מדיניות פרטיות — המסלול

עודכן לאחרונה: 29.9.2026

1. מי אנחנו

"המסלול" היא מערכת לניהול לידים, לקוחות ותקשורת עם לקוחות לעסקים קטנים ובינוניים. המערכת מופעלת על ידי בראנד פרודקשיינס בע"מ, ח.פ 517243531, מתחם אפקה, יגאל בשן 2, קריית ביאליק 2751432 ("אנחנו"). לכל שאלה: inquiries@brandprods.com.

2. על מי חלה המדיניות ומה התפקיד שלנו

משתמשי המערכת (בעלי עסקים ועובדיהם): אנחנו אחראים למידע על החשבון שלכם.

הלקוחות והלידים של העסקים: את המידע הזה מזין או מחבר העסק שמשתמש במערכת. העסק הוא בעל המידע ואחראי לו, ואנחנו מעבדים אותו רק לפי הוראות העסק וכדי לספק לו את השירות.

3. איזה מידע אנחנו מעבדים

  • פרטי חשבון: שם, שם משתמש, טלפון, מייל, תפקיד והרשאות.
  • מידע שהעסק מנהל במערכת: פרטי לידים ולקוחות (שם, טלפון, מייל, הערות, מקור הליד והקמפיין), פגישות, משימות, מנויים והיסטוריית פעילות.
  • מידע מחיבורים שהעסק מפעיל, רק בהרשאתו:
    • WhatsApp Business (Meta) — הודעות שנשלחות ומתקבלות במספר העסקי, מספרי הטלפון ושמות הפרופיל של המתכתבים, וסטטוס מסירה.
    • Meta Lead Ads — הפרטים שהשאירו מתעניינים בטפסי הלידים של העסק, ושם הקמפיין, המודעה והטופס.
    • נתוני מודעות (Meta Marketing API) — הוצאה, קמפיינים ותוצאות של חשבונות המודעות שהעסק חיבר.
    • חיבורים נוספים (למשל Make, Zapier או מערכת לניהול סטודיו) — המידע שהעסק בוחר לשלוח למערכת.
  • מידע טכני: לוגים של השרת וכתובות IP לצורכי אבטחה ומניעת שימוש לרעה, ונתוני שימוש מצטברים ואנונימיים.

4. למה אנחנו משתמשים במידע

רק כדי לספק לעסק את השירות שביקש: ניהול לידים ולקוחות, שליחה וקבלה של הודעות, תזכורות ומשימות, דוחות ומדדי שיווק, ומענה בעזרת בינה מלאכותית כשהעסק מפעיל אותו — וכן לאבטחה, לתמיכה ולשיפור השירות.

אנחנו לא מוכרים מידע, לא משתמשים בו לפרסום שלנו או של אחרים, ולא בונים ממנו פרופילים.

5. עם מי המידע משותף

רק עם ספקי תשתית שמעבדים אותו עבורנו, לפי הצורך:

  • Supabase — אחסון מסד הנתונים וההתחברות.
  • Vercel — אירוח האפליקציה ונתוני שימוש אנונימיים.
  • Anthropic — עיבוד בקשות לבינה מלאכותית, רק כשהעסק מפעיל את התכונה.
  • Meta Platforms — שליחה וקבלה של הודעות WhatsApp, קליטת לידים ונתוני מודעות, לפי החיבורים שהעסק הפעיל.
  • כלים שהעסק עצמו בוחר לחבר (למשל Make או Zapier) — לפי ההגדרות שלו.

בנוסף, נמסור מידע אם נחויב לכך על פי דין. השרתים של ספקי התשתית עשויים להימצא מחוץ לישראל.

6. מידע שמתקבל מפלטפורמות Meta

מידע שמתקבל דרך הממשקים של Meta (WhatsApp Business Platform, Lead Ads ו-Marketing API) משמש אך ורק לשירות לעסק שחיבר אותו ובהתאם להרשאות שנתן. הוא לא נמכר, לא מועבר לגורם שלישי מעבר לאמור בסעיף 5, ולא משמש לפרסום. כשעסק מנתק חיבור או מבקש מחיקה, אנחנו מפסיקים לקבל את המידע ומוחקים אותו כמתואר בסעיף 8. השימוש כפוף גם לתנאי הפלטפורמה של Meta.

