Privacy Policy

Last Updated: July 19, 2026

This Privacy Policy explains how we collect, use, store, share, transfer, and protect personal and business information when you use our website, dashboards, APIs, notifications, and related hospitality SaaS services (the "Service").

The Service is used by hotel and food-and-beverage businesses, their staff, and consumer users, primarily in Kathmandu, Nepal. We aim to handle data responsibly in accordance with applicable Nepalese law and relevant privacy frameworks in the United States, European Union, United Kingdom, and Australia.

Agreement on Signup and Use

By creating an account, onboarding a business, accepting a staff invitation, checking the legal consent box at signup, or using Dorbite, you acknowledge that you have read and agree to this Privacy Policy and our Terms & Conditions. If you do not agree, please do not use the Service.

1. Who This Policy Applies To

  • Business Users — hotel owners, business administrators, and authorized representatives
  • Staff Users — front desk, kitchen, housekeeping, helper, and other operational personnel
  • Consumer Users — individuals who discover businesses, place orders, make reservations, leave reviews, or use consumer features
  • Visitors — users who browse public pages without signing in

2. Information We Collect

Account and Identity Information

  • Name, email address, phone number, profile details, and account identifiers
  • Login credentials, authentication session data, MFA status, and security logs
  • Role, permissions, account status, and communications with support or verification teams

Business and Hotel Information

  • Business name, address, contact details, branding, and public profile content
  • Menus, pricing, room and table details, operating hours, and promotional materials
  • Staff records, role assignments, and operational configuration
  • Inventory, supplier, reservation, order, billing, guest credit, and analytics data entered into the platform
  • Subscription plan details, offline payment references, invoices, and verification records
  • Business documents or images uploaded for onboarding, compliance, or operations

Consumer Information

  • Search, discovery, booking, and ordering preferences
  • Order and reservation history, reviews, ratings, and feedback
  • Notification preferences, in-app activity, and support communications
  • Approximate or precise location data, where enabled, to support nearby search and venue features
  • Referral program data, including referral codes, username and email (when available), business signup attributions, qualifying subscription-purchase counts, payout eligibility, and payout records

Transaction and Payment Information

  • At present, we primarily process offline subscription payments and related verification details
  • We may store payment references, bank transfer details, invoices, and approval status provided by Business Users
  • When online payment integrations such as eSewa, Khalti, or Stripe are launched, payment data will be handled according to the relevant gateway's security standards and our updated notices
  • We do not intentionally store full payment card details on Dorbite servers unless expressly stated for an approved future integration

Technical, Device, and Usage Data

  • IP address, browser type, device information, operating system, and language settings
  • Pages viewed, feature usage, timestamps, referral URLs, and error logs
  • Cookies, local storage, session identifiers, and similar technologies
  • Real-time connection data for notifications, dashboards, and operational updates

Information from Third Parties

  • Analytics providers such as Google Analytics
  • Search and performance tools such as Google Search Console
  • Advertising partners such as Google AdSense
  • Future payment gateways, hosting providers, email services, and infrastructure vendors

Sensitive Information

We do not intentionally collect special categories of personal data such as health information, biometric identifiers, or government ID numbers except where you voluntarily provide them for a specific business or compliance purpose, such as registration verification. Please do not submit sensitive information unless explicitly requested.

3. How We Use Information

We use collected information to:

  • Provide, operate, maintain, personalize, and secure the Service
  • Create and manage accounts for businesses, staff, and consumers
  • Process subscriptions, offline payment verification, and future in-app transactions
  • Enable reservations, kitchen orders, dining tables, inventory, staff workflows, and guest services
  • Deliver notifications, announcements, promotions, and service communications
  • Display public business pages, reviews, and consumer discovery features
  • Generate analytics, reporting, and operational insights for authorized users
  • Operate marketing and promotional campaigns, including the Consumer Referral Program and related payout administration under then-current campaign policies
  • Receive, review, and act on feedback, bug reports, abuse reports, and support issues to improve platform reliability and user experience
  • Detect fraud, abuse, unauthorized access, and technical issues
  • Assess reported or reasonably suspected regulatory, consumer-health, or safety compliance concerns involving Business Users, where necessary to protect users and administer subscriptions
  • Improve Dorbite through product development, testing, and incremental platform enhancements, prioritizing known issues based on available company resources
  • Comply with legal obligations and respond to lawful requests

