Privacy Policy
How we collect, use, and protect your personal information.
ShabbatTime
Version: 1.0
Last updated: September 27, 2026
Contact email: contact@shabbattime.app
Section 1 - Introduction
1.1 User privacy is important to us. This Policy explains what personal information is collected in connection with use of the Service, how we use it, to whom it may be disclosed, how long it may be retained, and what rights you have in relation to it.
1.2 The Service is operated by:
Dor Yarchi (דור ירחי) A private venture operated from Israel.
In this Policy: the "Operator", "ShabbatTime", "we", "us", or the "Service".
1.3 For purposes of applicable privacy law, the Operator is the controller of the databases used to operate the Service, to the extent the law defines the Operator as such.
1.4 Privacy inquiries may be sent to:
contact@shabbattime.app
You may also contact us through the Service's support system.
1.5 This Policy applies to the website, any application that may be launched in the future, Service pages, and other online functions operated by us.
1.6 This Policy should be read together with the ShabbatTime Terms of Use and Community Guidelines.
1.7 For purposes of this Policy, an "Event" means a meal, gathering, or other activity published or managed through ShabbatTime in accordance with the purposes of the Service, including Shabbat and holiday meals, Oneg Shabbat gatherings, candle-lighting gatherings, study gatherings, and Jewish community events. Even if certain parts of the Service interface use the term "meal" or "Meal", references to an "Event" in this Policy also apply to such listings and activities.
Section 2 - Whether You Are Required to Provide Information
2.1 You are not legally required to provide personal information merely in order to open an account or use the Service.
2.2 However, providing certain information is a technical or operational condition for receiving some Service functions.
2.3 For example, without an email address and login information a regular account cannot be opened; without certain profile information the onboarding process cannot be completed; and without phone-number verification certain actions such as hosting, submitting a join request, or using certain functions with other users cannot be performed.
2.4 Information marked as optional in the interface may be left blank, subject to the limitations described on the relevant screen.
2.5 If you choose not to provide information required for a particular function, we will not be able to provide that function to you.
Section 3 - Information We Receive When an Account Is Opened
3.1 When an account is opened, we may receive:
- Email address.
- Password or account authentication information.
- Display name.
- Date of birth.
- Age calculated from the date of birth.
- Gender.
- City.
- Profile image.
3.2 Passwords are handled through the authentication infrastructure of our technology service provider. We do not store a readable copy of the password in the application's database.
3.3 A display name is not necessarily a verified legal name.
3.4 At this stage, we do not request an identity card, passport, or other government-issued document for identity verification.
Section 4 - Profile and Full Onboarding Information
4.1 As part of the profile, we may receive additional information such as:
- Self-description or bio.
- Kashrut preferences.
- Level of Shabbat observance as described by the user.
- Food preferences.
- Interest in hosting.
- City of residence or community city.
- Profile image.
- Phone number.
- Phone verification time.
- Information concerning profile-completion stages.
4.2 Kashrut preferences, Shabbat observance, and similar information may, depending on the circumstances, reveal or indicate religious belief, worldview, or religious lifestyle. We treat this information with increased sensitivity.
4.3 We request this information to support better matching between people and events, reduce mismatched expectations, and operate the search, filtering, and matching functions described below.
4.4 ShabbatTime does not determine a person's religious identity and does not verify whether a user's statement regarding Shabbat observance, kashrut preferences, or lifestyle is correct according to Halacha, any movement, community, or interpretation.
Section 5 - Phone Number Verification
5.1 Before certain actions, we require phone-number verification using a one-time code.
5.2 For this purpose, we may process:
- Phone number.
- Country or country code.
- Time the code was sent.
- Time of verification.
- Technical information needed to prevent abuse and repeated verification attempts.
5.3 The phone number may also be used to prevent duplicate accounts, circumvention of blocks, abuse, or repeated use of one-time benefits.
5.4 Phone-number verification is not verification of legal identity, name, age, photograph, or personal history.
5.5 SMS messages sent for this purpose are for verification and security. Providing a phone number for verification does not, by itself, subscribe a user to advertising by SMS.
