→ חזרה לעמוד הבית

מדיניות פרטיות — VendMe

עודכן לאחרונה: 2026-09-16

1. מי אנחנו

VendMe ("אנחנו", "האפליקציה") היא פלטפורמת מסחר סיטונאי (B2B) המחברת בין ספקים, מפיצים וקמעונאים בענף התוצרת הטרייה. המפעילה: VENDME LTD, ישראל. יצירת קשר: office@vendme.net.

2. איזה מידע אנחנו אוספים

תוכן זמני ("סטורי") וצפיות בו: תמונה או סרטון שאתם מפרסמים כסטורי נשמרים אצלנו באחסון פרטי ומוצגים 24 שעות. בנוסף אנו רושמים מי צפה בכל סטורי ומתי — הרישום גלוי למפרסם הסטורי כמונה צפיות, ונשמר אצלנו גם לאחר שהתוכן נעלם מהתצוגה.

3. מה משתמשים אחרים רואים

4. כיצד אנו משתמשים במידע

לספק ולתפעל את השירות (חשבון, פיד, קטלוג, עסקאות, צ׳אט, שיחות והתראות); לאבטח את הפלטפורמה ולמנוע הונאה; לתמוך במשתמשים; ולשפר את המוצר. איננו מוכרים מידע אישי ואיננו עוקבים אחר משתמשים בין אפליקציות/אתרים לצורכי פרסום.

סינון ציות לדיני התחרות. בנוסף לבדיקה לפני פרסום המתוארת להלן, טקסטים בשיחות קבוצה ובפורום הקהילתי נבדקים אוטומטית ותקופתית על ידי Anthropic, שקוראת חלון מוגבל מההתכתבות — ההודעות החדשות ומעט הודעות קודמות כהקשר — גם כשלא נתפס אף ביטוי מרשימת החשדות. הטקסט נשלח ללא שמות, מזהי משתמש או מזהה שיחה, וכל דובר מיוצג באות בלבד לצד תפקידו. גם טיוטה שאתם מקלידים בקבוצה, בפורום או בתיבת תגובה עשויה להישלח לאותה בדיקה כדי להציג התראה לפני השליחה; הטיוטה אינה נשמרת, אינה יוצרת רשומה ואינה חוסמת את השליחה. במסלול Anthropic זה, שיחות אישיות (1:1) ושיחות עסקה אינן נסרקות, וכך גם הודעות קוליות, תמונות ווידאו. רק בעת התאמה נשמר קטע של עד 500 תווים יחד עם מזהה המשתמש והביטויים שזוהו, ברשומה פנימית הגלויה למנהלי VendMe בלבד. הבדיקה עשויה להוביל לפעולת אכיפה.

סינון OpenAI לפני פרסום. כל תוכן ציבורי נתמך שאתם מבקשים לפרסם נבדק אוטומטית לפני הפרסום. הבדיקה חלה על הצ׳אט הכללי, קבוצות ודיונים ציבוריים, סטורי, פוסטים ותגובות, מוצרים ועסקאות כמות, כרטיסי עסק ומודעות עסקיות, פרופיל וגלריה ציבוריים, דירוגים ומוצרי מפיצים. לפי המשטח נבדקים טקסט, תמונות, וידאו וקול. בצ׳אטים ציבוריים עשויים להישלח טקסט ההודעה, המדיה שצורפה וחלון מוגבל של הודעות קודמות לצורך הקשר. בווידאו מופקים בתשתית VendMe/Supabase קובץ שמע מסוג WAV, תמונת תצוגה ופריימים שנדגמו לאורך הסרטון: קובץ השמע נשלח ל-OpenAI לתמלול, ולאחר מכן נשלחים לסיווג התמלול, הפריימים, תמונת התצוגה ומידע טכני מצומצם, כגון משך הסרטון וחותמות הזמן של הפריימים. בהודעה קולית נשלחים קובץ השמע לתמלול והתמלול לסיווג. לכל בקשת סיווג מצורף גם מזהה בטיחות מגובב של החשבון. קובץ ה-MP4 המלא אינו נשלח ל-OpenAI. תוכן שאושר מתפרסם אוטומטית; תוכן שסווג כאזהרה או כחסימה אינו מתפרסם. תוכן פרטי, לרבות שיחות אישיות (1:1) ותוכן של הזמנות, תשלומים ועסקאות, אינו נשלח ל-OpenAI במסגרת סינון התוכן הציבורי. חריג: תמלול שיחת קול/וידאו של עסקה עשוי להיבדק בנפרד — לא במסגרת סינון התוכן הציבורי המתואר כאן, אלא במסלול ציות לדיני התחרות — לאיתור סימנים לתיאום פסול בין מתחרים (למשל קביעת מחיר משותפת, חלוקת לקוחות או חרם). הבדיקה אינה חוסמת ואינה משנה את השיחה או את התמלול; בעת התאמה נפתחת רשומת בדיקה פנימית הגלויה למנהלי VendMe בלבד.

