מדיניות פרטיות — VendMe
עודכן לאחרונה: 2026-07-31
1. מי אנחנו
VendMe ("אנחנו", "האפליקציה") היא פלטפורמת מסחר סיטונאי (B2B) המחברת בין ספקים, מפיצים וקמעונאים בענף התוצרת הטרייה. המפעילה: VENDME LTD, ישראל. יצירת קשר: office@vendme.net.
2. איזה מידע אנחנו אוספים
- פרטי חשבון וזיהוי: שם, כתובת מייל מאומתת, מספר טלפון מאומת, סוג משתמש/תפקיד, מזהה משתמש. בעת התחברות עם Google/Apple — המזהה והמייל שהם מספקים.
- פרטי עסק: שם עסק, מספר עוסק/ח.פ, כתובת העסק וסניפים, שעות פתיחה, תחומי עיסוק, פרטי לוגיסטיקה (סוג רכב, ימי חלוקה, אזורי כיסוי). חלק מפרטים אלה מוצגים למשתמשים אחרים בפלטפורמה כחלק מהפעילות המסחרית (ראו סעיף 3).
- פרופיל ותוכן עסקי: קטלוג מוצרים, מודעות, עסקאות והזמנות.
- תוכן שהמשתמש יוצר: הודעות צ׳אט, תמונות ווידאו, הודעות קוליות, מודעות ותגובות, דירוגים וחתימות דיגיטליות על הסכמים.
- שיחות קול/וידאו — הקלטה ותמלול: שיחות קול ווידאו בתוך האפליקציה מוקלטות אוטומטית (שמע בלבד) ומתומללות לצורך תיעוד העסקה והצגת תמלול למשתתפי השיחה. וידאו אינו מוקלט. ההקלטה משמשת להפקת התמלול בלבד ונמחקת עם השלמתו; התמלולים נשמרים כחלק מרשומת השיחה וזמינים לשני הצדדים. גם הודעות קוליות בצ׳אט מתומללות והתמלול נשמר עם ההודעה.
- ראיות חתימה: בעת חתימה על הסכם דיגיטלי נאספים כתובת ה-IP שלך, מזהה מכשיר/דפדפן (user agent), חותמות זמן ויומן פעולות, והם מוטמעים במסמך החתום, שהצד שכנגד יכול להוריד ולשתף. המסמך אינו כולל את מספר הטלפון או את כתובת העסק שלך. יומני שרת ודיווחי שגיאות עשויים לכלול כתובת IP.
- מסמכי זיהוי (בחתימה על הסכמי אשראי/בטחונות בלבד): צילום תעודה מזהה, חותמת עסק ותעודת התאגדות — נאספים רק אם בחרת לחתום על הסכם כזה, נשמרים באחסון מוגן (ללא גישה ציבורית) וזמינים לצדדים להסכם בלבד.
- אימות עסק ("עסק מאומת"): כדי לפרסם מודעות, עודפים או קטלוג בפלטפורמה נדרש אימות עסק — זהו תנאי לפרסום ולא שלב אופציונלי. בבקשת האימות תמסרו את שם העסק, מספר עוסק/ח.פ, הערה חופשית (רשות) ובין תמונה אחת לשש: תעודת עוסק מורשה או תמצית רישום מרשם החברות, ו/או תמונות של העסק (חנות, דוכן, רכב עבודה או סחורה). איננו מבקשים צילום תעודת זהות; שימו לב כי אצל עוסק מורשה/פטור מספר העסק הוא מספר תעודת הזהות של הבעלים, והוא מופיע בדרך כלל גם על תעודת העוסק. התמונות נשמרות באחסון מוגבל-גישה ללא גישה ציבורית, וגלויות לכם ולמנהלי VendMe הבודקים את הבקשה בלבד. מסמכי האימות אינם נשלחים לשום צד שלישי — אין OCR, אין בינה מלאכותית ואין ספק אימות חיצוני. בקשות האימות והמסמכים המצורפים אליהן נשמרים כרשומת ביקורת למניעת הונאה, לרבות לאחר מחיקת החשבון.