Section 6 - Event Information
6.1 When a user creates an event, we may receive and process information such as:
- Event name.
- Event description.
- Date and time.
- Registration deadline.
- City and neighborhood.
- Street and street number.
- Floor, apartment, and entry details.
- Location hint or arrival instructions.
- Number of places offered by the Host.
- Event size.
- Age range.
- Audience characteristics selected by the Host using the options provided by the Service.
- Kitchen practices.
- Food preferences.
- Participation type, such as free, bring-an-item, contribution toward costs, or paid event.
- Price, if applicable.
- Special information and instructions.
- Prayer-related information or the character of the event.
- Cover image.
- Contact methods the Host chose to make available after a participant is approved.
6.2 We separate, as far as practicable, information intended to be displayed publicly or within the community from private information such as an exact address.
6.3 A full event address is not intended to be displayed to the general public.
6.4 As a general rule, the exact address is disclosed to a user only after that user has been approved to attend the event.
6.5 General event information, such as the title, city, date or time, number of places, cover image, and other event characteristics, together with public Host profile information such as the Host's display name and profile image, may also be displayed on public ShabbatTime pages, including the home page, in order to support event discovery and show Service activity.
6.6 Exact addresses, private contact details, and participant identities are not displayed on the public home page as part of such presentation.
Section 7 - Join Requests and Participation Information
7.1 When a user requests to join an event or when a Host handles a request, we may retain information such as:
- Time the request was submitted.
- The event to which the request relates.
- Request status.
- Time of approval, rejection, or withdrawal.
- Cancellation after approval.
- Attendance status.
- Reports regarding attendance or non-attendance.
- Information concerning cooldown periods or restrictions resulting from cancellations.
- Hosting and attendance history.
- Contact methods the Guest chose to make available to the Host if the join request is approved.
7.2 This information is used to operate the Service, manage requests, prevent abuse, calculate reliability measures, and determine display order.
7.3 The identities of Guests approved to attend an Event are not displayed to the general public as part of the public Event card. However, the public identity of the Host may be displayed alongside the Event on public pages of the Service.
7.4 Within the Service, registered users may see limited information about people approved for an Event, including through their public or community profiles, even before the viewing user has been approved to attend that Event, depending on the structure of the Service and the applicable visibility settings.
Section 8 - Community Updates
8.1 The Service may display community updates to registered users based on public or community-visible information within the Service.
8.2 Such updates may include, for example:
"Dor joined the Tel Aviv community"
or:
"Dor created a new event in Tel Aviv."
8.3 An update stating that a user joined a community refers to joining the Service and selecting a city in the profile, not to participation in a particular event.
8.4 Such updates may include the user's display name, city, and other information already intended to be visible within the community.
8.5 We will not display an exact home address or private information not intended for community visibility in this type of community update.
8.6 This Section concerns community updates. Separately, within the page of a particular Event, registered users may see limited information about approved participants as described in Section 7.4.
Section 9 - Matching, Ranking, and Display Order
9.1 The Service uses calculation and ranking systems to determine the default order in which events and requests are displayed.
9.2 Depending on the relevant function, the system may use information such as:
- City or general geographic compatibility.
- Age and the event's age range.
- Food preferences.
- Kashrut preferences or kitchen practices.
- Level of Shabbat observance as provided by the user or Host.
- Usage history.
- Reliability.
- Previous hosting experience.
- Demand for an event.
- Time remaining until the Event.
- The user's rating as a Host.
- Other information needed to operate the ranking mechanism.
9.3 Information concerning Shabbat observance and kashrut preferences may be used to calculate relative compatibility between a user and an event or between a participant and the hosting environment.
9.4 The purpose of this use is not to determine that one level of observance is better or more desirable than another, but to estimate proximity between characteristics and preferences provided by the parties.
9.5 Display order is not a determination of a person's value, quality, character, or safety.
9.6 The Service may also enforce eligibility conditions defined by the Host for an event, such as an age range or intended audience, according to the functions made available by the Service.
9.7 We do not use these ranking mechanisms to make legal, financial, or employment decisions about users.
9.8 Algorithms and weights may change from time to time to improve the Service, safety, fairness, discovery of new events, and prevention of abuse.
