Version 2026-09-v1
Privacy statement
Last updated 4 September 2026A plain-language statement. This version was written on 4 September 2026, replacing the one the founder read on 24 August, and nobody has reviewed it since.
This version is not something you agree to. Nothing on these pages asks you to tick a box, so there is no consent version here any more. The one that used to be shown, 2026-08-v2, belonged to the waitlist sign-up form; that form and everything it collected are gone, and the section below says so plainly.
Table42 is a small, independent project based in Utrecht. This page covers ordinary visiting: what this website itself does with you when you read it. Creating a member account is a separate thing with its own privacy statement, published beside this one — read that one if you have an account or are about to make one.
Who is responsible
Table42 is run by Tim Gelhard in the Netherlands and is registered with the Dutch Chamber of Commerce under KVK 86893416 and VAT number NL004142601B69. The registered address and telephone number are on the About page. For anything about your data — questions, corrections, or deletion — email [email protected] and a real person will answer.
What this website does with you
If you only read this website, we ask you for nothing and we store nothing that names you. There is no form on these pages that takes your details.
A visit still leaves technical data behind, because that is how the web works: your IP address, your browser, the time and the page you asked for. We use it to serve the page, to keep the site running and to keep abuse off it. It is not used to build a picture of you.
If you arrive through a campaign link, the address carries campaign tags — the ones that begin utm_. They tell us which channel brought people here. They are not attached to a person and they are not used to profile you.
Two places on this website do ask you for something, and both are described where they happen rather than here. Creating a member account has its own statement, linked below. The data-rights page takes an email address, because a request has to be answered somewhere and we have to be sure the address is yours; a request is kept for three years after we close it.
The waitlist is gone, and so is everything it held
There was a waitlist on this website until 27 August 2026. It closed, and on 3 September 2026 the sign-ups and the tools that read them were deleted from the database outright. We checked again on 4 September 2026: the table and the function are not there.
So there is nothing left to ask us about. No email address, no city, no language, no confirmation status and no campaign tags from that form survive anywhere we can reach, backups aside, and those expire on their own documented cycles. Confirmation links we sent while it was open no longer do anything at all.
The consent version those sign-ups agreed to, 2026-08-v2, is kept in our internal register as the record of what was once collected and under what text. Nothing is stored against it any more, and no new sign-up can ever carry it.
Legal basis
Serving these pages, keeping them available, keeping abuse off them and counting visits rest on our legitimate interest in running a website that works (Article 6(1)(f) GDPR). Nothing on these pages runs on your consent, because nothing on these pages asks you to agree to anything.
A member account is a different matter with a different basis — the agreement between you and us — and its own statement sets that out.
Cookies
There is no advertising cookie and no cross-site tracking cookie anywhere on this site.
Two are strictly necessary, and Dutch law does not require us to ask before setting those. One remembers which language you chose. The others appear only if you sign in to a member account: they are what keeps you signed in, they are needed for the account to work at all, and signing out removes them.
Two more remember one thing you did here, and nothing about you. If you follow a member's share link, your browser holds which link it was, so the invitation still works if you create an account later. If you scan the code on a venue's printed card or poster, your browser holds which venue that was for thirty days, so that venue is credited if you create an account later. Neither carries your name or anything else about you, neither is read by anything outside this website, and clearing your cookies removes both.
For visitor numbers we use Plausible Analytics in a cookieless configuration. We use its aggregate reports and send it nothing that identifies you.
Who else touches it
Hetzner hosts the website. Cloudflare handles DNS and edge security, and runs the anti-abuse check at the account door. Supabase holds the database and the accounts. Resend sends the mail the service has to send. Plausible supplies aggregate visitor numbers. Sentry receives the technical report when a page here fails, on a project hosted in the European Union: it carries what went wrong and where, not who you are, and email addresses are stripped from it before it is sent.
Each of these acts on our instructions and for no purpose of its own. Where a provider is outside the EU, the transfer runs on the European Commission's standard contractual clauses.
How long we keep it
Server and security logs are kept for 30 days. The language cookie stays until you change it or clear it. The share link and scanned venue held in your browser last thirty days and then expire on their own. A data-rights request is kept for three years after we close it.
That is the whole of it for ordinary browsing. What an account holds, and for how long, is in the account statement instead.
Your rights
Under the GDPR you can ask us to show you what we hold about you, correct it, delete it, restrict or object to what we do with it, and hand you back in a portable form anything you gave us. You can also complain about us to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl, whether or not you come to us first.
Being straight about what an answer will look like: for ordinary browsing we normally hold nothing that identifies you, so a request about your visits will usually find nothing to show you. That is the honest answer to the question, not a refusal of it. If you have an account, the account statement describes the rights that go with it and the pages inside your account that exercise them.
Changes to this statement
This page describes what the website does, so it changes when the website does. A material change to what we collect, why, who receives it or how long we keep it gets a new version and a new date at the top of this page. We will not change it quietly.
Exercising your rights
You do not have to write a letter to use any of the rights above. One page takes a deletion or a data request without a login, logs it, and puts it in front of a person: Delete your account or ask about your data.
Contact
Questions about your privacy? Email [email protected].