Skip to main content
← Back to TablePlay

This text is a translation of the Dutch version. In case of any discrepancy between the translation and the Dutch original, the Dutch version shall prevail. This agreement is governed by Dutch law.

What data do we process?

We process account data, restaurant data, contact details, billing data, support messages and technical logs needed to deliver TablePlay safely.

Where possible, game data is linked to table sessions and not to directly identifiable guests.

Why do we process this data?

For creating accounts, displaying and securing QR codes, billing, support, abuse prevention, troubleshooting and improving the service.

Retention periods

Data is not kept longer than needed for delivery, administration, security and legal obligations. Support and billing data may be kept longer for administrative and evidentiary purposes.

Contact

For privacy questions, a customer can get in touch via support@tableplay.online. For formal privacy requests, TablePlay may ask for additional verification.

Privacy Statement TablePlay Processing of personal data of website visitors, business customers and restaurant guests

TablePlay by Jimani Jimani B.V. Albert Plesmanweg 122, 4462 GC Goes Chamber of Commerce (KvK) 91644453 - VAT NL865722729B01 support@tableplay.online

Version 1.0 Last updated: 10 July 2026

Legal review note This document has been drawn up for business use by TablePlay. Have the final publication, international application, current suppliers, technical set-up and country-specific rules periodically reviewed by legal counsel.

Table of contents 1. General purport and scope of application 2. Identity of the provider 3. Privacy law roles 4. Categories of personal data 5. Source of data 6. Purposes and legal bases 7. Game data and visibility 8. Minors 9. Artificial intelligence 10. Automated processing 11. Recipients and suppliers 12. International transfer 13. Retention periods 14. Security 15. Cookies and advertising 16. Email communication 17. Rights of data subjects 18. Requests from restaurant guests 19. Complaints 20. Obligations of business customers 21. California 22. Additional international provisions 23. External services 24. Amendments 25. Contact

Privacy Statement TablePlay

Page 2 of 8

1. General purport and scope of application This privacy statement relates to every processing of personal data that takes place in connection with the development, operation, security, support, analysis and commercial offering of TablePlay, including the website, the business customer portal, the QR-based game environment, administrative functionalities, communication channels and related services. TablePlay enables businesses, including restaurants, cafés, terraces and other hospitality establishments, to offer interactive table games to guests. Guests can scan a QR code linked to a table or location and participate, using a temporary nickname, in games, table competitions and temporary leaderboards. This statement applies, depending on the actual relationship, to website visitors, business customers and their contact persons, users of the customer portal, restaurant guests and players, persons who make contact and recipients of business or commercial communications.

2. Identity of the provider TablePlay is offered under the product and trade designation TablePlay by Jimani by Jimani B.V., established at Albert Plesmanweg 122, 4462 GC Goes, the Netherlands, registered under Chamber of Commerce (KvK) number 91644453 and VAT identification number NL865722729B01. For privacy questions, objections, complaints and requests, please contact support@tableplay.online. As at the time of this version, TablePlay has not formally appointed a data protection officer.

3. Privacy law roles 3.1 TablePlay as data controller TablePlay is independently the data controller for, among other things, website visits, registration and management of business accounts, subscriptions, payments, invoicing, support, business marketing, platform security, fraud prevention, technical logging, statutory record-keeping, legal protection, general product analysis and anonymised benchmarks.

3.2 The business customer as data controller The restaurant or other business customer may be the data controller for the decision to offer TablePlay to guests, the placement of QR codes, the use of screens and leaderboards within the location, the business's own provision of information to guests, and any independent use of statistics or promotional data.

3.3 TablePlay as processor Insofar as TablePlay processes restaurant-specific game data solely on behalf of a business customer, TablePlay may act as processor. This may include temporary nicknames, table identifiers, answers, scores, sessions and restaurant-specific dashboard information. The further relationship is governed by the data processing agreement.

4. Categories of personal data 4.1 Website visitors When visiting the website, the following may be processed: IP address, date and time, pages visited, referring source, browser, operating system, device type, screen size, language setting, general location, cookie preferences, session data, error and performance data and - after consent - advertising and conversion data.

Privacy Statement TablePlay

Page 3 of 8

4.2 Business accounts When registering and managing accounts, the following may be processed: name of the contact person, company name, email address, telephone number, address, postal code, place, country, VAT number, Chamber of Commerce (KvK) or local registration number, website, company logo, language and country settings, number of tables, subscription information, price and currency, account status, role, rights, registration data, last login and relevant security history. Passwords are not stored as readable text but are protected using appropriate authentication and hashing techniques.

4.3 Payment and invoice data For payments, the following may be processed: Stripe customer number, subscription status, invoice numbers, invoice amounts, currency, payment status, payment method, payment history, last four digits of a payment card, card type, IBAN where relevant, outstanding amounts and data concerning trial or Founder periods. Full card numbers and security codes are, in principle, processed directly by Stripe.