Section 10 - Reliability, Reviews, and Scores
10.1 The Service may create and retain reliability measures based on user activity in the Service.
10.2 Such information may be based on hosting, attendance, cancellations, no-shows, reviews, reports, and other information related to conduct within the Service.
10.3 Reliability measures may include numerical scores, aggregated scores, internal measures, badges, or other indicators calculated by the Service. Some of these may remain internal only.
10.4 The Service may display to other users a numerical or aggregated score, badge, or other limited indicator, depending on the relevant function and product rules.
10.5 Reviews may include star ratings, structured responses, or tags.
10.6 Free text submitted as part of a report is not displayed as a public review.
10.7 Reliability information may also be used to determine the display order of events or requests and to prevent abuse.
Section 11 - Questions, Messages, and Communications Within the Service
11.1 The Service may retain certain communications between users, including:
- A question sent by a requester to a Host concerning an event.
- The Host's response.
- A message related to cancellation or a change in a request.
- Technical information relating to the request process.
11.2 A Host may choose to publish a question and answer for the benefit of other users. When a question is displayed publicly or within the community, the Service may remove the identity of the person who asked it in accordance with the structure and available functionality of the Service.
11.3 The Service does not currently operate a full private messaging system between users.
11.4 When creating an Event, the Host may choose which contact methods will be available to a user who is approved to attend. These methods may include a phone call, private WhatsApp message, a link to an Event WhatsApp group, or a combination of them.
11.5 When submitting a join request, the Guest may choose which contact methods will be available to the Host if the request is approved. These methods may include a phone call, private WhatsApp message, or both.
11.6 Each party independently chooses which contact methods to make available to the other party. As a general rule, private contact details or contact options are disclosed only after the join request has been approved and in accordance with the choices made by each party.
11.7 Selecting private WhatsApp messaging may allow the other party to see or infer the phone number associated with the WhatsApp account, even if the phone-call option was not separately selected.
11.8 Joining a WhatsApp group takes place through an external service and may expose the user's phone number, name, profile image, or other WhatsApp account information to group members, depending on WhatsApp settings and the user's settings. ShabbatTime does not control how WhatsApp or group members display or use information after the user joins the group.
11.9 We do not receive, read, or store the content of phone calls or communications conducted outside ShabbatTime merely because the users met through the Service.
Section 12 - Images and Automated Content Filtering
12.1 Users may upload images, such as a profile image or event cover image.
12.2 We may analyze or review images automatically or manually in order to detect sexual or inappropriate content and prevent content that is unsuitable for the Service from being uploaded.
12.3 As of the date of this Policy, image classification is performed using a model operated within ShabbatTime's server environment and does not send the image to an external artificial-intelligence service for classification.
12.4 The automated model is not 100 percent accurate and may make mistakes.
12.5 Classification results are used primarily to make approval or blocking decisions. Technical information relating to a classification result may be retained in system logs for security, testing, and adjustment of filtering thresholds.
12.6 We may also use local text filters to identify offensive or prohibited expressions.
Section 13 - Support, Reports, and Safety
13.1 The Service operates a support and reporting system.
13.2 When a user opens a support request or report, we may receive:
- Request category.
- Subject.
- Free-text content.
- Related event.
- Page from which the request was opened.
- Time of the request.
- Follow-up correspondence with support.
- Handling status.
13.3 Service administrators may add internal notes that are not displayed to the user.
13.4 A safety report or complaint may include information about another user.
13.5 Information contained in reports is not published to the public.
13.6 In order to review a complaint, we may, as needed and subject to applicable law, disclose to the user who is the subject of the complaint all or part of the relevant allegations or information where reasonably necessary for review, safety, or an opportunity to respond. This does not mean that we must disclose the identity of the reporting person or information that is not needed for the review.
13.7 We do not undertake to disclose the reporting user's identity in every case.
13.8 Reports and information concerning blocks, violations, fraud, safety, and support may be retained after account deletion where there is a legitimate need relating to safety, prevention of abuse, dispute management, enforcement, or legal defense.
