Money ClockעבריתעבDownload

Privacy Policy — Money Clock (שעון הכסף)

Last updated: 19 September 2026

The app "Money Clock" (Hebrew: שעון הכסף), bundle identifier com.izzy.GoldClockl, is built and
operated by an independent developer, Yisrael Fried
("we", "us"). This document explains what the app collects, why, where it is stored, who can see it,
and how to delete all of it.

In short

  • The personal clock — your shift history, pay, goals, work profiles and tasks — stays on your device. We never see it and never send it anywhere.
  • The business side — a business, its team, its schedule and worked hours — is stored on our server, because several people have to see the same schedule. Our server is hosted on Supabase, in the Frankfurt (EU) region.
  • Team chat — messages are stored on our server, encrypted in transit and at rest, but not end-to-end encrypted, and are deleted automatically after 180 days. "Top of the month" shows hours only — never pay — stays off until the business owner switches it on, and anyone can choose not to appear in it.
  • We do not sell your data, do not share it with advertisers, and do not track you across apps or websites. There are no ads, no in-app purchases and no analytics tools in the app.
  • You can delete your account from inside the app, and the deletion is real.

1. The personal clock — what never reaches us

The personal clock works with no account and no internet connection. Everything it stores — shift
history, hourly pay, currency, goals, work profiles, tasks, appearance settings and wallpaper — is
kept on the device itself (UserDefaults and the app's own folder) and shared with the widget and
the Apple Watch app through an on-device app group.

Shift history is also backed up to Apple's iCloud Key-Value Store, so it follows you to a new
phone. That backup goes to your own iCloud account, is controlled by Apple, and we have no
access to it and no way to read it.

"Settings → Delete all data" erases all of the above from the device and from that iCloud backup.

2. The business side — what is collected and why

The business side only opens if you choose to use it, and it asks you to sign in. From that point
the following data is collected:

| What | Why | When |
|---|---|---|
| Email address | To identify you at sign-in | At sign-in. With "Sign in with Apple" this may be Apple's private relay address; with "Continue with Google" it is the address of your Google account |
| Display name | So the team and the manager know who signed up for a shift | When joining; can be changed |
| Phone number (optional) | So a manager can reach you about shifts | Only if you fill it in on the join form |
| User ID | The key that links your rows on the server | Created automatically at sign-in |
| Device ID | The device's push token and its vendor identifier (identifierForVendor), so a notification reaches the right phone and nobody else can hijack your notifications | When you allow notifications |
| Business content | Businesses, memberships, roles, shifts, assignments, swap requests, availability, templates, notes | While you use the app |
| Worked hours | Start, break and end times of shifts you clocked for a given business, so the manager can see who is working now and how many hours were worked | When you run the clock on a shift of that business |
| Chat messages | So the team can write in the team channel and in direct messages: the text, the sender, the recipient (for a direct message), the business and the time sent, plus how far you have read each conversation, for the unread counts | When you send a message or read a conversation |
| Message reports | So the business owner can deal with abusive content: a copy of the reported message's text, who wrote it, who reported it and, if you gave one, the reason | When you report a message |
| Blocks | Whom you blocked and when, so their messages are hidden from you and they cannot send you direct messages | When you block someone |
| Preferences | Whether you muted the team channel and whether you chose not to appear on the leaderboard; for the business, whether the leaderboard is on | When you, or the business owner, change them |
| Precise workplace location | The coordinates and radius a business owner marks as the workplace, so the "am I at work" check works for the whole team | Only when a business owner marks the workplace |
| Language | So notifications arrive in your language | Automatically |
| Suggestions | If you write us a suggestion from Settings: the text you wrote, the device identifier (to keep it to five a week), which part of the app it came from, the app version and the language. Signed in, the suggestion is linked to your account; otherwise it is anonymous | Only when you send a suggestion |

What is never sent to the server from the personal clock: your pay amounts, your personal
history, goals, tasks, or any job that does not belong to that business.

3. Location — exactly what happens

  • Your own location as an employee never leaves your device. When a business owner has enabled the location check, your phone compares your current position with the workplace coordinates on the device itself and decides whether a shift may start. What gets stored is only "the shift started" — not where you were.
  • The location a business owner marks is stored with us. When an owner marks the workplace from their current position, the coordinates, the place name and the radius are saved on the business record on the server — otherwise the check could not work for the rest of the team. This is why the App Store listing declares that precise location is collected.
  • "Always" permission is requested only if you turn on the optional "Still at work?" reminder, which alerts you when you leave the work area during a shift. That alert is created on your own device, and the location that triggered it is not sent to anyone.
  • You can revoke location permission at any time in iOS Settings. The rest of the app keeps working.

4. Where the data is stored

The business side is hosted on Supabase (Supabase, Inc.), a managed PostgreSQL hosting provider.
Our project runs in the Frankfurt, Germany region — inside the European Union. All traffic
between the app and the server is encrypted (HTTPS/TLS).

Supabase acts as our hosting provider only: it runs the database and the sign-in service on our
behalf and makes no independent use of the data.

