Privacy Policy
Effective date: 6 August 2026 · Riyadh, Saudi Arabia
This Privacy Policy explains how Dish N Dash, the operator of the dishndash.co website ("Dish N Dash", "we", "us"), collects and processes personal data. Browsing restaurants and reading menus requires no account and no personal data at all; personal data is collected only if you choose to create an account to save the places you like.
We process personal data in accordance with the Personal Data Protection Law of the Kingdom of Saudi Arabia (issued by Royal Decree No. M/19 dated 09/02/1443H, as amended) and its Implementing Regulations (together, the "PDPL"). For the purposes of the PDPL, Dish N Dash is the controller of the personal data described in this Policy.
1. Data we collect
Browsing this website — searching restaurants, reading menus, opening a venue page — requires no account, and we collect no identifying data from you to do it.
If you create an account, we collect only what the account needs to work:
- Account data: your mobile number, which is verified by one-time code (OTP). The codes themselves are never stored in readable form.
- Optional profile data: your name, email address, and the day and month of your birthday. We never ask for or store your year of birth.
- Optional dietary data: a dietary preference and any allergens you choose to tell us, so we can flag dishes that do not suit you. You supply this yourself, it is never required, and you can clear it at any time.
- Saved restaurants: which venues you have hearted, so your list is there on your next visit.
- Consent records: whether you accepted the terms, and whether you opted in to personalisation, each stored with the date and time.
- Technical and security data: your IP address, used for rate limiting and abuse prevention.
- Product analytics: pseudonymous, cookieless events about how the site is used — a search, a saved restaurant, a menu opened. These are tied to a pseudonymous account token (usr_xxxxxx), never to your name, email or number.
ALLERGEN AND DIETARY INFORMATION IS HEALTH-RELATED DATA and is treated as sensitive data under the PDPL. We collect it only where you volunteer it, only to mark dishes that may not suit you, and only with your explicit consent; you may delete it at any time without losing your account. Apart from that, we collect no sensitive data: no payment details, no national identification numbers, and no precise location.
2. Purposes and legal bases
We process personal data for the following purposes, on the following PDPL bases:
- Operating your account — verifying your mobile number, signing you in, and keeping your saved restaurants: processing necessary to provide the service you asked for.
- Service messages — sending the one-time code needed to sign in: necessary for the same purpose; these are not marketing.
- Personalisation — using the dietary preference and allergens you gave us to flag dishes that may not suit you: only with your explicit consent, which you may withdraw at any time.
- Security and abuse prevention — rate limiting and detecting automated sign-in attempts: our legitimate interest in operating a safe service, in the manner permitted by the PDPL.
- Improving the product — pseudonymous, aggregate statistics such as how many people searched and found nothing: legitimate interest; this data does not profile you individually.
- Legal compliance — retaining or disclosing data where a competent authority lawfully requires it.
3. Personalisation and withdrawal of consent
We do not currently send marketing messages of any kind. The only messages we send are the one-time codes you request in order to sign in.
You may withdraw your consent to personalisation at any time by emailing privacy@dishndash.co. Withdrawal is free of charge, takes effect promptly, and does not affect your account or your saved restaurants. If we ever introduce marketing messages, we will ask for your explicit, separate, un-preticked consent for each channel first.
4. Who we share data with
We never sell personal data, and we never share it with third parties for their own marketing. We share data only with:
- Service providers who process data on our documented instructions and under contractual confidentiality and data-protection obligations: website hosting and content delivery (Vercel), our database (Supabase), SMS verification (Twilio), and privacy-conscious, aggregate website analytics.
- Rating and review providers, in one direction only: we retrieve public restaurant ratings from Google and Tripadvisor to display them beside a venue. We ask those services about restaurants, never about you, and we send them no personal data.
- Public authorities, where disclosure is required by the laws of the Kingdom or by a binding order of a competent authority.
5. International data transfers
Some of our service providers store or process data on infrastructure outside the Kingdom of Saudi Arabia. Where personal data is transferred outside the Kingdom, we do so in accordance with the PDPL and the Data Transfer Regulations issued by the competent authority — limiting the transfer to the minimum data necessary, using reputable providers bound by contractual safeguards, and ensuring the transfer does not prejudice national security or the vital interests of the Kingdom.
6. How long we keep data
- Account data and saved restaurants: for as long as your account exists. Ask us to delete it and it is deleted or irreversibly anonymised.
- Dietary preferences and allergens: until you clear them or your account is deleted, whichever comes first.
- One-time verification codes: expire within minutes and are purged shortly after.
- Security logs (such as rate-limiting records): kept briefly — on the order of days — then deleted automatically.
- Data may be kept longer only where the laws of the Kingdom require it.
7. Your rights under the PDPL
Subject to the PDPL, you have the right to:
- Be informed about how we process your personal data (this Policy).
- Access your personal data and obtain a copy of it, free of charge.
- Request correction, completion, or updating of your data.
- Request destruction of your data when it is no longer needed for the purposes above.
- Withdraw your consent to consent-based processing (such as marketing) at any time.
To exercise any of these rights, email privacy@dishndash.co from the address you registered with, or include your registered mobile number so we can verify it is you. We respond within the timeframes required by the PDPL and its regulations. If you believe we have not handled your data properly, you also have the right to lodge a complaint with the competent authority in the Kingdom (the Saudi Data & Artificial Intelligence Authority — SDAIA).
8. How we protect data
- All traffic to and from the website is encrypted (HTTPS/TLS).
- Verification codes are never stored in readable form, and mobile numbers are masked in our operational logs.
- The database is locked behind row-level security: a public visitor can read no personal data at all — no names, emails, or phone numbers.
- Our own admin tools show a pseudonymous token (usr_xxxxxx) rather than your identity; resolving one to a person is a separate, owner-only action that is logged each time it happens.
- Access to personal data is restricted to what is strictly needed to run the service, protected by secret credentials that are never exposed to the browser.
- Rate limiting and anti-abuse controls protect the service and your data against automated attacks.
9. Cookies and similar technologies
This website uses no advertising cookies and no cross-site tracking. We use only what is needed to operate the site and measure it in aggregate: privacy-conscious, cookieless performance analytics, and one strictly necessary cookie that keeps you signed in if you create an account. You can control cookies through your browser settings; browsing restaurants and reading menus works with cookies disabled.
10. Children
Accounts are not directed at individuals under 18, and we do not knowingly collect their data. If you believe a minor has created an account, contact privacy@dishndash.co and we will remove the record.
11. Changes to this Policy
We may update this Policy from time to time. The current version, with its effective date, is always published at this address. If a change materially affects how we process your data, we will announce it on the website and — where required by the PDPL — seek your consent again.
12. Contact us
Controller: Dish N Dash, Riyadh, Kingdom of Saudi Arabia.
Privacy and data-protection requests: privacy@dishndash.co.
This Policy is governed by the laws of the Kingdom of Saudi Arabia. The Arabic version of this Policy is available on this website; in case of divergence, the Arabic version prevails.