Back
Privacy Policy for Dishly
Last Updated: 2026-09-13 This Privacy Policy explains how Dishly (“we”, “us”, “our”) collects, uses, stores, and protects information when businesses (“Clients”) use our CRM platform, and when the customers of those businesses (“End Users”) interact with systems powered by Dishly. By accessing Dishly or using any of its services, you agree to the practices described in this Privacy Policy. 1. Information We Collect 1.1 Personal Data You voluntarily provide personal data to Dishly when creating a business account, using our CRM platform, integrating Dishly with your website or third-party services, communicating with our support team, submitting forms, importing customer databases, or interacting with Dishly in any other way. This may include information about both Clients (businesses using Dishly) and End Users (their customers). Personal data we may collect includes, but is not limited to: Names and contact details (email, phone number, delivery address) Order history and transaction details integrated with open API (monobank api) Scheduling preferences and operational data for order fulfillment, logistics, or customer notifications Business-related details (age, gender, location, purchase patterns, professional role) For Clients, we may also collect: Company name, affiliation, address of registration, and business registration number information Internal user accounts (employees) and authentication credentials CRM configuration settings and operational data necessary for service delivery By providing this information, you agree that Dishly may collect, store, process, transfer, and disclose this data in accordance with this Privacy Policy, GDPR, and other applicable laws. 1.2 Non-Personal Data We may use web cookies and similar technologies to collect non-personal information such as your IP address, browser type, device information, and browsing patterns. This information helps us to enhance your browsing experience, analyze trends, and improve our services. 2. Purpose of Data Collection Dishly collects and processes data solely for operational and service-related purposes, including: Enabling Clients to manage orders, deliveries, schedules, and customer notifications Supporting internal business operations, CRM automation, and analytics Improving platform security, performance, and user experience All processing is limited to what is necessary to provide CRM functionality to Clients and enable End Users to access services offered by Clients. 3. Data Sharing Dishly does not sell, trade, or rent personal information to third parties. Data is shared only with the processors listed below, each of which does one job for us, and with legal or regulatory authorities where the law requires it. Google Maps Platform (Google LLC, United States) — we send a delivery address to the Geocoding API to turn it into map coordinates, so a courier can be routed to it. We send the street, building number, postal code and city; we deliberately do not send the flat or floor number, because they do not change where a building is. We do not send the customer's name, phone number or any account identifier, so the address reaches Google without a person attached to it. Google Drive (Google LLC, United States) — where photographs uploaded through the platform are stored, including delivery-confirmation photographs taken by couriers and profile pictures. Our email provider — we send transactional email through an SMTP provider: account verification, password resets, order receipts and delivery notifications. It receives the recipient's email address, their name and the contents of the message. Our email templates load one image from Dropbox, which means Dropbox can see the IP address of a recipient whose mail client displays images. Monobank (Universal Bank, Ukraine) — payment processing. It receives what is needed to raise and settle an invoice; card details are entered on the bank's own systems and never reach Dishly. Our web interfaces and this site used to load their fonts and icons from Google's servers, which revealed every visitor's IP address to Google on every page load, whether or not they went on to use anything. Those files are now served from our own domain. International transfers. Google LLC and Dropbox are established in the United States, so using them involves transferring personal data outside Ukraine and the European Economic Area. These transfers rely on the standard contractual clauses those providers incorporate into their terms. This list is the whole of it. If we add a processor, we will update this section before that processor receives any data. 4. Data Security We apply industry-standard security measures to protect personal and non-personal data. Measures include encrypted data transmission, restricted access controls, continuous monitoring, and secure hosting infrastructure. Despite these safeguards, no system is completely immune to vulnerabilities, and Clients share the responsibility of maintaining secure access to their accounts. 5. Data Control Rights Under GDPR, individuals may have the right to: Access, correct, or update their personal data Request the deletion or complete erasure of personal data (“right to be forgotten”) Export their personal data Restrict or object to the processing of their personal data Requests should be submitted to the Client (Data Controller), and Dishly (Data Processor) will assist Clients in fulfilling these rights where applicable. 6. Anonymous and Aggregated Data Dishly may create anonymized or aggregated datasets derived from personal data. This information is processed in a way that permanently removes identifiers and does not allow the identification of any individual Client or End User. Anonymous data may include statistical insights, usage trends, operational patterns, performance metrics, or other de-identified information generated through the use of our platform. 7. Children's Privacy Dishly is not intended for anyone under the age of 18, and our Terms of Service require account holders to be at least 18 years old. We do not knowingly collect personal information from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at the email address provided below. 8. Updates to the Privacy Policy We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. Any updates will be posted on this page, and we may notify you via email about significant changes. 9. Contact Information For questions, concerns, or requests regarding personal data or this Privacy Policy, please contact: Email: dishly.team@gmail.com