Section 14 - Technical and Automatically Collected Information
14.1 When the website or Service is used, we may automatically receive technical information such as:
- IP address.
- Browser type.
- Operating system.
- Device type.
- Language and region.
- Time zone.
- Visit time.
- Pages viewed.
- Actions and interactions within the Service.
- Referring page.
- Landing page.
- Campaign parameters, such as UTM parameters.
- Online identifiers.
- Error and performance data.
- Approximate country, region, or city derived from an IP address.
14.2 ShabbatTime does not currently collect precise GPS location for the core operation of the Service.
14.3 A city in a profile and an event location are provided by users and are not background-measured GPS locations.
Section 16 - Purposes for Which We Use Information
16.1 Depending on the type of information and context, we use personal information for the following purposes:
- Creating and managing accounts.
- Verifying users and securing accounts.
- Creating, displaying, and managing events.
- Handling join requests.
- Disclosing event information to an approved user.
- Matching users and events.
- Search, filtering, and ranking.
- Operating reliability measures and reviews.
- Displaying community activity.
- Enabling contact between Hosts and Guests.
- Customer service and support.
- Handling reports, violations, and safety issues.
- Preventing fraud, spam, circumvention of blocks, and abuse.
- Information security and protection of the Service.
- Analyzing performance, use, and growth.
- Detecting problems and improving the product.
- Sending Service communications.
- Sending marketing communications where the required consent has been obtained.
- Protecting our rights and the rights of users.
- Managing disputes and legal claims.
- Complying with legal obligations, orders, or requirements of a competent authority.
- At our discretion and subject to applicable law, contacting the police, emergency services, or another competent authority where information that has come to our attention raises a reasonable concern regarding an offense, fraud, threat, violence, a risk to a person's safety, or another serious matter that reasonably justifies such contact.
16.2 The possibility of contacting an authority as described above is generally discretionary and does not create a duty for us to proactively monitor users, monitor every activity, conduct investigations, collect evidence, determine whether an offense occurred, reach criminal conclusions, or report every item of information that could potentially be interpreted as unlawful conduct. A duty to report, disclose, or act will apply only where and to the extent applicable law imposes such a duty on us.
16.3 If we seek to use personal information for a materially new purpose that is not reasonably compatible with the purposes for which it was collected, we will do so only where there is an appropriate legal basis and will provide additional notice or request additional consent where required by applicable law and the circumstances.
Section 17 - Information Visible to Other Users
17.1 The Service is community-oriented, and some information is intended from the outset to be visible to other users.
17.2 Depending on the function, visible information may include:
- Display name.
- Profile image.
- Age.
- City.
- Gender.
- Self-description.
- Preferences or lifestyle characteristics designated as visible.
- Events you created.
- Limited information about activity or experience within the Service.
- Limited information regarding participation in a particular Event, where such information is designated as visible to other users within that Event context.
- A score or badge intended to be displayed.
17.3 A Host may see additional information about a user who requests to join the Host's event for purposes of considering the request.
17.4 After a join request is approved, the Host and Guest may receive one another's contact details or contact options according to the choices made by each party. The Host may allow the Guest to contact the Host by phone call, private WhatsApp message, or the event's WhatsApp group; the Guest may allow the Host to contact the Guest by phone call or private WhatsApp message.
17.5 Joining a WhatsApp group may expose information from the user's WhatsApp account, including the user's name, profile image, phone number, or other information, to group members according to WhatsApp's settings and the user's settings. ShabbatTime does not control how WhatsApp or group members display or use information after the user joins the group.
17.6 Information disclosed to another user may be copied or retained by that user despite the Service rules. We cannot guarantee deletion from another user's device after information has been lawfully disclosed to that user.
Section 18 - Service Providers
18.1 We use technology providers to operate the Service.
18.2 As of the date of this Policy, these providers may include:
- Supabase - database, user authentication, and backend infrastructure.
- Vercel - website hosting, application infrastructure, and analytics services.
- Resend - delivery of email messages.
- An SMS provider used to send verification codes, such as 019.
- Google - Google Analytics for usage analysis, Google Search Console for search and website-performance data, and email services used to receive correspondence, as applicable and subject to relevant settings and consents.
