Skip to content

Version 2026-08-member-v4

Privacy for your account

Effective 4 September 2026What we hold about you, and what we do with it.

This version was written by Table42 and has not been reviewed by a lawyer. We are publishing it anyway rather than opening accounts with nothing to read. It will be replaced by a reviewed version, and that will be a new version with a new date.

This covers a Table42 member account: what we hold, why, who else touches it and how long it stays. It is separate from the statement covering ordinary browsing of this website. The website and the app are two doors onto one account, so this covers both.

Who is responsible

Table42 is run by Tim Gelhard in the Netherlands. KVK: 86893416. VAT: NL004142601B69. The registered address and telephone number are on the About page. Write to [email protected] and it reaches the person who decides.

Table42 is the controller for everything described here. There is no data protection officer, because the size of the service does not require one.

What we collect when you create the account

Your email address and a password, both handled by our authentication provider. The version of the terms and this statement that you accepted, the moment you accepted them, and whether you also said yes to optional email. Your language.

Why: to create the account, and because your acceptance is what allows us to hold everything else. The basis is the agreement between you and us, and separately your consent for the optional email, which you can withdraw at any time without it touching the account.

If you came here by scanning the code on a venue’s printed card or poster, we also store which venue that was. Before you sign up it sits in your browser for thirty days and nowhere else; from the moment you sign up it is one line joining your account to that venue, and it goes when you delete your account. The venue is told a number and nothing more — never your name, your address or anything else about you. Why: so we can see which of our own cards brought people in, and the basis is our legitimate interest in knowing that.

What we collect in your profile

Your first name, date of birth, gender, phone number, city, a short description of up to 280 characters, and between three and ten interests. Once you are accepted, one to four photographs.

Why: it is what a person reads to decide about you, and afterwards it is what other members see when Table42 suggests you to each other. The basis is the agreement between you and us. Your date of birth is also how we meet our own obligation not to admit anyone under 18. That date is what you tell us: we do not check it against a document, and if what you told us turns out to be untrue we close the account.

In the app you can also choose a country to represent. It is shown to other signed-in members and to nobody else, it is something you say about yourself rather than anything we check, and it plays no part in who you are shown or in any decision about your account. Leaving it empty is a real answer and costs you nothing.

What you have to give us, and what happens if you do not. An email address, a password and your acceptance of these documents are what make the account exist at all, and there is no account without them. What a person reads when deciding about you is the profile: your first name, date of birth, gender, phone number, city and your interests. After that a profile is only finished when those are there together with at least three interests and at least one photograph, and while it is unfinished Table42 introduces you to nobody and you cannot host a table or invite anyone. The description and the country you represent are optional, and leaving either out is held against you in nothing.

Your photographs, and who can open them

Once you are accepted you can put one to four photographs on your profile, and after a meetup you can post photographs to the community. Other members see them where you would expect: when Table42 suggests you to somebody, on your profile, and on the post itself.

Being straight about how they are stored, because it is not what most people assume. The photographs sit in a store that answers a plain web address. The address of each one is long and random, nothing lists what is in the store, and no page of ours shows a photograph to somebody without an account. But the address itself is the key: if it is copied out or shared, it opens that photograph for anybody, with no account and no login.

We are changing that so a photograph can only be opened through a link that we sign and that expires. Until that is done, this paragraph says what is true today rather than what we intend. Deleting a photograph, or deleting your account, removes it from the store — it cannot pull back a copy somebody already downloaded.

Your interests, and a question we have not answered yet

You pick between three and ten interests. Most are ordinary. Some could reveal something the law protects more strictly, such as a health condition, a belief or your sexual orientation.

This is an open question in our own compliance review and we are not going to pretend otherwise. Our own audit raises it, and no qualified person has answered it yet. Until one has, the honest position is this: we ask for interests so we can suggest people you might get along with, you choose freely which to give us, you can change or remove them at any time from your profile, and nobody outside Table42 receives them.

When that question is answered, this statement changes and you will see a new version.

The decision about you

We store your account status, and if we do not accept you, a reason, a short written note explaining it, the time, and which of your two attempts it was.

Why: to tell you why, to let you fix it and try again, and so we can account for the decision afterwards. The note is written by a person about you, and you can ask to see it.

No decision about your account is taken by a machine. A person reads your profile and decides. There is no score, no ranking and no automated rejection.

