Privacy Policy

Last updated: January 2026

  1. Introduction

    This Privacy Policy explains how &Dine Limited collects, uses, shares, and protects personal data when you interact with our website, platform, and services.

    &Dine operates a two-sided marketplace connecting businesses, individuals, and independent food Makers. Depending on how you use &Dine, we may act as a data controller, data processor, or joint controller under UK data protection law.

    This Privacy Policy should be read alongside any additional notices provided at the point we collect personal data.

  2. Who we are

    &Dine Limited

    Registered address: Beyond, Fox Court, 14 Gray’s Inn Road, London, WC1X 8HN

    Email: hello@anddine.co.uk

    For the purposes of UK data protection law, &Dine Limited is responsible for ensuring personal data is processed lawfully.

  3. Our role in relation to your data

    Corporate customers

    When a company creates an organisation account on &Dine, that company acts as the data controller for the personal data of its employees uploaded to or managed within the account.

    This typically includes names, work email addresses, telephone numbers, and role or permission information.

    In these circumstances, &Dine acts as a data processor and processes personal data only on the instructions of the company and for the purpose of providing the &Dine service.

    Where a company asks &Dine to assist with onboarding by uploading employee details on its behalf, the company remains responsible for ensuring it has a lawful basis to share that data with us.

    Employee users within a company account

    Employees invited to use &Dine through their employer generally use the platform as part of their employer’s account.

    For account administration and ordering:

    • the employer acts as data controller
    • &Dine acts as data processor

    Where an employee manages their own profile, selects dietary preferences or allergens, interacts directly with Makers, or opts into communications from &Dine, &Dine may act as a joint controller or independent controller for those specific activities.

    Individual and guest users

    Individuals may use &Dine outside of a company account, including guest users and individuals ordering food for personal use or delivery to residential addresses.

    In these cases, &Dine acts as the data controller for personal data processed in connection with account creation, ordering, payment, delivery coordination, and support.

    All users, including guest users, are subject to &Dine’s Terms of Service and this Privacy Policy.

    Makers and suppliers

    &Dine acts as a data controller for personal data provided by or about Makers and their authorised users. This may include business contact details, login credentials, and communications.

    Where Makers ask &Dine to assist with onboarding using information they provide, we process that data for the purpose of operating the marketplace and based on their instructions.

  4. Food preferences and special category data

    Users may optionally provide information relating to:

    • allergens
    • dietary preferences
    • religious dietary requirements
    • intolerance-related information

    This information is used solely to fulfil food orders safely and accurately. It may be visible to Makers, employers, and relevant guests where necessary to deliver the service.

    Where this information qualifies as special category data, we process it on the basis of explicit consent or because it is necessary to provide the service requested.

    Users can update or remove this information at any time.

  5. What personal data we collect

    Depending on how you interact with &Dine, we may collect:

    Identity and contact data

    • Name
    • Work or personal email address
    • Telephone number
    • Job title or role where relevant

    Account and usage data

    • Login credentials
    • Role and permission level
    • Order history and preferences
    • Communications with us

    Food-related data

    • Dietary preferences
    • Allergens
    • Other food-related requirements provided voluntarily

    Transactional and billing data

    • Order values
    • Payment status
    • Invoice references
    • Billing and delivery addresses

    Delivery data

    • Delivery instructions
    • Proof of delivery records (including photographs)

    Technical data

    • IP address
    • Browser type and version
    • Device and operating system information
    • Usage and interaction data

    We do not knowingly collect data about children.

  6. How we collect personal data

    We collect personal data:

    • directly from you when you create an account, place an order, or update your profile
    • from your employer when they create or manage an organisation account
    • from Makers during onboarding and ongoing account use
    • automatically through use of our website and platform
    • through third-party tools used to operate our business, such as CRM and support systems

    Where personal data is provided by a third party, they are responsible for ensuring they have a lawful basis to do so.