- Cloudflare - DNS services, related infrastructure, and email routing, depending on the services enabled for ShabbatTime.
18.3 Providers receive access only to information reasonably necessary for the service they provide to us, subject to the arrangements applicable to them.
18.4 The list of providers may change when we replace infrastructure or add services.
18.5 We do not sell users' personal information to advertisers or data brokers.
Section 19 - Transfers of Information Outside Israel
19.1 Some of our infrastructure providers operate outside Israel or use servers and service providers in different countries.
19.2 Personal information may therefore be processed, stored, or accessible outside Israel.
19.3 When information is transferred outside Israel, we will act in accordance with applicable rules concerning international data transfers and use appropriate contractual or legal mechanisms where required.
19.4 The level of legal protection for information in another country may differ from the level of protection in Israel.
Section 21 - Change of Ownership or Transfer of Operations
21.1 If ShabbatTime's operations are transferred in the future to a company, partnership, purchaser, or another party that continues the Service, personal information may be transferred as part of the operations.
21.2 Such a transfer will be made subject to applicable law, for purposes consistent with operation of the Service, and with any notice required by law.
21.3 If there is a material change in the identity of the information controller, we will update users as required.
Section 22 - Communications and Email
22.1 We may send Service communications needed to operate an account, such as:
- Verification and security messages.
- Notice of a join request.
- Changes in request status.
- Event information.
- Reviews or actions required after an event.
- Violation, cooldown, suspension, or blocking notices.
- Material notices concerning the account.
22.2 Users may be able to choose which non-essential communications they wish to receive, according to the settings available in the Service.
22.3 Newsletter or marketing-email registration will be handled separately and in accordance with the relevant consent requirements.
22.4 Marketing email can be unsubscribed from using the unsubscribe method included in the message or through account settings.
22.5 Unsubscribing from marketing does not stop Service communications that are essential to account management or safety.
Section 23 - Retention of Information
23.1 We retain information only for as long as reasonably necessary for the purposes for which it was collected, operation of the Service, safety, prevention of abuse, compliance with a legal obligation, or protection of legal rights.
23.2 Retention periods vary according to the type of information.
23.3 Active account information may be retained for as long as the account exists.
23.4 Event, request, and activity information may be retained as part of Service history.
23.5 Support correspondence, reports, blocks, and safety-related information may be retained after account deletion where reasonably necessary for protection of the community, dispute management, prevention of circumvention of blocks, or legal defense.
23.6 Certain security information and logs will be retained for periods required by applicable information-security law or reasonable security needs.
23.7 When there is no longer a legitimate need for information, we will act to delete it, de-identify it, or restrict its use, as appropriate.
Section 24 - Account Deactivation
24.1 A user may be able to deactivate an account temporarily.
24.2 Deactivation is not deletion.
24.3 During deactivation, we continue to retain the account, history, and related information in order to allow reactivation.
24.4 User activity within the Service is limited while the account is deactivated.
Section 25 - Account Deletion
25.1 A user may request deletion of an account using the function available in the Service, subject to restrictions intended to avoid harm to events to which the user has already committed.
25.2 A deletion request may require renewed verification by email or another method.
25.3 As of the date of this Policy, a deletion request includes a 30-day grace period during which the request may be cancelled.
25.4 After the grace period, and subject to applicable law and the provisions below, we act to delete the account and private information that is no longer required.
25.5 Deletion may include, among other things, deletion of:
- The account.
- Profile information.
- Phone number.
- Private profile-related information.
- Images stored for the account.
- Private addresses that are no longer required.
25.6 Shared information needed to preserve a coherent history for other users may be retained after direct identifiers have been removed and may appear, for example, as information associated with a "Former user."
25.7 Account deletion does not require us to delete information that we are permitted or required to retain for purposes such as:
- Safety.
- Reporting a violation.
- Fraud prevention.
- Enforcement of a block.
- Handling a dispute.
- Legal defense.
- Compliance with a legal obligation.