In addition:

  • Apple — Sign in with Apple, and delivery of notifications through the APNs service.
  • Google — only if you chose "Continue with Google" as your way of signing in.

The app contains no third-party advertising, measurement or analytics SDKs.

5. Who can see what

Permissions are not enforced in the app but in the database itself (Row Level Security), so even
a direct request to the server cannot return data you are not meant to see:

  • An employee sees only the businesses they are approved in: the published schedule, the team, and their own hours. Draft weeks and draft shifts are invisible until they are published.
  • A manager (the owner, or a member marked as a manager) sees their own business's team, the schedule including drafts, join and swap requests, and the worked hours of their team in that business.
  • Pay rates are readable by the business owner only. No employee, manager included, can read them.
  • Phone numbers are visible to a manager of that business and to the owner of the number. Team members cannot see each other's phone numbers.
  • No business can see another business. If you work in two places, each one sees only its own shifts and hours.
  • A business's change log (who changed what, and when) is readable only by a manager of that business, and cannot be altered by anyone.

5a. Team chat

Each business has one team channel ("Everyone"), and you can send direct messages to any
approved member of the same business. Messages are text only, up to 2,000 characters.

Who sees what (again enforced in the database, not only in the app):

  • The team channel — everyone who is an approved member of the business right now, and its owner. Someone who joins also sees earlier messages that have not yet been deleted (that is, up to 180 days back).
  • A direct message — only the two people in the conversation. The business owner and managers cannot read direct messages, with one exception: if one of the two reports a message, the business owner receives a copy of that message only.
  • Reports — the business owner and we see them: the copy of the text, who wrote it, who reported it and the reason. The person reported does not see the report. We receive every report so that we can review it within 24 hours (Apple's guideline 1.2), and we can delete the message and remove its author from that business.
  • Blocking — applies between two people, in every business they share. Someone you blocked cannot send you direct messages, and their messages are hidden from you — in the team channel too — and do not notify you. You can unblock at any time.
  • Deleting — you can delete any message you wrote. The business owner and managers can delete any message in the team channel (moderation), but not direct messages.
  • Anyone who leaves the business (or is removed from it) loses access to its chat at once.

Encryption, plainly: messages travel encrypted (HTTPS/TLS) and are stored encrypted by our
hosting provider. They are not end-to-end encrypted. The server holds the text in readable form —
that is how it shows it only to the people allowed to see it and builds the notification from it. So,
technically, whoever operates the server — we, and our hosting provider in running it — can access
messages. We do not read messages, except where needed to handle a report of abuse or where the law
requires it. Do not send passwords, ID numbers, card details or medical information in the chat.

Flood limit: the server accepts at most 30 messages a minute from each person. To do that it
records when you sent messages, and deletes that record after an hour.

Automatic filtering: before a message is stored, the server compares its text against a list of
objectionable expressions in Hebrew and English. The comparison is entirely automatic, no person
reads the message, and nothing is kept from it: a message that is caught is not stored and not sent,
and its writer is told that it was not sent.

5b. "Top of the month"

The leaderboard ranks team members by hours worked in the calendar month (in the business's time
zone), from the hours the business already records (section 2). It never shows or computes pay,
rates or amounts.

  • Off by default. Only the business owner or a manager can switch it on, and only from then on is it visible in the business.
  • What people see: an employee sees the month's top three and their hours, their own place and hours, and "Employee of the month" — last month's number one. The owner and managers see the full ranking.
  • "Don't show me on the leaderboard" — any team member can choose this at any time. Someone who does is left out of the leaderboard for everyone, the owner and managers included, and sees only their own hours, without a place. This way someone on reserve duty, on maternity leave or working part-time is not put on show in front of the team. The choice affects the leaderboard only: the manager still sees your worked hours as an attendance record, as before.
  • The business owner is not ranked. Anyone who has left, was removed or is still awaiting approval never appears.

5c. Suggestions

Settings has "Ideas for the app" — a box anybody can write in, with or without an account. What
is sent: the text you wrote, the device identifier (only to keep it to five suggestions a week per
device), which part of the app it came from, the app version and the language. Nothing else goes
with it
— no name, no hours, no pay. If you were signed in when you sent it, the suggestion is
linked to your account; otherwise it is entirely anonymous. Suggestions are read by the app's
developer only, pass through the same automatic filter for abusive language as the chat, and are
kept for up to two years so we can come back to them when a new version is built. They cannot be
read from the app, not even your own.

6. Notifications

When something relevant happens — a schedule is published, you are assigned to a shift, someone asks
to join — our server writes a row to a notification queue, and our own function composes the text in
your language and sends it directly to Apple's notification service (APNs). There is no
third-party push provider (no Firebase). The notification travels through Apple's servers, like every
iOS notification, so its text — which may contain a business name or a person's name — is visible to
Apple on the way. You can turn notifications off at any time in iOS Settings.

Chat notifications. A direct message notifies its recipient (not if they blocked the sender). A
team-channel message notifies the whole team except the sender, anyone who muted the team channel and
anyone who blocked the sender. The notification carries the sender's name (for the team channel, the
business name too) and a preview of up to 80 characters of the message, so it may appear on the
lock screen
and be seen by anyone looking at the phone. You can hide previews in iOS Settings, or
mute the team channel in the app. Reporting a message sends the business owner a notification that a
message was reported — without its text. When a message is deleted, any notification about it still
waiting in the queue is deleted too.

7. What we do not do

  • We do not sell or rent your data to anyone.
  • We do not track you across apps or websites, and we pass nothing to advertisers or data brokers. The app declares this in its privacy manifest as well (NSPrivacyTracking = false, no tracking domains).
  • We do not build marketing profiles and make no automated decisions about you.
  • We send no marketing email. The only email we send is the sign-in code you asked for.

8. How long things are kept

  • Hours worked are the employer's wage record, and they are kept. The hours you recorded and the shifts you actually worked stay with the business after you leave and after you delete your account, under the name you worked as. The reason: an employer is required by law to keep a wage and hours register for years (seven, in Israel), and it is also your own protection if a pay dispute ever arises. We keep them for at least five years and never delete them on our own initiative.
  • Other business content (future shifts, assignments, availability) is kept for as long as the business exists and you are a member of it, because it is that business's operational record.
  • A deleted shift is not erased from the server immediately but marked as removed, so a manager can undo an accidental deletion.
  • Suggestions are kept for up to two years.
  • The change log (change_log) — a record of every change to the main tables, including a snapshot of the row before and after — is kept for 180 days and then deleted automatically by a daily job. It may contain a copy of rows concerning you during that period, and it is readable only by a manager of that business.
  • Leaving a business (or being removed by its owner) takes you off the team, deletes your assignments to future shifts, cancels pending requests and deletes your join request. From that moment you no longer see the business. The hours you already worked stay with the business as an attendance record, like a timesheet.
  • Chat messages are deleted automatically after 180 days by a daily job. Until then they stay in the business even after their author has left (someone who left no longer sees them), unless they were deleted earlier — by the author, or by the owner or a manager in the team channel.
  • Message reports, including the copy of the text, are kept for 180 days and then deleted automatically. The copy stays even if the message itself was deleted, so the owner knows what was said.
  • Blocks and preferences are kept until you undo them, or until you delete your account.
  • When a business owner erases a former employee's personal details, the messages that person wrote in the business, their direct conversations there, the reports about their messages, their availability and their requests are erased. The hours they worked stay, for the reason above.
  • Deleting your account removes everything — see below.

9. Deleting your account

In the app: Settings → "Delete my account".

This is a real server-side deletion, not a flag. What is deleted:

  • the account itself and the ability to sign in, your contact details (email, phone) and the devices registered for notifications;
  • the availability you submitted, pending requests, your preferences and your blocks;
  • the chat messages you sent, in every business, and the direct conversations you were part of; reports about your messages; your blocks and preferences. A report you filed stays with the business owner until it is deleted after 180 days, but without your name;
  • future shifts you had signed up for are given back to the manager before deletion, so the schedule is not left with a hole;
  • if you are a business owner, the business is closed, and nobody can work in it any more. It is not erased: the team's hours, the schedule and the records stay as that business's record, because they are not only yours — they belong to everyone who worked there, and to the law.

What stays, and why: the hours you worked at each business, and the name you worked under there,
stay with that employer as a wage record, as an employer is required to keep. You no longer appear as
an active member, there is no way to sign in to the account, and we can no longer tie that record to
your email or phone. If you believe a particular record is no longer needed, write to us at
support@goldclockapp.com.

The personal clock on your device — history, goals and profiles — is not deleted by this action,
because it was never with us. To erase that, use "Settings → Delete all data".

10. Your rights

If you are in the European Union or in Israel, you have the right to access the data held about you,
correct it, delete it, restrict or object to its processing, and receive a copy of it in a portable
format. Most of this can be done directly in the app (edit your name, phone and availability; delete
messages you sent; hide yourself from the leaderboard; leave a business; delete your account). For anything else, contact us at the address in section 12 and we
will reply within 30 days.

The legal basis for processing is performance of the service you asked for (managing your shifts
in the business you joined) and your consent wherever something is optional (phone number,
location, notifications).

11. Children

The app is made for managing work and pay and is not directed at children. We do not knowingly
collect data about children under 16. If you become aware that a child has given us data, contact us
and we will delete it.

11b. Payments

The "Money Clock Premium" subscription is bought and managed through Apple only. Payment
details, the payment method and the billing address stay with Apple — we never receive or see
them
. The app keeps on the device only whether a subscription is active, to know what to unlock.

11a. Terms of Use

The App's Terms of Use apply alongside this document. Among other things they set out
that the App is not a payroll system and not a substitute for attendance and payroll records,
and how responsibility is divided between a business owner, an employee and us:
https://goldclockapp.com/terms

12. Contact

For questions, data requests or deletion requests: support@goldclockapp.com

13. Changes to this policy

If this policy changes, the date at the top will be updated and the new version published at the same
address. A material change in how data is used will also be shown inside the app.


מדיניות פרטיות — שעון הכסף (Money Clock)

עדכון אחרון: 19 בספטמבר 2026

האפליקציה "שעון הכסף" (Money Clock), מזהה com.izzy.GoldClockl, פותחה ומופעלת על ידי מפתח עצמאי,
ישראל פריד (Yisrael Fried) ("אנחנו", "אנו"). המסמך הזה מסביר מה האפליקציה אוספת,
למה, איפה זה נשמר, מי יכול לראות את זה ואיך מוחקים את הכול.

בקצרה

  • השעון האישי — היסטוריית המשמרות, השכר, היעדים, הפרופילים והמשימות — נשאר במכשיר שלך. אנחנו לא רואים אותו ולא שולחים אותו לשום מקום.
  • הצד העסקי — עסק, צוות, לוח משמרות ושעות עבודה — נשמר בשרת שלנו, כי כמה אנשים חייבים לראות את אותו לוח. השרת שלנו מתארח ב-Supabase, באזור פרנקפורט שבאיחוד האירופי.
  • צ׳אט הצוות — ההודעות נשמרות בשרת שלנו, מוצפנות בדרך ובאחסון, אבל לא מוצפנות מקצה לקצה, ונמחקות אוטומטית אחרי 180 יום. "מובילי החודש" מציגה שעות בלבד — אף פעם לא שכר — היא כבויה עד שבעל העסק מפעיל אותה, וכל אחד יכול לבחור לא להופיע בה.
  • אנחנו לא מוכרים מידע, לא מעבירים אותו למפרסמים ולא עוקבים אחריך בין אפליקציות או אתרים. אין באפליקציה פרסומות, אין רכישות מתוך האפליקציה ואין כלי אנליטיקה.
  • אפשר למחוק את החשבון מתוך האפליקציה, והמחיקה אמיתית.

1. השעון האישי — מה שלא מגיע אלינו

השעון האישי עובד בלי חשבון ובלי חיבור לאינטרנט. כל מה שהוא שומר — היסטוריית המשמרות, השכר לשעה,
המטבע, היעדים, פרופילי העבודה, המשימות, הגדרות העיצוב ותמונת הרקע — נשמר במכשיר עצמו
(UserDefaults ותיקיית האפליקציה), ומשותף עם הווידג׳ט ועם אפליקציית ה-Apple Watch דרך קבוצת
אפליקציות משותפת במכשיר.

היסטוריית המשמרות מגובה גם ל-iCloud Key-Value Store של Apple, כדי שתחזור אליך אם תחליף מכשיר.
הגיבוי הזה הולך לחשבון ה-iCloud שלך, נשלט על ידי Apple, ואנחנו לא ניגשים אליו ואין לנו אפשרות לקרוא אותו.

"הגדרות → מחיקת כל הנתונים" מוחקת את כל האמור לעיל מהמכשיר ומהגיבוי ב-iCloud.

2. הצד העסקי — מה נאסף ולמה

הצד העסקי נפתח רק אם בחרת להשתמש בו, והוא מבקש התחברות. מרגע זה נאספים הנתונים הבאים:

| מה | למה | מתי |
|---|---|---|
| כתובת אימייל | לזהות אותך בהתחברות | בהתחברות. ב"התחברות עם Apple" זו יכולה להיות כתובת ההעברה הפרטית של Apple, וב"המשך עם Google" הכתובת של חשבון Google שלך |
| שם תצוגה | כדי שהצוות והמנהל ידעו מי נרשם למשמרת | בהצטרפות, וניתן לשינוי |
| מספר טלפון (רשות) | כדי שהמנהל יוכל ליצור איתך קשר בענייני משמרות | רק אם מילאת אותו בטופס ההצטרפות |
| מזהה משתמש | המפתח שמקשר בין כל הרשומות שלך בשרת | נוצר אוטומטית בהתחברות |
| מזהה מכשיר | אסימון ההתראות של המכשיר ומזהה היצרן (identifierForVendor), כדי לשלוח התראה למכשיר הנכון ולמנוע מאדם אחר לחטוף את ההתראות שלך | כשאתה מאשר התראות |
| תוכן עסקי | עסקים, חברות בצוות, תפקידים, משמרות, שיבוצים, בקשות החלפה, אילוצי זמינות, תבניות, הערות | בזמן השימוש |
| שעות עבודה | זמני התחלה, הפסקה וסיום של משמרות שנרשמו דרך השעון בעסק מסוים, כדי שהמנהל יראה מי עובד עכשיו וכמה שעות נעשו | כשאתה מפעיל שעון על משמרת של אותו עסק |
| הודעות צ׳אט | כדי שהצוות יוכל לכתוב בערוץ הצוות ובהודעות אישיות: הטקסט, השולח, הנמען (בהודעה אישית), העסק ושעת השליחה, וגם עד איזו הודעה קראת בכל שיחה, בשביל מונה ההודעות שלא נקראו | כשאתה שולח הודעה או קורא שיחה |
| דיווח על הודעה | כדי שבעל העסק יוכל לטפל בתוכן פוגעני: עותק של טקסט ההודעה המדווחת, מי כתב אותה, מי דיווח, ואם כתבת — הסיבה | כשאתה מדווח על הודעה |
| חסימות | את מי חסמת ומתי, כדי להסתיר ממך את ההודעות שלו ולמנוע ממנו לשלוח לך הודעות אישיות | כשאתה חוסם מישהו |
| העדפות | אם השתקת את ערוץ הצוות, ואם בחרת לא להופיע בטבלת המובילים; ובעסק — אם הטבלה מופעלת | כשאתה, או בעל העסק, משנים אותן |
| מיקום מדויק של מקום העבודה | הקואורדינטות והרדיוס שבעל העסק מסמן כמקום העבודה, כדי שבדיקת "אני במקום העבודה" תעבוד אצל כל הצוות | רק כשבעל עסק מסמן את מקום העבודה |
| שפה | כדי שההתראות יגיעו בשפה שלך | אוטומטית |
| הצעות לשיפור | אם כתבת לנו הצעה בהגדרות: הטקסט שכתבת, מזהה המכשיר (כדי להגביל לחמש הצעות בשבוע), מאיזה חלק באפליקציה זה נשלח, גרסת האפליקציה והשפה. אם היית מחובר — ההצעה מקושרת לחשבון; אם לא — היא אנונימית | רק כשאתה שולח הצעה |

מה לא נשלח לשרת מהשעון האישי: סכומי שכר שלך, ההיסטוריה האישית, יעדים, משימות, ועבודות אחרות
שאינן של אותו עסק.

3. מיקום — בדיוק מה קורה

  • המיקום שלך כעובד לא עוזב את המכשיר. כשבעל העסק הפעיל בדיקת מיקום, הטלפון שלך משווה את המיקום הנוכחי לקואורדינטות של מקום העבודה על המכשיר עצמו, ומחליט אם אפשר להתחיל משמרת. התוצאה שנשמרת היא רק "המשמרת התחילה" — לא איפה היית.
  • המיקום שבעל העסק מסמן כן נשמר אצלנו. כשבעל עסק מסמן את כתובת העסק לפי מיקומו הנוכחי, הקואורדינטות, שם המקום והרדיוס נשמרים ברשומת העסק בשרת — אחרת הבדיקה לא הייתה יכולה לעבוד אצל שאר הצוות. זו הסיבה שאנחנו מצהירים בחנות על איסוף "מיקום מדויק".
  • הרשאת "תמיד" מבוקשת רק אם הפעלת את התזכורת האופציונלית "עדיין בעבודה?", שמתריעה לך כשיצאת מאזור העבודה בזמן משמרת. ההתראה הזו נוצרת במכשיר שלך, והמיקום שהפעיל אותה לא נשלח לאיש.
  • אפשר לבטל את הרשאת המיקום בכל רגע בהגדרות iOS. שאר האפליקציה תמשיך לעבוד.

4. איפה הנתונים נשמרים

הצד העסקי מאוחסן ב-Supabase (Supabase, Inc.), ספק אירוח מנוהל של מסד נתונים PostgreSQL.
הפרויקט שלנו פועל באזור פרנקפורט, גרמניה — בתוך האיחוד האירופי. כל התקשורת בין האפליקציה
לשרת מוצפנת (HTTPS/TLS).

Supabase משמשת אותנו כספק אירוח בלבד: היא מפעילה את מסד הנתונים ואת שירות ההתחברות עבורנו,
ולא עושה שימוש עצמאי בנתונים.

נוסף לכך:

  • Apple — "התחברות עם Apple", ושליחת ההתראות דרך שירות APNs.
  • Google — רק אם בחרת "המשך עם Google" כדרך התחברות.

אין באפליקציה ערכות פיתוח של פרסום, מדידה או אנליטיקה מצד שלישי.

5. מי רואה מה

ההרשאות אינן מוגדרות באפליקציה אלא במסד הנתונים עצמו (Row Level Security), כך שגם בקשה ישירה
לשרת לא תחזיר מידע שאינך אמור לראות:

  • עובד רואה רק את העסקים שהוא מאושר בהם: את לוח המשמרות שפורסם, את חברי הצוות ואת השעות שלו עצמו. טיוטות של שבוע או של משמרת אינן נראות לו עד הפרסום.
  • מנהל (בעל העסק, או עובד שהוגדר כמנהל) רואה את הצוות של העסק שלו, את הלוח כולל טיוטות, את בקשות ההצטרפות וההחלפה, ואת שעות העבודה של הצוות בעסק שלו.
  • שכר ותעריפים — רק בעל העסק. שום עובד, כולל מנהל, אינו יכול לקרוא אותם.
  • מספרי טלפון — רק מנהל של אותו עסק, והבעלים של המספר עצמו. חברי צוות אינם רואים את הטלפון של חבריהם.
  • אף עסק לא רואה עסק אחר. אם אתה עובד בשני מקומות, כל אחד מהם רואה רק את המשמרות והשעות שלו.
  • יומן השינויים של עסק (מי שינה מה ומתי) נקרא רק על ידי מנהל של אותו עסק, ואי אפשר לשנות אותו.

5א. צ׳אט הצוות

לכל עסק יש ערוץ צוות אחד ("כל הצוות"), ואפשר לשלוח הודעות אישיות לכל חבר צוות מאושר
באותו עסק. ההודעות הן טקסט בלבד, עד 2,000 תווים.

מי רואה מה (גם כאן — ברמת מסד הנתונים, לא רק באפליקציה):

  • ערוץ הצוות — כל מי שחבר מאושר בעסק כרגע, ובעל העסק. מי שמצטרף רואה גם הודעות קודמות שעוד לא נמחקו (כלומר עד 180 יום אחורה).
  • הודעה אישית — רק שני האנשים שבשיחה. בעל העסק והמנהלים אינם יכולים לקרוא הודעות אישיות, עם חריג אחד: אם אחד מהשניים מדווח על הודעה, בעל העסק מקבל עותק של אותה הודעה בלבד.
  • דיווחיםבעל העסק ואנחנו רואים אותם: עותק הטקסט, מי כתב, מי דיווח והסיבה. מי שדווח עליו אינו רואה את הדיווח. אנחנו מקבלים כל דיווח כדי לבדוק אותו תוך 24 שעות (דרישת Apple, סעיף 1.2), ויכולים למחוק את ההודעה ולהוציא את מי שכתב אותה מאותו עסק.
  • חסימה — חלה בין שני אנשים, בכל העסקים המשותפים להם. מי שחסמת לא יכול לשלוח לך הודעות אישיות, וההודעות שלו מוסתרות ממך — גם בערוץ הצוות — ואינן מקפיצות לך התראות. אפשר לבטל חסימה בכל רגע.
  • מחיקה — אפשר למחוק כל הודעה שכתבת. בעל העסק והמנהלים יכולים למחוק כל הודעה בערוץ הצוות (פיקוח), אבל לא הודעות אישיות.
  • מי שעוזב את העסק (או מוסר ממנו) מאבד את הגישה לצ׳אט של העסק מיד.

הצפנה — בלי לייפות: ההודעות עוברות מוצפנות (HTTPS/TLS) ונשמרות מוצפנות אצל ספק האחסון.
הן אינן מוצפנות מקצה לקצה. השרת מחזיק את הטקסט בצורה קריאה — כך הוא מציג אותו רק למי שמורשה,
ובונה ממנו את ההתראה. לכן, מבחינה טכנית, מי שמפעיל את השרת — אנחנו, וספק האחסון במסגרת התפעול —
יכול לגשת להודעות. איננו קוראים הודעות, אלא אם הדבר נדרש כדי לטפל בפנייה על שימוש לרעה או לפי
חובה שבדין. אל תשלחו בצ׳אט סיסמאות, מספרי תעודה, פרטי אשראי או מידע רפואי.

הגבלת הצפה: השרת מקבל עד 30 הודעות בדקה מכל אדם. לשם כך הוא רושם את זמני השליחה, ומוחק את
הרישום הזה אחרי שעה.

סינון אוטומטי: לפני שהודעה נשמרת, השרת משווה את הטקסט שלה לרשימת ביטויים פוגעניים בעברית
ובאנגלית. ההשוואה אוטומטית לחלוטין, אף אדם לא קורא את ההודעה, ולא נשמר ממנה דבר: הודעה שנתפסה
אינה נשמרת ואינה נשלחת, ומי שכתב אותה מקבל הודעה שהיא לא נשלחה.

5ב. "מובילי החודש"

טבלת המובילים מדרגת את חברי הצוות לפי שעות העבודה בחודש הקלנדרי (לפי אזור הזמן של העסק),
מתוך השעות שהעסק כבר רושם (סעיף 2). היא לא מציגה ולא מחשבת שכר, תעריפים או סכומים — אף פעם.

  • כבויה כברירת מחדל. רק בעל העסק או מנהל יכולים להפעיל אותה, ורק מאותו רגע היא נראית בעסק.
  • מה רואים: עובד רואה את שלושת המובילים של החודש ואת השעות שלהם, את המקום והשעות שלו עצמו, ואת "עובד החודש" — המקום הראשון בחודש הקודם. בעל העסק והמנהלים רואים את הדירוג המלא.
  • "לא להופיע בטבלת המובילים" — כל חבר צוות יכול לבחור בזה בכל רגע. מי שבחר בזה לא מופיע בטבלה אצל אף אחד, כולל בעל העסק והמנהלים, ורואה רק את השעות שלו, בלי מקום. כך מי שנמצא במילואים, בחופשת לידה או במשרה חלקית לא מוצג מול הצוות. הבחירה משפיעה על הטבלה בלבד: המנהל ממשיך לראות את שעות העבודה שלך כרישום נוכחות, כמו קודם.
  • בעל העסק עצמו לא מדורג. מי שעזב, הוסר או עדיין ממתין לאישור — לא מופיע.

