Effective Date: August 21, 2026 | Last Updated: August 21, 2026
Operator: Akhtar’s IT Solutions (“AKITS”, “we”, “us”, “our”), the developer and operator of the DinePro platform available at scantodinepro.com and app.scantodinepro.com (together, the “Service”).
This Privacy Policy explains how we collect, use, disclose, and safeguard information when restaurants, their staff, and their diners use the Service. It is written to align with the EU/UK General Data Protection Regulation (GDPR/UK GDPR), Pakistan’s applicable data protection framework (including the Prevention of Electronic Crimes Act and the draft Personal Data Protection framework), and Google’s Platform and API Policies for services that use Google Analytics or Google-based tools. By using DinePro, you agree to the practices described in this Policy.
1. Who We Are and How to Contact Us
DinePro is operated by Akhtar’s IT Solutions (AKITS), based in Rawalpindi, Punjab, Pakistan. For all privacy-related questions, data subject requests, or complaints, you can reach us at:
- Email: privacy@scantodinepro.com (or support@akhtarsitsolutions.com)
- WhatsApp / Support: via the contact details listed on scantodinepro.com/get-in-touch
- Postal address: Rawalpindi, Punjab, Pakistan
Because DinePro is used by restaurants across multiple countries, including the EU and UK, AKITS acts as the data controller for account and business data collected directly through the Service, and generally acts as a data processor on behalf of restaurant customers with respect to end-diner data submitted through QR ordering (see Section 8).
2. Scope of This Policy
This Policy applies to:
- The marketing website at scantodinepro.com
- The DinePro web application at app.scantodinepro.com
- Communications between AKITS and restaurant customers, staff users, and diners interacting with DinePro-powered menus
It does not apply to third-party websites, plugins, or services that may be linked from the Service, including payment processors, which maintain their own privacy policies.
3. Information We Collect
3.1 Information You Provide Directly
- Account and business information: restaurant name, business address, tax/registration details, owner or manager name, email address, phone number, and password (stored in hashed form).
- Billing information: billing name, billing address, and subscription plan selection. Full card payment details for DinePro subscription billing are collected and processed directly by our payment processor, Stripe, and are never stored on DinePro’s own servers. (Cash, card, or wallet payments that a diner makes to a restaurant at the point of sale are handled through the restaurant’s own POS/payment arrangements and are not processed by DinePro.)
- Menu and operational content: menu items, prices, images, table layouts, and reservation settings that a restaurant uploads to configure its account.
- Communications: information you provide when contacting support, booking a demo, or corresponding with us by email or WhatsApp.
3.2 Information Collected from Diners (End Customers)
- Order details: items ordered, table number, order time, and special instructions submitted through QR/self-order menus.
- Reservation details: name, contact number, party size, and reservation time, where a diner books a table through the Service.
3.3 Information Collected Automatically
- Device and usage data: IP address, browser type, device identifiers, operating system, pages visited, referring URLs, and timestamps.
- Cookies and similar technologies: session cookies necessary for the platform to function, and analytics cookies described in Section 6.
- Log and diagnostic data: error logs, performance metrics, and API request data used to maintain platform stability and security.
4. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the DinePro platform, including order processing, table reservations, billing, and reporting features.
- Create and manage restaurant accounts and staff user permissions.
- Process subscription payments through our third-party payment processors and manage billing history.
- Send transactional communications, such as order confirmations, account notifications, and service updates.
- Send marketing communications where you have opted in, with an option to unsubscribe at any time.
- Monitor, analyze, and improve platform performance, security, and user experience, including through aggregated and de-identified analytics.
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms and Conditions.
- Comply with applicable legal, tax, and regulatory obligations.
5. Legal Basis for Processing (GDPR/UK GDPR)
Where the GDPR or UK GDPR applies (for example, where a restaurant customer or diner is located in the EU or UK), we rely on the following legal bases:
- Performance of a contract – to create and manage your account and deliver the Service you have subscribed to.
- Legitimate interests – to secure the platform, prevent fraud, and improve our product, balanced against your rights and freedoms.
- Consent – for optional analytics/advertising cookies and marketing communications, which you may withdraw at any time.
- Legal obligation – where processing is required to comply with tax, accounting, or law-enforcement requirements.
6. Cookies, Analytics, and Advertising
DinePro currently uses the following cookies and tracking technologies on scantodinepro.com and app.scantodinepro.com. We do not use any tracking tool that is not listed here, and we will update this section before adding a new one.
- Essential cookies: required for login sessions, security, and core site functionality. These cannot be disabled without affecting the Service.
- Google Analytics (GA4): used to understand traffic patterns and aggregate usage of the site. Data collected is processed by Google in accordance with the Google Privacy Policy.
- Meta Pixel (Facebook/Instagram): used to measure the performance of our marketing campaigns and, where enabled, for ad personalization/retargeting. Data collected is processed by Meta in accordance with the Meta Privacy Policy.
