Privacy Policy


1. Who we are

HAVIT is a marketplace operated by Mazaya, company number 315869958, at A-Kurum 11, Reina, Israel.

Mazaya is the controller of the personal data described here, for the purposes of the Protection of Privacy Law, 5741-1981.

For anything in this policy — a question, a request to see or correct your data, or a complaint — contact [email protected], or write to us at the address above.

2. What we collect, and why

This section is written from the application's actual behaviour. Where it says "we do not", that is a property of the system, not an intention.

To identify you

DataWhyNotes
Phone numberIt *is* your account. You sign in with a code sent to it.One account per phone. We never store a password, because there isn't one.
One-time codesSign-inStored hashed, never in the clear, and short-lived.
Your nameThe merchant and the driver see it at handoverAsked once, at signup.
CityDelivery and discovery

To take an order

DataWhy
Delivery addressesTo deliver to you. Includes an optional map location and optional notes for the driver.
Cart and order contentsTo sell you the things
Order historySo you can see your past orders, and so support can help you

We do not store card details. Payment at launch is cash on delivery. If card payment is enabled later, card data is handled by the payment provider and does not reach our systems.

To make the app work

DataWhyNotes
Device push tokenTo notify you about your orderAn address for your handset. Not readable as anything about you.
Language preferenceTo show the app in your language
Session recordsTo keep you signed in and to let you sign out everywhere

To understand what people look for

We record what is searched for, and whether the search found anything. This is how we learn what to stock. A search is recorded against either your account or an anonymous session identifier — never both, and the anonymous one is not linked back to you.

We do not build advertising profiles, and we do not sell any of this.

3. What we do NOT collect

Stated because absence is easy to assume and hard to verify:

Cookies

Our public website sets no cookies. It is plain HTML — no analytics, no advertising pixels, no embedded third-party content, and nothing that loads from another domain. There is no cookie banner because there is nothing to consent to.

The apps do not use cookies either. They keep a session token on your device so you stay signed in, and you can end it from the app by signing out.

Marketing

We do not send marketing messages. The notifications you get are about your own orders — collected, on the way, delivered, a problem — and you can turn them off in your device settings. We do not build advertising profiles, we do not sell your data, and we do not share it with anyone for advertising.

4. Who sees your data

WhoWhat they see
The merchant you bought fromYour name, the items you ordered from them, and what is needed to prepare it
The driver delivering to youYour name, delivery address and phone, for that delivery
HAVIT staffWhat their role permits, and every staff action on your data is recorded
Our service providersDigitalOcean (hosting and databases, Frankfurt), EM100 (WhatsApp one-time codes), Google Firebase (push notifications), Meilisearch (search, self-hosted on our own infrastructure) — processing on our behalf, under contract
Courts, regulators and law enforcementWhat we are legally required to hand over, or what we need to disclose to establish or defend a legal claim, to investigate fraud or misuse, or to protect someone's safety. We disclose the minimum the request actually requires, and we do not treat a request as an obligation without checking that it is one
A buyer or successorIf the business is sold, merged or reorganised, your data moves with it, under this policy. We will tell you in the app before that happens

We do not sell your data. We do not share it for advertising.

Where your data is

Our servers and databases are in Frankfurt, Germany, and push notifications go through Google Firebase, which operates globally. So your data is stored and processed outside Israel. We use providers that are contractually bound to process it only on our instructions, and we do not move it anywhere else for our own convenience.

5. How long we keep it

DataKept
Account and ordersWhile your account exists, then per seven years from the end of the tax year in which the order was placed — orders are financial records and there are legal minimums
One-time codesMinutes
Session and rate-limit recordsBetween 7 and 90 days depending on type, then deleted automatically
Search records12 months, then deleted

6. Your rights

You can:

Account deletion cannot remove records we are legally required to keep, such as completed orders as financial records.

What deleting your account actually does

Stated table by table, because "we delete your data" is a sentence anybody can write.

Erased:

Kept, and why:

Everything kept is separated from your profile: the account it points at no longer holds your name or your phone number.

Signing up again with the same phone number creates a new, empty account. It is not a restore — none of the above comes back, and your old orders are not visible from it.

About the consent record, stated separately because it is not a financial record. We keep your record of accepting this policy and the terms after you delete your account. It is not kept under the legal-minimum rule that covers your orders — it is kept because it is the only evidence of what you agreed to and when, and we would rather say that outright than fold it into "records we must keep". It holds the document version and the date, and the account it points at no longer carries your name or your phone number.

Write to [email protected].

7. Security

Data is encrypted in transit. Access is limited by role and staff actions are audited. One-time codes are hashed.

Stated plainly because it is true: push tokens are stored unencrypted. A push token is an address for a handset — it cannot be replayed to read anything about you, and it is deleted when the session it belongs to ends.

If something goes wrong. If we discover a security incident affecting your personal data, we will notify you and the Privacy Protection Authority where the law requires it, and we will say what happened rather than that "an issue occurred". If you believe your data has been mishandled, or you see someone trying to reach it, write to [email protected].

8. Children

HAVIT is not intended for anyone under 18.

9. Changes

If this policy changes materially we will tell you in the app and ask you to accept the new version. Your acceptance is recorded against the version string at the top of this document.