Privacy Policy
Last updated: July 2026
1. Who we are
dishGO is a trading name of COMPERA LTD, a company registered in England and Wales with company number 12265681.
Our registered office is at 284 Chase Road A Block 2nd Floor (Take Account), London, England, N14 6HF. You can contact us about privacy matters at privacy@dishgo.uk or by phone at +44 7503 695000.
We operate the dishGO platform (website and APIs) and the dishGO Business mobile app for restaurant owners. The platform enables takeaway restaurants to create online ordering pages and allows customers to place orders directly with those restaurants.
For UK GDPR purposes, COMPERA LTD (dishGO) is a controller for restaurant accounts, platform security, fraud prevention, payments infrastructure, and legal compliance. The restaurant is the controller for customer order and fulfilment data it receives to prepare and deliver orders. dishGO acts as a processor when handling fulfilment data on the restaurant’s instructions, and as an independent controller for its own security, payment, and compliance purposes. We do not treat these roles as joint controllership unless a specific activity requires it.
2. What this policy covers
This privacy policy explains how we collect, use, store, and share personal data when you use dishGO services. It applies to:
- Business users who register and manage a restaurant on the web dashboard
- Business users of the dishGO Business iOS app (order management companion)
- Customers who place orders through dishGO-powered storefronts
- Visitors who browse the website or marketing pages
3. Personal data we collect
Business users (web and dishGO Business app)
When you register or use the business tools, we collect:
- Account details — name, email address, password
- Business information — restaurant name, address, phone number
- Payment account details — Stripe Connect account information for receiving customer payments
- Menu and operational data — menu items, prices, images, opening hours
- Device and push data (mobile app) — an installation identifier stored on the device, and a push notification token so we can alert you to new paid orders
- Operational product interaction — authenticated actions needed to run the service (for example order-status changes and settings updates), retained as part of providing the platform. We do not run separate advertising or behavioural analytics SDKs in the Business app
Customers
When you place an order, we collect:
- Contact details — name, email address, phone number
- Delivery address and related location hints (for delivery orders)
- Order details — items ordered, amounts, fulfilment mode, notes
- Payment information — processed securely by Stripe; we do not store full card details
Restaurant staff may see customer fulfilment details in the web dashboard and in the dishGO Business app so they can prepare and deliver orders.
Website visitors
When you browse the site, we may collect:
- Device and browser information
- IP address
- Pages visited and usage patterns
- Cookies and similar technologies (see our Cookie Policy)
4. How and why we use your data
We process personal data for the following purposes:
To provide the service (contractual necessity)
- Creating and managing business accounts
- Processing and fulfilling orders
- Facilitating payments between customers and restaurants
- Communicating order updates and confirmations by email
- Sending push notifications to the dishGO Business app about new paid orders and related kitchen events
To operate and improve the platform (legitimate interests)
- Maintaining platform security and preventing fraud
- Understanding limited website usage where cookies or similar technologies apply (see our Cookie Policy)
- Providing customer and business support
To comply with legal obligations
- Tax and financial reporting requirements
- Payment disputes, chargebacks, and fraud investigations
- Responding to lawful requests from authorities
With your consent
- Sending marketing communications (where consent is obtained)
- Setting non-essential cookies (see our Cookie Policy)
5. Who we share data with
We share personal data with service providers and partners only where needed to operate dishGO:
- Restaurants — customer order details and contact information are shared with the restaurant fulfilling the order
- Stripe — payment processing and Stripe Connect for restaurant payouts (card data is handled by Stripe under its own privacy policy)
- Supabase — authentication, database, and realtime infrastructure
- Vercel — website and API hosting
- Resend — transactional email delivery (for example order confirmations and account emails)
- Expo Push Service — routes push notifications from our servers to Apple devices
- Apple Push Notification service (APNs) — delivers notifications on iOS for the dishGO Business app
- Google Maps / Places — where the website uses address lookup or map features, the address you enter and related request data (such as IP address, device/browser information, and service identifiers) may be transmitted to Google. Google’s use of that data is governed by the Google Privacy Policy and Google Maps/Google Earth Additional Terms of Service. The dishGO Business iOS app does not embed the Google Maps/Places SDK
We do not sell personal data. We only share data with third parties where necessary to provide the service, comply with the law, or with your consent.
6. Data retention
We retain personal data for as long as needed to provide the service and fulfil the purposes described in this policy:
- Business accounts — retained while the account is active. After account deletion (see section 7), login access and public storefront content are removed; limited anonymised financial and legal records may remain as described below
- Order financial data — the minimum anonymised financial archive (amounts, fees, Stripe identifiers, refunds, dispute-related fields, payment ledger entries, and related snapshots) is retained for up to 7 years, calculated from the relevant financial or order record date where possible (not blindly from the account deletion date), subject to applicable law. Open disputes, investigations, or legal holds may extend retention. We do not retain that archive indefinitely unless a legal hold is active
- Customer fulfilment details — name, email, phone, delivery address, notes, and similar fields are retained while the order is active for fulfilment, then anonymised (about 90 days after completion or cancellation for ordinary orders, and as part of restaurant account deletion). Anonymised orders keep financial totals but no longer identify the customer
- Push tokens and installation IDs — retained while the device is registered; removed or disabled on logout, unregister, or account deletion
- Website cookies / similar technologies — as described in our Cookie Policy
7. Account deletion (business users)
Business users can delete their dishGO account from the dishGO Business app (Settings → Delete account) or via the web account controls. Deletion is selective:
- Your login is removed and you can no longer sign in
- Your public storefront is closed and menu, images, and operational profile content that are not required for legal or financial records are removed or anonymised
- Push devices and tokens for your account are removed
- Customer fulfilment personal data on your orders is anonymised
- Limited payment, tax, and dispute-related records (including order financial fields, payment ledger entries, and Stripe Connect history needed for reconciliation) may be retained where required for accounting, fraud prevention, chargebacks, or law
If an open payment dispute prevents completing Stripe disconnect at the moment of deletion, your login and storefront are still closed immediately; remaining financial cleanup may finish when the dispute is resolved. For privacy rights requests outside account deletion, contact privacy@dishgo.uk.
8. Cookies and similar technologies
We use cookies and similar technologies to operate the platform and improve your experience. For full details, including the types of cookies used and how to manage your preferences, please see our Cookie Policy.
9. International transfers
Our primary infrastructure is hosted within the EU/EEA. Where data is processed outside the UK or EEA (for example, by third-party service providers such as Apple, Expo, or email infrastructure), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or adequacy decisions, in line with UK GDPR requirements.
10. Your rights
Under UK data protection law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (where applicable)
- Object to or restrict certain processing
- Request data portability
- Withdraw consent at any time (where processing is based on consent)
Business users can also use in-app or web account deletion (section 7). To exercise any of these rights, contact us at privacy@dishgo.uk. We will respond within one month.
11. Children
dishGO is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Complaints
If you are unhappy with how we handle your personal data, please contact us first at privacy@dishgo.uk and we will do our best to resolve your concern.
You also have the right to complain to the Information Commissioner’s Office (ICO), the UK’s data protection authority:
- Website: ico.org.uk
- Phone: 0303 123 1113
13. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated through the platform or by email where appropriate. The “Last updated” date at the top of this page indicates when it was most recently revised.
14. Contact us
For privacy-related enquiries:
- Email: privacy@dishgo.uk
- Phone: +44 7503 695000
- Post: COMPERA LTD, 284 Chase Road A Block 2nd Floor (Take Account), London, England, N14 6HF