Finding people, and what another member sees

Once you are accepted, Table42 shows you other members and shows you to them. For that we hold the place you set as home, and the two filters you choose: an age range and a distance.

Your location never leaves our server and no member is ever given your coordinates, a distance in kilometres or a point on a map. What they get is a rough band, one of five, of how far away you are. On this website your location is rounded before it is even sent to us; in the app it is stored as precisely as your device reported it, so we cannot claim the rounding for both and we are not going to write it as if we could.

What another member actually sees is your first name, your age, your gender, your city, your description, your interests, your photographs, the country you chose to represent if you set one, and that distance band. Nothing else reaches them.

Every time you decide about somebody, one way or the other, we store that decision. It is what stops the same profile coming back round, and only you can ever see it.

Invitations, messages and the games in them

An invitation carries a short note, up to 280 characters. Before it is sent we check that note automatically for phone numbers, email addresses and social handles and refuse it if it has any. That check is not us reading what you wrote: it is a rule against moving people off Table42 in the first message, and no person sees the note because of it. Both of you can see an invitation and its note.

Messages are up to 2000 characters and are stored on our servers in a form we could technically read. We do not read them as a matter of course, and nothing scans them. We look at a specific message when somebody reports it to us. We also store which messages you have read, so your app knows what to mark as new.

The games you can play inside a conversation store what you type into them. Everyone in that conversation can see it, which in a group is more people than the two playing — worth knowing before you type a childhood story into one.

Reporting, blocking, and rating an evening

If you report somebody we store who reported, who was reported, which message you picked if you picked one, the category and your note of up to 1000 characters. The person reported is not told who reported them. A report cannot be edited or taken back once it is filed, because a safety record that can be rewritten afterwards is not a safety record.

If you block somebody we store the block. It is yours: only you can see it, and it stays in place even if the other person deletes their account, because it is your protection and not theirs to lift.

After a meetup you can rate it, including whether you felt safe, and write a comment of up to 1000 characters. Only you and Table42 can read what you wrote. The person you rated cannot, and that is deliberate: a rating that gets read back to its subject stops being an honest one.

Meetups, the venue, and your meetup tickets

When you accept an invitation or join an open meetup we store the meetup, who is in it, the part each of you plays and when you joined. When you arrive and check in at the venue we store the moment you did, and nothing else about the visit — no location, no till, no order.

Afterwards you can post about the evening: a caption, the people you tag, and photographs. A post is visible to every signed-in member, not only to the people who were there, so treat it as public within Table42.

Meetup tickets are bought on this website. The payment itself is handled by our payment provider and your card details never reach us. We keep the record of what was bought and when, and the ledger of tickets going into and out of your account.

Notifications on your phone

If you allow notifications, your phone hands the app a token that lets a message be delivered to it. We store that token with the platform and a device identifier. Nothing sends notifications yet, so today the token sits there unused, and Apple and Google receive nothing from us until it does.

One thing we have to say rather than tidy away: those tokens are not currently removed when an account is deleted. That is a fault, it is written down with an owner, and it is being fixed.

Keeping the door safe, and paying

When you sign up we check the request against an anti-abuse service, and our servers record the usual technical information: IP address, browser, time and page. The basis is our legitimate interest in a service that is not overrun by automated signups, and it is ordinary, short-lived data.

If you ever buy meetup tickets, the payment details go to our payment provider and never to us. We keep the record of what was bought and when, because tax law requires it.

What we do not do

We do not sell your data. We do not give it to advertisers. We do not use it to build a profile of you for anybody else's purposes.

Until you are accepted, your profile is visible to us and to nobody else. It appears on no public page and to no other member.

Who else processes it

Each of these acts on our instructions and for no purpose of their own. Where a provider is outside the EU, the transfer runs on the European Commission's standard contractual clauses.

  • Supabase — the database, the accounts and the photo storage.
  • Hetzner — the servers this website runs on.
  • Cloudflare — traffic in front of the site, and the anti-abuse check at signup.
  • Resend — sends the email the service has to send you.
  • Plausible — counts page visits, with no cookie and no personal data in the events.
  • Sentry — receives the technical report when something breaks, so we can find the fault. It carries what went wrong and where, not who you are.
  • Mollie — takes the payment, if and when you buy a meetup ticket.
  • Apple and Google — deliver a push notification to your phone, if you allow them.

