Privacy Policy
1. Who we are
HAVIT is a marketplace operated by Mazaya, company number 315869958, at A-Kurum 11, Reina, Israel.
Mazaya is the controller of the personal data described here, for the purposes of the Protection of Privacy Law, 5741-1981.
For anything in this policy — a question, a request to see or correct your data, or a complaint — contact [email protected], or write to us at the address above.
2. What we collect, and why
This section is written from the application's actual behaviour. Where it says "we do not", that is a property of the system, not an intention.
To identify you
| Data | Why | Notes |
|---|---|---|
| Phone number | It *is* your account. You sign in with a code sent to it. | One account per phone. We never store a password, because there isn't one. |
| One-time codes | Sign-in | Stored hashed, never in the clear, and short-lived. |
| Your name | The merchant and the driver see it at handover | Asked once, at signup. |
| City | Delivery and discovery |
To take an order
| Data | Why |
|---|---|
| Delivery addresses | To deliver to you. Includes an optional map location and optional notes for the driver. |
| Cart and order contents | To sell you the things |
| Order history | So you can see your past orders, and so support can help you |
We do not store card details. Payment at launch is cash on delivery. If card payment is enabled later, card data is handled by the payment provider and does not reach our systems.
To make the app work
| Data | Why | Notes |
|---|---|---|
| Device push token | To notify you about your order | An address for your handset. Not readable as anything about you. |
| Language preference | To show the app in your language | |
| Session records | To keep you signed in and to let you sign out everywhere |
To understand what people look for
We record what is searched for, and whether the search found anything. This is how we learn what to stock. A search is recorded against either your account or an anonymous session identifier — never both, and the anonymous one is not linked back to you.
We do not build advertising profiles, and we do not sell any of this.
3. What we do NOT collect
Stated because absence is easy to assume and hard to verify:
- No card numbers. There is no card data in our systems.
- No location tracking. We store the addresses you type. We do not follow your device.
- No contacts, photos, or microphone.
- No third-party advertising trackers.
Cookies
Our public website sets no cookies. It is plain HTML — no analytics, no advertising pixels, no embedded third-party content, and nothing that loads from another domain. There is no cookie banner because there is nothing to consent to.
The apps do not use cookies either. They keep a session token on your device so you stay signed in, and you can end it from the app by signing out.
Marketing
We do not send marketing messages. The notifications you get are about your own orders — collected, on the way, delivered, a problem — and you can turn them off in your device settings. We do not build advertising profiles, we do not sell your data, and we do not share it with anyone for advertising.
4. Who sees your data
| Who | What they see |
|---|---|
| The merchant you bought from | Your name, the items you ordered from them, and what is needed to prepare it |
| The driver delivering to you | Your name, delivery address and phone, for that delivery |
| HAVIT staff | What their role permits, and every staff action on your data is recorded |
| Our service providers | DigitalOcean (hosting and databases, Frankfurt), EM100 (WhatsApp one-time codes), Google Firebase (push notifications), Meilisearch (search, self-hosted on our own infrastructure) — processing on our behalf, under contract |
| Courts, regulators and law enforcement | What we are legally required to hand over, or what we need to disclose to establish or defend a legal claim, to investigate fraud or misuse, or to protect someone's safety. We disclose the minimum the request actually requires, and we do not treat a request as an obligation without checking that it is one |
| A buyer or successor | If the business is sold, merged or reorganised, your data moves with it, under this policy. We will tell you in the app before that happens |
We do not sell your data. We do not share it for advertising.
Where your data is
Our servers and databases are in Frankfurt, Germany, and push notifications go through Google Firebase, which operates globally. So your data is stored and processed outside Israel. We use providers that are contractually bound to process it only on our instructions, and we do not move it anywhere else for our own convenience.
5. How long we keep it
| Data | Kept |
|---|---|
| Account and orders | While your account exists, then per seven years from the end of the tax year in which the order was placed — orders are financial records and there are legal minimums |
| One-time codes | Minutes |
| Session and rate-limit records | Between 7 and 90 days depending on type, then deleted automatically |
| Search records | 12 months, then deleted |
6. Your rights
You can:
- See what we hold about you
- Correct it
- Delete your account — there is a button for this in the app
- Object to a particular use
- Complain to the Privacy Protection Authority
Account deletion cannot remove records we are legally required to keep, such as completed orders as financial records.
What deleting your account actually does
Stated table by table, because "we delete your data" is a sentence anybody can write.
Erased:
- Your name, city, language preference and phone number are cleared from your account, and the account is marked deleted.
- Your whole address book — every saved address, including ones you had already deleted. The recipient name, phone, street, building, apartment, floor, driver notes and map coordinates are all overwritten. The database itself then refuses to let any of them be written back.
- Your favourites — every product and every store you saved.
- The basket you were in the middle of.
- Your searches, where they were recorded against your account.
Kept, and why:
- Your orders, with the items, the prices and what was paid. These are financial records and there are legal minimums.
- The delivery address of each order. Not from your address book — a separate copy, frozen at the moment you ordered, which is what makes the record of where a delivered order actually went. It cannot be edited and it is kept with the order.
- Your record of accepting this policy and the terms, so we can show what you agreed to and when.
Everything kept is separated from your profile: the account it points at no longer holds your name or your phone number.
Signing up again with the same phone number creates a new, empty account. It is not a restore — none of the above comes back, and your old orders are not visible from it.
About the consent record, stated separately because it is not a financial record. We keep your record of accepting this policy and the terms after you delete your account. It is not kept under the legal-minimum rule that covers your orders — it is kept because it is the only evidence of what you agreed to and when, and we would rather say that outright than fold it into "records we must keep". It holds the document version and the date, and the account it points at no longer carries your name or your phone number.
Write to [email protected].
7. Security
Data is encrypted in transit. Access is limited by role and staff actions are audited. One-time codes are hashed.
Stated plainly because it is true: push tokens are stored unencrypted. A push token is an address for a handset — it cannot be replayed to read anything about you, and it is deleted when the session it belongs to ends.
If something goes wrong. If we discover a security incident affecting your personal data, we will notify you and the Privacy Protection Authority where the law requires it, and we will say what happened rather than that "an issue occurred". If you believe your data has been mishandled, or you see someone trying to reach it, write to [email protected].
8. Children
HAVIT is not intended for anyone under 18.
9. Changes
If this policy changes materially we will tell you in the app and ask you to accept the new version. Your acceptance is recorded against the version string at the top of this document.