5. שיתוף עם ספקי שירות (מעבדי משנה)

אנו משתפים מידע רק כנדרש לתפעול השירות, עם:

6. שמירת מידע ומחיקה

אנו שומרים מידע כל עוד החשבון פעיל וכנדרש חוקית. באפליקציה קיימת אפשרות מחיקת חשבון (הגדרות → מחיקת חשבון), הסוגרת את חשבון ההתחברות לצמיתות ומסירה את פרטי הפרופיל המזהים. רשומות עסקיות (הזמנות, עסקאות חתומות, תשלומים) נשמרות כנדרש בדין, ותוכן שכבר נמסר למשתמשים אחרים (הודעות, מסמכים, תמלולים) עשוי להישאר זמין להם. בנוסף, רשומות המשמשות לאכיפה ולמניעת הונאה אינן נמחקות אוטומטית עם מחיקת החשבון: בקשות אימות עסק והמסמכים המצורפים אליהן, ורשומות סינון ציות פתוחות או מסומנות (רשומות ציות שנסגרו נמחקות אוטומטית לאחר 180 יום). גם רשומת הזמנת ספק שיצרתם נשמרת. רשומות אלה, ארכיון תמלולי השיחות, והסכמי אשראי חתומים והמסמכים שצורפו להם (לרבות צילום תעודת זהות) נשמרים עד 7 שנים ממועד מחיקת החשבון, ולאחר מכן נמחקים. ניתן לבקש את מחיקתם של פריטים אלה בפנייה אלינו, ונשקול כל בקשה בכפוף לחובותינו החוקיות. פרטים מלאים בעמוד מחיקת חשבון. ניתן גם לפנות אלינו ב-office@vendme.net לבקשת גישה, תיקון או מחיקה — נטפל בבקשה תוך 30 יום לכל היותר.

OpenAI מצהירה שנתוני API אינם משמשים לאימון המודלים שלה כברירת מחדל, אלא אם הלקוח בוחר במפורש לשתף אותם. כברירת מחדל, יומני ניטור שימוש לרעה עשויים לכלול תוכן ומטא-נתונים ולהישמר עד 30 יום. השמירה עשויה להיות ארוכה יותר אם הדין מחייב או אם היא נחוצה באופן סביר להגנת שירותי OpenAI או צד שלישי מפגיעה. לקוחות זכאים יכולים, בכפוף לאישור OpenAI, להפעיל Zero Data Retention או Modified Abuse Monitoring כדי להחריג תוכן לקוח מיומנים אלה, בכפוף למגבלות. תמונות וקבצים נסרקים לאיתור חומר פגיעה מינית בילדים (CSAM); אם מסווג חשד כזה, התמונה עשויה להישמר לבדיקה אנושית גם כאשר אחת מבקרות השמירה מופעלת.

בנוסף לאמור לעיל, רישום הביקורת הפנימי של בקשות ליווי נשמר גם הוא לאחר מחיקת החשבון — ראו סעיף 7.

7. ליווי משתמש (הדרכה מרחוק)

כדי לעזור לך בטלפון, איש צוות VendMe יכול לבקש "ליווי": בקשה שמופיעה על המסך שלך עם שמו והסיבה שנרשמה. בלי אישור מפורש שלך לא נפתח דבר. האישור הוא לפעם אחת בלבד — אין אפשרות לאשר מראש או לצמיתות.

מה הצוות רואה בזמן ליווי: שם המסך שאתה נמצא בו (למשל "פרסום מודעה") ורשימת האלמנטים שניתן לסמן באותו מסך. זהו כל המידע שעובר.

מה הצוות לא רואה ולא עושה: אינו רואה את המסך שלך, אינו קורא הודעות, פרטי קשר או מסמכים, אינו רואה טקסט שהקלדת ולא שלחת, ואינו מבצע פעולות בשמך. הסימון מראה לך היכן ללחוץ — הלחיצה נשארת שלך.

בזמן ליווי מוצג במסך שלך פס קבוע שלא ניתן לסגור, ובו כפתור סיום. הליווי נעצר אוטומטית לאחר 15 דקות, וגם כאשר אתה או הצוות מסיימים אותו.

שקיפות: כל בקשת ליווי — כולל בקשה שסירבת לה — מתועדת, ומוצגת לך במסך "מי ליווה אותי במערכת" (הגדרות) יחד עם מה שסומן לך בפועל; המסך מציג את 50 הבקשות האחרונות. ליווי אינו יכול להתקיים בלי שהוא מתועד.

