Security

Last updated: October 2026

What we do to keep your restaurant safe, in plain words. And what we don't do yet.

Your money

Diners pay into your own Stripe account or your own DuitNow QR. We never hold your takings, so there is no payout to wait for and nothing we can freeze.

Card details are typed into Stripe's own payment page. We and your staff never see them.

Your prices

Every bill is worked out on our servers from your menu. A diner can't change a price or a total from their phone.

Your team

Each person gets their own sign-in. Remove someone and they are signed out at once, on every device. The activity log shows every sign-in and who changed what.

You can turn on two-step sign-in for yourself: Face ID or a fingerprint (a passkey), or a code from an authenticator app. Then a stolen password alone can't get in.

Kitchen cooks sign in with a PIN, so the kitchen tablet never needs your password.

Your customers' data

Only your team can see it. We never sell it, share it with other restaurants, or use it to market anything to your diners.

If a customer asks you to delete their details, you can erase them yourself. You can also export all your data as one file, any time.

Behind the scenes

If something goes wrong

If your data is ever exposed, we will tell you within 24 hours of finding out: what happened, what data, what we are doing, and what you need to do.

Under Malaysia's PDPA, a restaurant may have to report a data breach within 72 hours. Our 24 hours leaves you time to do that.

What we don't have yet

An outside security firm hasn't tested us yet. We will say so here once one has.

Found a problem?

Email service@dinergrid.com. A person reads it within a business day. Please don't test against a real restaurant's data.