Privacy Statement TablePlay
Processing of personal data of website visitors, business
customers and restaurant guests
TablePlay by Jimani
Jimani B.V.
Albert Plesmanweg 122, 4462 GC Goes
KvK 91644453 - VAT NL865722729B01
support@tableplay.online
Version 1.0
Last updated: 10 July 2026
Legal review note
This document has been drawn up for business use by TablePlay. Have the final publication, international
application, current suppliers, technical set-up and country-specific rules reviewed periodically by legal counsel.
Table of contents
1. General purport and scope of application
2. Identity of the provider
3. Roles under data protection law
4. Categories of personal data
5. Source of data
6. Purposes and legal bases
7. Game data and visibility
8. Minors
9. Artificial intelligence
10. Automated processing
11. Recipients and suppliers
12. International transfer
13. Retention periods
14. Security
15. Cookies and advertising
16. Email communication
17. Rights of data subjects
18. Requests from restaurant guests
19. Complaints
20. Obligations of business customers
21. California
22. Additional international provisions
23. External services
24. Amendments
25. Contact
Privacy Statement TablePlay
Page 2 of 8
1. General purport and scope of application
This privacy statement relates to any processing of personal data that takes place in connection with
the development, operation, security, support, analysis and commercial provision of TablePlay,
including the website, the business customer portal, the QR-based game environment, administrative
functionalities, communication channels and related services.
TablePlay enables businesses, including restaurants, cafés, terraces and other hospitality establishments, to
offer interactive table games to guests. Guests can scan a QR code linked to a table or location and, using a
temporary nickname, take part in games, table competitions and temporary leaderboards.
Depending on the actual relationship, this statement applies to website visitors, business customers and their
contact persons, users of the customer portal, restaurant guests and players, persons who make contact,
and recipients of business or commercial communications.
2. Identity of the provider
TablePlay is offered under the product and trade name TablePlay by Jimani by Jimani B.V.,
established at Albert Plesmanweg 122, 4462 GC Goes, the Netherlands, registered under KvK number 91644453
and VAT identification number NL865722729B01.
For privacy-related questions, objections, complaints and requests, please contact
support@tableplay.online. At the time of this version, TablePlay does not have a formally appointed data
protection officer.
3. Roles under data protection law
3.1 TablePlay as data controller
TablePlay is an independent data controller for, among other things, website visits, registration and management
of business accounts, subscriptions, payments, invoicing, support, business marketing, platform security,
fraud prevention, technical logging, statutory record-keeping, legal protection, general product analysis and
anonymised benchmarks.
3.2 The business customer as data controller
The restaurant or other business customer may be a data controller in respect of the decision to offer TablePlay
to guests, the placement of QR codes, the use of screens and leaderboards within the venue, the
provision of its own information to guests, and any independent use of statistics or promotional data.
3.3 TablePlay as processor
Insofar as TablePlay processes restaurant-specific game data solely on behalf of a business customer,
TablePlay may act as a processor. This may include temporary nicknames, table identifiers, answers, scores, sessions
and restaurant-specific dashboard information. The further relationship is governed by the
data processing agreement.
4. Categories of personal data
4.1 Website visitors
When visiting the website, the IP address, date and time, pages visited, referring source, browser,
operating system, device type, screen size, language setting, general location, cookie preferences,
session data, error and performance data and, subject to consent, advertising and conversion data may be
processed.
Privacy Statement TablePlay
Page 3 of 8
4.2 Business accounts
Upon registration and account management, the following may be processed: the name of the contact person,
company name, email address, telephone number, address, postal code, city, country, VAT number, KvK or local
registration number, website, company logo, language and country settings, number of tables, subscription
information, price and currency, account status, role, rights, registration data, last login and relevant security
history.
Passwords are not stored as plain text but are protected using appropriate authentication and
hashing techniques.
4.3 Payment and Invoicing Data
For payments, TablePlay may process Stripe customer number, subscription status, invoice numbers, invoice
amounts, currency, payment status, payment method, payment history, last four digits of a payment card,
card type, IBAN where relevant, outstanding amounts and data concerning trial or Founder periods.
Full card numbers and security codes are, in principle, processed directly by Stripe.
4.4 Contact, Support and Sales
When someone makes contact, name, e-mail address, telephone number, company name, job title, subject,
content and date of the communication, previous correspondence, technical information, interest in
TablePlay and internal follow-up status may be processed.
4.5 Restaurant Guests and Players
During a game session, a temporary nickname, table number or unique table ID, restaurant, game choice,
game mode, answers, game progress, score, win or loss, ranking, date, time, session ID, language choice and
necessary technical data may be processed.
