What DineTracer collects, how we use it, and the choices you have.
DineTracer ("we", "us") runs a business-to-business service for suppliers who sell to U.S. restaurants and food businesses. It turns public records, such as liquor licenses, building and food-service permits, health inspections and business registrations, into sales leads.
This policy covers three groups of people:
Leads describe businesses. They come from public government records and the business's own public information. We add details such as phone number, website and hours from Google business listings and the business's own website.
Some leads name a person. Public licenses and business-registration filings often list an owner, principal or registered agent, and a lead can show that name and role. Building permits can also name contractors, architects, property owners or applicants.
Owner and agent contact. For records in our restaurant database, we send the business name and state to a data provider, FastAppend. FastAppend looks up the people tied to that business in public business-registration filings and returns their names, roles, phone numbers and email addresses. These can be personal phone numbers and email addresses. We only show a match we can tie to the business, and we show at most one person per business: their name, role, one phone number and one email address.
Removing your information. If you're named in a lead and want your name or contact details removed, email [email protected] with the business name and address. We'll remove them and stop looking them up. We can't recall copies customers already downloaded.
If you sign in with Google, we ask for the openid, email and
profile scopes. We keep only your verified email address, and we use it only to
create your DineTracer account and sign you in. Our use and transfer of information received
from Google APIs follows the
Google API Services User Data Policy,
including the Limited Use requirements. We don't use Google user data for advertising, and we
don't sell it.
We don't sell or share your account information. The leads we sell can include names and contact details of business owners and registered agents (see Section 3).
We use these service providers to run DineTracer. Each gets only what its job needs:
If you add a webhook to a Monitor, we send that Monitor's new leads to the address you entered. We may also disclose information when the law requires it, to protect our rights or people's safety, or as part of a merger or sale of the business.
We keep your account information while your account is open. You can delete your account yourself on the Account page, or email us and we'll do it.
When you delete your account, we remove: your email address (replaced with a placeholder), your password, your name and occupation, your webhook and email settings, your home state, your two-step sign-in and API keys, your sign-in location and IP codes, and any internal support notes about you. Your Monitors and their delivery records are deleted, your invite link stops working, every session ends, and unused credits are lost.
We keep: records of your purchases and unlocks, with your email removed, for accounting and fraud prevention; which account invited which, by account number only, next to the referral credits it explains; a one-way code made from your email address and from the network you signed up on, so the same email can't claim free starter credits twice; and our log of account actions, such as the deletion itself. Stripe keeps its own payment records under its own policy.
Backups and logs. Our encrypted database backups roll over, so deleted information can stay in them for up to three weeks. Our web server's access logs, which include IP addresses and the pages requested, are kept for up to 90 days. Application logs, which record errors and security events and can include an IP address, are removed as they reach a size limit.
We use HTTPS, store passwords and recovery codes only as one-way hashes, check sign-ins for bots, offer two-step sign-in, limit each account to its own data, and encrypt our backups. No system is perfectly secure, but we work to protect your information.
You can see and update most of your account information on the Account page. You can also ask us what personal information we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. This includes people named in leads. Email [email protected] from the email address on your account, or, if you're named in a lead, with the business name and address. We may need to confirm who you are before we act, and we aim to respond within 45 days. You can have someone you authorize make a request for you. We won't treat you differently for making a request.
Depending on where you live, your state's law may give you more rights. We don't sell or share your account information.
We use a session cookie to keep you signed in. If you open a customer’s invite link, we set a
cookie holding only their invite code for 30 days, so we can credit them if you sign up and buy
credits. We use Google Analytics 4 to see how the site
is used. It sets its own cookies (such as _ga). We turn off its advertising features
and Google signals, and we remove the query part of each page address before it's sent, since
one-time links and searches can appear there. The password-reset, email-confirmation and
two-step sign-in pages send nothing to Google Analytics. Our site does not respond to browser Do Not Track signals.
DineTracer is a business tool for people 18 and older. It isn't meant for children, and we don't knowingly collect information from them.
If we change this policy, we'll update the "Last updated" date above. For a significant change, we'll also take reasonable steps to tell you, such as an email or a notice in the app.
Questions about this policy or your information? Email [email protected].