DineMio legal

Privacy Policy

This policy explains what personal data DineMio handles, why we handle it, who we share it with, and the choices available to restaurant teams, guests, and people we contact.

Last updated: May 16, 2026

1. Who we are and when this applies

DineMio, formerly TableLite, is a restaurant reservation platform operated by Lekasoft in the Netherlands. We provide restaurant dashboards, embeddable booking widgets, reservation emails, guest CRM tools, setup flows, checkout, and related support and sales communications.

This policy applies to DineMio websites, apps, booking widgets, emails, and related services. If you have questions or want to make a privacy request, contact us at [email protected].

For personal data about restaurant account users, buyers, support contacts, and sales contacts, DineMio is usually the controller. For guest and reservation data entered by or collected for a restaurant, the restaurant is usually the controller and DineMio acts as its service provider or processor.

2. Personal data we collect

The data we collect depends on how you use DineMio.

  • Account data: name, email address, preferred language, password authentication data, Google sign-in identifiers when you use Google login, role, invitation status, account status, and session information.
  • Restaurant data: restaurant name, address, city, country, timezone, phone, email, website, social links, logo, cover images, opening hours, tables, seating areas, floor-plan layouts, widget settings, plans, and team membership information.
  • Guest and reservation data: guest name, salutation, email, phone number, party size, reservation date and time, status, cancellation reason, special requests, notes, tags, visit counts, no-show counts, guest events, and reservation activity history.
  • Payment and checkout data: purchaser name, email, restaurant name, selected plan, quoted amount, currency, checkout status, Stripe customer, checkout, and payment identifiers. DineMio does not store full card numbers.
  • Communications data: messages you send us, restaurant invitations, password reset and magic-link emails, reservation emails, sales emails, replies, unsubscribe or suppression records, and email delivery, bounce, or complaint events.
  • Historical sales lead and attribution data: restaurant lead details such as public business contact details, website, location, booking software signals, outreach status, link click events, referrer, user agent, and hashed IP address.
  • Technical and security data: IP address, user agent, device and browser data, request metadata, timestamps, authentication events, rate-limit records, diagnostic logs, error reports, and sampled Sentry session replay or performance data.

Special requests and restaurant notes can contain sensitive details, such as allergies, dietary needs, accessibility needs, or other health-related information. Please only provide or enter sensitive information that is needed to manage the reservation or restaurant service.

3. How we use personal data

  • Provide, secure, maintain, and improve DineMio.
  • Create and manage accounts, sessions, teams, roles, and invitations.
  • Let restaurants configure availability, tables, widgets, and booking flows.
  • Create, update, confirm, remind, cancel, and manage reservations.
  • Send transactional emails, support replies, product notices, and sales communications.
  • Process purchases, refunds, invoices, plan access, and payment records.
  • Detect abuse, enforce limits, prevent fraud, investigate incidents, and debug errors.
  • Retain historical campaign records for reference and honor recorded opt-outs.
  • Comply with legal, tax, accounting, security, and regulatory obligations.

5. Vendors and third parties

We share personal data only as needed to operate DineMio, comply with law, or protect rights and security. Current categories include:

  • Hosting, database, infrastructure, backup, and deployment providers.
  • Cloudflare R2 or compatible object storage for uploaded logos, cover images, and floor-plan images.
  • Stripe for checkout, payment processing, refunds, payment records, and fraud controls.
  • Email providers, including SMTP and Amazon SES, for transactional and sales email delivery and delivery event handling.
  • Sentry for error monitoring, performance diagnostics, logging, and sampled session replay diagnostics.
  • Google services for Google sign-in and maps links.
  • OpenAI for optional AI floor-plan image analysis when a restaurant user chooses to use that feature.
  • Internal operations and notification tools, professional advisers, auditors, authorities, or parties involved in a business transaction where needed.

Restaurants and their authorized team members can access guest and reservation data for their own restaurant. Guests should contact the restaurant directly for restaurant-specific booking, hospitality, or data questions; we can help route requests where appropriate.

6. Cookies and similar technologies

DineMio uses cookies and similar technologies for authentication, security, language preferences, and interface preferences. For example, we use session cookies to keep users signed in, a locale cookie to remember language choice, and a sidebar preference cookie in the dashboard. The retired outbound campaign no longer creates or reads attribution cookies.

We do not currently use third-party advertising cookies on DineMio. If we add non-essential analytics or marketing cookies that require consent, we will update the product and this policy accordingly.

7. Optional AI features

If a restaurant user uploads a floor-plan image for AI analysis, the image is sent to OpenAI to detect table positions and layout data. Use of this feature is optional. Do not upload floor plans or images containing information you are not permitted to process or share for this purpose.

8. International transfers

DineMio is operated from the Netherlands, but some providers may process data in other countries, including outside the European Economic Area. Where required, we rely on appropriate safeguards such as contractual protections, transfer mechanisms, and provider security commitments.

9. How long we keep data

We keep personal data for as long as needed for the purposes described in this policy, including to provide DineMio, comply with legal and accounting obligations, resolve disputes, enforce agreements, secure the service, and maintain backups.

  • Account and restaurant data is generally kept while the account or restaurant workspace remains active.
  • Guest and reservation data is kept for the restaurant workspace unless deleted, exported, or otherwise handled under the restaurant's instructions or legal obligations.
  • Payment records, invoices, and related checkout records are kept as needed for accounting, tax, chargeback, and fraud purposes.
  • Sales lead, outreach, suppression, unsubscribe, and attribution data is kept while relevant for sales operations, compliance, opt-out handling, and suppression hygiene.
  • Security logs, diagnostic data, and backups may be kept for shorter or longer periods depending on operational and security needs.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent and to complain to a data protection authority.

We do not sell personal information. We also do not share personal information for cross-context behavioral advertising as those concepts are commonly used in US state privacy laws. If that changes, we will update this policy and provide required choices.

To make a request, contact [email protected]. If your request concerns a reservation or guest profile held for a restaurant, we may need to forward the request to that restaurant or ask you to contact it directly.

11. Security

We use technical and organizational measures designed to protect personal data, including authentication, role-based access, rate limiting, secure transport, provider controls, monitoring, and access restrictions. No system is perfectly secure, so you should use strong passwords, limit team access, and keep account credentials private.

12. Children

DineMio is not directed to children. Restaurant guests may include children in party sizes or child-seat requests, but children should not create DineMio accounts.

13. Changes to this policy

We may update this policy as DineMio changes. The updated version will be posted at /privacy. If changes are material, we will take reasonable steps to notify affected users.