Merchant Terms of Service
Last updated: July 28, 2026
Table of Contents
These Merchant Terms of Service ("Merchant Terms") are a legal agreement between you, the restaurant, café, bar, or other food-service establishment ("Merchant," "you," or "your") and Dashi Inc. ("Dashi," "we," "us," or "our"). These Merchant Terms govern your access to and use of the Dashi platform, including reservation and waitlist management, guest relationship tools, marketing and loyalty features, point-of-sale services, analytics, and any related services (collectively, the "Services").
By accessing or using the Services, you agree to these Merchant Terms, our Privacy Policy, and any other policies referenced herein. If you do not agree, do not use the Services.
These Merchant Terms do not apply to Guests who interact with Dashi directly; Guest use is governed by our Terms of Service.
1. Definitions
"Guest" means an identifiable individual who makes a reservation, joins a waitlist, places an order, or otherwise interacts with your establishment through the Services.
"Guest Data" means personal information relating to a Guest that is processed through or stored in Dashi's systems in connection with your use of the Services, including name, phone number, email address, reservation and waitlist details, party size, timestamps, visit history, dietary preferences, communication preferences, and staff notes.
"Dashi Diner Profile" means a consumer account created by Dashi when a Guest independently opts in to Dashi's consumer services (such as the loyalty network, consumer app, or account features) under Dashi's own Terms of Service and Privacy Policy.
"Service Communications" means operational or transactional messages strictly related to a reservation, waitlist, order, or Guest account (for example, confirmations, reminders, waitlist status updates, and post-visit feedback requests), excluding any promotional content.
"Marketing Communications" means messages that encourage participation in a commercial activity or promote your establishment, including offers, events, and loyalty promotions, whether sent by email, SMS, or other electronic means.
"Consent Record" means an audit record evidencing a Guest's opt-in or opt-out for Marketing Communications, including the fields described in Section 7.
"Suppression List" means the list of identifiers (phone numbers, email addresses) for Guests who have opted out, withdrawn consent, or must not receive Marketing Communications for any legal or compliance reason.
"Sub-processor" means a third party engaged by Dashi to process Guest Data on Dashi's behalf, such as cloud hosting, SMS delivery, email delivery, or analytics providers.
"Merchant Products" means food, beverages, merchandise, and other goods or services offered, sold, prepared, or supplied by you through the Services.
"Merchant Content" means menus, prices, descriptions, photographs, videos, trademarks, logos, business information, instructions, and other content supplied or made available by you.
"Order" means a Guest's request to purchase Merchant Products through the Services.
"Payment Processor" means an independent provider, including Stripe or Moneris, that processes payments, connected accounts, settlements, refunds, disputes, or related financial services.
"Third-Party Provider" means an independent payment, delivery, integration, telecommunications, internet, hardware, or other provider whose products or services interoperate with the Services.
2. The Services
2.1 What Dashi Provides
Dashi provides technology services that enable you to manage reservations and waitlists, accept orders and payments, run loyalty and marketing programmes, and access analytics for your establishment. The specific features available to you depend on your subscription plan.
2.2 Acceptance of Terms
By using the Services, you represent that you are an authorized representative of your establishment and have the authority to bind it to these Merchant Terms.
2.3 Changes to These Terms
We may update these Merchant Terms from time to time. If changes materially reduce your rights or increase your obligations, we will provide you with at least 30 days' notice by email or through the Services. Your continued use of the Services after the effective date of any update constitutes acceptance.
2.4 Dashi's Role; Merchant Is the Seller
Dashi provides technology that enables transactions and operational workflows. Unless an applicable product addendum expressly states otherwise, you—not Dashi—are the seller, retailer, and supplier of Merchant Products. Title to and responsibility for Merchant Products remain with you until transferred by you to the Guest or your fulfillment provider. Dashi does not prepare, handle, inspect, manufacture, transport, or guarantee Merchant Products.
The parties are independent contractors. Nothing in these Merchant Terms creates a partnership, franchise, employment, fiduciary, agency, or joint-venture relationship, except that you appoint Dashi and its Payment Processors as your limited payment collection agents solely to collect and facilitate amounts paid by Guests for Orders.