Section 26 - Continuity Identifiers After Deletion
26.1 In order to prevent circumvention of blocks, repeated use of one-time benefits, and to maintain safety mechanisms, we may retain after deletion a cryptographic value derived from an identifier such as an email address or phone number.
26.2 Such a value is not retained as the original email address or phone number, but it may allow the system to identify a future match to an identifier used in the past.
26.3 We therefore do not describe such information as fully anonymous.
26.4 Its use is limited to continuity, security, prevention of abuse, and enforcement of restrictions.
26.5 Registering again after deletion does not automatically restore the user's previous profile, history, or reliability score.
Section 27 - Information Security
27.1 We use technical and organizational measures intended to protect personal information against unauthorized access, use, modification, copying, or disclosure.
27.2 These measures may include, as appropriate, permission mechanisms, authentication, access controls, separation between public and private information, event logging, and database- and server-level security measures.
27.3 Administrative access to information is limited to persons who need such access for their role.
27.4 No computer system is completely immune from security incidents. We cannot guarantee that a security incident will never occur.
27.5 If an incident occurs that requires reporting or notification under applicable law, we will act in accordance with the obligations that apply to us.
Section 28 - Minors
28.1 The Service is intended only for account holders aged 18 or older.
28.2 We do not knowingly allow a minor to open an independent account.
28.3 A minor may attend an event with a responsible adult in accordance with the Service rules, but we do not ask the minor to create a profile or provide the profile information required from a regular user.
28.4 If we learn that a minor opened an account in violation of the rules, we may block or delete the account in accordance with the circumstances and applicable law.
Section 29 - Your Rights Regarding Information
29.1 Subject to the Israeli Protection of Privacy Law and applicable law, you have the right to review personal information about you held in a database of the Service.
29.2 If you find that personal information about you is inaccurate, incomplete, unclear, or out of date, you may request correction in accordance with applicable law.
29.3 Much of the profile information can be updated directly through account settings.
29.4 Requests for access or correction may be sent to:
contact@shabbattime.app
29.5 We may take reasonable steps to verify the identity of a person making a request before disclosing or changing information, in order to protect user privacy.
29.6 You may also use the account-deletion mechanism described above.
29.7 The right to deletion is not absolute, and in some circumstances we may be permitted or required to retain information under applicable law or for another legitimate purpose described in this Policy.
29.8 You may withdraw consent to marketing communications or other optional processing using the tools we provide, without affecting the lawfulness of processing carried out lawfully before withdrawal.
Section 30 - Inaccurate Information
30.1 We rely to a significant extent on information provided by users themselves.
30.2 Users are responsible for updating information that has changed when relevant to the Service.
30.3 If we become aware that material information is inaccurate, we may correct it, ask the user to update it, or restrict use of a function until the matter is clarified.
Section 31 - External Links and Services
31.1 The Service may contain links to services that are not operated by us.
31.2 For example, users may proceed to WhatsApp, a mapping service, or another website.
31.3 This Policy does not apply to how those parties process information after you leave ShabbatTime.
31.4 We recommend reviewing the privacy policy of the relevant external service.
Section 32 - Changes to This Privacy Policy
32.1 We may update this Policy due to changes in the Service, technology, providers, purposes of processing, or applicable law.
32.2 The last-updated date will be displayed at the top of the document.
32.3 Where a change is material, we will provide an appropriate notice through the Service or another contact method.
32.4 Where a change requires new consent or a new choice under applicable law, we will not rely solely on continued use and will request the appropriate action.
32.5 A non-material change may take effect upon publication.
Section 33 - Languages
33.1 This Policy may be available in Hebrew and English.
33.2 The Hebrew version is the controlling version in the event of a conflict between versions, subject to mandatory provisions of applicable law.
33.3 We will make reasonable efforts for the English version to faithfully reflect the Hebrew version.
Section 34 - Privacy Contact
34.1 For questions, access or correction requests, deletion-related requests, complaints, or other privacy matters, you may contact us at:
Dor Yarchi (דור ירחי) ShabbatTime Email: contact@shabbattime.app
34.2 You may also contact us through the support system within the Service.
34.3 We may request additional information reasonably necessary to identify the requester and safely handle the request.