Binding document

Privacy Policy

farmers.shukotef.co.il גרסה 1.0 · בתוקף מ-24.7.2026 נערכה לאור תיקון 13 לחוק הגנת הפרטיות, התשמ"א-1981, שנכנס לתוקף ב-14.8.2025.

1. Controller

Kniyot U'Mishlochim Online Ltd., company no. 515131274. Privacy contact: support@salkniyot.co.il · +972-58-788-5771. Data Protection Officer: *(to be completed on appointment — section 12.)*

2. What we collect

From you: phone number (required, for verification) · business and display name · region and town · what you grow or buy · seasons, volumes and trading terms · certifications · photos · a short free text · email and exact address if you choose to provide them. Automatically: IP address, browser and device type, pages viewed, basic usage. Analytics are collected only after you consent. From public sources: we collect business information from government registries, certification bodies' public lists, growers' organizations, business directories and business websites. From this we retain business information only: name, town, activity, crops, certifications and website. A phone number found in a public source is not stored — it is immediately converted to a one-way encrypted value used solely to verify ownership when the business owner claims the profile. Emails, exact addresses and precise location data are not stored at all.

3. Purposes

Operating the index and displaying business profiles · verifying identity and ownership · relaying contact requests · preventing fraud and misuse · improving search and service · meeting legal obligations.

4. What is public and what is not

Your business profile is public and appears in search engines. Your contact details are visible to no one. They are stored separately and encrypted, with the key held by a separate service the website cannot reach. Contact details are disclosed in one scenario only: you received a request and you approved it — at which point the *sender's* details are disclosed to you, not the reverse.

5. Sharing

We do not sell or trade information. We share it only with service providers processing it on our behalf and instructions — hosting, messaging, analytics, error reporting — and where required by law or court order.

6. Transfers outside Israel

The database is hosted in Ireland (EU), regarded as providing an adequate level of protection. Some service providers operate outside Israel under appropriate contractual safeguards.

7. Cookies and analytics

Essential cookies always operate. Analytics cookies operate only after your consent, which you may withdraw at any time. We use PostHog (EU servers) for usage analytics and Sentry for error reporting.

8. Retention

Active profile — while the account exists · deleted profile — erased within 30 days, save a minimal marker preventing re-collection · contact request and disclosure records — 7 years, for evidence and abuse prevention · technical logs — 90 days.

9. Your rights

Access · correction · deletion of profile and account · export · withdrawal of consent to marketing or analytics · one-click removal of a profile collected from public sources, with no registration and no reason required. Removal requests are handled within 48 hours, are permanent, and we retain an internal marker preventing that business from being re-collected. Access, correction and export are available within the site. If unanswered, you may contact the Privacy Protection Authority at the Ministry of Justice.

10. Messages we send

We message only those who registered and agreed: verification codes, notice of a received request, and service updates. A business whose profile was collected from a public source and who has not registered receives nothing from us. Marketing messages require separate consent and every message carries a simple opt-out.

11. Security

Encryption in transit and at rest · contact details encrypted in a separate table with the key held outside the website · role-based access · immutable logging of every disclosure · rate limiting, anomaly detection and daily monitoring · security review before every release. In a serious security incident we will notify the Authority and affected persons as required by law.

12. Data Protection Officer

Given the volume of business information we manage, the Company appoints a Data Protection Officer. Their details will be published here on appointment, and they are the address for any privacy matter.

13. Minors

The service is for businesses and adults only. We do not knowingly collect information about minors.

14. Changes

We will update this policy from time to time. Material changes will be posted 14 days in advance.

Back to the home page