2.5 Merchant Operating Responsibilities
You are solely responsible for:
- maintaining accurate menus, prices, taxes, fees, descriptions, photographs, ingredients, dietary labels, required warnings, allergen information, hours, locations, availability, and fulfillment areas;
- accepting, rejecting, preparing, packaging, and completing Orders safely, accurately, lawfully, and within reasonable operational standards;
- obtaining and maintaining all licences, permits, registrations, inspections, food-safety practices, and tax accounts required for your operations and Merchant Products;
- training staff and maintaining sufficient staffing, equipment, connectivity, and procedures to receive and fulfill Orders;
- customer service concerning Merchant Products, including missing or incorrect items, substitutions, quality complaints, cancellations, refunds, recalls, and food-safety incidents;
- preventing the sale of prohibited or age-restricted products unless Dashi has enabled the applicable feature and you comply with all additional requirements; and
- promptly correcting inaccurate information and notifying Dashi of health, safety, fraud, recall, regulatory, or other material risks affecting the Services or any Order.
You will not make a substitution that materially increases the Guest's charge without authorization or misrepresent a Merchant Product, price, discount, fee, availability, or delivery condition.
2.6 Product Addenda and Order of Precedence
Specific products may be governed by an order form, rate card, implementation statement, or product addendum, including addenda for online ordering, payments and payouts, third-party delivery, loyalty and marketing, age-restricted products, integrations, hardware, or support. If terms conflict, the following order applies unless the applicable document expressly states otherwise: (1) product addendum; (2) signed order form or rate card; (3) these Merchant Terms; and (4) documentation or policies incorporated by reference.
2.7 Payments, Payouts, Taxes, Refunds, and Disputes
You authorize Dashi and applicable Payment Processors to collect Order amounts as your limited payment collection agents, deduct agreed fees, refunds, reversals, disputes, chargebacks, reserves, taxes, or adjustments, and remit the balance according to your order form and processor terms. Payment Processor terms, onboarding, identity verification, connected-account requirements, prohibited-business rules, and reserve policies may apply directly to you.
You are responsible for Merchant Product prices, sales taxes, tax registration, tax invoices, refunds, chargebacks arising from your products or fulfillment, and the accuracy of payout and banking information. Dashi may withhold, offset, or recover amounts reasonably required to address refunds, chargebacks, fraud, negative balances, legal requirements, or amounts you owe under the agreement.
Dashi is not a bank, money transmitter, or insurer and does not guarantee Payment Processor availability, authorization, settlement timing, or access to funds. Dashi is responsible only for exercising commercially reasonable care in transmitting payment instructions within the Services.
You must review transactions and payouts promptly and notify Dashi of a suspected error within 30 days after it appears in the Services or applicable statement. This contractual notice period does not limit a right that cannot lawfully be limited.
2.8 Merchant Content and Limited Licence
You retain ownership of Merchant Content. You grant Dashi and its service providers a worldwide, non-exclusive, royalty-free, sublicensable licence during the service relationship to host, copy, format, display, distribute, and technically modify Merchant Content only to provide, operate, support, secure, demonstrate, and promote the Services and your availability through them.
You represent that you have all rights needed to provide Merchant Content and that it is accurate, lawful, non-infringing, and not misleading. If you enable or approve AI-assisted descriptions, images, translations, or other enhancements, you remain responsible for reviewing and correcting the resulting Merchant Content before publication. Dashi may remove content that creates legal, security, health, safety, or reputational risk.
2.9 Third-Party Providers and Integrations
Third-Party Providers are independent from Dashi and are responsible for the services they provide. Your use of their services may be subject to separate terms, fees, privacy notices, technical requirements, and availability. Dashi does not control and, to the fullest extent permitted by law, is not responsible for a Third-Party Provider's acts, omissions, outages, delays, security, pricing, routes, personnel, or performance.
If you enable third-party delivery, you remain responsible for clearly identifying the applicable fulfillment model to Guests and for Merchant-controlled preparation, packaging, handoff, and refund decisions. The delivery provider is responsible for the delivery services it performs.
2.10 Suspension
Dashi may immediately suspend affected Services, Orders, payouts, integrations, users, or locations when reasonably necessary to address suspected fraud, unlawful conduct, prohibited products, food or public-safety risk, a security incident, non-payment, processor or regulatory direction, material breach, repeated fulfillment failure, or risk to Guests, Dashi, or a third party. Where reasonable, Dashi will provide notice and an opportunity to cure.
2.11 Insurance
You will maintain insurance appropriate to your operations and risks, including commercial general liability and product liability coverage, workers' compensation coverage required by law, and cyber or privacy coverage where commercially reasonable for the volume and sensitivity of Guest Data you handle. Upon reasonable request, you will provide evidence of coverage.
3. Data Roles and Responsibilities
3.1 Merchant as Controller; Dashi as Processor
For Guest Data processed in connection with your reservation, waitlist, ordering, guest relationship management, and marketing activities, you are the controller (you determine purposes and means of processing) and Dashi is the processor (we process Guest Data on your documented instructions as set out in these Merchant Terms and through your in-product configuration).