A guest is not required to provide an account, e-mail address, telephone number, date of birth or real name.
Because a nickname in a restaurant context may sometimes be indirectly identifiable, TablePlay treats this as
pseudonymous and potentially identifiable information.
Players are requested not to use a real or full name as a nickname.
4.6 Technical and Security Data
For reliability and security purposes, IP addresses, timestamps, browser and device data, server logs, session
data, login attempts, error messages, suspicious activities, technical identifiers and data for misuse or fraud
investigation may be processed.
4.7 Special Categories of Personal Data
TablePlay does not intend to systematically process special categories of personal data, criminal or other
sensitive personal data. Users should not include such information in nicknames, games, free text fields or
support messages. Sensitive data received unintentionally may be deleted or restricted.
5. Source of Data
Data may be obtained directly from the data subject, via a business customer, via registration and contact
forms, via the customer portal, during game sessions, via cookies, via hosting and security providers, via
Stripe, via advertising platforms following consent, and from public business sources.
Privacy Statement TablePlay
Page 4 of 8
6. Purposes and Legal Bases
TablePlay only processes personal data where a valid legal basis exists for doing so. Depending on the
processing in question, this may be the performance of a contract, pre-contractual measures, a legal
obligation, a legitimate interest, consent or another applicable basis.
6.1 Performance of the Service
Data is used for account registration, authentication, linking of tables and QR codes, execution of games,
calculation of scores, temporary leaderboards, dashboards, language settings, subscriptions and support. The
basis is, in principle, the performance of the contract or a pre-contractual measure.
6.2 Payment and Administration
Data is used for payments, invoices, subscriptions, accounts receivable management, tax administration and
audits. The basis is the contract, a legal obligation and, where applicable, a legitimate business interest.
6.3 Contact and Support
Data is used to handle queries, complaints, demo requests, onboarding, technical issues and privacy requests.
6.4 Security and Misuse Prevention
Technical data is processed for account security, fraud prevention, attack detection, protection of scores,
evidence in the event of incidents and continuity. This is based on the legitimate interest in a secure and
reliable service.
6.5 Analysis and Product Improvement
Data may be used for usage statistics, popularity of games, troubleshooting, capacity planning, general
benchmarks and development. Where possible, data is anonymised or aggregated. Non-essential tracking is
only applied following the required consent.
6.6 Marketing
Business contact data may be used for news, new games, upgrades, promotions and relevant services. Consent
is used for this purpose where required; in other cases, an existing customer relationship or legitimate interest
may form the basis. Opting out is possible via the unsubscribe link or support@tableplay.online.
7. Game data and visibility
Nicknames, scores and results may be visible on the player's device, to the player's own table, to other
participating tables within the same restaurant, on a screen in the restaurant and in the restaurant
dashboard.
This data is not published publicly on the internet by default, shared between restaurants, used for a
persistent player profile, personalised advertisements or structural prediction of individual preferences.
Active nicknames and leaderboards are visible for a maximum of one day. Underlying data may be retained
for the period specified below.
TablePlay Privacy Statement
Page 5 of 8
8. Minors
TablePlay may be used by families and children. No personal account is required for regular play. TablePlay
does not ask children for a full name, email address, telephone number, date of birth, address, school or
photo.
Children are not structurally personally tracked or commercially approached on the basis of individual game
behaviour. Parents or legal representatives may request investigation or deletion via
support@tableplay.online.
9. Artificial intelligence
TablePlay may use AI services for translation, support assistance, game questions, classification, quality
improvement and product development. TablePlay does not intend to use directly identifiable guest data for
the general training of public AI models.
With external AI services, the amount of information is limited as much as possible and data is anonymised,
pseudonymised or aggregated where possible.
10. Automated processing
TablePlay does not apply solely automated decision-making regarding restaurant guests that has legal or
similarly significant effects for them. Business Accounts may, in the event of non-payment, be automatically
restricted, blocked or terminated on the basis of objective payment data. The customer may request human
reassessment.
11. Recipients and suppliers
Personal data may, insofar as necessary and lawful, be processed by or shared with Vercel for hosting,
Supabase for database and authentication, Stripe for payments, Twilio SendGrid for email, Google services
for analytics and advertising, Meta and LinkedIn for marketing measurement after consent, any AI suppliers
and professional advisers or competent authorities.
In the event of a reorganisation, investment, merger, sale or acquisition, data may be shared under
appropriate confidentiality with the parties and advisers involved.
12. International transfers
The primary environment is hosted in a European region insofar as technically arranged. However,
international suppliers may process or make data accessible outside the European Economic Area.
Where required, TablePlay uses adequacy decisions, standard contractual clauses, data processing
agreements and additional technical or organisational measures.