5ג. הצעות לשיפור

בהגדרות יש "הצעות לשיפור" — תיבה שכל אחד יכול לכתוב בה, גם בלי חשבון. מה שנשלח: הטקסט שכתבת,
מזהה המכשיר (רק כדי להגביל לחמש הצעות בשבוע לכל מכשיר), מאיזה חלק באפליקציה זה נכתב, גרסת
האפליקציה והשפה. לא נשלח איתה שום דבר אחר — לא שם, לא שעות ולא שכר. אם היית מחובר לחשבון
בזמן השליחה, ההצעה מקושרת אליו; אחרת היא אנונימית לגמרי. ההצעות נקראות על ידי מפתח האפליקציה
בלבד, עוברות את אותו סינון אוטומטי של ביטויים פוגעניים כמו הצ׳אט, ונשמרות עד שנתיים כדי שנוכל
לחזור אליהן כשבונים גרסה חדשה. אי אפשר לקרוא אותן מהאפליקציה, גם לא את שלך.

6. התראות

כשקורה משהו שרלוונטי לך — לוח פורסם, שובצת למשמרת, הוגשה בקשת הצטרפות — השרת שלנו כותב שורה
בתור התראות, ופונקציה שלנו בונה את הטקסט בשפה שלך ושולחת אותו ישירות לשירות ההתראות של Apple (APNs).
אין ספק התראות צד-שלישי (אין Firebase). ההתראה עוברת דרך שרתי Apple, כמו כל התראה ב-iOS, ולכן
טקסט ההתראה — שעשוי לכלול שם עסק או שם של אדם — נראה ל-Apple בדרך.
אפשר לכבות התראות בכל רגע בהגדרות iOS.

התראות צ׳אט. הודעה אישית מקפיצה התראה לנמען (לא אם הוא חסם את השולח). הודעה בערוץ הצוות
מקפיצה התראה לכל הצוות, חוץ מהשולח, ממי שהשתיק את ערוץ הצוות וממי שחסם את השולח. ההתראה כוללת
את שם השולח (בערוץ הצוות — גם את שם העסק) ותצוגה מקדימה של עד 80 תווים מההודעה, ולכן היא
עשויה להופיע על המסך הנעול
ולהיראות למי שמסתכל בטלפון. אפשר להסתיר תצוגות מקדימות בהגדרות iOS,
או להשתיק את ערוץ הצוות באפליקציה. דיווח על הודעה מקפיץ לבעל העסק התראה שדווחה הודעה — בלי הטקסט
שלה. כשהודעה נמחקת, גם התראה עליה שעוד ממתינה בתור נמחקת.

7. מה אנחנו לא עושים

  • לא מוכרים ולא משכירים מידע לאף אחד.
  • לא עוקבים אחריך בין אפליקציות או אתרים, ולא מעבירים מידע למפרסמים או למתווכי מידע. האפליקציה מצהירה על כך גם במניפסט הפרטיות שלה (NSPrivacyTracking = false, ללא דומייני מעקב).
  • לא בונים פרופיל שיווקי ולא מקבלים החלטות אוטומטיות לגביך.
  • לא שולחים דיוור פרסומי. המייל היחיד שנשלח הוא קוד ההתחברות שביקשת.

8. כמה זמן הדברים נשמרים

  • שעות עבודה הן רשומת שכר של המעסיק, והן נשמרות. שעות שדיווחת, והמשמרות שעבדת בפועל, נשארות אצל העסק גם אחרי שעזבת וגם אחרי שמחקת את החשבון — תחת השם שבו עבדת שם. הסיבה: מעסיק חייב בחוק לנהל פנקס שכר ושעות עבודה ולשמור אותו שנים (בישראל — שבע שנים), וזו גם ההגנה שלך אם תתגלה מחלוקת על שכר. אנחנו שומרים אותן לפחות חמש שנים, ולא מוחקים אותן ביוזמתנו.
  • תוכן עסקי אחר (משמרות עתידיות, שיבוצים, זמינות) נשמר כל עוד העסק קיים ואתה חבר בו, מפני שזה רישום התפעול של העסק.
  • משמרת שנמחקה אינה נמחקת מיד מהשרת אלא מסומנת כמוסרת, כדי שמנהל יוכל לשחזר מחיקה בטעות.
  • הצעות לשיפור נשמרות עד שנתיים.
  • יומן השינויים (change_log) — רישום של כל שינוי בטבלאות המרכזיות, כולל צילום השורה לפני ואחרי — נשמר 180 יום ואז נמחק אוטומטית מדי יום. ייתכן שהוא מכיל עותק של שורות שנגעו בך בתקופה הזו, והוא נגיש למנהל של אותו עסק בלבד.
  • יציאה מעסק (או הסרה על ידי הבעלים) מסירה אותך מהצוות, מוחקת את השיבוצים שלך למשמרות עתידיות, מבטלת בקשות ממתינות ומוחקת את בקשת ההצטרפות. מאותו רגע אינך רואה עוד את העסק. השעות שכבר עבדת נשארות אצל העסק כרישום נוכחות, כמו כרטיס עבודה.
  • הודעות צ׳אט נמחקות אוטומטית אחרי 180 יום, בעבודה שרצה פעם ביום. עד אז הן נשארות בעסק גם אחרי שהכותב עזב (מי שעזב כבר לא רואה אותן), אלא אם נמחקו קודם — בידי הכותב, או בידי בעל העסק או מנהל בערוץ הצוות.
  • דיווחים על הודעות, כולל עותק הטקסט, נשמרים 180 יום ואז נמחקים אוטומטית. העותק נשאר גם אם ההודעה עצמה נמחקה, כדי שבעל העסק יידע מה נאמר.
  • חסימות והעדפות נשמרות עד שתבטל אותן, או עד מחיקת החשבון.
  • כשבעל העסק מוחק את הפרטים האישיים של עובד לשעבר, נמחקים ההודעות שכתב בעסק, השיחות האישיות שלו שם, הדיווחים על ההודעות שלו, האילוצים והבקשות. השעות שעבד נשארות, מאותה סיבה שלמעלה.
  • מחיקת חשבון מוחקת את החשבון ואת מה שאישי — ראה בסמוך.

