Starpha

Privacy Policy

מדיניות פרטיות — the Hebrew text is the binding one.

Draft. Not yet final; anything in square brackets is a blank still to be filled.

This explains what is collected about you, why, who it is shared with, and what you can do about it. It is written to be understood, not to be long.

1. Who is responsible

Ido Lavon, Haifa, Israel. Privacy contact: ido@ereris.com.

2. What is collected
  • Account details — display name, email, year of birth or age declaration.
  • Location at the moment of a scan — device coordinates when you tap to scan a card, and only then.
  • Platform activity — cards collected, products bought, intent declarations before an auction, crew chat messages, files you upload.
  • Technical data — browser and device type, IP address, for security and fault-finding.
  • We do not collect card details. Payment happens at the processor and we receive only a transaction reference.
3. Location, in detail, because this is the sensitive part

Location is read only at the moment of a scan, to confirm you are actually at the business. It is compared with the business location within roughly 300 metres, and what is stored is the fact of the scan and which business it happened at. There is no background tracking, no movement history, and your location is never passed to the business or to another user. You may decline the location permission; you then cannot earn a card, and the rest of the platform works normally.

4. Why we use it
  • To run your account, your crew and your cards.
  • To verify physical presence at a scan, and to prevent spoofing.
  • To compute aggregate demand for businesses. A business sees numbers only — how many people, roughly how far away — and never anyone's identity.
  • To pay crews and businesses, and to meet tax and reporting obligations.
  • To send operational messages. Marketing only with separate consent, revocable at any time.
5. Minors

A user under 18 registers only after parental or guardian consent. The parent may inspect what is held about the minor, ask for correction, ask for deletion, and withdraw consent at any time. Without that consent we will not collect location from the minor and will not publish their image.

6. Who it is shared with
  • Supabase — storage and database, on servers in the EU region.
  • [payment processor] — to take payment. They receive the payment details; we do not.
  • Resend — operational email.
  • Anthropic — text processing for the in-app assistants, when you invoke them.
  • Authorities, to the extent required by law.

We do not sell personal data and do not pass it to advertisers.

7. How long it is kept

Account data — while the account is active and up to [12] months after closure. Scan and sale records — [7 years] as required for tax and accounting. Crew messages — to the end of the season plus [12] months.

8. Your rights

To inspect, to correct, to request deletion, and to withdraw marketing consent. Write to ido@ereris.com and we will answer within [30] days.

9. Security

Access is restricted at the database level so that a user sees only their own data. Traffic is encrypted. In a material security incident we will notify those affected and the authorities as required.

10. Changes

Material changes are announced in advance. This version takes effect [date].

המסמך הזה מסביר איזה מידע נאסף עליכם, למה, עם מי הוא משותף ומה אתם יכולים לעשות בנוגע אליו. הוא כתוב כדי שיהיה מובן, לא כדי להיות ארוך.

1. מי אחראי על המידע

עדו לבון, חיפה, ישראל. לפניות בנושא פרטיות: ido@ereris.com.

2. איזה מידע נאסף
  • פרטי חשבון — שם תצוגה, כתובת אימייל, שנת לידה או הצהרת גיל.
  • מיקום בעת סריקה — קואורדינטות המכשיר ברגע שאתם לוחצים לסרוק כרטיס, ורק אז.
  • פעילות בפלטפורמה — כרטיסים שנאספו, מוצרים שנרכשו, הצהרות כוונה לפני מכירה פומבית, הודעות בצ'אט הצוות, קבצים שהעליתם.
  • מידע טכני — סוג דפדפן ומכשיר, וכתובת IP, לצורך אבטחה ותקלות.
  • אנחנו לא אוספים פרטי אשראי. תשלום מתבצע אצל ספק הסליקה ואנחנו מקבלים ממנו מזהה עסקה בלבד.
3. מיקום — בפירוט, כי זה החלק הרגיש

המיקום נקרא רק ברגע הסריקה, כדי לוודא שאתם באמת נמצאים בבית העסק. הוא נשווה למיקום בית העסק ברדיוס של כ‑300 מטר, והתוצאה שנשמרת היא עצם הסריקה ובית העסק שבו בוצעה. אין מעקב ברקע, אין היסטוריית תנועה, ואין העברה של מיקומכם לבית העסק או למשתמש אחר. אפשר לסרב להרשאת המיקום; במקרה כזה לא ניתן לזכות בכרטיס, וכל שאר הפלטפורמה פועלת כרגיל.

4. למה אנחנו משתמשים במידע
  • לתפעל את החשבון, הצוות והכרטיסים.
  • לאמת נוכחות פיזית בעת סריקה, ולמנוע זיוף.
  • לחשב ביקוש מצרפי לבתי עסק. בית עסק רואה מספרים בלבד — כמה אנשים, מאיזה מרחק בקירוב — ולעולם לא זהות של אדם.
  • לבצע תשלומים לצוותים ולבתי עסק, ולעמוד בחובות דיווח ומס.
  • לשלוח הודעות תפעוליות. דיוור שיווקי רק בהסכמה נפרדת שאפשר לבטל בכל עת.
5. קטינים

משתמש מתחת לגיל 18 נרשם רק לאחר הסכמת הורה או אפוטרופוס. ההורה רשאי לעיין במידע שנאסף על הקטין, לבקש את תיקונו ולבקש את מחיקתו, ולחזור בו מההסכמה בכל עת. ללא הסכמה כזו לא נאסוף מיקום מהקטין ולא נפרסם את תמונתו.

6. עם מי המידע משותף
  • Supabase — אחסון ובסיס נתונים, בשרתים באזור האיחוד האירופי.
  • [ספק הסליקה] — לצורך ביצוע התשלום. הם מקבלים את פרטי התשלום, לא אנחנו.
  • Resend — שליחת דואר אלקטרוני תפעולי.
  • Anthropic — עיבוד טקסט עבור כלי העזר בתוך האפליקציה, כאשר אתם מפעילים אותם.
  • רשויות, ככל שנדרש על פי דין.

אנחנו לא מוכרים מידע אישי ולא מעבירים אותו למפרסמים.

7. כמה זמן נשמר

מידע חשבון — כל עוד החשבון פעיל ועד [12] חודשים לאחר סגירתו. רשומות סריקה ורכישה — [7 שנים] ככל שנדרש לצורכי מס וחשבונאות. הודעות צוות — עד סוף העונה ו‑[12] חודשים אחריה.

8. הזכויות שלכם

לעיין במידע, לתקן מידע שגוי, לבקש מחיקה, ולבטל הסכמה לדיוור. פנייה ל‑ido@ereris.com תיענה בתוך [30] ימים.

9. אבטחה

הגישה למידע מוגבלת ברמת בסיס הנתונים כך שמשתמש רואה את שלו בלבד. התעבורה מוצפנת. במקרה של אירוע אבטחה מהותי נודיע למי שנפגע ולרשויות ככל שנדרש.

10. שינויים

נודיע מראש על שינוי מהותי. גרסה זו בתוקף מיום [תאריך].

All documents · Starpha