13. Retention periods
Personal data is not retained longer than necessary, except in the case of legal obligations, outstanding
payments, fraud investigations, security incidents or legal claims.
• Business Account data: for the duration of the active Account and for a maximum of one year after
termination, unless a longer period is necessary.
• Invoices and tax records: at least seven years.
• Active guest nicknames and leaderboards: visible for a maximum of one day.
TablePlay Privacy Statement
Page 6 of 8
• Game sessions, nicknames in technical sessions, scores and results: maximum one year, thereafter deleted
or anonymised.
• Technical and security logs: maximum one year, save for incidents or disputes.
• Contact, sales and support data: maximum one year after the last relevant contact or handling thereof.
• Incomplete registrations: maximum one year.
• Marketing data: until unsubscription, objection or the end of relevance; a suppression record may be
retained for longer.
• Backups: in principle, maximum one month.
• Anonymised or sufficiently aggregated data: for as long as it no longer qualifies as personal data.
14. Security
TablePlay implements appropriate technical and organisational measures, including HTTPS/TLS, hashed
passwords, authorisation, separated restaurant accounts, Supabase Row Level Security where applicable,
logging, restricted administrative rights, backups, monitoring and agreements with suppliers.
No digital service can guarantee absolute security. Incidents are investigated and, where legally required,
reported to the supervisory authority and data subjects.
15. Cookies and advertising
Necessary techniques may be used for login, session security, language selection and cookie preferences.
Analytical and marketing techniques, including Google Analytics, Google Ads, Meta Pixel and LinkedIn Insight
Tag, are only activated after consent insofar as legally required. Preferences can be changed via Cookie
Settings.
16. Email communication
TablePlay sends necessary messages regarding registration, security, invoices, subscriptions, changes and
support. It is not always possible to opt out of such communication as long as an Account or legal obligation
exists. One can opt out of commercial messages.
17. Rights of data subjects
Depending on the applicable legislation, data subjects may have the right to information, access, correction,
erasure, restriction, portability, objection, withdrawal of consent, objection to direct marketing, human review
and the lodging of a complaint.
Requests may be sent to support@tableplay.online. TablePlay may request reasonable identification and, in
principle, responds within one month. Rights are not absolute and may be limited by legal obligations, rights of
third parties, evidentiary interests or statutory exceptions.
18. Requests from restaurant guests
Because restaurant guests generally do not have a personal Account, TablePlay cannot always establish which
session belongs to which person. For investigation purposes, information may be requested regarding
restaurant, location, table, date, time, nickname, game and session context.
Where it is not sufficiently plausible that data relates to the requester, such data will not be provided.
TablePlay may involve the restaurant where the restaurant is the controller for the relevant processing.
TablePlay Privacy Statement
Page 7 of 8
19. Complaints
Complaints may first be submitted via support@tableplay.online. Data subjects retain the right to lodge a
complaint with the competent privacy supervisory authority. For the Netherlands, this is the Autoriteit
Persoonsgegevens.
20. Obligations of business customers
Business customers should use TablePlay in a privacy-friendly manner. They may not require guests to use real
names, must not include sensitive data in games, must not engage in unauthorised profiling, must not apply
unlawful marketing and must not share administrator access with unauthorised persons.
They are responsible for informing guests, account security, correct display of leaderboards, local legislation
and their own marketing.
21. Additional information for California
Insofar as Californian privacy legislation is applicable, categories such as identification data, account data,
internet data, commercial data, payment data, general location and pseudonymous game data may be
processed.
TablePlay does not sell personal data for direct payment. Certain advertising techniques may qualify as sharing
under Californian legislation. Where applicable, residents may request access, correction, erasure and
objection to sale or sharing. Objection can be made via Cookie Settings or support@tableplay.online.
22. Additional international provisions
For individuals in, among others, the United Kingdom, Switzerland, Canada, Brazil, Australia, Turkey and China,
local additional rights may apply, including information, access, correction, erasure, restriction, portability,
objection, withdrawal of consent and the lodging of a complaint with a local supervisory authority.
TablePlay handles requests in accordance with the law applicable to the specific processing concerned.
23. External services
The website and services may refer to services provided by third parties. TablePlay is not responsible for the
privacy practices of external parties over which it has no control. Users should consult the privacy information
of those parties.
24. Amendments
TablePlay may amend this statement in the event of changes to services, technology, suppliers, legislation,
retention periods or international activities. The current version is published on the website. In the event of
material amendments, business customers may be additionally informed.
25. Contact
TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - The Netherlands - Companies
Register (KvK) 91644453 - VAT NL865722729B01 - support@tableplay.online.
TablePlay Privacy Statement
Page 8 of 8