Privacy Statement TablePlay
Processing of personal data of website visitors, business
clients and restaurant guests
TablePlay by Jimani
Jimani B.V.
Albert Plesmanweg 122, 4462 GC Goes
KvK 91644453 - Btw NL865722729B01
support@tableplay.online
Version 1.0
Last updated: 10 July 2026
Legal review note
This document has been drafted for business use by TablePlay. Have the final publication, international
application, current suppliers, technical setup and country-specific rules periodically reviewed by legal counsel.
Table of contents
1. General purport and scope of application
2. Identity of the provider
3. Data protection roles
4. Categories of personal data
5. Source of data
6. Purposes and legal grounds
7. Game data and visibility
8. Minors
9. Artificial intelligence
10. Automated processing
11. Recipients and suppliers
12. International transfer
13. Retention periods
14. Security
15. Cookies and advertising
16. E-mail communication
17. Rights of data subjects
18. Requests from restaurant guests
19. Complaints
20. Obligations of business clients
21. California
22. Additional international provisions
23. External services
24. Amendments
25. Contact
Privacy Statement TablePlay
Page 2 of 8
1. General purport and scope of application
This privacy statement relates to every processing of personal data that takes place in connection
with the development, operation, security, support, analysis and commercial provision of TablePlay,
including the website, the business client portal, the QR-based game environment, administrative
functionalities, communication channels and related services.
TablePlay enables businesses, including restaurants, cafés, terraces and other hospitality establishments, to
offer interactive table games to guests. Guests can scan a QR code linked to a table or location and
participate, using a temporary nickname, in games, table competitions and temporary
leaderboards.
This statement applies, depending on the factual relationship, to website visitors, business clients and their
contact persons, users of the client portal, restaurant guests and players, persons who
make contact, and recipients of business or commercial communications.
2. Identity of the provider
TablePlay is offered under the product and trade designation TablePlay by Jimani by Jimani B.V.,
established at Albert Plesmanweg 122, 4462 GC Goes, the Netherlands, registered under KvK number 91644453
and VAT identification number NL865722729B01.
For privacy questions, objections, complaints and requests, contact may be made via
support@tableplay.online. At the time of this version, TablePlay has not formally appointed a
data protection officer.
3. Data protection roles
3.1 TablePlay as controller
TablePlay is the independent controller for, among other things, website visits, registration and management
of business accounts, subscriptions, payments, invoicing, support, business marketing, platform security,
fraud prevention, technical logging, statutory administration, legal protection, general product analysis and
anonymised benchmarks.
3.2 The business client as controller
The restaurant or other business client may be the controller for the decision to offer TablePlay to
guests, the placement of QR codes, the deployment of screens and leaderboards within the location, its
own provision of information to guests, and any independent use of statistics or promotional data.
3.3 TablePlay as processor
Insofar as TablePlay processes restaurant-related game data solely on behalf of a business client, TablePlay
may act as processor. This may include temporary nicknames, table identifiers, answers, scores, sessions
and restaurant-related dashboard information. The further relationship is governed by the
data processing agreement.
4. Categories of personal data
4.1 Website visitors
When visiting the website, IP address, date and time, pages visited, referring source, browser,
operating system, device type, screen size, language setting, general location, cookie preferences,
session data, error and performance data and - subject to consent - advertising and conversion data may be
processed.
Privacy Statement TablePlay
Page 3 of 8
4.2 Business accounts
When registering and managing an account, the name of the contact person, company name, e-mail address,
telephone number, address, postal code, city, country, VAT number, KvK or local registration number, website,
company logo, language and country settings, number of tables, subscription information, price and currency,
account status, role, rights, registration data, last login and relevant security history may be processed.
Passwords are not stored as plain text but are protected using appropriate authentication and
hashing techniques.
**4.3 Payment and Invoice Data**
For payments, Stripe customer number, subscription status, invoice numbers, invoice amounts, currency,
payment status, payment method, payment history, last four digits of a payment card, card type, IBAN where
relevant, outstanding amounts and data regarding trial or Founder periods may be processed.
Full card numbers and security codes are, in principle, processed directly by Stripe.
**4.4 Contact, Support and Sales**
When someone gets in touch, name, e-mail address, telephone number, company name, position,
subject, content and date of the communication, prior correspondence, technical information, interest in
TablePlay and internal follow-up status may be processed.
**4.5 Restaurant Guests and Players**
During a game session, a temporary nickname, table number or unique table ID, restaurant, game choice,
game mode, answers, game progress, score, win or loss, ranking, date, time, session ID, language choice
and necessary technical data may be processed.
A guest is not required to provide an account, e-mail address, telephone number, date of birth or real name.
Because a nickname in a restaurant context can sometimes be indirectly identifiable, TablePlay treats such
information as pseudonymous and potentially identifiable information.
