01. מי אנחנו Who we are
בעלת מאגר המידע ("המפעילה" / "אנחנו") הינה SAN MAI-GYOZA BAR, מספר עוסק מורשה (ע.מ) 345590996, כתובת: יום טוב 17, תל אביב-יפו. אנו מפעילים את בר הגיוזה San Mai ואת מערכת ההזמנות באתר ובמסכי הסניף.
האחראי על הגנת הפרטיות ומאגר המידע מטעם העסק הוא בעל העסק (עוסק מורשה 345590996). לכל פנייה בנושא פרטיות ניתן לכתוב אלינו לכתובת: [email protected].
The data controller ("we") is SAN MAI-GYOZA BAR, Israeli business ID (osek murshe) 345590996, address: 17 Yom Tov St, Tel Aviv-Yafo. We operate the San Mai gyoza bar and its in-store and online ordering systems.
The person responsible for privacy and the database on behalf of the business is the business owner (osek murshe 345590996). For any privacy enquiry, write to [email protected].
02. איזה מידע אנו אוספים What we collect
בעת ביצוע הזמנה או הצטרפות למועדון אוהבי הגיוזה, אנו עשויים לאסוף את הקטגוריות הבאות של מידע אישי:
- פרטי זיהוי — שם מלא ומספר טלפון נייד (פורמט E.164).
- אימייל — אופציונלי, רק אם בחרת להצטרף למועדון.
- היסטוריית הזמנות — פריטים שהוזמנו, מחירים, מועדים, סוג הזמנה (במקום / לקחת) ומספר שולחן.
- מצב הסכמה לשיווק — האם סימנת קבלת דיוור, מועד ההסכמה ומועד ביטולה.
- תיעוד הסכמה — כתובת IP, מזהה דפדפן (User-Agent) ונוסח הטקסט שאישרת — כראייה למתן הסכמה מדעת.
- מידע סליקה — פרטי כרטיס האשראי נמסרים ישירות לחברת הסליקה Tranzila ואינם נשמרים אצלנו. אנו שומרים רק מטא-נתונים: 4 ספרות אחרונות, סוג כרטיס, מספר אישור, סכום ומועד.
When you place an order or join the Gyoza Lovers Club, we may collect the following categories of personal data:
- Identification details — full name and mobile phone number (E.164 format).
- Email — optional, only if you choose to join the club.
- Order history — items ordered, prices, timestamps, order type (dine-in / takeaway) and table number.
- Marketing consent status — whether you opted in to marketing, when, and when you opted out.
- Consent evidence — IP address, browser identifier (User-Agent) and the exact text version you accepted — as proof of informed consent.
- Payment metadata — card details are submitted directly to our PCI-DSS-compliant payment processor Tranzila and are not stored on our servers. We only retain metadata: last 4 digits, card scheme, authorisation code, amount and timestamp.
03. מטרות העיבוד Purposes of processing
אנו משתמשים במידע אך ורק למטרות הבאות, בהתאם לעקרון תכלית-מוגבלת:
- תפעולי / חוזי — קבלת הזמנה והכנתה, שליחת אישור הזמנה ב-SMS, הנפקת חשבונית מס, מתן שירות לקוחות ובירור פניות.
- ניתוח אגרגטיבי — סטטיסטיקות מצרפיות אנונימיות (פריטים פופולריים, שעות עומס) — ללא זיהוי לקוח אישי.
- שיווק ישיר — שליחת מבצעים, קופונים ועדכוני תפריט ב-SMS ובאימייל — אך ורק אם סימנת במפורש הסכמה נפרדת, בהתאם לסעיף 30א לחוק התקשורת (תיקון 40).
לא נשתמש במידע למטרות שלא צוינו לעיל ללא הסכמה נוספת.
We use your data strictly for the following purposes, under the principle of purpose limitation:
- Transactional / contractual — receiving and fulfilling your order, sending an SMS order confirmation, issuing a tax invoice, providing customer support.
- Aggregate analytics — anonymous aggregated statistics (popular items, peak hours) — with no individual identification.
- Direct marketing — sending offers, coupons and menu updates by SMS and email — only if you have separately and explicitly opted in, per Communications Law §30A (Amendment 40).
We will not use your data for purposes other than those listed above without additional consent.
04. הבסיס החוקי Legal basis
עיבוד המידע נשען על הבסיסים החוקיים הבאים:
- חוק הגנת הפרטיות, התשמ"א-1981, כולל תיקון 13 (2024) — סעיף 1 (הסכמה מדעת ומפורשת), סעיף 11 (חובת יידוע), סעיפים 13 ו-14 (זכות עיון ותיקון).
