers or consent with third parties for their own marketing.
Meta platform data
Data received from Meta's APIs (ad account insights and lead form submissions) is used only to report advertising results to the business that owns the ad account and to enroll the guests who asked to join that business's program. It is stored for as long as the business keeps its Meta account connected, and deleted within 30 days of disconnection or on request.
Retention and deletion
Loyalty data is kept while the business runs its program with us and for up to 12 months after, then deleted. You can ask the business, or us at support@dinerondemand.com, to delete your data at any time; see our data deletion instructions. Business account data is deleted within 90 days of the account closing, except records we must keep for tax or legal reasons.
Your choices
- Reply STOP to any text to stop receiving texts.
- Remove the card from your phone wallet at any time.
- Ask us to access, correct or delete your information by emailing support@dinerondemand.com.
Security
Data is encrypted in transit and at rest. Access inside Diner on Demand is limited to the business you joined and to our staff who need it to run the service.
Changes
If this policy changes in a way that matters, we'll post the new version here with a new effective date.
Questions: support@dinerondemand.com