- הזמנת ספק שאינו משתמש: אם תזמינו ספק להצטרף, תתבקשו להזין את מספר הטלפון שלו ואת שמו (רשות). את מספר הטלפון עצמו איננו שומרים — נשמר רק סימן חד-כיווני (HMAC) שלו, ארבע הספרות האחרונות, והשם שהזנתם. השימוש היחיד הוא למנוע הזמנה כפולה של אותו ספק ולזקוף את ההצטרפות למזמין. ההזמנה נשלחת מהמכשיר שלכם דרך אפליקציית השיתוף שתבחרו — VendMe אינה שולחת הודעה למוזמן. לאחר 90 יום ההזמנה מפסיקה לחסום את המספר, אך הרשומה נשמרת אצלנו; ניתן לבקש את מחיקתה בפנייה ל-office@vendme.net.
- מיקום: מיקום מקורב/מדויק (בהרשאה, בזמן שימוש בלבד) — למילוי כתובת אוטומטי, להצגת ספקים ומפיצים באזורך, ולסימון נקודות איסוף/מסירה בהובלות. אם השתמשת ב"המיקום שלי" בהרשמה, הקואורדינטות נשמרות בפרופיל שלך ומוצגות למשתמשים אחרים בקירוב של כ-1 ק"מ בלבד; נקודת איסוף/מסירה מדויקת שתגדיר בבקשת הובלה נשמרת בבקשה ותוצג למוביל ולצדדים המעורבים.
- מדיה והרשאות מכשיר: גישה למצלמה ולספריית התמונות (להעלאת תמונות ולשיחות וידאו) ולמיקרופון (הודעות קוליות ושיחות).
- נתוני מכשיר והתראות: אסימוני התראות (push tokens) וסוג מערכת ההפעלה (Android/iOS) לצורך שליחת התראות. איננו אוספים מזהי פרסום ואיננו מבצעים טביעת אצבע של המכשיר.
- פרטי צד שלישי: אם ציינת משווק/גורם קשור (למשל מספר הטלפון של המשווק שלך), פרט זה ישמש ליצירת קישור או הזמנה בין החשבונות.
- שימוש ואבחון: אירועי שימוש באפליקציה (צפיות במסכים ופעולות עיקריות), דיווחי קריסות/שגיאות, וקוד הפניה (referral) אם הצטרפת דרך קישור הזמנה.
3. מה משתמשים אחרים רואים
- פרופיל עסקי: כל משתמש מחובר במגזר שלך רואה את שמך, שם העסק, עיר/אזור, אודות, גלריה, קטלוג, דירוגים וביקורות (כולל שם הכותב), נתוני פעילות (עסקאות שהושלמו, ביטולים), ותק, זמינות ומיקום מקורב (כ-1 ק"מ).
- פרטי קשר: מספר הטלפון וקישור הוואטסאפ שלך אינם נחשפים לאף משתמש אחר — גם לא לצד שכנגד בעסקה, בהזמנה או בהובלה. הקשר נשאר בתוך האפליקציה (צ׳אט ושיחות), והגישה אליהם קיימת לך ולמנהלי VendMe בלבד. כתובת העסק והאתר נחשפים לצד שכנגד בעסקה, בהזמנה או בהובלה משותפת לצורך ביצועה, וכן לכל משתמש מחובר — אך ורק אם הפעלת בעצמך את המתג המתאים לאותו שדה בעורך הפרופיל. שני המתגים כבויים כברירת מחדל.
- חברים חדשים: עם השלמת ההרשמה, כרטיס "ברוך הבא" עם פרטי הפרופיל מוצג בפיד המגזר למשך כ-30 יום.
