SocialDine Data Governance & Security Architecture

Data Policy

Effective Date: September 2026 • Version 2.1 • SocialDine Inc.

Data Minimization Architecture

SocialDine adheres to strict data minimization principles. We only collect the minimal telemetry required to power live social dining matchmaking, verified reservations, and dining safety. We never sell, lease, or broker your personal information.

1. Data Collection & Ingestion Tiers

We organize user data into isolated, principle-of-least-privilege tiers:

Primary Authentication Tier

Credentials, salted password hashes, multi-factor tokens, and session refresh keys stored in isolated encrypted vaults.

Social Dining Profile Tier

Culinary taste preferences, dining radius, bio, verified badge state, attended tables, and review bookmarks.

Ephemeral Table Chat Tier

Pre-meal table coordination messages. Message records expire and are scrubbed 72 hours following the scheduled dining event.

Public Demo Web Sandbox Tier

Guest preview sessions on web.socialdine.online are temporary and automatically pruned periodically.

2. Storage, Transit & Encryption Standards

All telemetry and personal data are safeguarded with defense-in-depth protocols:

  • In-Transit Security: All API and WebSocket connections require TLS 1.3 encryption with strict HTTPS enforcement and HSTS preloading.
  • At-Rest Encryption: Database clusters and backups are encrypted utilizing AES-256 with automated key rotation.
  • Token Separation: Access tokens and sensitive profile information are partitioned across isolated memory stores.

3. Data Retention Lifecycle

We do not retain customer data indefinitely. Our automated pruning schedules include:

  • Event Group Messages: Retained for 72 hours post-dinner for safety reporting, then permanently purged.
  • Location Coordinates: Real-time geolocation coordinates used for nearby radar are discarded immediately after venue calculation.
  • Inactive Accounts: Accounts dormant for greater than 24 consecutive months are flagged for automated archival and deletion notice.

4. Data Deletion & Export Requests

Users retain total dominion over their records. You may at any moment request:

  • Full Data Archive: A machine-readable JSON bundle containing your complete reservation history and profile attributes.
  • Irreversible Deletion: Immediate erasure of profile entries, photo reviews, and associated account credentials across all production nodes.

5. Data Security Inquiries

For data compliance, audit requests, or vulnerability disclosure: