Privacy Policy
Version 4.0 (5 September 2026) is superseded and is available on request from [email protected].
This Privacy Policy explains how Thursday Night LLC, a Michigan limited liability company ("Tabletop Lynk," "we," "us"), collects, uses, shares, and protects personal information when you use the Tabletop Lynk mobile application and related services (the "Service").
This Policy is written for users in the United States. Additional rights that apply only to residents of certain states are described in Section 12. The Service is offered to users in the United States and is not directed to users in the European Economic Area or the United Kingdom.
1. Who can use the Service
The Service is for people aged 13 and older. It is not directed to anyone under 13, and we do not knowingly collect personal information from anyone under 13. The Children's Online Privacy Protection Act (COPPA) applies to children under 13, and we do not permit accounts in that age range.
When you create an account, you are asked to provide your date of birth. We rely on that self-reported information. If the date you give is under 18, we also ask for a parent or guardian's email address so we can request their approval.
If we learn or reasonably believe that an account holder is under 13, we will suspend the account, delete the personal information associated with it, and remove the account's public content from the Service. We aim to complete deletion within 30 days of confirming the account holder is under 13. Limited records of the report and the action taken may be retained as described in Section 8 so that the account is not simply recreated. Information about a parent or guardian. Where an account holder is aged 13 to 17, we collect the email address they give us for their parent or guardian. We use it only to ask for approval, to confirm the outcome, and to let them withdraw approval later. We do not use it for marketing, we do not show it to any other user, and we delete it with the account. Rights of a parent or guardian. If you have approved an account for someone aged 13 to 17, you may at any time withdraw your approval, which stops the account joining events immediately; ask us to provide a copy of their personal information; or ask us to correct or delete it. Contact us at [email protected]. We may ask for information to confirm your relationship to the account holder before we act.
If you believe someone under 13 has created an account or provided us information, contact us at [email protected] and we will look into it.
2. Information we collect
We collect the following, drawn directly from how the Service works:
- Date of birth. Provided at signup to check your age and, if you are under 18, to ask a parent or guardian for approval.
- Email address. To create your account, log you in, verify you, and send notifications.
- Display name. Your public identity shown on posts, chat, and your profile.
- Password. Stored only in hashed form, never in plain text, and used to authenticate you.
- Approximate location. To show nearby games and players. See Section 5 for exactly how this works.
- Profile details. Your bio, preferences, and badges, shown to other users.
- Session and looking-for-group posts. Public listings you create to match tables with players.
- Chat messages. Group and party messages between matched users.
- Requests and invites. Records of joining, accepting, and declining games.
- Friend and block lists. Your social graph; blocking hides content between users.
- Abuse reports. Content you flag, and the reports you submit, used for moderation.
- Log and device data. When you use the Service, our systems and infrastructure providers automatically receive technical data such as your IP address, general device and app information, and app activity, which we use to operate, secure, and troubleshoot the Service.
We do not use third-party analytics or crash-reporting services, and we do not collect advertising identifiers. If that changes, we will update this Policy before the change takes effect.
3. How we use your information
We use this information to create and secure your account, confirm that you are eligible to use the Service, help you and other users discover nearby games and players, match tables with players, enable messaging between matched users, moderate the community and respond to abuse reports, and send you service-related notifications.
We also combine attendance information from events across many venues into de-identified, aggregated statistics, for example which kinds of events tend to fill, or how attendance at a type of event is changing over time. We use these to operate and improve the Service and to show benchmarks to venues. They never identify you, and they never identify any single venue.
4. How we share your information
- With other users: your display name, profile, and posts are visible to other users, and your approximate location supports nearby discovery. Chat is visible to the users in your party. Your date of birth and email address are not shown to other users.
- With venues: when you sign up for an event hosted by a venue, that venue sees your display name and whether you attended, for its own events. If you are under 18, the venue is told that too, so it knows a young player is attending; it is never shown your date of birth. A venue cannot see who attends any other venue's events.
- Benchmarks shown to venues: venues may see the de-identified, aggregated statistics described in Section 3. A statistic is only shown when it draws on enough venues that no single venue, and no individual player, can be identified from it. We do not use one venue's attendee list to promote other venues to the people on it.
- With service providers: we share data with the vendors listed in Section 6, under agreements that limit their use of it to providing services to us.