For visitors in the EU/UK and other jurisdictions where prior consent is legally required, Google Analytics and Meta Pixel scripts are not loaded until the visitor affirmatively consents through our cookie consent banner. Visitors who decline or do not respond will only receive essential cookies. This section is a description of our actual technical setup, and it is our responsibility to keep the live cookie-consent implementation in sync with it if analytics or advertising tools are added, removed, or reconfigured.
You can control cookies through your browser settings and through the cookie consent tool presented on first visit. You can also opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on, and manage Meta ad personalization through your Meta account’s ad settings.
In line with Google’s policies on user data, DinePro does not use Google Analytics data to identify individual users personally, does not sell Google user data, and limits the use of any Google API data to providing and improving user-facing features of the Service.
7. How We Share Information
We do not sell personal information. We share information only in the following circumstances:
- Service providers: our hosting provider, our payment processor (Stripe), and our analytics/advertising providers (Google Analytics and Meta Pixel), each bound by confidentiality and data protection obligations, and, for restaurants covered by our Data Processing Agreement, listed as sub-processors there.
- Restaurant customers: order, reservation, and contact data submitted by a diner is shared with the specific restaurant the diner is ordering from or booking with, as that restaurant is the data controller for its own diner relationships.
- Legal and safety reasons: where required to comply with a legal obligation, enforce our Terms, or protect the rights, property, or safety of AKITS, our users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality commitments consistent with this Policy.
8. Our Role as Processor for Diner Data
For personal data submitted by diners through a restaurant’s DinePro-powered ordering or reservation page (for example, a name or phone number left with a reservation), AKITS acts as a data processor on behalf of the restaurant, who is the data controller for that information. Diners with questions about how a specific restaurant uses their data should contact that restaurant directly. AKITS processes such data only as instructed by the restaurant customer, as necessary to operate the Service, and in accordance with our Data Processing Agreement (DPA), which forms part of our agreement with every Restaurant Customer and is available on request or at scantodinepro.com/dpa.
9. International Data Transfers
DinePro serves restaurants in Pakistan and internationally, including the EU and UK. Where personal data is transferred outside of the country in which it was collected (for example, to hosting infrastructure or sub-processors located in other jurisdictions), we take steps designed to ensure an adequate level of protection, including the use of Standard Contractual Clauses (SCCs) or equivalent safeguards recognized under GDPR/UK GDPR where required, and contractual data protection commitments with our infrastructure and processing providers.
10. Data Retention
- Account and business data: retained for as long as the restaurant maintains an active DinePro account.
- Order and reservation data: retained for as long as the restaurant’s account remains active. If a Restaurant Customer closes its account, or a diner contacts us directly to request deletion of their order/reservation data, we will delete that data upon verified request, in accordance with Section 11 below.
- Billing and financial records: retained for the minimum period required under applicable Pakistani tax and accounting law, and any additional period required under the law of a Restaurant Customer’s home jurisdiction where applicable. We are in the process of confirming the exact statutory retention period with our accountant and will update this figure here once confirmed, rather than state an unverified number.
- Analytics data (Google Analytics / Meta Pixel): retained according to the retention window configured in our Google Analytics and Meta Ads Manager settings. We commit to reviewing and disclosing the exact configured window here; in the interim, you may request it directly from us.
Except where a specific retention period is stated above, we do not retain personal data for longer than is necessary for the purpose it was collected, and we will delete or anonymize it once that purpose has been fulfilled, subject to any legal obligation to retain it for longer.
11. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you and request a copy of it.
- Correct inaccurate or incomplete personal data.
- Request deletion (“right to be forgotten”) of your personal data, subject to legal exceptions.
- Object to or restrict certain processing, including for direct marketing.
- Request data portability, where technically feasible.
- Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing.
- Lodge a complaint with your local data protection authority (for EU/UK users, your national supervisory authority; for users elsewhere, the relevant local regulator).
To exercise any of these rights, contact us using the details in Section 1. We will respond within the timeframe required by applicable law (generally within 30 days under GDPR).
12. Data Security
We implement administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including encryption in transit, access controls, and regular security reviews. Payment card data is handled exclusively by our PCI-DSS-compliant payment processors and is never stored in full on DinePro servers. No system can be guaranteed 100% secure, and we encourage users to safeguard their own account credentials.
13. Children’s Privacy
DinePro is intended for business use by restaurants and their staff, and for diners placing food orders. The Service is not directed at children, and we do not knowingly collect personal data from individuals under the age of 16 for account-holder purposes. If we become aware that we have inadvertently collected such data, we will take steps to delete it.
14. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party services (including payment processors and calendar/social integrations). We are not responsible for the privacy practices of those third parties, and we encourage you to review their respective privacy policies.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on this page with a revised “Last Updated” date, and where changes are material, we will provide additional notice (such as an email or in-app notification).
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Akhtar’s IT Solutions (AKITS) — Rawalpindi, Punjab, Pakistan
Email: privacy@scantodinepro.com / support@akhtarsitsolutions.com
Website: https://scantodinepro.com