
The offsite is in three weeks. HR has the hunt built. The ticket has been sitting in IT's queue for nine days with the status "needs more information," and the information IT needs is whether they're being asked to push another app to four hundred managed phones.
They aren't. That's the whole answer, and it's the sentence that unsticks the ticket. PlayTours is a web app. Players click a link or scan a QR and there's nothing to push through MDM. If your phones can't sideload, they don't need to.
I've sat on those calls. The hunt is the easy part; the install is what stalls it. So everything below is written to be copied straight into the ticket, in the order IT and Legal usually ask. If someone wants the longer argument for browser-based games, this post covers it.
The paragraph for the ticket
PlayTours is a browser-based scavenger hunt platform. There is no App Store or Play Store download. The free tier allows 25 concurrent devices with all features, a PlayTours watermark, and commercial use permitted. Paid tiers remove the watermark and raise the concurrent-device cap; features are identical across tiers. PlayTours is ISO 27001 certified and externally audited. Data is hosted on Google Cloud in Japan, which the European Commission recognises as adequate under the EU-Japan adequacy decision.
URLs for the ticket: security, privacy policy. Join links use the pyts.link domain.
What happens on the day
HR builds the hunt in a web editor as a few chapters of tasks (a photo to take, a code to scan, a question to answer), and one person watches a dashboard while it runs. Staff open Safari or Chrome, scan a QR that resolves to a short pyts.link address, type a team name, and the first chapter appears. Locked-down iPhones still have a browser. Guest devices join the same QR, and you image nothing. If you'd prefer the PlayTours name not appear in the URL, that's what pyts.link is for.
Compared with a store-listed app you lose on brand familiarity and win on MDM. For most fleets that's a good trade.
The only thing anyone pays for is concurrent devices: how many phones can be in a game at once. A device is one phone or tablet actively playing; a shared phone counts once; the cap is account-wide. If you hit it, new joins wait and nobody active gets dropped. Billing is monthly with no proration, so cancel after the offsite. Subscribe at admin.playtours.app/subscription, and use this guide to size the plan.
What we collect, and what to keep out of tasks
Teams type a team name and play. You download results from the session screen afterwards. Design tasks accordingly: no passport numbers, and no required photos of badges with readable employee IDs if that conflicts with your DLP policy.
The facilitator dashboard can show live team location, but only if you turn it on. If your works council would rather not, leave it off. The hunt runs the same way.
ISO 27001 covers how we run the company. It isn't a GDPR waiver, so you still need your own lawful basis for the event. We act as processor for the game data you create, and the DPA conversation starts from the security and privacy pages.

For EU buyers
Adequacy means Japan is on the Commission's list and that's where this stack lives. It does not mean we store data in Frankfurt. If your policy requires EU-resident data, we're not your vendor, and it's better for both of us to know that now than after HR has built the hunt.
Player translation and a default language setting exist for DE, FR, and NL sessions. The multi-language guide has the details.
The one-page checklist
- No store install
- Join via HTTPS link or QR
- Watermark on the free tier, removed on paid
- Concurrent cap chosen for peak phones, not headcount
- Live GPS off unless there's a reason
- Results downloaded after the event and stored in your own drive
- Security and privacy URLs attached
- A named owner at HR who will stop the session from the facilitator dashboard if the timer needs to end early (timers don't pause)
Questions that come up on the same call
Camera and location permissions. The browser asks only when a task needs them. Location tasks and live team GPS need location; photo tasks need the camera. You can build a hunt that needs neither, using QR codes, typed access codes, multiple choice, and check-off tasks. If a managed browser blocks the camera, photo tasks become check-off tasks. Test one fleet phone.
Network and content filters. If corporate wifi blocks games, whitelist playtours.app, pyts.link, and our Firebase and Google hosting domains, or have people use cellular. Photo upload needs a connection either way; this post covers what happens when signal is thin.
Accessibility. Text size follows the phone's OS settings because we're a browser page. If a task would otherwise mean squinting at a tiny QR on a shiny floor, pair people up on a team.
Cookies and third parties. The player is a web app on our hosting. The security and privacy pages list subprocessors, and Legal can request the DPA.
SSO. Not part of the join path for a staff event; people tap a link. If you need SSO for the people building games, that's an admin conversation.
Retention. Download what you need after the event and store it in your own systems. Give someone ownership of any written debrief answers sitting in a session.
If the checklist isn't enough, book a call and bring IT. Japan hosting is usually the question, and the answer is in the paragraph at the top. Or email me at hello@playtours.app.
-Mo