Privacy Policy
This page explains in detail what data we collect, why we collect it, who we share it with, how long we keep it, and how you take back control of it. It was written to be read, not signed.
30 July 2026
1. Introduction and scope
This policy explains how the Dexel platform collects, uses, stores, and protects personal data, when it is shared, and what your rights are. It applies to our marketing site (deuxel.com), to the restaurant owner dashboard, and to the digital menu pages we publish for restaurants under the /r/ path.
We use “personal data” in its broad sense: any information that identifies a natural person, or that can be linked to them — such as a name, phone number, email address, or delivery address.
Reading this page places no obligation on you. Using the platform — by registering as a restaurant owner, or by browsing a restaurant's menu and placing an order — means you have read this policy and understand how your data is handled.
2. Who we are, and who is responsible for your data
Dexel is a digital menu platform for restaurants and cafés. Our website is deuxel.com, and our contact address for privacy matters is info@deuxel.com.
It matters that we play two different roles, because the party you should approach with a request differs between them:
- Restaurant owners' data: we are the controller. You create the account with us directly, and we decide the purposes for processing account and subscription data.
- Restaurant customers' data: the restaurant is the controller and we process it on its behalf. When you place an order from a restaurant's menu you are dealing with that restaurant; our role is technical — delivering the order to it and storing it in its account.
So if you are a restaurant's customer and want an order's data accessed or deleted, the shortest route is to contact that restaurant; you may also contact us, and we will help the restaurant carry out your request.
3. Definitions used in this policy
- “The platform”: the whole Dexel service — the website, the owner dashboard, the admin panel, and the menu pages.
- “Owner”: the holder of a subscribed account who manages one or more restaurant menus.
- “Customer” or “visitor”: anyone who opens a restaurant's menu page, whether they place an order or only browse.
- “Controller”: the party that decides why and how data is processed. “Processor”: the party that processes it on the controller's behalf and on its instructions.
4. The data we collect
We collect the minimum the service needs in order to work, and we do not ask for data we do not use. In detail, by type of user:
a) Owner account data
- The owner's name and phone number — the phone number itself is the basis of login.
- The restaurant's name and its URL identifier (slug), and the number of branches if any.
- The password, stored **hashed** at our authentication provider; we neither see it nor can retrieve it.
- Subscription data: plan, trial and renewal dates, account status, and the administrative event log on the account.
b) Restaurant content
- Categories, dishes, prices, descriptions, options, add-ons, and tags.
- Images and videos uploaded for the menu, the cover, and the branding.
- Restaurant settings: the receiving WhatsApp number, contact phone, currency, VAT, working hours, and social links.
Most of this is not personal data, but it does include contact numbers the restaurant chooses to show its guests, and we protect it in the same way.
c) Order data from restaurant customers
- A name if requested, and the order type (dine-in, pickup, or delivery).
- A table number for dine-in, or a delivery address and phone number for delivery.
- The ordered items, their quantities and options, any note the customer writes, and the total amount.
- A star rating and its note if the customer chooses to rate their experience — visible to the restaurant only, never published.
We ask customers for no payment data, no card numbers, and no account registration. The order is sent to the restaurant to be fulfilled and paid for there.
d) Usage and performance data
- Aggregate usage events on the menu page: a page visit, a dish view, adding a dish to the cart, completing an order — used for that restaurant's own statistics.
- Technical error reports when something breaks: the error type and its location in the code, plus general browser and device information.
Error reports pass through **automatic scrubbing before they leave your browser**: WhatsApp links and any long run of digits that could be a phone number are removed, and we do not use session replay at all — nothing “records” a customer's screen or the contents of their order.
e) What we do not collect
- We do not collect payment card data and it does not pass through our systems.
- We do not use advertising cookies, we do not build advertising profiles of visitors, and we do not sell data to anyone.
- We do not collect the device's precise location, nor do we request permission for it.
- We do not ask for sensitive data (health, religious, political), and it must not be entered into menu or order fields.
5. Where this data comes from
- Directly from you: when registering, entering your menu, filling in the contact form, or completing an order.
- From your use of the platform: the aggregate events and error reports described above.
- From the restaurant: if an owner grants you access or enters data about your order on your behalf.
- Automatically from your browser: the technical data any browser sends to any site (browser type, and the IP address seen by our hosting providers).
6. Why we use the data
- To run the service: displaying the menu, completing and delivering orders to the restaurant, and managing accounts and subscriptions.
- For authentication and security: verifying an owner's identity and preventing unauthorised access to anyone else's data.
- To give owners their statistics: visitors, best-selling dishes, and menu performance.
- To improve the platform and fix bugs, using the scrubbed error reports.
- To communicate with you: replying to your enquiry, or notifying you about your account or subscription.
- To comply with the law: invoices and legally required records, and responding to a binding official request.
We do not use one restaurant's customer data for another restaurant, nor for our own marketing, nor to train systems at the expense of the data's owners.
7. Legal basis for processing
Each processing activity rests on one of the following bases:
- Performance of a contract: what is necessary to deliver the service you subscribed to or the order you placed.
- Legitimate interests: platform security, abuse prevention, and performance improvement — where these do not override your rights.
- Consent: where it is explicitly requested; you may withdraw it at any time, without affecting lawful processing that already took place.
- Legal obligation: where a law or competent authority requires us to retain or disclose data.
Because the platform operates from, and mostly serves, the Kingdom of Bahrain, we work within its applicable personal data protection law, and we apply the same principles to restaurants elsewhere in the Gulf.
8. Cookies and on-device storage
We use no advertising or third-party marketing cookies. What we do use is local storage in your browser that the service needs in order to function:
- Login session: an owner's session is kept so they are not asked to log in on every page.
