Role access
Document which of the 6 workspaces can view, create, change, approve or export each type of restaurant and guest data.
Security claims should describe the environment that is actually deployed. PayMyDine discussions therefore start with roles, connected systems, data responsibilities and operational controls rather than generic promises.

Document which of the 6 workspaces can view, create, change, approve or export each type of restaurant and guest data.
Map the source, destination, purpose, retention and responsible party for table, order, guest, payment and reporting data.
Record the API permissions, available fields, authentication method and failure handling for every external POS, payment or delivery system.
Review hosting, backups, logging, monitoring, incident handling and provider responsibilities for the actual deployed environment.
The answer may involve PayMyDine, the restaurant, the hosting environment and external POS or payment providers. Responsibilities should be explicit before go-live.
Bring the roles, providers, data types and integration diagram so the security conversation can assign clear controls and responsibilities.