Privacy Policy
Last updated: 23 August 2026
This policy explains how we handle personal data. It is a review-ready draft and should be confirmed by legal counsel before launch.
1. Controller
The controller for this website is ThreeB IT GmbH, Bergstrang 105, 49479 Ibbenbüren, Germany, hello@threebit.io. For questions about data protection, contact us at the same address. See our Imprint for full company details.
2. Data minimisation principle
BookDinePlay is built to collect only what is needed: business details for venue operators, and the minimum contact details required to confirm a reservation, order or payment for guests. We do not sell personal data.
3. Data we process and why
- Website visitors: server log data (IP address, timestamp, request) to deliver and secure the site — legitimate interest, Art. 6(1)(f) GDPR.
- Demo, waitlist and contact requests: name, email and message to respond to you — pre-contractual steps / legitimate interest, Art. 6(1)(b)/(f) GDPR.
- Venue operators (customers): account, venue, billing and usage data to provide the Service — contract performance, Art. 6(1)(b) GDPR.
- Guests of a venue: reservation, order and (where enabled) payment details, processed by us on behalf of the venue as a processor. The venue is the controller for that guest data.
4. Payments
Where online payments or deposits are enabled, payment data is processed by our payment provider (e.g. Stripe) as an independent controller/processor under its own privacy terms. BookDinePlay does not store full card numbers or security codes.
5. Processors and transfers
We use carefully selected processors to host and operate the Service (for example cloud hosting on Microsoft Azure in the EU, and error/performance monitoring). Where a transfer outside the EU/EEA occurs, we rely on appropriate safeguards such as EU Standard Contractual Clauses.
6. Cookies
The marketing site uses only strictly necessary cookies (for example to remember your language choice). We do not use advertising trackers on this site. Application areas may use additional functional cookies required to keep you signed in.
7. Retention
We keep personal data only as long as necessary for the purposes above or as required by statutory retention periods (for example commercial and tax law), then delete or anonymise it.
8. Your rights
Subject to the GDPR you have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interests, and to withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority. For guest data held on behalf of a venue, please direct requests to that venue as controller; we will assist it as processor.
9. Contact
To exercise your rights or ask a question, contact hello@threebit.io.