Legal information
Privacy Policy
This policy explains what information TIMI uses, why we use it, how long we keep it and the choices available to you.
On this page
Who is responsible for your data
Yami Yami Kft., trading as TIMI BAR & COFFEE, is the data controller for the processing described on this page. Contact us at timiclub.hu@gmail.com for privacy questions or requests.
- Trading name
- TIMI BAR & COFFEE
- Data controller and operator
- Yami Yami Kft.
- Registered office
- 1161 Budapest, Szabadkai utca 30., Hungary
- Company registration number
- 01-09-428502
- Tax number
- 32520985-2-42
- Venue address
- 1082 Budapest, Üllői út 42., Hungary
- Privacy and support contact
- timiclub.hu@gmail.com
Where this policy applies
This policy applies to the TIMI official website, online booking pages, QR table ordering and the optional My TIMI account. A third-party website you open from TIMI follows its own privacy policy.
Website delivery and security
Cloudflare processes technical request data, which may include an IP address, browser information, requested page, time and security signals, to deliver and protect the website. TIMI relies on its legitimate interest in providing a secure and reliable service.
TIMI does not intentionally write full IP addresses into its custom website analytics dataset. Provider security logs follow the provider settings that apply to our account.
Aggregate website analytics
On non-legal pages, TIMI may record an event name, page path and family, language, booking type, landing source or campaign, and event identifier. This helps us understand which pages work and improve the service under our legitimate interest.
These custom events do not contain your name, email address, My TIMI member ID or a full IP address. They are stored in Cloudflare Workers Analytics Engine for three months. Legal pages do not run this analytics component or write campaign data to browser storage.
Bookings
When you make a booking, TIMI uses your name, email address, booking type, date and time, party size, expected duration, note, language and marketing choice. We use the required details to take steps at your request and perform the booking service.
We keep booking information while it is needed to manage the visit, follow up and handle a reasonable dispute or legal claim. If a separate invoice or statutory accounting record is created, that record follows the legally required retention period. The current booking system does not promise an automatic deletion date.
Optional marketing
Event or marketing email is sent only when you give separate consent. You can withdraw consent through the unsubscribe link or by contacting TIMI. Withdrawal does not affect processing that already took place lawfully.
After an unsubscribe request, TIMI may keep the minimum suppression record needed to make sure marketing is not sent again. Booking and My TIMI use do not require marketing consent.
Google sign-in and My TIMI
Google sign-in is optional. You can browse the menu and place an anonymous table order without signing in. If you choose Google sign-in, TIMI requests only openid, email and profile.
TIMI uses the Google account identifier (sub) as the stable external identity key and stores your verified email address, display name, language, internal member ID and account status. TIMI does not store Google access tokens, ID tokens or refresh tokens after the sign-in exchange.
We use this information to provide the My TIMI account you request and to protect it. In this release, My TIMI is not connected to XGD membership, points, balances, member prices, recharge, financial benefits or ownership of previous orders. Google data is not sold or used for advertising.
Favorites
If favorites are enabled later, TIMI stores the stable identifiers of items you save. Favorites remain until you remove them or delete the My TIMI account. The feature is disabled for the initial login release and does not affect anonymous ordering.
Service providers
TIMI uses a limited number of providers to operate the service: Cloudflare for hosting, security, database and aggregate analytics; Google for optional sign-in and, on some non-legal pages, font delivery; and Resend for booking and consented email delivery.
Providers receive only the information needed for their role. They process data under the applicable contract and privacy terms; some services may also act as an independent controller for their own security and account obligations.
International transfers
Some providers may process information outside Hungary or the European Economic Area. Where required, TIMI relies on an applicable adequacy decision, standard contractual clauses or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.
How long information is kept
- OAuth transaction
- Hashed state, PKCE verifier, nonce and safe return path expire after 10 minutes and are consumed once.
- My TIMI account
- Kept until you delete the account or TIMI has a documented legal reason to retain limited information.
- Member session
- Expires after 30 days. Expired or revoked session rows are scheduled for deletion within a further 30 days.
- Security events
- Minimal security records are scheduled for deletion after 12 months. They must not contain Google sub, full email addresses, tokens or secrets.
- Protected recovery history
- Deleted database information may remain temporarily in provider-managed recovery history for the active recovery window, never longer than 30 days under the current platform limit.
Your rights
Depending on the processing, you may ask for access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent at any time. You also have the right not to be subject to a qualifying decision based only on automated processing; TIMI does not use My TIMI for such decisions in this release.
Email timiclub.hu@gmail.com. TIMI may ask for proportionate information to confirm that the request concerns your data. We normally respond within one month, subject to the extensions allowed by law.
Complaints
Please contact TIMI first so we can try to resolve the issue. You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9-11; postal address 1363 Budapest, Pf. 9; ugyfelszolgalat@naih.hu. Your right to seek a court remedy is not affected.
Changes to this policy
TIMI updates this page when the service or legal requirements change. The version and update date are shown at the top. If a change materially affects an active My TIMI account, TIMI will use an appropriate notice before the change takes effect where required.