שמירה ומחיקה: רשומות הליווי המוצגות לך נמחקות יחד עם מחיקת החשבון. במקביל נשמר רישום ביקורת פנימי של כל בקשת ליווי — ובו מזהה החשבון שאליו הופנתה הבקשה והסיבה שאיש הצוות רשם — והוא אינו נמחק עם מחיקת החשבון ואין לו מועד מחיקה קבוע.

8. אבטחה

המידע מוגן בהצפנה בתעבורה ובאמצעי בקרת גישה (RLS) בבסיס הנתונים; מדיה של שיחות צ׳אט ומסמכי הסכמי אשראי וביטחונות שמורים באחסון מוגבל-גישה. שימו לב כי מדיה של מודעות, מוצרים וגלריית פרופיל נגישה בכתובות ציבוריות (סעיף 3). אף שיטת העברה או אחסון אינה מאובטחת ב-100%.

9. ילדים

השירות מיועד לעסקים ולמשתמשים מעל גיל 18. איננו אוספים ביודעין מידע מקטינים.

10. שינויים

נעדכן מדיניות זו מעת לעת; מועד העדכון האחרון מופיע למעלה.

11. יצירת קשר

VENDME LTD · office@vendme.net · https://www.vendme.net


Privacy Policy — VendMe

Last updated: 2026-09-16

1. Who we are

VendMe ("we", "the app") is a B2B wholesale marketplace connecting suppliers, distributors, and retailers in the fresh-produce sector. Operated by VENDME LTD, Israel. Contact: office@vendme.net.

2. Information we collect

Temporary content ("stories") and views of it: an image or video you post as a story is stored by us in private storage and displayed for 24 hours. We also record who viewed each story and when — the record is surfaced to the story's author as a view count, and is retained by us after the content disappears from display.

3. What other users can see

4. How we use information

To provide and operate the service (account, feed, catalog, deals, chat, calls, notifications); to secure the platform and prevent fraud; to support users; and to improve the product. We do not sell personal information and we do not track users across other apps or websites for advertising.

Competition-law compliance screening. In addition to the pre-publication screening described below, text in group conversations and the community forum is reviewed automatically and periodically by an AI model operated by Anthropic, which reads a limited window of the conversation — the new messages and a few preceding messages for context — even when no listed expression matched. The text is sent without names, user ids, or a conversation id, and each speaker is represented only by a letter alongside their role. While you type in a group, forum, or comment box, your draft may be sent for the same check to show a warning before it is sent; the draft is not stored, creates no record, and does not block sending. In this Anthropic path, private 1:1 chats and deal chats are not scanned, and neither are voice messages, images, or video. Only when a match is found is an excerpt of up to 500 characters retained, together with the user id and matched expressions, in an internal record visible only to VendMe administrators. The check may lead to enforcement action.

OpenAI pre-publication screening. Every supported item of public content that you ask to publish is checked automatically before publication. The screening applies to the general chat, public groups and discussions, Stories, posts and comments, products and volume deals, business listings and business ads, public profiles and galleries, ratings, and distributor products. Depending on the surface, text, images, video, and audio are checked. In public chats, the message text, attached media, and a limited window of preceding messages may be sent for context. For video, VendMe/Supabase infrastructure produces a WAV audio file, a poster image, and frames sampled across the video: the audio file is sent to OpenAI for transcription, and the transcript, sampled frames, poster image, and limited technical information, such as video duration and frame timestamps, are then sent for classification. For a voice message, the audio file is sent for transcription and the transcript for classification. A hashed account safety identifier is also attached to each classification request. The full MP4 file is not sent to OpenAI. Content classified as allowed is published automatically; content classified as a warning or block is not published. Private content, including private 1:1 chats and order, payment, and transaction content, is not sent to OpenAI under public-content screening. Exception: a deal voice/video call transcript may be screened separately — not under the public-content screening described here, but under the competition-law compliance screen — for signs of unlawful coordination between competitors (for example, joint pricing, customer allocation, or a boycott). This check never blocks or changes the call or its transcript; on a match it opens an internal review record visible only to VendMe administrators.