- אינטרס לגיטימי + צורך חוזי — לעיבוד תפעולי (קבלת ההזמנה, הכנתה, אספקתה). ללא עיבוד זה לא נוכל להעניק את השירות שביקשת.
- הסכמה מפורשת ונפרדת — לשיווק ישיר בלבד, לפי סעיף 30א לחוק התקשורת (תיקון 40). הסכמה זו ניתנת לביטול בכל עת, בחינם, באותה קלות בה ניתנה.
- חובה חוקית — להנפקת חשבונית ושמירת מסמכי הנהלת חשבונות, לפי פקודת מס הכנסה (סעיף 25) וחוק מע"מ.
Our processing relies on the following legal bases:
- Protection of Privacy Law, 5741-1981, including Amendment 13 (2024) — §1 (meaningful, explicit consent), §11 (notification duty), §13 and §14 (rights of access and correction).
- Legitimate interest + contractual necessity — for transactional processing (taking, preparing and delivering your order). Without this processing, we cannot provide the service you requested.
- Separate, explicit consent — for direct marketing only, per Communications Law §30A (Amendment 40). This consent may be withdrawn at any time, free of charge, as easily as it was given.
- Statutory obligation — for issuing tax invoices and preserving accounting records, per Income Tax Ordinance §25 and the VAT Law.
05. תקופת שמירה Retention period
רשומת לקוח (שם, טלפון, אימייל, היסטוריית הזמנות) נשמרת למשך 7 שנים מההזמנה האחרונה, לצורך עמידה בחובות חשבונאות, מס וביקורת (פקודת מס הכנסה סעיף 25, חוק מע"מ).
הסכמה לדיוור מבוטלת באופן מיידי עם קבלת בקשת ההסרה — משלוח דיוור נוסף יחדל בתוך 3 ימי עסקים (בפועל מיידית במערכת). הרשומה עצמה תישמר לתקופת השמירה החוקית גם לאחר ביטול ההסכמה, אך לא תשמש לשיווק.
יומן הסכמות (תיעוד מועד, IP ונוסח הטקסט) נשמר לכל אורך ההסכמה ועוד 5 שנים לאחר ביטולה — כראייה במקרה של פנייה רגולטורית.
Customer records (name, phone, email, order history) are retained for 7 years from your most recent order, in order to comply with accounting, tax and audit obligations (Income Tax Ordinance §25, VAT Law).
Marketing consent is revoked immediately on receipt of your opt-out request — further marketing dispatch ceases within 3 business days (in practice, instantly in our system). The record itself is retained for the statutory period even after consent is withdrawn, but will not be used for marketing.
The consent log (timestamp, IP and exact text version) is kept for the duration of consent plus 5 years after revocation — as evidence in case of a regulatory enquiry.
06. צדדים שלישיים Third-party sub-processors
אנו עובדים עם מספר ספקי שירות מצומצם, כל אחד למטרה מוגדרת:
- Tranzila — סליקת אשראי והנפקת חשבוניות מס. חברה ישראלית הכפופה לתקן PCI-DSS וחוק הגנת הפרטיות. פרטי הכרטיס מועברים אליה ישירות מהדפדפן שלך.
- Firebase / Google Cloud — אחסון מאגר הלקוחות וההזמנות (Firestore) ושירותי הזדהות (Auth). אזור עיבוד: me-west1 (תל אביב, ישראל).
- ספק שירותי SMS חיצוני — מקבל את מספר הטלפון ואת תוכן ההודעה לצורך משלוח הודעות עסקה ודיוור (למי שנרשם).
- Cloudflare — רשת CDN לטעינת נכסי האתר (HTML/CSS/JS). חשופה לכתובת IP בלבד בעת טעינת העמוד.
אנו לא מוכרים מידע אישי לאף גורם. כל ספק מחויב לעבד את המידע אך ורק בהתאם להנחיותינו ולמטרה לשמה נמסר.
We work with a small set of service providers, each for a defined purpose:
- Tranzila — credit card processing and tax invoicing. An Israeli company bound by PCI-DSS and the Protection of Privacy Law. Card details are transmitted directly to it from your browser.
- Firebase / Google Cloud — hosting of the customer and order database (Firestore) and authentication services (Auth). Processing region: me-west1 (Tel Aviv, Israel).
- External SMS gateway provider — receives the phone number and message body to deliver transactional and (for subscribers) marketing messages.
- Cloudflare — CDN for serving static site assets (HTML/CSS/JS). Exposed to IP address only at page-load time.
We do not sell personal data to anyone. Every provider is contractually bound to process the data solely on our instructions and for the purpose for which it was disclosed.
