Privacy Policy
At DineDM AI, we are committed to safeguarding the privacy of your restaurant business, your team members, and the dining guests who interact with your Instagram Direct Messages.
Your private restaurant conversations and guest memories are never used to train public LLM models.
All customer records, API tokens, and message threads are protected using AES-256 and TLS 1.3.
Guests and merchants can request deletion of all associated profile records and memories at any time.
1. Information We Collect
We collect information in the following categories:
- Account and Merchant Data: Full name, business email, restaurant name, location, and encrypted credentials provided during signup.
- Meta / Instagram Direct Data: Instagram scoped user IDs (IGSID), public username, profile pictures, and direct message text received via official webhooks from Meta Platforms, Inc.
- Customer Memory & Guest Tags: Dietary restrictions, preferred seating, visit frequency, and staff notes explicitly extracted during conversations to assist restaurant hospitality.
- Technical Log Data: IP addresses, browser user-agent strings, and request timestamps strictly for rate limiting and security auditing.
2. How We Use Collected Information
We use information strictly for operational and hospitality purposes:
- Generating automated replies to guest inquiries (menus, reservations, hours, and directions).
- Populating the shared team inbox for manager review and human-in-the-loop takeover.
- Remembering repeat diner preferences (e.g. “Prefers booth”, “Gluten allergy”) across consecutive visits.
- Maintaining system stability, detecting unauthorized access, and complying with Meta API guidelines.
3. AI Processing & Third-Party LLM Providers
DineDM utilizes enterprise-grade AI model APIs (such as OpenAI or Google Cloud Vertex) to parse messages and draft replies. Under our enterprise agreements:
- Your data is transmitted via secure, zero-retention API endpoints where applicable.
- Your messages, menu documents, and diner details are never used to train foundation AI models.
- Data is retained by AI inference providers only as required for transient abuse monitoring.
4. Meta Platform Data & Third-Party Sharing
We do not sell, rent, or monetize your customer data or Instagram conversation history. We share information only with:
- Infrastructure Vendors: Cloud hosting, database providers, and authentication services bound by strict confidentiality.
- Meta Platforms, Inc.: In order to transmit replies back through the official Instagram Messaging Graph API.
5. Data Retention & Deletion Requests (GDPR / CCPA)
We retain guest messages and memories only as long as your workspace account remains active or until deleted by a workspace manager.
How to Request Immediate Data Deletion:
Any restaurant guest or account owner may request complete erasure of their conversations and memory attributes by emailing [email protected] or by submitting a request through the Meta User Data Deletion Callback endpoint. Deletions are processed within 30 days.
6. Contact the Data Protection Officer
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
DineDM AI Privacy Office
Email: [email protected]
Address: 100 Innovation Way, Suite 400, San Francisco, CA 94105