Players are requested not to use their real or full name as a nickname.
**4.6 Technical and Security Data**
For reliability and security purposes, IP addresses, timestamps, browser and device data,
server logs, session data, login attempts, error messages, suspicious activity, technical identifiers and
data for abuse or fraud investigations may be processed.
**4.7 Special Categories of Personal Data**
TablePlay does not intend to systematically process special categories of personal data, criminal
record data or other sensitive personal data. Users should not include such information in nicknames, games,
free-text fields or support messages. Sensitive data unintentionally received may be deleted or
restricted from access.
**5. Source of Data**
Data may be obtained directly from the data subject, via a business customer, via registration and
contact forms, via the customer portal, during game sessions, via cookies, via hosting and
security providers, via Stripe, via advertising platforms following consent, and from public business sources.
Privacy Statement TablePlay
Page 4 of 8
**6. Purposes and Legal Bases**
TablePlay only processes personal data where a valid legal basis exists for doing so. Depending
on the processing, this may be the performance of a contract, pre-contractual measures, a legal
obligation, a legitimate interest, consent or another applicable legal basis.
**6.1 Performance of the Services**
Data are used for account registration, authentication, linking of tables and QR codes, execution
of games, calculation of scores, temporary leaderboards, dashboards, language settings, subscriptions and
support. The legal basis is, in principle, performance of the contract or a pre-contractual
measure.
**6.2 Payment and Administration**
Data are used for payments, invoices, subscriptions, accounts receivable management, tax administration
and audits. The legal basis is the contract, a legal obligation and, where applicable, a
legitimate business interest.
**6.3 Contact and Support**
Data are used to handle questions, complaints, demo requests, onboarding, technical issues and
privacy requests.
**6.4 Security and Abuse Prevention**
Technical data are processed for account security, fraud prevention, attack detection,
protection of scores, evidence in the event of incidents and continuity. This is based on the legitimate interest in a
secure and reliable service.
**6.5 Analysis and Product Improvement**
Data may be used for usage statistics, popularity of games, troubleshooting,
capacity planning, general benchmarks and development. Where possible, data are anonymised
or aggregated. Non-essential tracking is only applied following the required consent.
**6.6 Marketing**
Business contact data may be used for news, new games, upgrades, promotions and relevant
services. Consent is relied upon for this where required; in other cases, an existing
customer relationship or legitimate interest may form the legal basis. Opting out is possible via the unsubscribe link or
support@tableplay.online.
7. Game Data and Visibility
Nicknames, scores and results may be visible on the player's device, to the player's own table, to other
participating tables within the same restaurant, on a screen in the restaurant and in the
restaurant dashboard.
This data is not published publicly on the internet by default, shared between restaurants, used
for a persistent player profile, personalised advertising or structural prediction of individual
preferences. Active nicknames and leaderboards are visible for a maximum of one day. Underlying data
may be retained for the period referred to below.
Privacy Statement TablePlay
Page 5 of 8
8. Minors
TablePlay may be used by families and children. A personal account is not required for regular play.
TablePlay does not ask children for a full name, e-mail address, telephone number, date of birth,
address, school or photograph.
Children are not structurally personally tracked or commercially approached on the basis of individual
gameplay behaviour. Parents or legal representatives may request investigation or
deletion via support@tableplay.online.
9. Artificial Intelligence
TablePlay may use AI services for translation, support assistance, gameplay queries, classification,
quality improvement and product development. TablePlay does not intend to use directly identifiable
guest data for the general training of public AI models.
Where external AI services are used, the amount of information is limited as far as possible and
data is, where possible, anonymised, pseudonymised or summarised.
10. Automated Processing
TablePlay does not apply solely automated decision-making concerning restaurant guests that has for them
legal or similarly significant consequences. Business Accounts may, in the event of non-payment, be
automatically restricted, blocked or terminated on the basis of objective payment data. The customer may
request human review.
11. Recipients and Suppliers
Personal data may, insofar as necessary and lawful, be processed by or shared with Vercel
for hosting, Supabase for database and authentication, Stripe for payments, Twilio SendGrid for e-mail,
Google services for analytics and advertising, Meta and LinkedIn for marketing measurement following consent,
any AI suppliers and professional advisors or competent authorities.
In the event of a reorganisation, investment, merger, sale or acquisition, data may be shared under appropriate
confidentiality with the parties and advisors involved.
12. International Transfer
The primary environment is, insofar as technically arranged, hosted in a European region. International
suppliers may, however, process or make accessible data outside the European Economic Area.
Where required, TablePlay uses adequacy decisions, standard contractual clauses,
data processing agreements and additional technical or organisational measures.