4.4 Contact, support and sales When a person makes contact, the following may be processed: name, email address, telephone number, company name, position, subject, content and date of the communication, prior correspondence, technical information, interest in TablePlay and internal follow-up status.

4.5 Restaurant guests and players During a game session, the following may be processed: a temporary nickname, table number or unique table ID, restaurant, game choice, game mode, answers, game progress, score, win or loss, ranking, date, time, session ID, language choice and necessary technical data. A guest is not required to provide an account, email address, telephone number, date of birth or real name. Because a nickname in a restaurant context may sometimes be indirectly identifiable, TablePlay treats such nicknames as pseudonymous and potentially identifiable information. Players are requested not to use their real or full name as a nickname.

4.6 Technical and security data For reliability and security purposes, the following may be processed: IP addresses, timestamps, browser and device data, server logs, session data, login attempts, error messages, suspicious activity, technical identifiers and data for abuse or fraud investigation.

4.7 Special categories of personal data TablePlay does not intend to systematically process special categories of personal data, criminal-related data or other sensitive personal data. Users must not include such information in nicknames, games, free text fields or support messages. Sensitive data received unintentionally may be deleted or shielded from access.

5. Source of data Data may be obtained directly from the data subject, via a business customer, via registration and contact forms, via the customer portal, during game sessions, via cookies, via hosting and security providers, via Stripe, via advertising platforms following consent, and from public business sources.

TablePlay Privacy Statement

Page 4 of 8

6. Purposes and legal grounds TablePlay processes personal data only where a valid legal ground exists for doing so. Depending on the processing activity, this may be the performance of an agreement, pre-contractual measures, a statutory obligation, a legitimate interest, consent or another applicable ground.

6.1 Performance of the service Data are used for account registration, authentication, linking of tables and QR codes, running of games, calculation of scores, temporary leaderboards, dashboards, language settings, subscriptions and support. The ground is, in principle, the performance of the agreement or a pre-contractual measure.

6.2 Payment and administration Data are used for payments, invoices, subscriptions, accounts receivable management, tax administration and audits. The ground is the agreement, a statutory obligation and, where applicable, a legitimate business interest.

6.3 Contact and support Data are used to handle questions, complaints, demo requests, onboarding, technical issues and privacy requests.

6.4 Security and abuse prevention Technical data are processed for account security, fraud prevention, detection of attacks, protection of scores, evidence in the event of incidents and continuity. This is based on the legitimate interest in a safe and reliable service.

6.5 Analysis and product improvement Data may be used for usage statistics, popularity of games, troubleshooting, capacity planning, general benchmarking and development. Where possible, data are anonymised or aggregated. Non-essential tracking is applied only after the required consent has been obtained.

6.6 Marketing Business contact data may be used for news, new games, upgrades, promotions and relevant services. Consent is used for this purpose where required; in other cases, an existing customer relationship or legitimate interest may form the ground. Opting out is possible via the unsubscribe link or support@tableplay.online.

7. Game data and visibility Nicknames, scores and results may be visible on the player's device, to the player's own table, to other participating tables within the same restaurant, on a screen in the restaurant and in the restaurant dashboard. This data is not published publicly on the internet by default, shared between restaurants, used for a persistent player profile, personal advertisements or structural prediction of individual preferences. Active nicknames and leaderboards are visible for a maximum of one day. Underlying data may be retained for the period stated below.

TablePlay Privacy Statement

Page 5 of 8

8. Minors TablePlay may be used by families and children. A personal account is not required for regular play. TablePlay does not ask children for a full name, e-mail address, telephone number, date of birth, address, school or photograph. Children are not structurally tracked on a personal basis or approached commercially on the basis of individual game behaviour. Parents or legal representatives may request investigation or removal via support@tableplay.online.

9. Artificial intelligence TablePlay may use AI services for translation, support assistance, game questions, classification, quality improvement and product development. TablePlay does not intend to use directly identifiable guest data for the general training of public AI models. Where external AI services are used, the amount of information is limited as far as possible and data is, where possible, anonymised, pseudonymised or aggregated.

10. Automated processing TablePlay does not apply solely automated decision-making concerning restaurant guests that has legal or similarly significant effects on them. Business Accounts may, in the event of non-payment, be automatically restricted, blocked or terminated on the basis of objective payment data. The customer may request human review.

11. Recipients and suppliers Personal data may, insofar as necessary and lawful, be processed by or shared with Vercel for hosting, Supabase for database and authentication, Stripe for payments, Twilio SendGrid for e-mail, Google services for analytics and advertising, Meta and LinkedIn for marketing measurement following consent, any AI suppliers and professional advisers or competent authorities. In the event of a reorganisation, investment, merger, sale or acquisition, data may, subject to appropriate confidentiality, be shared with the parties involved and their advisers.