- Your chosen language and interface direction.
- The current cart on a restaurant's page, so it is not lost if you refresh.
- One-time display flags: for example showing a featured dish, or the page's opening sequence once per session.
- A file cache (service worker) that speeds up page loads and keeps the page usable on a weak connection.
You can clear this storage at any time from your browser settings. Clearing the login session means logging in again, and clearing the cart means starting the order again — nothing else is affected.
9. Third parties we rely on
We do not sell data and we do not share it for marketing. We share it only with technical service providers, to the extent needed to run the platform:
- Our database, authentication, and storage provider (Supabase): holds accounts, menus, orders, and images.
- Our frontend hosting provider (Vercel): serves the site and menu pages and, like any host, sees standard request metadata.
- Our error tracking provider (Sentry): receives the scrubbed error reports described in section 4.
- WhatsApp (Meta): when you send an order or a message over WhatsApp, the conversation passes through WhatsApp's service and its own policy applies as well.
- Our font provider (Google Fonts): the font is fetched from its service, so it sees a request from your browser (your IP address) for the font only.
- The stock-image host for starter templates: sample images in templates load from an external image host, which sees the image request itself.
There is no online payment provider connected to the platform today; subscriptions are collected outside it. If a payment provider is added later it will be named here explicitly, and card data will not pass through our systems in any case.
10. Where data is stored, and international transfers
Platform data is currently stored on our database provider's servers in the **Tokyo, Japan** region, and we intend to move hosting to a geographically closer region (Frankfurt or Mumbai) to reduce latency. This section will be updated when any such move actually happens.
The site and menu pages themselves are served from a global delivery network, meaning they are served from the point closest to the visitor — so your data may be processed or transferred outside your country.
In all cases data is encrypted in transit (HTTPS), and we work only with providers that offer contractual data protection commitments.
11. How long we keep data
We keep data for as long as the purpose it was collected for still exists, then delete it or render it unlinkable to a person:
- Owner account data and menu content: for the life of the subscription, then for a reasonable period after cancellation to allow recovery or to meet a legal obligation, after which it is deleted.
- Orders and ratings: they remain in the restaurant's account as its own business record, and the owner can delete them.
- Usage events: used for statistics, and an owner can reset them from their dashboard.
- Error reports: retained at the tracking provider for a limited diagnostic period, then expire automatically.
- Contact messages: they live in the WhatsApp conversation or the mailbox that received them, and are governed by that mailbox's retention.
If you explicitly request deletion, we carry it out to the extent it does not conflict with a legal obligation to retain.
12. How we protect data
- Account isolation enforced in the database itself: every query is scoped to its own account, so one restaurant cannot read another's data even if it tries.
- Encryption in transit (HTTPS) on every page and connection.
- Passwords are hashed at the authentication provider, and nobody on our side has any way to read them.
- Role-based permissions: the admin panel does not display restaurants' menus or orders, and each restaurant's files sit in its own path that nobody else can write to.
- Scrubbing of error data before it is sent, and session replay disabled entirely.
That said, no method of electronic transmission or storage is one hundred per cent secure. If a security incident occurs that may affect your data we will inform you — and the competent authority where required — explaining what happened and what we did.
13. Your rights and how to exercise them
Under the applicable law you have the following rights:
- To know what we hold about you and to obtain a copy of it.
- To have inaccurate or incomplete data corrected.
- To request deletion of your data when no lawful reason to keep it remains.
- To object to a particular processing activity, or to ask that it be restricted.
- To withdraw your consent at any time where the processing was based on it.
- To complain to the competent data protection authority if you are not satisfied with how we handled your request.
To make a request: write to info@deuxel.com from the address or number linked to your account and state your request clearly. We verify your identity first, to protect your own data, then respond as soon as possible and within the statutory period. There is no charge, unless a request is clearly repetitive or excessive.
If your request concerns data from an order you sent to a restaurant, address it to that restaurant as the controller, and we will assist it in carrying the request out.
14. The restaurant owner's responsibilities
Because the restaurant is the controller of its customers' data, it carries obligations we cannot discharge on its behalf:
- Not to use order data for anything other than fulfilling the order and serving the guest — not for marketing the guest did not agree to.
- Not to ask guests for data it does not actually need, and to keep order fields to the necessary minimum.
- To keep its account and password secure, and to control who on its team can reach the orders.
- To hold the rights to the images and text it uploads, and not to upload images of people without their permission.
- Not to enter sensitive data into menu fields or order notes.
For our part, we process that data on its instructions and within the limits of the service, and never for our own purposes.
15. Children's privacy
The platform is intended for businesses and adults. We do not intend to collect data from children, and we ask menu visitors for no age information. If we learn that a child's data reached us unintentionally, we delete it once verified.
16. External links and services
Menu pages contain links the restaurant places itself: its social accounts, a map of its location, and a WhatsApp number for ordering. Those destinations are outside our control and their own privacy policies apply, so read them before sharing your data there.
Likewise, the QR code you scan collects nothing about you by itself; it is simply a link to the menu page, and it may carry a table number so that it fills in automatically on your order.
17. Updates to this policy
We may update this policy if the service, its providers, or the applicable law change. The last-updated date appears at the top of this page, and the version published here is the one in force.
If a change is material and affects your rights, we will tell restaurant owners through the channel we normally use before it takes effect.
18. Contacting us about privacy
For any privacy question, request, or complaint: info@deuxel.com — or through the Contact page on our site. We prefer email for formal matters so that the request keeps a written record.
This policy is an honest operational description of how the platform behaves. It is not legal advice, and it does not create contractual rights beyond what the applicable law provides.