Privacy statement
Last updated on 2 September 2026.
Joint Mission is a trade name of Ninjai (company number BE 1034.682.172), based in Ghent. We are the controller for the data you provide us via this website or by e-mail. Questions about your data: info@jointmission.be.
1. What data we process and why
Request, quote, contact or Team Check
Name, e-mail address, phone number, company or organisation, number of players, preferred period or date and your preferences (for example pace or goal of the activity). We use that data to answer your request, make a proposal and follow up on it. Legal basis: the steps needed to enter into an agreement, and our legitimate interest in correctly following up a request you made yourself.
Booking and payment
In addition to the data above: invoicing details (company name, VAT number, address) and the status of your payment. The payment itself goes through Mollie; we never see or receive your card or bank details. Legal basis: performance of the contract and our statutory accounting obligations.
Unfinished forms
If you fill in a form partially and leave the page after entering a valid e-mail address, we keep that data temporarily so we can help you if you got stuck. It is automatically deleted after 30 days if no request or booking follows. Legal basis: legitimate interest; you can object with a single e-mail to info@jointmission.be.
Follow-up by e-mail
After a request, quote or booking we send a limited number of follow-up e-mails that are only about your request: a confirmation, a reminder if a booking was not completed, a question whether you were able to look at our proposal, and after the game a thank-you with a request for a review. If you reply to such an e-mail, the automatic series stops and a team member takes over. Every automatic e-mail has an unsubscribe link at the bottom. Legal basis: legitimate interest in following up your own request.
For the e-mails we send ourselves, we measure whether they arrived and whether you clicked a link, and which one. If you click through to our website from such an e-mail, we place a cookie that recognises you, so we can attach the pages you view afterwards to your request. That tells us whether our e-mail was useful and what you are interested in, so we can help you more precisely instead of asking everything again. That cookie is optional: if you refuse the cookie bar, we only see that the link was clicked and we do not follow your visit. We keep the page history for at most one year. Legal basis: consent for following your visit, legitimate interest for measuring the e-mail itself. You can object at any time with a single e-mail.
On those pages we also record, again only with your consent, how long each page was visible. Your browser reports that when you leave the page; time spent in a background tab does not count. That tells us which information you really needed, so we do not have to ask you again. This is more detailed than a bare list of visited pages, which is why it depends on the same consent: if you refuse the cookie bar, we measure no time at all. Retention period: one year, together with the page history. Legal basis: consent.
Newsletters, marketing and WhatsApp
We only send general marketing e-mails (for example about new cities) if you expressly agreed via the checkbox on the form or the waiting list. Follow-up via WhatsApp only happens if you ticked that box yourself. You can withdraw both at any time via the unsubscribe link, by replying "stop" or by e-mail. Legal basis: consent.
Website use and origin
To know which channels and ads lead to requests, we keep, if you allow it via the cookie bar, the origin of your visit (the campaign parameters in the link you came in with, the referring site and the click identifier from Google or Meta) and link it to your request. Without consent that does not happen and we simply handle your request without origin. Legal basis: consent.
2. Cookies and measurement
We count how many visitors make which choice (everything, analytics only, marketing only, or only the necessary). That is a daily counter without a cookie, without a visitor and without an IP, so it cannot be traced back to you; we need it to be able to show that we asked for consent.
On your first visit the website shows a cookie bar. We always place necessary cookies; all others only after your consent. If you want to change your choice later, clear the cookies for jointmission.be in your browser; the bar will appear again.