5. Sharing with service providers (sub-processors)

We share information only as needed to operate the service, with: Supabase (data storage, auth, backend); Google / Apple (sign-in; push delivery via FCM/APNs; and the operating system's geocoding services, which process coordinates or city names for address autofill and maps); Twilio (SMS verification codes); LiveKit (voice/video call infrastructure, including call audio recording); Cloudflare R2 (call-recording storage); Expo (push notification service and app updates — notification title and body pass through Expo, Google FCM, and Apple APNs infrastructure: for chat this is the sender's name and a short excerpt of the message; for an internal business-verification review alert it includes the applicant's business name and business/tax registration number); Resend (transactional auth emails); OpenAI (transcription of voice messages, voice input, and call recordings; and, for the public-content pre-publication screening described above, text and images and, depending on the surface, voice messages and video. For video, a WAV audio file is sent to OpenAI for transcription, and the transcript, poster image, sampled frames, and limited technical information are sent for classification; for a voice message, the audio file and transcript are sent. A hashed account safety identifier is attached to every classification request. The full MP4 is not sent to OpenAI); Anthropic (Claude) (AI-assistant answers — your questions plus relevant account data such as your deals, orders including amounts, and conversation previews — deal-summary extraction, which sends the business conversation's messages including the other party's messages, also when it is the counterparty who triggers the feature; and competition-compliance classification, which sends a window of a group, forum or general-chat conversation (the new messages plus a little context), a draft typed there but not yet sent, or a flagged excerpt — in every case without any name, user id or conversation id, with each speaker represented only by a letter — see section 4); Sentry (crash reporting, if enabled); data.gov.il (address autocomplete — search text only; and validation of a company/association registration number against the public registries — only the number is sent, never your name, phone or documents, and sole-proprietor numbers are not sent at all; the registry's answer is stored on your profile as a point-in-time record); OpenStreetMap and public CDNs (map tiles on the delivery-route screen); Tranzila (payment processing, if and when in-app payments are enabled — card details are entered directly with the processor and never stored by us).

6. Data retention & deletion

We retain data while the account is active and as legally required. The app provides account deletion (Settings → Delete account), which permanently closes the login and removes the profile's identifying details. Business records (orders, signed deals, payments) are retained as required by law, and content already delivered to other users (messages, documents, transcripts) may remain available to them. In addition, records used for enforcement and fraud prevention are not automatically removed when an account is deleted: business-verification requests and their attached documents, and open or flagged compliance-screening records (closed compliance records are deleted automatically after 180 days). A supplier-invite record you created is also retained. You may request deletion of these items by contacting us, and we will consider each request subject to our legal obligations. See the account deletion page for details. You may also contact office@vendme.net to request access, correction, or deletion — we will handle requests within 30 days at most.

OpenAI states that API data is not used to train or improve its models by default, unless the customer explicitly opts in to share it. By default, abuse-monitoring logs may include content and metadata and are retained for up to 30 days. Retention may be longer if required by law or reasonably necessary to protect OpenAI’s services or any third party from harm. Eligible customers may, subject to OpenAI approval, enable Zero Data Retention or Modified Abuse Monitoring to exclude customer content from those logs, subject to limitations. Images and files are scanned for child sexual abuse material (CSAM); if potential CSAM is detected, the image may be retained for manual review even when one of those retention controls is enabled.

In addition to the above, the internal audit record of guidance requests is also retained after the account is deleted — see section 7.

7. User guidance (remote guided support)

To help you over the phone, a VendMe team member can request "guidance": a request that appears on your screen with their name and the reason they recorded. Nothing opens without your explicit approval. The approval is for a single session only — there is no way to approve in advance or permanently.

What the team sees during guidance: the name of the screen you are on (for example "posting a listing") and the list of elements that can be highlighted on that screen. That is all the information that passes.

What the team does not see and does not do: it does not see your screen, does not read messages, contact details or documents, does not see text you typed but did not send, and does not perform actions on your behalf. The highlight shows you where to tap — the tap stays yours.

During guidance a fixed bar that cannot be closed is shown on your screen, with an end button. Guidance stops automatically after 15 minutes, and also when you or the team end it.

Transparency: every guidance request — including one you refused — is recorded, and is shown to you in the "Who guided me in the system" screen (Settings) together with what was actually highlighted for you; that screen lists the 50 most recent requests. Guidance cannot take place without being recorded.

Retention and deletion: the guidance records shown to you are deleted together with your account. In parallel we keep an internal audit record of every guidance request — carrying the identifier of the account the request was directed at and the reason the team member recorded — and it is not deleted with the account and has no fixed deletion date.

8. Security

Data is protected with encryption in transit and database access controls (RLS); chat media and credit/collateral-agreement documents are kept in access-restricted storage. Note that media attached to posts, listings, and profile galleries is reachable at public URLs (section 3). No method of transmission or storage is 100% secure.

9. Children

The service is intended for businesses and users aged 18+. We do not knowingly collect information from minors.

10. Changes

We may update this policy from time to time; the last-updated date appears above.

11. Contact

VENDME LTD · office@vendme.net · https://www.vendme.net