- For legal and safety reasons: we may disclose information where required by law, in response to lawful requests from law enforcement, or where necessary to protect the safety of users or the public.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. How location works
Location is used only to power nearby discovery. How it works matters, so we describe it precisely:
- When you enable location, we request only coarse, reduced-accuracy location from your device operating system. We never request precise GPS coordinates.
- Your device's position is used on your device to determine general proximity. We do not transmit your coordinates to our servers, and we do not store latitude, longitude, or any equivalent coordinate for your account in our database.
- Because coordinates are never sent or stored, there is no location history associated with your account for us to retain, disclose, or produce.
You can turn location off at any time in your device settings, or decline the permission when asked. If you do, nearby discovery will be limited or unavailable, but the rest of the Service continues to work.
6. Service providers
We use a small number of vendors to operate the Service. Each processes data only to provide services to us, under contractual terms that prohibit using it for their own purposes:
- Railway. Hosts our backend application and database.
- Resend. Delivers transactional email, such as verification and account notices.
- Cloudflare. Provides DNS and network security for our domain.
- Expo (EAS). Provides our mobile build pipeline and delivers push notifications.
If we add a vendor that processes personal information, we will update this list before that vendor begins processing.
7. When we may review your content
We do not routinely read private messages. Our moderators may review messages, profiles, listings, and other content in specific circumstances:
- When a user submits an abuse report, we may review the reported content and the surrounding conversation needed to understand it.
- When we are investigating a suspected violation of our Terms of Service or Community Guidelines.
- When we believe review is necessary to address a risk to someone's safety, or to respond to a lawful request from law enforcement.
- When required to diagnose a technical fault affecting the Service.
Review is limited to what is reasonably needed for the purpose. We do not use the contents of private messages for advertising or profiling, and we do not sell them.
8. How long we keep your information
We keep your information while your account is active. When you delete your account, we begin deletion promptly and complete it within 30 days, with the following exceptions:
- Abuse reports and moderation records: retained for up to 2 years after the report is closed, so that we can identify repeat offenders and respond to patterns of harmful conduct.
- Records of accounts banned for safety violations: a minimal record, limited to the identifiers needed to enforce the ban, retained for up to 3 years to prevent the banned user from returning.
- Backups: residual copies may persist in encrypted backups for up to 90 days before being overwritten in the ordinary course.
- Legal holds: where we are required to preserve records for a legal claim, investigation, or law-enforcement request, we retain them for as long as that obligation lasts.
What remains after deletion. Messages you sent to other users may remain visible to those recipients, because they are part of their conversation history. Where content remains visible in this way, it is disassociated from your profile. Anonymized or aggregated data that can no longer be linked to you may be retained without time limit.
9. Public and shared information
Your display name, profile, and posts are public within the Service, and messages are visible to the users in your party. Posts and profiles may reveal information about your general area, your availability, and your plans to meet others. Please be thoughtful about what you share, and avoid posting your home address, phone number, workplace, or other sensitive details in public fields.
10. Your choices
You can review and update your profile, control location sharing through your device settings, block other users, report content, and delete your account from within the app. You can also contact us at [email protected] with any request about your information.
11. Security
We take reasonable measures to protect your information, including storing passwords in hashed form and transmitting data over encrypted connections. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
12. State privacy rights (United States)
Some states give residents specific rights over their personal information. Where your state's law provides them, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate personal information.
- Delete your personal information.
- Receive a portable copy of your personal information.
- Opt out of the sale of your personal information or its sharing for cross-context behavioral advertising. We do not sell or share personal information in this way, so there is nothing to opt out of.
- Not be treated differently for exercising any of these rights.
To make a request, contact us at [email protected]. We will verify your identity, usually by confirming control of the email address on the account, and respond within the period your state's law requires. If we decline a request, we will explain why, and where your state's law provides an appeal, we will tell you how to appeal.
13. Changes to this Policy
We may update this Policy as the Service changes. Each version carries an effective date and a version number, and we will post the current version in the app. Where changes are material, we will notify you in the app before they take effect.
14. Contact
Questions about this Policy or your information: [email protected]
Thursday Night LLC, a Michigan limited liability company.
1670 Makaloa St. #204-271, Honolulu, HI 96814