12. International transfer The primary environment is, insofar as technically arranged, hosted in a European region. International suppliers may, however, process or access data outside the European Economic Area.

Where required, TablePlay uses adequacy decisions, standard contractual clauses, data processing agreements and additional technical or organisational measures.

13. Retention periods Personal data is not retained for longer than necessary, save for statutory obligations, outstanding payments, fraud investigation, security incidents or legal claims. • Business Account data: for the duration of the active Account and up to a maximum of one year after termination, unless a longer period is necessary. • Invoices and tax records: at least seven years. • Active guest nicknames and leaderboards: visible for a maximum of one day.

TablePlay Privacy Statement

Page 6 of 8 • Game sessions, nicknames in technical sessions, scores and results: a maximum of one year, after which they are deleted or anonymised. • Technical and security logs: a maximum of one year, save in the case of incidents or disputes. • Contact, sales and support data: a maximum of one year after the last relevant contact or handling. • Incomplete registrations: a maximum of one year. • Marketing data: until unsubscription, objection or the end of relevance; a suppression record may be retained for longer. • Back-ups: in principle a maximum of one month. • Anonymised or sufficiently aggregated data: for as long as it no longer qualifies as personal data.

14. Security TablePlay takes appropriate technical and organisational measures, including HTTPS/TLS, hashed passwords, authorisation, separated restaurant accounts, Supabase Row Level Security where applicable, logging, restricted administrative rights, back-ups, monitoring and agreements with suppliers. No digital service can guarantee absolute security. Incidents are investigated and, where legally required, reported to the supervisory authority and the data subjects concerned.

15. Cookies and Advertising Necessary techniques may be used for login, session security, language selection and cookie preferences. Analytical and marketing techniques, including Google Analytics, Google Ads, Meta Pixel and LinkedIn Insight Tag, are activated only after consent insofar as legally required. Preferences may be changed via Cookie Settings.

16. E-mail Communication TablePlay sends necessary messages regarding registration, security, invoices, subscriptions, changes and support. It is not always possible to unsubscribe from such communications for as long as an Account or a statutory obligation exists. One may unsubscribe from commercial messages.

17. Rights of Data Subjects Depending on the applicable legislation, data subjects may have the right to information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent, objection to direct marketing, human review and the lodging of a complaint. Requests may be sent to support@tableplay.online. TablePlay may request reasonable identification and will in principle respond within one month. Rights are not absolute and may be limited by statutory obligations, rights of third parties, evidentiary interests or statutory exceptions.

18. Requests from Restaurant Guests Because restaurant guests generally do not have a personal Account, TablePlay cannot always determine which session belongs to which person. For investigation purposes, information may be requested regarding restaurant, location, table, date, time, nickname, game and session context. Where it is not sufficiently plausible that data relates to the requester, such data will not be provided. TablePlay may involve the restaurant where the restaurant is the controller for the relevant processing.

TablePlay Privacy Statement

Page 7 of 8

19. Complaints Complaints may first be submitted via support@tableplay.online. Data subjects retain the right to lodge a complaint with the competent privacy supervisory authority. For the Netherlands, this is the Autoriteit Persoonsgegevens.

20. Obligations of Business Customers Business customers should use TablePlay in a privacy-friendly manner. They may not require guests to use real names, may not include sensitive data in games, may not engage in unlawful profiling, may not apply unlawful marketing and may not share administrative access with unauthorised persons. They are responsible for information provided to guests, account security, correct display of leaderboards, local legislation and their own marketing.

21. Additional Information for California Insofar as California privacy legislation applies, categories such as identification data, account data, internet data, commercial data, payment data, general location and pseudonymous game data may be processed. TablePlay does not sell personal data in exchange for direct payment. Certain advertising techniques may qualify as sharing under California legislation. Where applicable, residents may request access, rectification, erasure and objection to sale or sharing. Objections may be made via Cookie Settings or support@tableplay.online.

22. Additional International Provisions For persons in, among others, the United Kingdom, Switzerland, Canada, Brazil, Australia, Turkey and China, local additional rights may apply, including information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent and the lodging of a complaint with a local supervisory authority. TablePlay handles requests in accordance with the law applicable to the specific processing concerned.

23. External Services The website and services may refer to services of third parties. TablePlay is not responsible for the privacy practices of external parties over which it has no control. Users should consult the privacy information of those parties.

24. Changes TablePlay may amend this statement in the event of changes to its services, technology, suppliers, legislation, retention periods or international activities. The current version will be published on the website. In the event of material changes, business customers may be additionally informed.

25. Contact TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - Netherlands - Chamber of Commerce (KvK) 91644453 - VAT NL865722729B01 - support@tableplay.online.

TablePlay Privacy Statement

Page 8 of 8