This allocation is consistent with the mainstream approach used by leading restaurant technology platforms and reflects Canadian accountability principles under PIPEDA.
3.2 Dashi as Independent Controller for Dashi Consumer Services
When a Guest independently creates a Dashi Diner Profile — for example, by signing up on a Dashi loyalty page, downloading the Dashi app, or opting in to Dashi's consumer network — the Guest enters a direct relationship with Dashi. For that relationship, Dashi collects and processes personal information as an independent controller under Dashi's own Terms of Service and Privacy Policy.
To be clear: you own your Guest Data. Dashi's creation of a Dashi Diner Profile does not transfer ownership of your Guest Data to Dashi, and Dashi will not use your Guest Data to market competing establishments to your Guests.
3.3 How These Roles Work in Practice
When a Guest makes a reservation at your restaurant, that data belongs to you and Dashi processes it for you. If that same Guest separately opts in to a Dashi loyalty programme or creates a Dashi account, they are also entering a relationship with Dashi. Both relationships can exist at the same time, but they are distinct and governed by separate consent.
3.4 No Sale of Guest Data
Dashi will not sell Guest Data. Dashi will not share identifiable Guest Data with other merchants without the Guest's consent.
4. Permitted Processing
4.1 What Dashi May Do with Guest Data
Dashi may process Guest Data to:
- (a) provide, maintain, and secure the Services;
- (b) display Guest Data in your staff dashboard for operational use;
- (c) send Service Communications as configured by you;
- (d) provide reporting and operational insights to you based on your Guest Data;
- (e) provide marketing and loyalty features as configured by you, subject to Section 5; and
- (f) create and maintain Dashi Diner Profiles where the Guest has independently opted in under Section 3.2.
4.2 Processing Limits
Dashi will not send Marketing Communications on your behalf unless you have configured the relevant marketing feature and valid consent has been obtained and recorded.
4.3 Acceptable Use
You will not use Guest Data obtained through the Services to harass Guests, take adverse action unrelated to legitimate hospitality operations, or engage in any use that violates applicable law.
5. Marketing and Loyalty
5.1 You Are Responsible for Marketing Compliance
You are solely responsible for:
- (a) determining whether you have valid consent (express or implied) for Marketing Communications under Canada's Anti-Spam Legislation (CASL) and any other applicable law;
- (b) the content of your Marketing Communications; and
- (c) complying with all applicable law for marketing, including CASL.
This allocation of responsibility is standard across the restaurant technology industry.
5.2 CASL Requirements Summary
Under CASL, Marketing Communications may only be sent if the recipient has given consent (express or implied), and each message must include:
- (a) your business name, mailing address, and at least one of phone number, email address, or website URL;
- (b) a clear and prominent unsubscribe mechanism that is easy to perform; and
- (c) unsubscribe contact information and links that remain valid and functional for at least 60 days.
Unsubscribe requests must be honoured without delay and in any event within 10 business days. The burden of proving consent rests with the sender.
5.3 Implied Consent
CASL allows implied consent only in defined circumstances, notably where there is an existing business relationship based on a purchase or lease within the prior two years, or an inquiry or application within the prior six months. You are responsible for determining whether implied consent applies and for being able to evidence it.
5.4 Separation of Service and Marketing Communications
You will not include promotional content in Service Communications unless you have valid marketing consent and the message otherwise complies with applicable law.
5.5 Suppression Lists and Opt-Outs
You acknowledge that Dashi maintains a Suppression List within the Services for your establishment. The marketing features will not send Marketing Communications to suppressed identifiers. If you export Guest Data and use external tools for marketing, you must also export and apply the Suppression List and must not message suppressed Guests.
5.6 No Bypassing Compliance Controls
You will not use exports, re-uploads, or any workaround to send Marketing Communications to Guests who are on the Suppression List or who have not provided valid consent.
5.7 SMS-Specific Rules
Where SMS marketing is used, you will ensure recipients can opt out by replying "STOP" (where supported by the carrier) and that opt-outs are applied to the Suppression List without delay.
6. Consent Capture
6.1 Consent Must Be Opt-In and Purpose-Specific
You will obtain marketing consent in a manner that is clear, purpose-specific, and separate by channel (email versus SMS). Consent for marketing must not be bundled with acceptance of reservation or ordering services — a Guest must be able to use your restaurant's core services while declining marketing.
6.2 Required Information in the Consent Request
Under CASL regulations, a request for marketing consent must include your business identity, mailing address, at least one of phone number, email, or web address, and a statement that consent can be withdrawn. You will ensure your consent requests include this information.