- שיתוף על ידי אחרים: כרטיס ביקור שמשותף בשיחה כולל שם, תפקיד ואזור בלבד — ללא מספר טלפון. משתמשים יכולים לשתף מסמכים חתומים גם מחוץ לאפליקציה.
- מדיה בכתובות ציבוריות: תמונות ווידאו של מודעות, מוצרים וגלריית פרופיל נשמרים בכתובות ציבוריות — מי שמחזיק בקישור יכול לצפות בהם גם ללא התחברות.
4. כיצד אנו משתמשים במידע
לספק ולתפעל את השירות (חשבון, פיד, קטלוג, עסקאות, צ׳אט, שיחות והתראות); לאבטח את הפלטפורמה ולמנוע הונאה; לתמוך במשתמשים; ולשפר את המוצר. איננו מוכרים מידע אישי ואיננו עוקבים אחר משתמשים בין אפליקציות/אתרים לצורכי פרסום.
סינון ציות לדיני התחרות. תוכן טקסט שאתם מפרסמים בקבוצות, בפורום הקהילתי ובפיד נסרק אוטומטית במסד הנתונים שלנו מול רשימת ביטויים המעידים על חשד לתיאום אסור בין מתחרים. שיחות אישיות (1:1) ושיחות מתווכות אינן נסרקות כלל, וכך גם הודעות קוליות, תמונות ווידאו. רק כאשר מזוהה התאמה נשמר קטע של עד 500 תווים מהטקסט, יחד עם מזהה המשתמש, הביטויים שזוהו ומספר המשתתפים באותו צד — ברשומה פנימית הנגישה למנהלי VendMe בלבד. מנהל VendMe יכול להפעיל בדיקה ידנית שבה נשלח ל-Anthropic קטע הטקסט שסומן בלבד, ללא שמכם, ללא מזהה המשתמש וללא מזהה השיחה. הבדיקה עשויה להוביל לפעולת אכיפה. הקטע נשמר מילה במילה, ולכן עשוי לכלול אגב כך גם פרטים של לקוח, ספק או מתחרה שהוזכרו בהודעה.
5. שיתוף עם ספקי שירות (מעבדי משנה)
אנו משתפים מידע רק כנדרש לתפעול השירות, עם:
- Supabase — אחסון נתונים, אימות ו-backend.
- Google / Apple — התחברות (Sign in with Google / Apple), משלוח התראות (Firebase Cloud Messaging / APNs) ושירותי הכתובות (geocoding) של מערכת ההפעלה, המעבדים קואורדינטות או שמות יישובים לצורך השלמת כתובות ומפות.
- Twilio — שליחת קודי אימות ב-SMS.
- LiveKit — תשתית שיחות קול/וידאו, כולל הקלטת שמע השיחה.
- Cloudflare (R2) — אחסון הקלטות שיחות.
- Expo — שירות התראות ועדכוני אפליקציה. כותרת ההתראה וגוף ההודעה עוברים דרך שרתי Expo ומשם דרך Google (FCM) ו-Apple (APNs): בצ׳אט מדובר בשם השולח ובקטע קצר מההודעה; בהתראה פנימית על בקשת אימות עסק נכללים שם העסק ומספר העוסק/ח.פ של מגיש הבקשה.
- Resend — משלוח מיילים תפעוליים (אימות מייל, איפוס סיסמה).
- OpenAI (Whisper) — תמלול הודעות קוליות, קלט קולי והקלטות שיחות.
- Anthropic (Claude) — עוזר ה-AI, חילוץ סיכומי עסקה וסיווג ציות לדיני התחרות. בעת שימוש בעוזר מועברות שאלותיך יחד עם נתוני חשבון רלוונטיים (עסקאות, הזמנות וסכומים, תצוגות שיחות); בעת הפקת סיכום עסקה מועברות הודעות השיחה העסקית — כולל הודעות הצד השני — גם כאשר הצד שכנגד הוא שמפעיל את הפיצ׳ר; בבדיקת ציות מועבר קטע הטקסט שסומן בלבד (עד 500 תווים) בליווי הדפוסים שנתפסו, ללא שם או מזהה של הכותב (ראו סעיף 4).