  7. How we use personal data

    We use personal data where permitted by law, including where:

    • it is necessary to perform a contract
    • it is necessary for our legitimate business interests
    • we are required to comply with a legal obligation
    • you have given consent

    We use personal data to:

    • operate and manage the &Dine platform
    • administer accounts, permissions, and access
    • process and fulfil food orders
    • coordinate and confirm deliveries
    • communicate with users, customers, Makers, and delivery partners
    • manage billing, invoicing, and payments
    • improve products and services
    • ensure platform security and prevent fraud
    • meet legal, tax, and regulatory obligations

    Where personal data is shared with delivery partners, processing is necessary for the performance of a contract and for our legitimate interest in fulfilling orders, preventing fraud, and maintaining service quality.

  8. Payments

    &Dine does not store or process card details.

    Payments are handled by third-party payment providers such as Stripe or via bank transfer. These providers process payment information independently and securely.

    &Dine receives only transactional data such as payment status, amounts, and references necessary for accounting, reconciliation, and support.

    Billing and delivery addresses may be stored at account or company level where required to fulfil orders and manage invoicing.

  9. Marketing and communications

    We may send communications about &Dine where permitted by law.

    Where we communicate with users at work, this is generally treated as communication with the organisation. You can opt out at any time.

    Where consent is required, we will only send marketing communications with your consent. You can withdraw consent or opt out at any time.

    We do not sell personal data to third parties for marketing purposes.

  10. Delivery partners and proof of delivery

    To fulfil food orders, &Dine shares limited personal data with third-party delivery partners via secure integrations and APIs. This typically includes the delivery address, contact name, telephone number, and any delivery instructions required to complete the drop-off.

    Delivery drivers may access this information only for the purpose of completing the delivery and only for the duration necessary to do so.

    As part of delivery confirmation, drivers may upload proof of delivery, which can include photographs of the food being handed over or left at a delivery location. These images may incidentally include individuals or personal surroundings. Proof of delivery is used solely to confirm fulfilment of an order, resolve disputes, and maintain service quality.

    Depending on the delivery partner and service model, delivery partners may act as data processors on behalf of &Dine or as independent data controllers. Where required, appropriate contractual and data protection safeguards are in place.

    Delivery data is not used for marketing purposes and is retained only in line with operational and legal requirements.

  11. Data sharing

    We may share personal data with trusted third parties where necessary to operate our services, including:

    • payment providers
    • hosting and infrastructure providers (such as AWS)
    • CRM and customer support platforms (such as HubSpot)
    • delivery partners
    • professional advisers

    All third parties are required to process data securely and only in accordance with applicable data protection laws and contractual safeguards.

    We may also disclose data where required by law or in connection with a business sale, investment, or restructuring.

  12. International data processing

    &Dine uses infrastructure and service providers based in the UK, EU, and US.

    Members of our technology team and contractors may access systems from outside the UK, including Serbia. All access is limited, monitored, and subject to confidentiality and contractual safeguards.

    Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including standard contractual clauses or equivalent protections.

  13. Data security

    We implement appropriate technical and organisational measures to protect personal data, including access controls, secure infrastructure, and confidentiality obligations.

    You are responsible for keeping your account credentials confidential. We will never ask you for your password.

  14. Data retention

    We retain personal data only for as long as necessary to:

    • provide our services
    • meet legal, accounting, and tax requirements
    • resolve disputes
    • enforce agreements

    When data is no longer required, it is securely deleted or anonymised.

  15. Your rights

    You have rights under UK data protection law, including the right to:

    • access your personal data
    • correct inaccurate or incomplete data
    • request deletion
    • restrict or object to processing
    • request data portability
    • withdraw consent where applicable

    Where &Dine acts as a data processor on behalf of a company, requests should usually be directed to that company.

  16. Cookies

    We use cookies and similar technologies to operate and improve our website and platform. Details are set out in our Cookie Policy.

  17. Changes to this policy

    We may update this Privacy Policy from time to time. The most recent version will always be available on our website and clearly dated.

  18. Contact

    If you have any questions about this Privacy Policy or how we handle personal data, contact us at:

    &Dine Limited

    Beyond, Fox Court, 14 Gray’s Inn Road, London, WC1X 8HN

    Email: hello@anddine.co.uk

    You also have the right to complain to the Information Commissioner’s Office.