Your Booth Game Is Not a Lead Form. Decide the Data Path Before You License HTML5 Games.
Before you license HTML5 games for a booth, decide where the lead data lands. The organiser's badge scanner and your own game sit on different legal footing.
The brief almost always arrives the other way round. Somebody books the stand, somebody specifies a game โ a reaction test, a claw machine, a branded runner with a leaderboard โ and the lead question gets answered on the last slide with four words: the game captures emails. Then the show ends, and there are two spreadsheets on the shared drive. Only one of them can be loaded into the CRM without a conversation with legal first.
This is not a compliance footnote bolted onto a marketing decision. It is the decision. A game that feeds the organiser's scanner is a crowd-stopper with somebody else's consent paperwork behind it. A game that runs its own entry form is a data collection point, and every obligation attached to it is yours. Two different products, two different briefs, two different questions for whoever supplies the game.
๐ซ The Organiser Owns the Registration Database and Rents You a View of It
At most large shows, lead retrieval is a rental. You order handheld scanners or app seats from the organiser or their appointed vendor, and each scan pulls a contact record out of the organiser's registration database. The fields you get back are the ones that registration form collected โ typically name, company, job title, email, phone. You cannot add to it. If the organiser never asked for budget authority or procurement timeline, no amount of scanning produces it.
A scan is defensible because somebody else built the consent chain and documented it. The attendee registered, agreed to terms covering their badge data being shared with exhibitors who scan them, and the scan is the timestamped record of that sharing. You inherit a lawful basis you did not have to construct.
Inherit is the operative word. That chain is only as strong as the registration wording, and guidance aimed at organisers sharing delegate data with sponsors is blunt about the standard: consent must be "clear and explicit that you are passing on data and the sponsors to whom the data will be given named", with no pre-ticked boxes, nothing buried in a contract, and consent that is not a precondition of attending. It also flags the harder problem for exhibitors: for marketing by electronic mail, the person must have intended their consent to reach the organisation actually doing the marketing, and the ICO's position is not to rely on indirect consent given more than six months ago.
Read that against how exhibition leads get worked: a scan in March, a nurture sequence starting in November, and the inherited basis went stale in a spreadsheet. The scanner buys a defensible starting point with a shelf life, not a solution to follow-up.
What a badge scan will not give you
- Qualification. A scan records that a badge passed a device. It says nothing about whether the person stopped, played, understood the product, or has any authority to buy it.
- Fields you did not buy. The registration form is the ceiling on record quality, and it was designed for the organiser's purposes, not yours.
- Anyone unbadged. Consumer activations, retail pop-ups, conference fringe events and street-level sampling have no registration database behind them at all.
๐น๏ธ Your Booth Game Collects Under Your Own Legal Basis, Not the Organiser's
The moment your game asks for an email address, the inheritance stops. You are collecting, you set the purpose, and you owe the notice at collection, the retention period and the route to object. That much is the same standard as any form on your website. What catches teams out is the second layer: the rules on marketing by electronic mail sit separately from data protection law, and they turn on what kind of address was typed in.
Under UK PECR, as the Data Protection Network's summary of the ICO guidance sets out, a corporate subscriber is any corporate body with its own phone number or internet connection, and "you do not need their consent under PECR to send such messages". An individual subscriber is different โ and sole traders and most partnerships "technically fall under the definition of individual subscribers, where consent or the soft-opt-in exemption would be required".
The soft opt-in will not rescue a booth game. Its conditions are that the details were collected during a sale or the negotiation of one, that an opt-out was offered at collection and in every message since, and that the marketing covers your own similar products. A prize draw entry is not the negotiation of a sale. So for any personal address that lands in your game, you need consent captured inside the game, at the moment of entry, as its own explicit action.
That has a design consequence, and it is the most common thing to get wrong: the prize entry and the marketing permission must be two separate interactions. If the only tick box says "enter my score into the leaderboard", you have a leaderboard, not a mailing list. If it says "enter me and send me updates", the consent is bundled rather than freely given, and the entry is worth less than the badge scan you already paid for.