- Sentry — דיווחי קריסות ואבחון (אם מופעל).
- data.gov.il — השלמת כתובות (טקסט החיפוש בלבד), ואימות מספר חברה/עמותה מול מרשמי החברות והעמותות הציבוריים. נשלח המספר בלבד — לעולם לא שמכם, הטלפון או המסמכים; מספרים של עוסק מורשה/פטור אינם נשלחים כלל. תשובת המרשם (שם רשום, סטטוס וסימון פיקוח אם קיים) נשמרת בפרופיל כרשומה נכון למועד הבדיקה.
- OpenStreetMap ו-CDN ציבוריים — טעינת מפות במסך מסלולי חלוקה.
- ספק סליקה (Tranzila) — אם וכאשר יופעלו תשלומים בתוך האפליקציה; פרטי הכרטיס מוזנים ישירות אצל ספק הסליקה ואינם נשמרים אצלנו.
6. שמירת מידע ומחיקה
אנו שומרים מידע כל עוד החשבון פעיל וכנדרש חוקית. באפליקציה קיימת אפשרות מחיקת חשבון (הגדרות → מחיקת חשבון), הסוגרת את חשבון ההתחברות לצמיתות ומסירה את פרטי הפרופיל המזהים. רשומות עסקיות (הזמנות, עסקאות חתומות, תשלומים) נשמרות כנדרש בדין, ותוכן שכבר נמסר למשתמשים אחרים (הודעות, מסמכים, תמלולים) עשוי להישאר זמין להם. בנוסף, רשומות המשמשות לאכיפה ולמניעת הונאה אינן נמחקות אוטומטית עם מחיקת החשבון: בקשות אימות עסק והמסמכים המצורפים אליהן, ורשומות סינון ציות פתוחות או מסומנות (רשומות ציות שנסגרו נמחקות אוטומטית לאחר 180 יום). גם רשומת הזמנת ספק שיצרתם נשמרת. ניתן לבקש את מחיקתם של פריטים אלה בפנייה אלינו, ונשקול כל בקשה בכפוף לחובותינו החוקיות. פרטים מלאים בעמוד מחיקת חשבון. ניתן גם לפנות אלינו ב-office@vendme.net לבקשת גישה, תיקון או מחיקה — נטפל בבקשה תוך 30 יום לכל היותר.
7. אבטחה
המידע מוגן בהצפנה בתעבורה ובאמצעי בקרת גישה (RLS) בבסיס הנתונים; מדיה של שיחות צ׳אט ומסמכי הסכמי אשראי וביטחונות שמורים באחסון מוגבל-גישה. שימו לב כי מדיה של מודעות, מוצרים וגלריית פרופיל נגישה בכתובות ציבוריות (סעיף 3). אף שיטת העברה או אחסון אינה מאובטחת ב-100%.
8. ילדים
השירות מיועד לעסקים ולמשתמשים מעל גיל 18. איננו אוספים ביודעין מידע מקטינים.
9. שינויים
נעדכן מדיניות זו מעת לעת; מועד העדכון האחרון מופיע למעלה.
10. יצירת קשר
VENDME LTD · office@vendme.net · https://www.vendme.net
Privacy Policy — VendMe
Last updated: 2026-07-13
1. Who we are
VendMe ("we", "the app") is a B2B wholesale marketplace connecting suppliers, distributors, and retailers in the fresh-produce sector. Operated by VENDME LTD, Israel. Contact: office@vendme.net.
2. Information we collect
- Account & identifiers: name, verified email, verified phone number, user role/type, user ID. When you sign in with Google/Apple, the identifier and email they provide.
- Business details: business name, business/tax registration number, business address and branches, opening hours, specializations, logistics details (vehicle type, delivery days, coverage areas). Some of these are visible to other users as part of marketplace activity (see section 3).