How long we keep it

An account whose email address is never confirmed is deleted after 30 days. An account we did not accept is deleted twelve months after the final decision, together with the note about you. An account waiting for a decision is held while it waits; if no decision has been taken after twelve months we ask you, and delete it if you do not answer. An account you delete yourself goes when you ask.

We keep the record of which version you accepted for as long as you have an account and for seven years afterwards, because it is the evidence of what you agreed to. We keep what you bought for seven years, because tax law requires it. Server and security logs are kept for 30 days. A data-rights request is kept for three years after we close it.

What you make while using Table42 follows its own rules. Your decisions in the deck, your invitations and their notes, the blocks you placed, your home location and your filters all go when your account goes. A safety report is kept for three years after the case is closed — every report, including one about somebody who has since deleted their account, because the record of what we decided has to outlive the account it was about. The basis for that keep is our legitimate interest in being able to show what we decided and why, and to defend it if it is challenged. What you bought stays seven years, for tax. Messages, meetups and what you wrote about an evening are in the next section, because they are tangled up with other people's records and they do not simply go.

One thing to be straight about: almost none of this is automated. A person works through it by hand on a monthly review, and for the report period there is no automatic deletion at all yet. We would rather publish the rule and tell you a person runs it than publish a period and let you assume a machine is enforcing it. If you want something gone sooner than the periods above, ask and it goes — unless the law makes us keep it. Tax law keeps what you bought for its seven years, and a safety report stays the three years after the case is closed described above, because that is the record we would have to stand behind if the decision were challenged. When one of those two applies we tell you which, rather than refusing without a reason.

Deleting your account

You can delete your account yourself at any time, in the app or from your account on this website.

What goes: your profile and everything personal in it — your name, date of birth, gender, description, phone number, city, home location, interests, the country you represented — your photographs, both profile and post, the decisions you made in the deck, the blocks you placed, and the likes and comments you left. Your email address is scrambled, so the account cannot be signed into and cannot be matched back to you.

What stays, and why. This list is longer than you would guess and we would rather you read it here than find it out later. Your messages stay in the conversations you had, because deleting them would tear holes in the other person's record of their own evening. Meetups you took part in stay, with the part you played and the moment you checked in. The caption and the tags on a post you shared with other people stay. Ratings you wrote stay, so that leaving and coming back cannot wipe a trail behind you. Reports you filed stay, and so do reports filed about you, for the three years described above. A block somebody placed on you stays, because that protection is theirs. Your meetup ticket ledger stays, and the record of what you bought stays for seven years, because tax law requires it.

What is left of you in all of that is an anonymous marker: a row with no name, no face and no way back to you. It is what lets other people keep their own history without keeping you in it.

Two things we have not fixed yet, and we are not going to write around them: the notification token your phone gave us, and anything you typed into one of the in-chat games, are not removed today. A pending invitation is cancelled rather than deleted, so its note survives too. All three are written down as faults with an owner. Until they are fixed we will not tell you that deleting your account removes everything you wrote.

Your rights

These are yours, and you can use them before you are accepted, while you wait, or afterwards. Ask at [email protected] or use the pages in your account. We answer without undue delay and normally within one month, and it costs you nothing.

  • See what we hold. Your account page builds it for you and tells you what it could not read.
  • Correct it. Your name, city, description, interests and photographs are yours to change directly; anything else, tell us.
  • Delete it, as described above.
  • Take it elsewhere, as one file that another service can read.
  • Pause it. Ask us to keep your data but stop using it while something is being checked.
  • Object to anything we do on the basis of legitimate interest, and we stop unless we have a compelling reason not to, which we would have to explain to you.
  • Take back a permission you gave us. The optional email is the one thing here that runs on your permission, and the control that takes it back is in your account. Withdrawing it does not make what we did before you withdrew it unlawful, and it does not touch the account itself.
  • Complain about how we handled your data, to us and to the Dutch data protection authority. The next section says how, and you do not have to come to us first.

Complaining

If you think we have handled your data badly, tell us first at [email protected] so we can put it right.

You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. That right is yours whether or not you ask us first.

Changes

A material change to what we collect, why, who receives it or how long we keep it is a new version with a new date, published here and shown to you. We will not change what this covers quietly.

Contact

Questions about your data, or want to use one of your rights? Email [email protected].