6.3 Dashi Diner Profile Consent
Consent for a Dashi Diner Profile is separate from marketing consent. Where a Guest opts in to Dashi's consumer services (such as a loyalty programme or app), Dashi will present its own consent flow explaining what data is collected and how it will be used.
7. Consent Records and Auditability
7.1 Minimum Consent Record Fields
For each marketing opt-in or opt-out processed through the Services, Dashi will log (and you may export) at least:
- (a) timestamp with time zone;
- (b) your venue identifier;
- (c) staff user identifier (if captured in person) or source (web, QR, app);
- (d) channel (email and/or SMS);
- (e) consent text shown (exact wording or version reference); and
- (f) Guest identifier (email or phone) and action (opt-in, opt-out, or withdrawal).
7.2 Retention of Consent Records
Consent Records will be retained within Dashi's systems during the service relationship and for at least 24 months after the last Marketing Communication sent, unless a longer period is required by applicable law or for active dispute resolution.
7.3 Audit Right
Dashi may request reasonable proof that your consent practices are compliant as a condition of enabling or continuing marketing functionality. If Dashi reasonably believes you are using marketing features unlawfully, Dashi may suspend those features until the issue is corrected.
8. Exports and Staff Access
8.1 Export Responsibility
If you export Guest Data from the Services (including guest lists, CSV files, or similar), you are responsible for:
- (a) limiting access to authorized personnel;
- (b) storing exported data securely;
- (c) respecting the Suppression List and consent status in any downstream use;
- (d) not repurposing reservation data for new purposes (such as marketing) without proper consent; and
- (e) securely deleting exported data when no longer needed.
8.2 No Selling or Renting Guest Data
You will not sell, rent, or share Guest Data lists with third parties, except as necessary for your legitimate hospitality operations and only under appropriate legal authority.
8.3 Staff Training
You will maintain internal policies and provide training for staff who access Guest Data through the Services.
9. Guest-Facing Notices
9.1 Your Responsibility
You are responsible for providing Guests with a clear notice at or before collection that explains what information is collected, the reservation or ordering purposes, any optional marketing purposes, and any cross-border processing (if applicable). Dashi provides template notice language for your convenience, but compliance with notice requirements is your responsibility.
10. Security and Breach Notification
10.1 Dashi's Safeguards
Dashi maintains physical, technical, and organizational safeguards appropriate to the sensitivity of Guest Data, including access controls, authentication, encryption, and logging.
10.2 Your Safeguards
You will maintain appropriate safeguards for credentials, staff access, and any exported Guest Data.
10.3 Breach Notification
If Dashi becomes aware of a security incident affecting Guest Data in Dashi's systems, Dashi will notify you without undue delay and provide reasonably available information to support your legal obligations (scope, categories of data, and mitigation steps).
If you become aware of a security incident arising from your systems or exports that affects Guest Data originating from the Services, you will notify Dashi without undue delay.
10.4 PIPEDA Breach Obligations
Under PIPEDA's mandatory breach regime, businesses must report breaches that pose a real risk of significant harm, notify affected individuals as soon as feasible, and keep breach records for at least two years. The party determined to be in control of the personal information for a given incident is responsible for required reporting and individual notification, but both parties will provide reasonable cooperation.
11. Sub-processors
11.1 Use of Sub-processors
Dashi uses Sub-processors to deliver the Services. Dashi will restrict Sub-processor access to what is necessary, enter into written agreements requiring appropriate protections, and remain responsible for Sub-processors' compliance.
11.2 Sub-processor List
A current list of Sub-processors is available at dashipos.com/sub-processors or upon request. Dashi will provide notice of material changes to the Sub-processor list.
12. Analytics, Benchmarking, and Aggregated Data
12.1 Merchant Reports
Dashi may provide you with analytics and insights about your operations derived from your Guest Data.
12.2 Aggregated and De-identified Analytics
Dashi may create and use aggregated or de-identified data derived from Guest Data to improve Dashi's products, develop industry insights and trends, and create city-level or neighbourhood-level benchmarking outputs. Dashi will not:
- (a) attempt to re-identify any Guest from aggregated or de-identified data;
- (b) disclose Guest-identifiable data to other merchants; or
- (c) disclose your identifiable competitive metrics to other merchants without your permission.
13. Termination and Data
13.1 Export on Discontinuation
If you discontinue use of the Services, Dashi will provide you with a reasonable opportunity to export your Guest Data and Consent Records through Dashi's standard export tools for a period of 30 days.
13.2 Deletion
After the export window, Dashi will delete or anonymize Guest Data associated with your establishment from active systems within 90 days, subject to legal retention requirements and technical retention in backups (which will remain protected and be overwritten in the ordinary course).