What happens if you refuse
Even when you dismiss the cookie bar or refuse everything, Google's measurement software (the Google tag) loads on our pages. It is then fully set to "denied": no cookies are placed and you are not recognised, not during this visit and not on a next one. What does happen is that your browser sends one request to Google with your IP address and the page you are viewing. Google may not link that to you and only uses it to estimate how many visitors in total requested something. Without that estimate we do not know whether our ads produce anything, and that is why we set it up this way. If you do not want that either, an ad blocker or a browser that blocks trackers stops the Google tag. Legal basis: legitimate interest in measuring our own ads, limited to what is strictly necessary; you can object with a single e-mail.
| Cookie or service | Purpose | Type | Retention period |
|---|---|---|---|
| Session and security cookies (Odoo) | Stay logged in, secure forms, remember your cookie choice | Necessary | Session up to 1 year |
| Cloudflare Turnstile | Protect forms against spam without a captcha puzzle | Necessary | Session |
| Google Analytics 4 | Anonymous statistics about the use of the site (pages visited, origin, features used such as the Team Check) | Optional: statistics | Maximum 14 months |
| Meta Pixel | Measure which Facebook and Instagram ads lead to a request or booking and show relevant ads to those who visited the site | Optional: marketing | Maximum 90 days |
| Google Ads (conversion measurement) | Measure which Google ad led to a request or booking, so we can focus our budget on what works | Optional: marketing | Maximum 90 days |
| Origin cookies (utm, gclid, fbclid) | Remember which campaign or link you came in through, until you make a request | Optional: marketing | 31 days |
| E-mail recognition cookie (tb_rcpt) | Recognise that you arrived via a link in our e-mail, so your visit is attached to your own request | Optional: marketing | 30 days |
Measurement of ad results at Google and Meta
If you allowed marketing cookies, we tell Google Ads and Meta that an ad led to a request, a qualified request or a paid booking, together with the amount. For that we send an encrypted (hashed) version of your e-mail address and phone number, which the platforms can only match against their own users and cannot read. That way those platforms show our ads to people for whom they are relevant, and less to others. Without your consent we do not pass on that personal data. Google and Meta also process it in the United States, under the EU-US Data Privacy Framework and with standard contractual clauses.
One thing does happen without cookie consent, and only for Google Ads. If you land on our site via a Google ad, the link contains a click identifier for that ad. If you then request a quote yourself or fill in the contact form, we keep that identifier with your request and tell Google that this click led to a request, with the estimated value. No personal data goes with it: no name, no e-mail address, no phone number. The identifier only tells Google which of its own ad clicks produced something. Nothing extra is stored on your device either: we keep it server-side during your visit. Without this we do not know which ads work and we pay for impressions to people who have no use for them. Legal basis: legitimate interest in measuring our own ads; you can object with a single e-mail, and we then remove the identifier from your request.
3. Who we share data with
Never for sale or rent. But with service providers who process it on our behalf, each only for their task: Mollie (payments, Netherlands), Hetzner (hosting and encrypted backups, Germany), Google (e-mail via Google Workspace, Analytics, Ads), Meta (Pixel and ad measurement), Cloudflare (spam protection) and Odoo S.A. (the connection of our social media pages). With each of them we have a data processing agreement or their contractual guarantees apply. Beyond that only if the law requires it.
4. How long we keep data
- Unfinished forms: 30 days.
- Requests and quotes without a booking: 24 months after the last contact, then deleted or anonymised.
- Bookings, invoices and payment data: 7 years (statutory accounting period).
- Consent for marketing or WhatsApp: until you withdraw it.
- Statistics and ad measurement: according to the periods in the table above.
- Visited pages linked to a request: 1 year.
- Technical server logs (IP address, requested page, time): 30 days. We use them to detect outages and abuse, not to profile visitors.
5. Your rights
You have the right to access your data, to have it corrected or erased, to restrict processing, to data portability and to object to processing based on legitimate interest. Consent you gave can be withdrawn at any time without affecting earlier processing. One e-mail to info@jointmission.be is enough; we reply within a month. Not happy with our answer? Then you can lodge a complaint with the Data Protection Authority.
6. Security
The website and all connections are encrypted (https). Your data is stored on servers in the European Union, with daily encrypted backups, and is only accessible to those who need it to handle your request.
7. Changes
If the way we work changes, we update this statement and mention the date at the top. For major changes we inform anyone with an ongoing request or booking.