One caveat, because the internet routinely gets this wrong: the corporate-subscriber carve-out is a UK feature. National implementations of the EU ePrivacy rules differ, and the exemption for business contacts is not universal. If the show is in Cologne, Barcelona or Lisbon, get the local position before you design the form, not after the leads land.
๐งพ Three Data Paths, and What Each One Is Actually For
Almost every booth game resolves to one of three architectures. Pick deliberately, at brief stage โ retrofitting one into another after the build is expensive, and it always happens in show week.
1. Scanner only โ the game emits nothing
The game has no form, no email field, no account. Its job is to stop traffic and hold someone in front of a rep long enough for a conversation and a scan. Every lead comes through the organiser's chain. This is the cleanest option and the right default for pan-European shows, regulated industries, and any programme where legal review would outlast the build. It is also where a licensed catalogue title drops straight in, because nothing has to come out of it.
2. Game with its own form โ you own the consent
Justified when you need fields the registration database does not hold, or when there is no such database โ consumer activations, shopping-centre stands, sponsor zones at public events, anything running on an attendee's own phone via a QR code. Budget for the form, the notice, the consent record, the storage and the deletion, not just the game. If nobody can say today where those records live in eighteen months, you are not ready for this path.
3. Game as qualifier, scanner as capture
The rep scans the badge as usual, then records what the game revealed โ which product path the visitor picked, which difficulty, whether they finished โ as a qualifier against that lead in the retrieval app. You keep the organiser's consent chain and add the qualification a scan cannot produce. In practice a rep reads the result off the screen and taps it into the lead app, because a licensed third-party build in an iframe will not post a score into your systems. Normal constraint, not a supplier failing โ and designing around it takes ten minutes at brief stage, or a fortnight afterwards.
๐ท The Cost Per Lead Maths Argues for the Scanner
Benchmarks published by momencio put the reported cost per lead for raw badge scans at $100 to $300, with roughly one in four scans surviving qualification, which drags the true cost per qualified lead to three to five times the reported figure. Their worked example: a $30,000 mid-size exhibit producing 300 scans and 75 qualified leads lands at $400 per qualified lead. The same analysis cites Gartner's finding that B2B buyers spend around 17% of their total buying time with potential suppliers, and as little as 5% to 6% with any single vendor when several are in the running.
Sit those numbers together and the brief writes itself. The expensive item is the stand; the scarce item is the buyer's attention while they stand on it. A game that lifts scan volume by a third against the same floor cost moves the qualified-lead number. A game that produces four hundred typed addresses in place of three hundred scans has swapped a stronger record for a weaker one and called it growth โ the scans carry a documented consent chain and a real registration record, and the typed addresses carry whatever somebody felt like typing to get a go on the machine.
The exception is real: when the audience is unbadged, or the fields you need do not exist in the organiser's database, the form earns its place. Decide it on that basis, not because a form felt like more of a lead.
โ ๏ธ The Statistic Your Deck Will Quote, and Why I Would Cut It
Somebody will put "80% of trade show leads are never followed up" on a slide. It is everywhere in 2026 exhibition content, always attributed to CEIR. Chase the citations and they stop at CEIR's homepage โ no study title, no date, no methodology, no sample. That does not make it false. It makes it unusable as the load-bearing number in a business case, and if a finance team pulls the thread, the rest of your case gets read with the same suspicion.
Use your own denominator. Take the last show you exhibited at, count the records captured, and count how many got a first contact within two weeks. That number is specific to your team and defensible in the room โ and if follow-up turns out to be the leak, a game that captures more records is the wrong intervention entirely.
๐ซ Five Ways Booth Game Lead Capture Goes Wrong
- Prize entry doubling as marketing consent. One tick box covering both makes the consent bundled, and bundled consent is not freely given. Two boxes, two purposes, and the prize must be winnable without the second.