Product Development and Intellectual Property

We may use aggregated, anonymized, or de-identified data and operational insights derived from platform usage to improve Dorbite, develop new features, and support our intellectual property, provided we do not unlawfully infringe individual rights and do not sell personal data.

4. Legal Bases for Processing

Depending on your location and the type of processing, we rely on one or more of the following legal bases:

  • Contract — to provide the Service, manage accounts, and process subscriptions or transactions you request
  • Consent — for optional features such as marketing communications, certain location uses, browser notifications, or non-essential cookies where required
  • Legitimate interests — to secure, improve, administer, and promote the platform, prevent fraud, and protect users, subject to your rights
  • Legal obligation — to comply with applicable law, tax, regulatory, audit, or law-enforcement requirements

5. How We Share Information

We may share information only as necessary and in the following circumstances:

  • Between users of the Service — for example, sharing booking, order, or contact details between a Consumer User and the relevant Business User
  • Service providers and subprocessors — hosting, email, analytics, advertising, security, storage, customer support, and infrastructure vendors that process data on our instructions
  • Payment processors — current offline verification workflows and future gateways such as eSewa, Khalti, or Stripe
  • Business transfers — in connection with a merger, acquisition, restructuring, or asset sale, subject to appropriate safeguards
  • Legal and safety purposes — when required by law, court order, or to protect rights, safety, and platform integrity

We Do Not Sell Personal Data

Dorbite does not sell personal information or business data to third parties for their own marketing or commercial exploitation. We also do not share personal information for cross-context behavioral advertising in a manner that qualifies as a "sale" or "share" under applicable U.S. state privacy laws, except as permitted by those laws and disclosed here through advertising technologies described below.

6. Controller and Processor Roles

  • Dorbite generally acts as a data controller for account registration, platform security, billing, analytics, advertising configuration, and Service-operation data
  • Business Users generally act as independent controllers of guest, reservation, order, staff, and operational data they enter or generate in connection with their business
  • Dorbite acts as a data processor when processing Business User-controlled operational data solely to provide the Service, subject to the Business User's instructions and applicable law
  • Business Users are responsible for providing any required notices and obtaining any required consents from their guests, staff, and customers

7. Cookies, Analytics, and Advertising

We use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and improve user experience.

Types of Technologies We Use

  • Essential cookies — required for login, security, session management (including session, CSRF, and authentication tokens), and core functionality
  • Functional cookies / local storage — may remember preferences such as theme or dashboard settings
  • Analytics cookies — reserved for a future release; Google Analytics is not currently active on the Service
  • Advertising cookies — support ad delivery and measurement on certain consumer-facing pages when you consent

Google Services

  • Google Search Console — helps us monitor search visibility, indexing, and site performance (server-side / webmaster tooling; not a visitor tracking cookie banner category)
  • Google AdSense — may display advertisements on certain consumer-facing areas of the Service. AdSense scripts load only after you accept advertising cookies via our cookie banner

Google Analytics may be introduced in a future release. Until then, selecting “Accept All” records analytics preference for forward compatibility but does not load Google Analytics today.

Where required by law, we request consent before placing non-essential cookies or similar technologies.