- Profile & business content: product catalog, listings, deals, and orders.
- User-generated content: chat messages, photos and videos, voice messages, posts, comments, ratings, and digital signatures on agreements.
- Calls — recording & transcription: in-app voice and video calls are automatically recorded (audio only) and transcribed to document the deal and show a transcript to call participants. Video is not recorded. The recording is used solely to produce the transcript and is deleted once transcription completes; transcripts are kept as part of the conversation record, available to both parties. Chat voice messages are likewise transcribed and the transcript is stored with the message.
- Signature evidence: when you sign a digital agreement we record your IP address, device/browser identifier (user agent), timestamps, and an action log, and embed these in the signed document, which the counterparty can download and share. The document does not include your phone number or business address. Server logs and error reports may include IP addresses.
- Identity documents (collateral/credit agreement signing only): a photo of an ID document, business stamp, and company registration deed — collected only if you choose to sign such an agreement, stored in access-restricted storage (no public access) and available only to the agreement's parties.
- Business verification ("verified business"): a verified-business badge is required in order to publish offers, surplus listings or your catalog — it is not an optional step. A verification request includes your business name, business/tax registration number, an optional free-text note, and 1–6 images: a dealer certificate (תעודת עוסק מורשה) or a companies-registry extract, and/or photos of your business (store, stall, work vehicle or goods). We do not ask you to upload a national ID card; note that for a sole proprietor the business registration number is the owner's national ID number, and a dealer certificate typically prints it. Images are held in access-restricted storage with no public access, visible only to you and to VendMe administrators reviewing the request. Verification documents are never sent to any third party — no OCR, AI, or external verification vendor is involved. Requests and their attached documents are kept as an anti-fraud audit record, including after account deletion.
- Inviting a supplier who is not yet a user: if you invite a supplier, you enter their phone number and optionally their name. We do not store the phone number itself — only a one-way keyed hash (HMAC) of it, its last four digits, and the name you entered. It is used solely to prevent the same supplier being invited twice and to credit the join to the inviter. The invitation is sent from your own device through whichever sharing app you choose — VendMe does not message the invitee. After 90 days the invite stops blocking that number, but the record is retained; you may request its deletion at office@vendme.net.
- Location: coarse/precise location (with permission, while-in-use only) for address autofill, showing suppliers and distributors near you, and marking pickup/dropoff points for transports. If you use "my location" during onboarding, your coordinates are saved to your profile and shown to other users only in approximate (~1 km) form; a precise pickup/dropoff point you set on a transport request is stored on the request and shown to the carrier and involved parties.
- Media & device permissions: camera and photo library (to upload images and for video calls) and microphone (voice messages and calls).
- Device & notifications: push notification tokens and the device platform (Android/iOS) to deliver notifications. We do not collect advertising identifiers and do not fingerprint devices.
- Third-party contact details: if you name a related party (e.g. your marketer's phone number), it is used to link or invite that account.
- Usage & diagnostics: in-app usage events (screen views and key actions), crash/error reports, and a referral code if you joined via an invite link.
3. What other users can see
- Business profile: every signed-in user in your sector sees your name, business name, city/region, bio, gallery, catalog, ratings and reviews (including reviewer names), activity statistics (completed orders, cancellations), join date, availability, and approximate (~1 km) location.
- Contact details: your phone number and WhatsApp link are not exposed to any other user — not even to a counterparty in a deal, order, or transport. Contact stays inside the app (chat and calls), and only you and VendMe administrators can access them. Your business address and website are shared with a counterparty in a shared deal, order, or transport for the purpose of performing it, and with any signed-in user only if you yourself enable that field's toggle in the profile editor; both toggles are off by default.
- New members: upon completing onboarding, a "welcome" card with your profile details appears in the sector feed for about 30 days.
- Sharing by others: a contact card shared in a chat carries name, role, and region only — no phone number. Users can also share signed documents outside the app.