- An unattended tablet in kiosk mode that isn't. If the last entrant's details are still on screen, or a back gesture reaches browser history, the stand leaks personal data all day. Lock the device into guided access and clear state between plays.
- No offline path for the form. Hall wifi fails at 10am on day one. If entries post to an endpoint and nothing queues locally, the morning is gone with no error anyone noticed.
- No owner for the data after the show. The spreadsheet ends up on an agency laptop, gets reused for the next campaign, and nobody can answer a deletion request. Name the controller, the retention period and the destruction date in the statement of work.
- Assuming the licensed build hands over the data. A game you licensed and embedded is not instrumented for your CRM. If the plan depends on scores, entries or emails coming out of the game itself, agree it with the licensor before signature rather than discovering it in rehearsal.
๐ What to Settle Before the Show
Split the questions by who can answer them. Most stalled booth projects are stalled because all of them went to the agency.
- To the organiser: which fields does a scan return? What did attendees agree to at registration, and can we see that wording? Are third-party scanning apps permitted, or is the official unit mandatory? What does lead retrieval cost per rep, per show?
- To legal or your DPO: in this territory, does the business-contact exemption cover the addresses we expect? What retention period are we committing to, and who deletes?
- To the game supplier or licensor: does the build need to emit anything? Can it run with the network down? Can it be locked to one orientation and one device? Are we licensing an existing title, branding one, or commissioning โ and what is the lead time for each?
- To yourself: if the game does not need a form, are we still building one out of habit?
If you are scoping a stand now, look at what already exists before commissioning anything โ our trade show games and games for events pages are there for that comparison. A title that already runs offline on a tablet removes three of the five failure modes above on day one.
๐ฏ What You Get When You License HTML5 Games From a Direct Licensor
For an event, a licence from a direct licensor is a route to a working title in days rather than a build cycle. Forestry Games has operated since 2017 and licenses a catalogue of 1,049 titles covering HTML5 and Android APK builds, with HTML5 development done in house. For a booth that means picking a title that already runs, having it branded to the campaign, and hosting it yourself or having it hosted โ rather than starting a bespoke project eight weeks out from a date that will not move.
Catalogue size matters less as a headline than as a filter. The useful question is how many titles survive your constraints โ offline capable, orientation locked, playable in ninety seconds, understandable with no instructions and no sound in a loud hall. That set is far smaller than any catalogue total, and it is the one worth asking a licensor to shortlist. You can license HTML5 games for a single activation or across a season of shows, and the same conversation covers APK builds for stands running on Android tablets that never touch a browser.
๐งธ Licensing Branded Games for Events, Campaigns and Portals
Where a campaign needs recognisable characters rather than generic gameplay, that is a branded licence rather than a standard one. Forestry Games works with branded IP and has brand partnerships including Disney, Nickelodeon, Cartoon Network and Warner Bros, and businesses can license branded game content through Forestry Games for campaigns, portals, events and apps. Branded work carries an approval process, so it belongs in the schedule earlier than a generic title.
If that is the direction, the next step is a scoping conversation rather than a purchase: browse the catalogue, tell us the show dates, the territory and whether the stand must run offline, and ask for a licence scope covering the titles that fit. Portal demos are available where the event game is really the front door to a longer-running games destination.
โ Ask the Data Path Question at the Next Kickoff
One question, asked before anyone picks a game, settles most of this: which of the three paths are we on, and who controls the records at the end of it? If the answer is the scanner, the game gets a simpler brief and a shorter build, and you should be licensing something that already exists rather than commissioning. If the answer is the form, the consent design and the retention plan are project deliverables with names against them, not a paragraph in the privacy policy.
The failure mode is not choosing wrong. It is not choosing at all โ running a game with a half-built form, inheriting neither the organiser's consent chain nor a clean one of your own, and finishing the show with a spreadsheet nobody will sign off on emailing. Decide the data path first, then pick the game.