9. מחיקת החשבון

באפליקציה: הגדרות → "מחיקת החשבון שלי".

זו מחיקה אמיתית בשרת, לא סימון. מה שנמחק:

  • החשבון עצמו ואפשרות ההתחברות אליו, פרטי הקשר (אימייל, טלפון) והמכשירים הרשומים להתראות;
  • האילוצים שהגשת, הבקשות הממתינות, ההעדפות והחסימות שלך;
  • הודעות הצ׳אט ששלחת, בכל העסקים, והשיחות האישיות שהיית צד להן; דיווחים על ההודעות שלך; החסימות וההעדפות שלך. דיווח שאתה הגשת נשאר אצל בעל העסק עד שיימחק אחרי 180 יום, אבל בלי שמך;
  • המשמרות העתידיות שנרשמת אליהן משוחררות חזרה למנהל לפני המחיקה, כדי שלא ייווצר חור בסידור;
  • אם אתה בעל עסק — העסק נסגר, ואי אפשר לעבוד בו יותר. הוא אינו נמחק: השעות של הצוות, הסידור והרישומים נשארים כרשומה של אותו עסק, מפני שהם לא רק שלך — הם של כל מי שעבד שם, ושל החוק.

מה שנשאר, ולמה: השעות שעבדת בכל עסק, והשם שבו עבדת בו, נשארים אצל המעסיק כרשומת שכר, כפי
שמעסיק חייב לשמור. אינך מופיע יותר כחבר צוות פעיל, אין דרך להתחבר לחשבון, ואין לנו יותר דרך
לקשר את הרשומה הזאת לאימייל או לטלפון שלך. אם אתה סבור שרשומה מסוימת אינה נחוצה עוד, אפשר לפנות
אלינו ב-support@goldclockapp.com.

השעון האישי שבמכשיר — היסטוריה, יעדים ופרופילים — אינו נמחק בפעולה הזו, כי הוא מעולם לא היה
אצלנו. למחיקתו יש "הגדרות → מחיקת כל הנתונים".

10. הזכויות שלך

אם אתה נמצא באיחוד האירופי או בישראל, יש לך זכות לעיין במידע שנשמר עליך, לתקן אותו, למחוק אותו,
להגביל או להתנגד לעיבודו, ולקבל עותק ממנו בפורמט נגיש. את רוב זה אפשר לעשות ישירות באפליקציה
(עריכת השם, הטלפון והזמינות; מחיקת הודעות ששלחת; הסתרה מטבלת המובילים; יציאה מעסק; מחיקת חשבון). לכל בקשה אחרת אפשר לפנות אלינו בכתובת שבסעיף 12,
ונשיב תוך 30 יום.

הבסיס החוקי לעיבוד הוא קיום השירות שביקשת (ניהול המשמרות שלך בעסק שהצטרפת אליו)
והסכמתך בכל מקום שבו הדבר אופציונלי (טלפון, מיקום, התראות).

11. ילדים

האפליקציה מיועדת לניהול עבודה ושכר ואינה מיועדת לילדים. איננו אוספים ביודעין מידע על ילדים מתחת
לגיל 16. אם נודע לך שילד מסר לנו מידע, פנה אלינו ונמחק אותו.

11ב. תשלומים

המנוי "שעון הכסף פרימיום" נרכש ומנוהל דרך Apple בלבד. פרטי התשלום, אמצעי התשלום
וכתובת החיוב נשארים אצל Apple — אנחנו לא מקבלים אותם ולא רואים אותם. האפליקציה שומרת
על המכשיר רק אם יש מנוי פעיל, כדי לדעת מה לפתוח.

11א. תנאי השימוש

לצד מסמך זה חלים תנאי השימוש של האפליקציה, ובהם, בין היתר, ההבהרה שהאפליקציה אינה
מערכת שכר ואינה תחליף לרישומי נוכחות ושכר, והגדרת האחריות בין בעל העסק, העובד ובינינו:
https://goldclockapp.com/terms

12. יצירת קשר

לשאלות, בקשות מידע או בקשת מחיקה: support@goldclockapp.com

13. שינויים במדיניות

אם המדיניות תשתנה, התאריך בראש המסמך יתעדכן, והשינויים יפורסמו באותה כתובת. שינוי מהותי
באופן השימוש בנתונים יוצג גם בתוך האפליקציה.