How We Store Cookie Preferences and Consent Evidence

  • Your cookie preference (essential only vs accept all) is stored in your browser (local storage) so we can gate advertising scripts on this device
  • A separate compliance record of your choice — including timestamp, policy version, technical identifiers (such as a stable anonymous identifier), IP address, and user agent — is stored securely on our servers for accountability, whether or not you have an account
  • When you sign up or sign in, we may link that anonymous consent record to your user account without altering the historical choice itself
  • Consent audit records are retained for at least two years or longer where required by law

These third-party advertising services may collect information such as browser identifiers, device data, pages visited, and ad interactions according to their own privacy policies. You can review Google's policies and available opt-out or control tools through Google account settings, browser controls, and industry opt-out pages where available.

8. Marketing Communications

We may send service-related messages, account notices, security alerts, and product updates. With consent or as permitted by law, we may also send promotional communications about Dorbite features or offers. You can opt out of promotional emails by using the unsubscribe link in the message or contacting privacy@dorbite.com. Service-critical communications may still be sent even if you opt out of marketing.

9. Consumer Referral Program

If you participate in Dorbite's Consumer Referral Program, we process limited account and campaign data to attribute referrals, measure progress toward promotional goals, verify eligibility, and administer payouts, compensations, or other benefits under the then-current referral policy.

  • Validity. The referral payout feature is valid until July 15, 2027 at 6:56 AM, unless Dorbite extends or renews the campaign.
  • Policy updates. Dorbite may update referral program terms, eligibility rules, payout amounts, currencies, benefits, and campaign duration at any time. Processing of referral and payout data will follow Dorbite's latest published policies as reflected in the Service, these Terms and Policies, or related notices.
  • Campaign terms. The program is promotional. Goals, payout amounts, currency, eligibility, and validity may change and do not create a guaranteed entitlement to prior campaign terms.
  • Payouts. After a Consumer User reaches the applicable goal under then-current policy, a payout may be issued in the configured campaign currency, subject to verification, fraud checks, and Dorbite approval. We may process identity, contact, and payment-delivery details you provide solely to complete approved payouts.
  • Scope. Unless expressly stated otherwise in the then-current policy, payout eligibility is limited to annual and tri-annual subscription purchases by referred businesses.
  • Identifiers. We may use your referral code together with username and email (when available), including for accounts created via Google or Facebook sign-in, to track and verify referral activity.
  • Retention. Referral and payout records may be retained for campaign administration, fraud prevention, accounting, dispute resolution, and legal compliance, consistent with our retention practices in this Policy.

10. Data Retention

We retain information for as long as necessary to:

  • Provide the Service and maintain active accounts
  • Meet legal, tax, accounting, audit, and dispute-resolution obligations
  • Resolve fraud, security incidents, and support requests
  • Support historical reporting and operational continuity for authorized business users

Typical retention periods depend on the data type and legal requirements. For example, account profile data is retained while your account remains active; billing and verification records may be retained for several years where required by law; security logs may be retained for a shorter operational period unless needed for an investigation. When data is no longer required, we delete, anonymize, or securely archive it in accordance with our retention practices and applicable law.

11. Data Security

We implement reasonable technical and organizational safeguards, which may include:

  • Encrypted connections for data in transit
  • Access controls, role-based permissions, and authentication protections
  • Secure hosting, monitoring, logging, and backup procedures
  • Internal policies limiting access to personal information on a need-to-know basis

No method of transmission or storage is completely secure. You are responsible for protecting your account credentials and promptly reporting suspected unauthorized access.

12. Data Breach Notification

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will investigate promptly and take reasonable steps to mitigate harm. Where required by applicable law, we will notify affected users and relevant supervisory authorities within the timeframes required by that law.

13. Your Rights and Choices

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate or incomplete information
  • Request deletion or account closure, subject to legal retention requirements
  • Object to or restrict certain processing activities
  • Withdraw consent where processing is consent-based
  • Request data portability in a structured, commonly used format where applicable
  • Opt out of certain marketing communications
  • Lodge a complaint with a supervisory authority or relevant regulator

To exercise these rights, contact privacy@dorbite.com or dpo@dorbite.com. We may need to verify your identity before responding. We will respond within the timeframes required by applicable law.

Nepal

We handle privacy requests in accordance with applicable Nepalese law, including electronic transaction and evolving data protection requirements.

European Economic Area and United Kingdom

Where GDPR or UK GDPR applies, you may exercise the rights above and contact our data protection contact at dpo@dorbite.com. You also have the right to lodge a complaint with your local supervisory authority.

United States

Residents of certain U.S. states, including California, may have additional rights to know, access, correct, delete, and opt out of certain data uses. We do not sell personal information. Authorized agent requests may be accepted where required by law and properly verified.

Australia

Where the Australian Privacy Act 1988 applies, you may request access to or correction of personal information and complain to the Office of the Australian Information Commissioner if concerns remain unresolved.

Data Removal Requests

Business Users and Consumer Users may request removal of their account data from Dorbite servers, subject to legal retention obligations, fraud prevention, billing records, and outstanding disputes. Removal requests can be sent to privacy@dorbite.com.

14. International Data Transfers

Your information may be processed in Nepal and in other countries where our service providers operate. Where required, we use appropriate safeguards such as contractual protections, vendor assessments, access controls, and security measures to protect transferred data.

15. Automated Decision-Making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you without human involvement, except where permitted by law and disclosed to you. We may use automated systems for fraud detection, security monitoring, search ranking, and operational recommendations.

16. Children's Privacy

The Service is not directed to children under 16. We do not knowingly collect personal information from children without appropriate parental or guardian consent. If you believe a child has provided personal data to us, contact privacy@dorbite.com so we can take appropriate action.

17. Accuracy and User Responsibility

Business Users, Staff Users, and Consumer Users are responsible for the accuracy of information they submit to Dorbite. Incorrect or misleading data may affect reservations, orders, billing, notifications, analytics, and daily operations. Dorbite is not responsible for disruptions caused by inaccurate user-provided information.

Dorbite does not control Merchant premises or on-site activities. Personal information processed through the Service does not make Dorbite responsible for Consumer User conduct at any venue, or for accidents, injuries, illnesses, property damage, or other incidents occurring at Merchant premises. Such matters are governed primarily by the relationship between the consumer and the relevant business and by applicable law.

18. Tax and Regulatory Responsibility

Dorbite does not provide tax or legal advice. Businesses and consumers remain responsible for their own tax, licensing, consumer-health, food-safety, hygiene, tourism, and other regulatory compliance. We may retain and process records needed for lawful verification, billing, audit, regulatory requests, or subscription administration, including where subscription access is restricted or cancelled due to reported or reasonably suspected non-compliance with applicable consumer-health or regulatory requirements.

19. Feedback, Issue Reports, and Product Improvement

When you submit feedback, bug reports, abuse reports, or support requests, we process the content of your message together with relevant account and technical details to investigate and improve the Service. We prioritize resolving known issues that affect reliability and user experience. New features and non-critical fixes may be delayed based on available company resources. We may retain issue and feedback records for quality assurance, security, and product-improvement purposes consistent with this Policy.

20. Third-Party Links and Business Pages

Public business pages, promotions, and external links may direct you to third-party websites or services. Their privacy practices are governed by their own policies. Dorbite is not responsible for the privacy practices of independent businesses listed on the platform or third-party sites you choose to visit.

21. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or business changes, including future payment integrations, advertising updates, and changes to referral or payout program administration. Material changes will be communicated through the Service, email, or other reasonable notice where required. Continued use after the effective date constitutes acceptance, unless applicable law requires a different consent process.

22. Contact Us

For privacy questions, data access requests, or account removal requests:

Email: privacy@dorbite.com
Data Protection Contact: dpo@dorbite.com
Legal: legal@dorbite.com
Address: Dorbite Pvt. Ltd., Kathmandu, Nepal

Effective Date: July 19, 2026