13. Retention Periods
Personal data is not retained for longer than necessary, save for statutory obligations,
outstanding payments, fraud investigation, security incidents or legal claims.
• Business Account data: for the duration of the active Account and a maximum of one year after termination, unless a
longer period is necessary.
• Invoices and tax records: at least seven years.
• Active guest nicknames and leaderboards: visible for a maximum of one day.
Privacy Statement TablePlay
Page 6 of 8
• Game sessions, nicknames in technical sessions, scores and results: a maximum of one year, after which they are
deleted or anonymised.
• Technical and security logs: a maximum of one year, save in the case of incidents or disputes.
• Contact, sales and support data: a maximum of one year after the last relevant contact or handling thereof.
• Incomplete registrations: a maximum of one year.
• Marketing data: until unsubscription, objection or the end of relevance; a suppression record may be
retained for longer.
• Backups: in principle a maximum of one month.
• Anonymised or sufficiently aggregated data: for as long as this no longer qualifies as personal
data.
14. Security
TablePlay takes appropriate technical and organisational measures, including HTTPS/TLS, hashed
passwords, authorisation, segregated restaurant accounts, Supabase Row Level Security where applicable,
logging, restricted administrative rights, backups, monitoring and agreements with suppliers.
No digital service can guarantee absolute security. Incidents are investigated and, where legally
required, reported to the supervisory authority and the data subjects concerned.
15. Cookies and advertising
Necessary techniques may be used for login, session security, language selection and cookie
preferences. Analytical and marketing techniques, including Google Analytics, Google Ads, Meta Pixel and
LinkedIn Insight Tag, will only be activated after consent insofar as legally required. Preferences may
be changed via Cookie Settings.
16. E-mail communication
TablePlay sends necessary messages regarding registration, security, invoices, subscriptions, changes
and support. It is not always possible to unsubscribe from such communication for as long as an Account or a legal
obligation exists. It is possible to unsubscribe from commercial messages.
17. Rights of data subjects
Depending on the applicable legislation, data subjects may have the right to information, access, rectification,
erasure, restriction, portability, objection, withdrawal of consent, objection to direct
marketing, human review and lodging a complaint.
Requests may be sent to support@tableplay.online. TablePlay may request reasonable identification
and generally responds within one month. Rights are not absolute and may be limited by legal
obligations, rights of third parties, evidentiary interests or statutory exceptions.
18. Requests from restaurant guests
Because restaurant guests generally do not have a personal Account, TablePlay cannot always establish which
session belongs to which person. For investigation purposes, the restaurant, location, table, date, time,
nickname, game and session context may be requested.
Where there is insufficient likelihood that data relates to the requester, such data will not be
provided. TablePlay may involve the restaurant where it is the controller for the relevant
processing.
Privacy Statement TablePlay
Page 7 of 8
19. Complaints
Complaints may first be submitted via support@tableplay.online. Data subjects retain the right to lodge a
complaint with the competent privacy supervisory authority. For the Netherlands, this is the Autoriteit
Persoonsgegevens.
20. Obligations of business customers
Business customers are required to use TablePlay in a privacy-friendly manner. They may not require guests
to use real names, may not include sensitive data in games, may not engage in unauthorised profiling, may not
apply unlawful marketing and may not share administrative access with unauthorised persons.
They are responsible for information provided to guests, account security, correct display of leaderboards,
local legislation and their own marketing.
21. Additional information for California
To the extent that California privacy legislation applies, categories such as identification data,
account data, internet data, commercial data, payment data, general location and pseudonymous
game data may be processed.
TablePlay does not sell personal data for direct payment. Certain advertising techniques
may qualify as sharing under California legislation. Where applicable, residents may request access,
rectification, erasure and objection to sale or sharing. Objection may be submitted via Cookie Settings or
support@tableplay.online.
22. Additional international provisions
For persons in, among other places, the United Kingdom, Switzerland, Canada, Brazil, Australia, Turkey and China,
local additional rights may apply, including information, access, rectification, erasure, restriction,
portability, objection, withdrawal of consent and lodging a complaint with a local supervisory authority.
TablePlay handles requests in accordance with the law applicable to the specific processing.
23. External services
The website and services may refer to services of third parties. TablePlay is not responsible
for the privacy practices of external parties over which it has no control. Users are advised to
consult the privacy information of those parties.
24. Amendments
TablePlay may amend this statement in the event of changes in service provision, technology, suppliers, legislation,
retention periods or international activities. The current version is published on the website. In the case of
material amendments, business customers may be additionally informed.
25. Contact
TablePlay by Jimani - Jimani B.V. - Albert Plesmanweg 122 - 4462 GC Goes - The Netherlands - KvK 91644453 - VAT
NL865722729B01 - support@tableplay.online.
Privacy Statement TablePlay
Page 8 of 8