Start with access hygiene
Assign staff roles that match their responsibilities, update access when people leave or change jobs, and collect customer data only where an enabled workflow requires it.
How access and payment data are separated
- Hub limits data by the signed-in user’s shop membership and role
- Unrelated restaurants cannot open another shop’s data by changing a URL or identifier
- Advisor uses the signed-in user’s existing permissions and cannot grant itself owner access
- Payment partners handle full card entry; VDine keeps the payment result and order state needed for fulfillment
- Sensitive payment credentials are masked in the interface and restricted by role
Responsibility and limitations
The restaurant still owns staff-account hygiene, customer notices, data minimization, and permissions granted to external services. Use current contracts, the public privacy policy, and official contacts for formal data-processing, legal, or certification questions. VDine does not claim zero risk or unverified certifications.