- Media at public URLs: photos and videos attached to posts, listings, and profile galleries are stored at publicly reachable URLs — anyone with the link can view them without logging in.
4. How we use information
To provide and operate the service (account, feed, catalog, deals, chat, calls, notifications); to secure the platform and prevent fraud; to support users; and to improve the product. We do not sell personal information and we do not track users across other apps or websites for advertising.
Competition-law compliance screening. Text you post in groups, in the community forum, and in the feed is automatically scanned in our database against a list of expressions indicating suspected unlawful coordination between competitors. Private 1:1 chats and brokered conversations are not scanned at all, and neither are voice messages, images or video. Only when a match is found do we store an excerpt of up to 500 characters together with the user id, the matched expressions, and the number of participants on that side — in an internal record accessible to VendMe administrators only. A VendMe administrator may run a manual review in which only the flagged text excerpt is sent to Anthropic, without your name, user id, or conversation id. A review may lead to enforcement action. The excerpt is stored verbatim and may therefore incidentally include details of a customer, supplier or competitor mentioned in the message.
5. Sharing with service providers (sub-processors)
We share information only as needed to operate the service, with: Supabase (data storage, auth, backend); Google / Apple (sign-in; push delivery via FCM/APNs; and the operating system's geocoding services, which process coordinates or city names for address autofill and maps); Twilio (SMS verification codes); LiveKit (voice/video call infrastructure, including call audio recording); Cloudflare R2 (call-recording storage); Expo (push notification service and app updates — notification title and body pass through Expo, Google FCM, and Apple APNs infrastructure: for chat this is the sender's name and a short excerpt of the message; for an internal business-verification review alert it includes the applicant's business name and business/tax registration number); Resend (transactional auth emails); OpenAI (Whisper) (transcription of voice messages, voice input, and call recordings); Anthropic (Claude) (AI-assistant answers — your questions plus relevant account data such as your deals, orders including amounts, and conversation previews — deal-summary extraction, which sends the business conversation's messages including the other party's messages, also when it is the counterparty who triggers the feature; and competition-compliance classification, which sends only the flagged text excerpt of up to 500 characters plus the matched patterns, without the author's name or id — see section 4); Sentry (crash reporting, if enabled); data.gov.il (address autocomplete — search text only; and validation of a company/association registration number against the public registries — only the number is sent, never your name, phone or documents, and sole-proprietor numbers are not sent at all; the registry's answer is stored on your profile as a point-in-time record); OpenStreetMap and public CDNs (map tiles on the delivery-route screen); Tranzila (payment processing, if and when in-app payments are enabled — card details are entered directly with the processor and never stored by us).
6. Data retention & deletion
We retain data while the account is active and as legally required. The app provides account deletion (Settings → Delete account), which permanently closes the login and removes the profile's identifying details. Business records (orders, signed deals, payments) are retained as required by law, and content already delivered to other users (messages, documents, transcripts) may remain available to them. In addition, records used for enforcement and fraud prevention are not automatically removed when an account is deleted: business-verification requests and their attached documents, and open or flagged compliance-screening records (closed compliance records are deleted automatically after 180 days). A supplier-invite record you created is also retained. You may request deletion of these items by contacting us, and we will consider each request subject to our legal obligations. See the account deletion page for details. You may also contact office@vendme.net to request access, correction, or deletion — we will handle requests within 30 days at most.
7. Security
Data is protected with encryption in transit and database access controls (RLS); chat media and credit/collateral-agreement documents are kept in access-restricted storage. Note that media attached to posts, listings, and profile galleries is reachable at public URLs (section 3). No method of transmission or storage is 100% secure.
8. Children
The service is intended for businesses and users aged 18+. We do not knowingly collect information from minors.
9. Changes
We may update this policy from time to time; the last-updated date appears above.
10. Contact
VENDME LTD · office@vendme.net · https://www.vendme.net