עדכון אחרון: אפריל 2026
✅ נבדק חיצונית (יוני 2026): ציון A+ ב-SSL Labs (הצפנה) · ציון A בכותרות אבטחה. אפשר לאמת בעצמכן: SSL Labs · Security Headers
זירת האדריכלות ("האתר", "השירות", "אנחנו") מפעילה פלטפורמה למעצבי פנים ואדריכלים, בכתובת https://www.ziratadrichalut.co.il. מדיניות זו מפרטת אילו נתונים אנו אוספים, כיצד אנו משתמשים בהם, כיצד אנו מאחסנים ומגנים עליהם, עם מי אנו חולקים אותם וכיצד ניתן לבקש למחוק אותם. מדיניות זו חלה על כל המשתמשים באתר ובמיוחד על משתמשים שמחברים את חשבון Google שלהם לשירות.
אנחנו לא משתמשים בנתוני משתמש, ובפרט לא בנתוני Google, לצורכי אימון מודלים של בינה מלאכותית, פרסום, פרופיילינג שיווקי, או כל שימוש שאיננו מתן השירות שהמשתמש ביקש.
השימוש שלנו במידע המתקבל מ-Google APIs כפוף ל-Google API Services User Data Policy, כולל דרישות Limited Use.
openid email profile — משמש להתחברות ("Sign in with Google"). אנו מקבלים: מזהה Google ייחודי (sub), כתובת אימייל, שם מלא ותמונת פרופיל ציבורית.https://www.googleapis.com/auth/calendar — משמש לסנכרון יומן, רק לאחר שהמשתמש לוחץ במפורש על "חבר את Google Calendar" בהגדרות ה-CRM. באמצעות scope זה אנו יכולים ליצור, לקרוא, לעדכן ולמחוק אירועים ביומן הראשי של המשתמש ב-Google Calendar.https://www.googleapis.com/auth/gmail.send — משמש אך ורק לשליחת מיילים יוצאים מטעם המעצב/ת אל כתובות הלקוחות שהיא בחרה במפורש בפלטפורמה (המיילים שהמערכת שולחת ממילא — תבניות, מיילים מתוזמנים, לינק לאזור האישי, אישורי פגישה וכו'), רק לאחר שהמשתמש/ת לחץ/ה במפורש על "חבר/י מייל אישי" בהגדרות. scope זה אינו מאפשר קריאה, גישה, סנכרון או הצגה של תוכן תיבת הדואר כלל — שליחה בלבד.איננו מוכרים, משכירים, או מעבירים נתוני Google של משתמשים לצדדים שלישיים. נתוני Google מועברים רק חזרה אל Google (לצורך יצירת אירוע ביומן המשתמש) ונשמרים אצל ספקי תשתית מוגדרים שאיתם יש לנו הסכמי עיבוד נתונים:
שימוש שלנו בנתוני Google מוגבל ל-Limited Use: איננו מעבירים נתונים אלה לצדדים שלישיים מלבד הנדרש למתן השירות שהמשתמש ביקש, לציות לחוק, או לצרכי אבטחה.
לנוחותך: טופס ציבורי למחיקת נתונים זמין בכל עת ב- /data-deletion. אין צורך להיות מחובר/ת כדי להגיש בקשה.
האתר משתמש בעוגיות הכרחיות לתפקוד (session, CSRF). איננו משתמשים בעוגיות פרסום, בעוגיות צד שלישי לצורך פרופיילינג, או ב-trackers שיווקיים.
בכל עת באפשרותך לבקש: לעיין במידע שלנו עליך, לתקן מידע שגוי, לייצא את המידע, או למחוק את המידע באופן מלא. הפנייה בדוא"ל אל z.adrichalut@gmail.com. אם חיברת את חשבון Google שלך, באפשרותך בכל עת לבטל את הגישה של זירת האדריכלות דרך https://myaccount.google.com/permissions.
אנו נוקטים אמצעי אבטחה מקובלים בתעשייה: הצפנה בתעבורה (TLS), הצפנה במנוחה ברמת ספק התשתית, הצפנת סיסמאות (bcrypt), בקרת גישה מבוססת-תפקיד, ותיעוד פעולות רגישות. במקרה של חשד לפריצה המשפיעה על נתוני משתמש, נודיע למשתמשים הרלוונטיים בהתאם לחוק.
השירות מיועד למשתמשים מעל גיל 18. אנו לא אוספים ביודעין מידע מקטינים.
נעדכן מדיניות זו מעת לעת. תאריך העדכון האחרון מופיע בראש הדף. שינויים מהותיים ימסרו למשתמשים הרשומים באמצעות אימייל.
אחראית הגנת הפרטיות: תמר. לכל שאלה בנושא פרטיות, אבטחה או מחיקת מידע: z.adrichalut@gmail.com.
Zirat Architecture operates the platform at https://www.ziratadrichalut.co.il.
Data Accessed from Google: We request the OAuth scopes openid email profile for sign-in (Google account ID, email, name, profile picture); https://www.googleapis.com/auth/calendar (only when the user explicitly connects Google Calendar in the CRM settings) to create and update calendar events on the user's primary calendar; and https://www.googleapis.com/auth/gmail.send (only when the user explicitly connects their personal email in settings) to send outgoing emails on the user's behalf to client email addresses they have explicitly chosen in the platform. The gmail.send scope is send-only: it does NOT permit reading, accessing, syncing, or displaying any mailbox content.
Data Usage: Profile data is used to create/identify the user's account and render their display name/avatar in the UI. Calendar access is used only to push meeting events that the designer created inside our CRM to their Google Calendar — we do not read, analyze, or repurpose calendar events that originated outside the platform. Gmail access (gmail.send) is used only to send outgoing emails to client email addresses chosen explicitly by the user via the platform. We do not read, sync, display, or analyze any mailbox content whatsoever, and do not use Gmail data for advertising, recommendation engines, or AI/ML training.
Data Sharing: We do not sell, rent, or transfer Google user data to any third party. Data is only transmitted back to Google APIs as required to perform the user-requested action. Our subprocessors (Render — web hosting, EU Central; Neon — managed PostgreSQL, EU Central; Cloudflare R2 — file storage; Resend — transactional email; iCount — subscription billing) handle infrastructure only and do not receive Google user data beyond what is necessary for the service to function.
Data Storage & Protection: OAuth tokens are stored in our managed PostgreSQL database, encrypted in transit (TLS 1.2+) and at rest. Access is restricted to the site operator. We do not use Google user data for AI/ML model training, advertising, or marketing profiling.
Data Retention & Deletion: Users can disconnect Google Calendar at any time from the CRM settings (which deletes the stored tokens immediately) or from https://myaccount.google.com/permissions. Full account deletion can be requested via our public Data Deletion form or by emailing z.adrichalut@gmail.com with the subject "Delete my account"; deletion is completed within 30 days and includes all Google OAuth tokens, profile data, and user-generated content.
Limited Use: Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.