13.3 Dashi Diner Profiles
Dashi Diner Profiles are maintained under the Guest's direct relationship with Dashi and are not affected by your discontinuation of the Services.
14. Indemnity and Liability
14.1 Your Indemnity
To the fullest extent permitted by law, you will defend, indemnify, and hold harmless Dashi, its affiliates, and their directors, officers, employees, and agents from third-party claims, regulatory investigations, penalties, fines, losses, and reasonable legal costs arising from or relating to:
- Merchant Products, including preparation, ingredients, allergens, contamination, packaging, labelling, quality, safety, recalls, bodily injury, or property damage;
- your menu, prices, Merchant Content, intellectual-property infringement, representations, taxes, licences, regulatory compliance, staff, premises, or business operations;
- your acceptance, rejection, preparation, substitution, cancellation, refund, or fulfillment of an Order;
- your Marketing Communications, failure to obtain or retain valid consent, failure to honour opt-outs, or unlawful use or disclosure of Guest Data;
- your breach of these Merchant Terms, product addendum, order form, law, or third-party right; or
- your fraud, negligence, wilful misconduct, or misuse of the Services.
Your obligations apply only to the extent the claim or loss was caused by you or a person for whom you are legally responsible and do not require you to indemnify Dashi for Dashi's own gross negligence, wilful misconduct, or fraud.
14.2 Dashi Indemnity
Dashi will indemnify you for third-party claims arising directly from Dashi's gross negligence, wilful misconduct, or fraud in providing the Services, including an unauthorized disclosure of Guest Data in Dashi's systems caused by that conduct. This is your exclusive contractual indemnity from Dashi.
14.3 Limitation of Liability
To the fullest extent permitted by law, Dashi will not be liable for indirect, incidental, special, exemplary, punitive, or consequential damages; lost profits, revenue, savings, business, goodwill, or data; business interruption; replacement services; or losses arising from Merchant Products, Merchant Content, Guests, staff, Third-Party Providers, payment processor decisions, delivery performance, internet or utility failures, or events beyond Dashi's reasonable control, even if advised that such loss is possible.
To the fullest extent permitted by law, Dashi's total aggregate liability arising from or relating to the agreement or Services will not exceed the fees paid or payable by you to Dashi for the affected Services during the six months immediately before the event giving rise to the claim.
The exclusions and cap do not apply to the extent liability cannot lawfully be excluded or limited, or to Dashi's fraud, wilful misconduct, or gross negligence. Merchant payment obligations, your indemnity obligations, and liability for your fraud, wilful misconduct, infringement, unlawful marketing, misuse of Guest Data, or breach of confidentiality are not limited by this Section.
14.4 Disclaimers
Except as expressly stated in a signed order form or product addendum and to the fullest extent permitted by law, the Services are provided "as is" and "as available." Dashi disclaims all express, implied, statutory, and collateral warranties, representations, conditions, and guarantees, including merchantability, fitness for a particular purpose, title, non-infringement, uninterrupted availability, error-free operation, compatibility, results, revenue, savings, Guest demand, or business outcomes.
Dashi does not warrant or endorse Merchant Products or Third-Party Providers and does not guarantee that Merchant Content, third-party information, delivery estimates, analytics, recommendations, or integrations are accurate, complete, or suitable for your purposes. You are responsible for reviewing outputs and maintaining appropriate operational controls, backups, reconciliation, and business-continuity procedures.
15. Québec Note (Law 25)
If you are subject to Québec's private-sector privacy law as amended by Law 25, you are responsible for completing any required privacy impact assessments for the adoption or overhaul of information systems handling Guest Data and for the communication of personal information outside Québec. Dashi will provide reasonable cooperation for these assessments.
16. General
16.1 Governing Law
These Merchant Terms are governed by the laws of Ontario and the federal laws of Canada applicable therein.
16.2 Amendments
Dashi may update these Merchant Terms in accordance with Section 2.3. Material changes to data processing or marketing compliance terms will be communicated with at least 30 days' notice.
16.3 Entire Agreement
These Merchant Terms, together with the Privacy Policy, applicable product addenda, order forms, rate cards, and subscription confirmations, constitute the entire agreement between the parties regarding the subject matter herein.
16.4 Severability
If any provision of these Merchant Terms is found to be unenforceable, the remaining provisions will continue in full force and effect.
17. Contact
If you have questions about these Merchant Terms, contact us:
Email: legal@dashipos.com
Support: support@dashipos.com
Mail:
Dashi Inc.
Attn: Legal Department
8171 Yonge St
Toronto, ON L3T 2C6
Last updated: July 28, 2026
