How OnyxDine protects your restaurant's data, your guests' information, and your ability to keep serving when things go wrong.
All traffic between your devices, guests' phones and our servers is encrypted with TLS 1.2+. Data at rest — databases, backups, uploaded files — is encrypted on disk.
Subscription payments are handled by Paddle; guest payments by your chosen gateway (Stripe, PayPal and others). Both are PCI DSS Level 1 providers. OnyxDine stores only the last four digits and a payment token.
Every staff login has a role. Servers see tables and orders; kitchen sees tickets; managers see reports; only owners see billing, settings and exports. Access is logged.
Full backups daily, retained for 30 days, stored encrypted in a separate location from production. Restores are tested regularly.
The Counter POS keeps taking orders and payments if your internet drops, queues them locally, and syncs when the connection returns. Kitchen tickets can fall back to a printer.
Production runs on hardened Linux servers in Canada with firewalling, automatic security patching, isolated environments, and monitoring with alerting to the on-call engineer.
If we detect or are told of a security incident, we contain it, assess who is affected, and notify affected restaurants within 72 hours — sooner where there is a risk of serious harm — along with the privacy regulators required by PIPEDA and Québec's Law 25. A post-incident summary is published on the status page.
Found something? Email hello@onyxdine.com with the subject "Security". We acknowledge within 2 business days, don't pursue good-faith researchers, and credit fixes publicly if you'd like.
We don't yet hold a SOC 2 or ISO 27001 certification. We follow the controls above and will publish attestations when they're complete. If your organisation requires a security questionnaire, send it — we answer them.