Legal

DineDash Privacy Policy

Last updated: July 21, 2026

This Privacy Policy is subject to change. We will post any updates on this page and revise the date above; material changes will also be announced by email or in-app notice before they take effect.

1. Who this policy covers

This Privacy Policy explains how DineDash LLC ("DineDash," "we," "us") collects, uses, shares, and protects personal information when you use dinedash.io and our mobile apps (the "Platform"), whether you're a diner, a home cook, or a visitor. It applies to all users nationwide. Section 13 below adds rights that apply specifically if you live in a state with its own comprehensive privacy law.

2. Information we collect

Information you give us directly: Account information (name, email, phone number, password, profile photo); delivery and pickup addresses; order details including allergen notes you choose to add; messages sent through in-app chat; payment details (DineDash does not store your full card number — payment processing runs through Stripe); if you're a home cook: kitchen address, business details, government-issued ID for identity verification, food handler certification where required, bank/payout details via Stripe Connect, tax information, and photos of your food and kitchen; reviews, ratings, and support requests.

Information collected automatically: Device and browser information; approximate location (from IP address) and, if you grant permission, precise device location, used to find nearby cooks and estimate delivery; usage analytics that may be associated with your account; crash and error reports used only to fix bugs; cookies and similar technologies (Section 8).

Information from third parties: Basic profile information if you sign in through Google or another identity provider; address/location suggestions from Google's mapping service; delivery status from courier partners if used for your order.

Sensitive information: Precise geolocation, government ID (for cook verification), financial account details (for cook payouts), and any health-related information you choose to disclose (like an allergy note) are treated as sensitive personal information under state law. We use this only for the specific purposes below and never for advertising.

3. How we use your information

Operating the marketplace (processing orders, payments, cook payouts; connecting diners with cooks; facilitating pickup and delivery); verifying cook identity and eligibility under applicable state home-kitchen/cottage-food laws; communicating with you about orders, your account, and support; safety and trust (fraud prevention, dispute resolution, content moderation); sending service updates and, only if you opt in, marketing messages; improving the Platform through aggregated, de-identified analytics; legal compliance (tax reporting, food-safety recordkeeping, lawful requests); sending legally required notices such as a safety alert affecting a dish you've ordered. We do not use sensitive personal information, precise location, or health-related information to build advertising profiles.

4. How we share information

DineDash does not sell personal information, and we do not share it with data brokers or advertising partners. The only sharing that occurs is what's necessary to run the Platform: service providers under contract, limited to the purpose specified (Stripe for payments and cook payouts, our database/hosting infrastructure, our email provider, Google for maps/location autocomplete and optional sign-in, error-monitoring tooling, and courier partners for delivery logistics); other users only as needed to complete a transaction; legal and safety reasons (subpoena, court order, fraud investigation, protecting anyone's safety, public-health/food-safety authorities); and business transfers if DineDash is acquired or merges with another company.

5. Data retention

We keep personal information only as long as your account is active, and after that only as long as needed for tax and food-safety recordkeeping, dispute resolution, or fraud prevention as required by law.

6. Security

We use industry-standard safeguards including encrypted connections, access controls, and Stripe's PCI-compliant payment infrastructure. No system is completely secure. If you believe your account has been compromised, contact [email protected] immediately.

7. Analytics

We use product analytics (PostHog) and error monitoring (Sentry) to understand how the Platform is used and to fix problems. These tools may associate activity — such as pages viewed or an order being placed — with your account. We do not use this data for advertising, we do not sell it, and we do not share it with advertising partners. You can request a copy or deletion of this data using the rights described in Section 12.

8. Cookies and tracking technologies

We use cookies to keep you signed in, remember your preferences, and support aggregate analytics. We do not use cookies for cross-site advertising. We honor recognized opt-out preference signals, including the Global Privacy Control (GPC).

9. Children's privacy

DineDash is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from children; if we learn we have, we delete it. Contact [email protected] if you believe a minor has provided us information.

10. Loyalty and rewards programs

If you participate in a DineDash loyalty, stamp, or gift card program, we use your order history to calculate and apply rewards. Participation is optional.

11. Do Not Track

DineDash does not currently respond differently to browser "Do Not Track" signals, but does honor the Global Privacy Control as described in Section 8.

12. Your privacy rights (all users, nationwide)

You can access a copy of your personal information; correct inaccurate information; delete your account and associated personal information, subject to legal retention needs; opt out of marketing emails and push notifications while continuing to receive transactional order updates; and withdraw consent for anything consent-based, such as precise location access.

How to exercise these rights: Use Settings → Privacy in the app, or email [email protected]. We verify your identity before fulfilling access or deletion requests and respond within the timeframe required by applicable law — generally within 45 days, extendable once by an additional 45 days for complex requests.

Appeals: If we deny your request, you may appeal by replying to our denial email. If we uphold the denial, you may file a complaint with your state Attorney General.

Authorized agents: You may designate an authorized agent to submit a request for you; we may require proof of authorization and separately verify your identity.

Non-discrimination: We will never deny you service, charge a different price, or provide a different level of service because you exercised a privacy right.

13. Additional state-specific disclosures

More than twenty states now have their own comprehensive consumer privacy laws, including California, Colorado, Connecticut, Virginia, Utah, and a growing list of others. Most provide the rights in Section 12, plus data portability; opt-out of sale, sharing, and targeted advertising (DineDash does not engage in any of these, but will honor the right immediately if that changes); the right to know specific categories of third parties we've shared information with in the past 12 months (Section 4); and limits on sensitive personal information to what's reasonably necessary to provide the service.

California residents additionally have rights under the CCPA/CPRA, including the right to know whether we've disclosed sensitive personal information for any purpose beyond limited business purposes (we have not), and rights under California's "Shine the Light" law (Civil Code § 1798.83) regarding disclosure to third parties for their own direct marketing (we do not do this).

Nevada residents have the right to opt out of the sale of "covered information," which does not apply here since DineDash does not sell personal information — you may still submit a request to be recognized on our do-not-sell list at [email protected].

Virginia, Colorado, Connecticut, Utah, and residents of every other state with a comprehensive privacy law have the rights described in Section 12 under their state's law (e.g., VCDPA, Colorado Privacy Act, Connecticut Data Privacy Act, Utah Consumer Privacy Act, and comparable statutes elsewhere).

DineDash is not a data broker and is not required to register as one in any state.

14. International users

DineDash currently operates only in the United States, and this policy is written for U.S. users only.

15. Changes to this policy

We may update this Privacy Policy at any time. Material changes will be announced by email or in-app notice before they take effect, and the "Last updated" date above will reflect the most recent revision.

16. Contact us

Email: [email protected]
For general support, use the in-app Help/Support section or contact [email protected].
Administrative correspondence: [email protected].
Phone: +1 (757) 354-3428.

Mailing address (registered agent — not a DineDash-operated office):
DineDash LLC
c/o Registered Agents Inc, 7533 S Center View Ct, Ste R, West Jordan, UT 84084

To exercise any of the rights described above, visit Settings → Privacy or email [email protected].
Refunds, cancellations, and disputes are governed by our Refund & Cancellation Policy.