07. זכויות נושא המידע Your rights as a data subject
בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, עומדות לך הזכויות הבאות:
- זכות עיון (סעיף 13) — לקבל פירוט המידע אודותיך השמור במאגר.
- זכות תיקון (סעיף 14) — לבקש תיקון מידע שגוי, לא מדויק או חסר.
- זכות מחיקה — בכפוף לחובות שמירה רגולטוריות (לדוגמה: רישומי חשבוניות לפי דרישות מס הכנסה ומע"מ — בדרך כלל 7 שנים).
- זכות התנגדות לדיוור (סעיף 30א(ד) לחוק התקשורת) — מיידית, בחינם, באותה קלות בה ההסכמה ניתנה. ניתן להסיר על ידי לחיצה על הקישור בכל אימייל שיווקי, השבת המילה "הסר" להודעת SMS, או פנייה ל-[email protected].
- זכות תלונה — לרשות להגנת הפרטיות במשרד המשפטים.
למימוש זכויותיך, כתוב/כתבי אלינו ל-[email protected]. נשיב לפנייתך תוך 30 ימים. שים/שימי לב — נתונים הכפופים לחובת שמירה רגולטורית יישארו לתקופת השמירה החוקית גם לאחר בקשת המחיקה.
Under the Protection of Privacy Law, 5741-1981, you have the following rights:
- Right of access (§13) — to receive a list of the data we hold about you.
- Right of correction (§14) — to request correction of inaccurate, outdated or incomplete information.
- Right of deletion — subject to regulatory retention duties (e.g., invoice records under Income Tax / VAT — typically 7 years).
- Right to object to marketing (Communications Law §30A(d)) — immediately, free of charge, and as easily as consent was given. You may opt out by clicking the link in any marketing email, replying "STOP" to an SMS, or writing to [email protected].
- Right to complain — to the Privacy Protection Authority (Ministry of Justice).
To exercise your rights, write to us at [email protected]. We respond within 30 days. Note: data subject to a regulatory retention duty will be kept for the statutory period even after a deletion request.
08. רישום מאגר ומנהל מאגר Database registration & manager
בעקבות תיקון 13 לחוק הגנת הפרטיות (נכנס לתוקף באוגוסט 2025), בוטלה חובת הרישום הכללית של מאגרי מידע אצל רשם מאגרי המידע. מאגר הלקוחות של העסק אינו נכלל בקטגוריות המחייבות רישום, ועל כן אינו רשום.
האחריות לעמידה בדרישות החוק ולהגנה על המידע מוטלת על בעל העסק. לכל פנייה בנושא ניתן ליצור קשר בכתובת [email protected].
Following Amendment 13 to the Protection of Privacy Law (in force August 2025), the general obligation to register databases with the Database Registrar was repealed. The business's customer database does not fall within the categories that still require registration, and is therefore not registered.
Responsibility for compliance with the Law and for protecting the data rests with the business owner. For any related enquiry, contact [email protected].
09. העברה מחוץ לישראל Cross-border data transfer
מאגר הלקוחות וההזמנות מאוחסן בשירותי Firebase / Google Cloud באזור ישראל — me-west1 (תל אביב). ככלל, המידע נשמר בגבולות המדינה.
ככל שפעולות עיבוד או תמיכה מסוימות של Google מתבצעות מחוץ לישראל, הן כפופות לתקנות הגנת הפרטיות (העברת מידע אל מאגרי מידע שמחוץ לגבולות המדינה), התשס"א-2001 ולהתחייבות החוזית של Google להחיל סטנדרט הגנה שווה-ערך, כמפורט בהסכם עיבוד הנתונים של Google Cloud.
The customer and order database is hosted on Firebase / Google Cloud in the Israel region — me-west1 (Tel Aviv). As a rule, the data remains within the country.
To the extent certain Google processing or support operations occur outside Israel, they are subject to the Protection of Privacy Regulations (Transfer of Data to Databases Outside the State), 5761-2001 and to Google's contractual undertaking to apply an equivalent standard of protection, as set out in the Google Cloud Data Processing Addendum.
10. יצירת קשר וגרסה Contact & version
לכל בקשה למימוש זכויות, שאלה או תלונה בנושא פרטיות — כתוב/כתבי אלינו ל-[email protected]. נשיב תוך 30 ימים.
שינויים מהותיים במדיניות זו יודעו ללקוחות שנתנו הסכמה לדיוור, באמצעות SMS או אימייל. הגרסה העדכנית תפורסם תמיד בעמוד זה.
For any request to exercise your rights, a question or a complaint on a privacy matter — write to [email protected]. We respond within 30 days.
Material changes to this policy will be notified to customers who consented to marketing, by SMS or email. The current version is always published on this page.