TIMI
MenuMahjongBoard gamesEventsGalleryBookJoin us
EN中文HU
Map

Legal information

Privacy Policy

This policy explains what information TIMI uses, why we use it, how long we keep it and the choices available to you.

Version: 1.0.0Last updated: August 29, 2026

On this page
  1. Who is responsible for your data
  2. Where this policy applies
  3. Website delivery and security
  4. Aggregate website analytics
  5. Bookings
  6. Optional marketing
  7. Google sign-in and My TIMI
  8. Favorites
  9. Service providers
  10. International transfers
  11. How long information is kept
  12. Your rights
  13. Complaints
  14. Changes to this policy
On this page
  1. Who is responsible for your data
  2. Where this policy applies
  3. Website delivery and security
  4. Aggregate website analytics
  5. Bookings
  6. Optional marketing
  7. Google sign-in and My TIMI
  8. Favorites
  9. Service providers
  10. International transfers
  11. How long information is kept
  12. Your rights
  13. Complaints
  14. Changes to this policy

Who is responsible for your data

Yami Yami Kft., trading as TIMI BAR & COFFEE, is the data controller for the processing described on this page. Contact us at timiclub.hu@gmail.com for privacy questions or requests.

Trading name
TIMI BAR & COFFEE
Data controller and operator
Yami Yami Kft.
Registered office
1161 Budapest, Szabadkai utca 30., Hungary
Company registration number
01-09-428502
Tax number
32520985-2-42
Venue address
1082 Budapest, Üllői út 42., Hungary
Privacy and support contact
timiclub.hu@gmail.com

Where this policy applies

This policy applies to the TIMI official website, online booking pages, QR table ordering and the optional My TIMI account. A third-party website you open from TIMI follows its own privacy policy.

Website delivery and security

Cloudflare processes technical request data, which may include an IP address, browser information, requested page, time and security signals, to deliver and protect the website. TIMI relies on its legitimate interest in providing a secure and reliable service.

TIMI does not intentionally write full IP addresses into its custom website analytics dataset. Provider security logs follow the provider settings that apply to our account.

Aggregate website analytics

On non-legal pages, TIMI may record an event name, page path and family, language, booking type, landing source or campaign, and event identifier. This helps us understand which pages work and improve the service under our legitimate interest.

These custom events do not contain your name, email address, My TIMI member ID or a full IP address. They are stored in Cloudflare Workers Analytics Engine for three months. Legal pages do not run this analytics component or write campaign data to browser storage.

Bookings

When you make a booking, TIMI uses your name, email address, booking type, date and time, party size, expected duration, note, language and marketing choice. We use the required details to take steps at your request and perform the booking service.

We keep booking information while it is needed to manage the visit, follow up and handle a reasonable dispute or legal claim. If a separate invoice or statutory accounting record is created, that record follows the legally required retention period. The current booking system does not promise an automatic deletion date.

Optional marketing

Event or marketing email is sent only when you give separate consent. You can withdraw consent through the unsubscribe link or by contacting TIMI. Withdrawal does not affect processing that already took place lawfully.

After an unsubscribe request, TIMI may keep the minimum suppression record needed to make sure marketing is not sent again. Booking and My TIMI use do not require marketing consent.

Google sign-in and My TIMI

Google sign-in is optional. You can browse the menu and place an anonymous table order without signing in. If you choose Google sign-in, TIMI requests only openid, email and profile.

TIMI uses the Google account identifier (sub) as the stable external identity key and stores your verified email address, display name, language, internal member ID and account status. TIMI does not store Google access tokens, ID tokens or refresh tokens after the sign-in exchange.

We use this information to provide the My TIMI account you request and to protect it. In this release, My TIMI is not connected to XGD membership, points, balances, member prices, recharge, financial benefits or ownership of previous orders. Google data is not sold or used for advertising.

Favorites

If favorites are enabled later, TIMI stores the stable identifiers of items you save. Favorites remain until you remove them or delete the My TIMI account. The feature is disabled for the initial login release and does not affect anonymous ordering.

Service providers

TIMI uses a limited number of providers to operate the service: Cloudflare for hosting, security, database and aggregate analytics; Google for optional sign-in and, on some non-legal pages, font delivery; and Resend for booking and consented email delivery.

Providers receive only the information needed for their role. They process data under the applicable contract and privacy terms; some services may also act as an independent controller for their own security and account obligations.

  • Cloudflare Privacy Policy
  • Google Privacy Policy
  • Resend Privacy Policy

International transfers

Some providers may process information outside Hungary or the European Economic Area. Where required, TIMI relies on an applicable adequacy decision, standard contractual clauses or another lawful safeguard. You may contact us for information about the safeguard relevant to your data.

How long information is kept

OAuth transaction
Hashed state, PKCE verifier, nonce and safe return path expire after 10 minutes and are consumed once.
My TIMI account
Kept until you delete the account or TIMI has a documented legal reason to retain limited information.
Member session
Expires after 30 days. Expired or revoked session rows are scheduled for deletion within a further 30 days.
Security events
Minimal security records are scheduled for deletion after 12 months. They must not contain Google sub, full email addresses, tokens or secrets.
Protected recovery history
Deleted database information may remain temporarily in provider-managed recovery history for the active recovery window, never longer than 30 days under the current platform limit.

Your rights

Depending on the processing, you may ask for access, correction, deletion, restriction or portability, object to processing based on legitimate interests, and withdraw consent at any time. You also have the right not to be subject to a qualifying decision based only on automated processing; TIMI does not use My TIMI for such decisions in this release.

Email timiclub.hu@gmail.com. TIMI may ask for proportionate information to confirm that the request concerns your data. We normally respond within one month, subject to the extensions allowed by law.

  • Email TIMI about your data

Complaints

Please contact TIMI first so we can try to resolve the issue. You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): 1055 Budapest, Falk Miksa utca 9-11; postal address 1363 Budapest, Pf. 9; ugyfelszolgalat@naih.hu. Your right to seek a court remedy is not affected.

  • NAIH complaint information

Changes to this policy

TIMI updates this page when the service or legal requirements change. The version and update date are shown at the top. If a change materially affects an active My TIMI account, TIMI will use an appropriate notice before the change takes effect where required.

← Back to TIMI

© 2026 TIMI BAR & COFFEE
PrivacyTermsAccount deletion
Staff login