Privacy
Last updated 1 August 2026
dish.ly holds your restaurant's takings, your customers' phone numbers and your staff's accounts. This page says plainly what we store, where it lives, who can reach it and how long we keep it, no defined terms, no clauses that need a lawyer.
What we store
For the restaurant: your restaurant's name, address, phone, logo, tax registration numbers (NTN and STRN), your menu, your tables, and the email address and hashed password of every staff account you create.
For your trade: every order, its line items, the tax charged, how it was paid, refunds, shift and cash-drawer records, and your audit log of who did what.
For your customers: only what you enter about them. If you use khata, that is typically a name, a phone number, sometimes an address, plus their credit ledger. Guests who order by scanning a table QR code are anonymous, they get a random session cookie and are never asked to identify themselves.
We do not store card numbers. dish.ly records how a customer paid; it does not process payments, and no card details ever reach it.
Where it's stored
In a single PostgreSQL database hosted by Neon, in their US East region, encrypted at rest and in transit. Dish photos and logos are stored in that same database rather than a separate file service.
The application runs on Render. Email (verification, password resets and staff invites) is sent through Resend. Those three companies are the only third parties that touch your data.
Who can see it
Your staff, according to the role you give them. Owners and managers see the admin panel and reports; waiters see the till and the order board.
No other restaurant, ever. Every query is scoped by restaurant, so one restaurant's data is not reachable from another's account.
Us, only when we need to. Operating the platform means we can technically reach the database. That is unavoidable for anyone who hosts software for you. We look at your records when you ask us to help with a problem, or where we are legally required to. We do not sell data, share it with advertisers, or use your trade figures for anything but running your account.
How long it's kept
For as long as your account exists. Your books are a business record. You may need them for tax years after the fact, so we do not quietly delete them.
If your subscription lapses, your account becomes read-only: you keep full access to everything you have entered and can still export it. Nothing is deleted for non-payment.
Ask us to delete your restaurant and we will, permanently, along with its orders, customers and images. Export your books to CSV first, once it's gone we cannot get it back for you.
Backups
The database is backed up nightly and backups are kept for 90 days. They exist so your records survive a mistake or a failure. A deletion request removes your data from the live database immediately; copies inside existing backups age out with those backups.
Cookies
Only ones the site needs to work: a signed session cookie so staff stay logged in, an anonymous session cookie so a guest can see the order they just placed, and a cookie remembering whether you chose light or dark.
There is no analytics, no advertising, and no third-party tracking on dish.ly.
Security
Passwords are hashed with bcrypt and are not recoverable, not by us either. Sessions are signed tokens in httpOnly cookies that expire after twelve hours, and changing a password signs out every other device immediately.
Repeated failed logins lock an account for ten minutes. Uploaded images are re-encoded server-side, which strips embedded metadata such as camera location.
If we ever discover a breach affecting your data, we will tell you what happened and what was exposed. We would rather deliver bad news than have you find out elsewhere.
Your rights
Ask us for a copy of your data, a correction, or its deletion, and we will act on it. Most of it you can already get yourself: the books export to CSV and reports print to PDF from inside the app, without asking anyone.
Questions about this?
Get in touch and a person will answer. You can also read the pricing page, which covers billing in plain language.