Privacy Policy

This page explains in detail what data we collect, why we collect it, who we share it with, how long we keep it, and how you take back control of it. It was written to be read, not signed.

30 July 2026

1. Introduction and scope

This policy explains how the Dexel platform collects, uses, stores, and protects personal data, when it is shared, and what your rights are. It applies to our marketing site (deuxel.com), to the restaurant owner dashboard, and to the digital menu pages we publish for restaurants under the /r/ path.

We use “personal data” in its broad sense: any information that identifies a natural person, or that can be linked to them — such as a name, phone number, email address, or delivery address.

Reading this page places no obligation on you. Using the platform — by registering as a restaurant owner, or by browsing a restaurant's menu and placing an order — means you have read this policy and understand how your data is handled.

2. Who we are, and who is responsible for your data

Dexel is a digital menu platform for restaurants and cafés. Our website is deuxel.com, and our contact address for privacy matters is info@deuxel.com.

It matters that we play two different roles, because the party you should approach with a request differs between them:

So if you are a restaurant's customer and want an order's data accessed or deleted, the shortest route is to contact that restaurant; you may also contact us, and we will help the restaurant carry out your request.

3. Definitions used in this policy

4. The data we collect

We collect the minimum the service needs in order to work, and we do not ask for data we do not use. In detail, by type of user:

a) Owner account data

b) Restaurant content

Most of this is not personal data, but it does include contact numbers the restaurant chooses to show its guests, and we protect it in the same way.

c) Order data from restaurant customers

We ask customers for no payment data, no card numbers, and no account registration. The order is sent to the restaurant to be fulfilled and paid for there.

d) Usage and performance data

Error reports pass through **automatic scrubbing before they leave your browser**: WhatsApp links and any long run of digits that could be a phone number are removed, and we do not use session replay at all — nothing “records” a customer's screen or the contents of their order.

e) What we do not collect

5. Where this data comes from

6. Why we use the data

We do not use one restaurant's customer data for another restaurant, nor for our own marketing, nor to train systems at the expense of the data's owners.

7. Legal basis for processing

Each processing activity rests on one of the following bases:

Because the platform operates from, and mostly serves, the Kingdom of Bahrain, we work within its applicable personal data protection law, and we apply the same principles to restaurants elsewhere in the Gulf.

8. Cookies and on-device storage

We use no advertising or third-party marketing cookies. What we do use is local storage in your browser that the service needs in order to function:

You can clear this storage at any time from your browser settings. Clearing the login session means logging in again, and clearing the cart means starting the order again — nothing else is affected.

9. Third parties we rely on

We do not sell data and we do not share it for marketing. We share it only with technical service providers, to the extent needed to run the platform:

There is no online payment provider connected to the platform today; subscriptions are collected outside it. If a payment provider is added later it will be named here explicitly, and card data will not pass through our systems in any case.

10. Where data is stored, and international transfers

Platform data is currently stored on our database provider's servers in the **Tokyo, Japan** region, and we intend to move hosting to a geographically closer region (Frankfurt or Mumbai) to reduce latency. This section will be updated when any such move actually happens.

The site and menu pages themselves are served from a global delivery network, meaning they are served from the point closest to the visitor — so your data may be processed or transferred outside your country.

In all cases data is encrypted in transit (HTTPS), and we work only with providers that offer contractual data protection commitments.

11. How long we keep data

We keep data for as long as the purpose it was collected for still exists, then delete it or render it unlinkable to a person:

If you explicitly request deletion, we carry it out to the extent it does not conflict with a legal obligation to retain.

12. How we protect data

That said, no method of electronic transmission or storage is one hundred per cent secure. If a security incident occurs that may affect your data we will inform you — and the competent authority where required — explaining what happened and what we did.

13. Your rights and how to exercise them

Under the applicable law you have the following rights:

To make a request: write to info@deuxel.com from the address or number linked to your account and state your request clearly. We verify your identity first, to protect your own data, then respond as soon as possible and within the statutory period. There is no charge, unless a request is clearly repetitive or excessive.

If your request concerns data from an order you sent to a restaurant, address it to that restaurant as the controller, and we will assist it in carrying the request out.

14. The restaurant owner's responsibilities

Because the restaurant is the controller of its customers' data, it carries obligations we cannot discharge on its behalf:

For our part, we process that data on its instructions and within the limits of the service, and never for our own purposes.

15. Children's privacy

The platform is intended for businesses and adults. We do not intend to collect data from children, and we ask menu visitors for no age information. If we learn that a child's data reached us unintentionally, we delete it once verified.

16. External links and services

Menu pages contain links the restaurant places itself: its social accounts, a map of its location, and a WhatsApp number for ordering. Those destinations are outside our control and their own privacy policies apply, so read them before sharing your data there.

Likewise, the QR code you scan collects nothing about you by itself; it is simply a link to the menu page, and it may carry a table number so that it fills in automatically on your order.

17. Updates to this policy

We may update this policy if the service, its providers, or the applicable law change. The last-updated date appears at the top of this page, and the version published here is the one in force.

If a change is material and affects your rights, we will tell restaurant owners through the channel we normally use before it takes effect.

18. Contacting us about privacy

For any privacy question, request, or complaint: info@deuxel.com — or through the Contact page on our site. We prefer email for formal matters so that the request keeps a written record.

This policy is an honest operational description of how the platform behaves. It is not legal advice, and it does not create contractual rights beyond what the applicable law provides.