7. אבטחת מידע

התקשורת מוצפנת (HTTPS); המידע של כל עסק מופרד ברמת מסד הנתונים (Row Level Security) כך שעסק אחד לא יכול לראות מידע של עסק אחר; טוקנים ומפתחות של חיבורים חיצוניים נשמרים בצד השרת בלבד ולא מוצגים שוב; וההרשאות במערכת נקבעות לפי תפקיד. אין שיטה מאובטחת לחלוטין, אבל אנחנו עושים מאמץ סביר להגן על המידע.

8. שמירה ומחיקה

המידע נשמר כל עוד החשבון של העסק פעיל. כשעסק או משתמש מבקשים מחיקה, אנחנו מוחקים את המידע תוך 30 יום, למעט מידע שחובה עלינו לשמור לפי דין. הוראות מפורטות: מחיקת מידע.

9. הזכויות שלכם

לפי חוק הגנת הפרטיות, התשמ"א-1981, אפשר לבקש לעיין במידע עליכם, לתקן אותו או למחוק אותו. אם אתם לקוחות או לידים של עסק שמשתמש במערכת — פנו קודם אל העסק עצמו; אפשר גם לפנות אלינו ונעביר את הבקשה. פניות: inquiries@brandprods.com.

10. עוגיות

אנחנו משתמשים רק בעוגיות הכרחיות להתחברות ולשמירת העדפות, ובנתוני שימוש אנונימיים.

11. שינויים במדיניות

נעדכן את הדף הזה כשהמדיניות משתנה ונציין את תאריך העדכון. על שינוי מהותי נודיע לבעלי העסקים במערכת.

Privacy Policy — Maslul CRM

Last updated: September 29, 2026

1. Who we are

Maslul CRM ("Maslul") is a lead, customer and messaging management system for small and medium businesses, operated by Brand Productions Ltd, company no. 517243531, Afeka Complex, 2 Yigal Bashan St., Kiryat Bialik 2751432, Israel ("we"). Contact: inquiries@brandprods.com.

2. Our role

For account data of our users (business owners and their staff) we are the controller. Data about a business's leads and customers is entered or connected by that business, which owns it; we process it only on the business's instructions in order to provide the service.

3. Data we process

  • Account data: name, username, phone, email, role and permissions.
  • Business data: leads and customers (name, phone, email, notes, lead source and campaign), meetings, tasks, memberships and activity history.
  • Data from integrations a business enables, only with its authorization: WhatsApp Business messages sent and received on the business number, the correspondents' phone numbers and profile names, and delivery status; Meta Lead Ads form submissions with campaign, ad and form names; ad performance data (spend, campaigns, results) of ad accounts the business connected; and data the business sends from tools such as Make or Zapier.
  • Technical data: server logs and IP addresses for security and abuse prevention, and aggregated anonymous usage data.

4. How we use data

Only to provide the service the business requested — managing leads and customers, sending and receiving messages, reminders and tasks, marketing reports, and AI-assisted replies when the business enables them — and for security, support and service improvement. We do not sell data, use it for advertising, or build profiles from it.

5. Sharing

Only with infrastructure providers that process it for us as needed: Supabase (database and authentication), Vercel (hosting and anonymous analytics), Anthropic (AI processing, only when the business enables AI features), Meta Platforms (WhatsApp messaging, lead capture and ad data, per the business's connections), and tools the business itself chooses to connect. We may also disclose data when required by law. Providers' servers may be located outside Israel.

6. Meta Platform Data

Data received through Meta APIs (WhatsApp Business Platform, Lead Ads and Marketing API) is used solely to provide the service to the business that connected it, within the permissions it granted. It is not sold, not shared with third parties beyond section 5, and not used for advertising. When a business disconnects an integration or requests deletion, we stop receiving the data and delete it as described in section 8. Our use is also subject to the Meta Platform Terms.

7. Security

Traffic is encrypted (HTTPS); each business's data is isolated at the database level (Row Level Security); integration tokens and keys are stored server-side only and never shown again; and access inside the product is role-based.

8. Retention and deletion

Data is kept while the business account is active. On a deletion request we delete the data within 30 days, except data we must keep by law. Instructions: Data deletion.

9. Your rights

Under the Israeli Protection of Privacy Law, 5741-1981, you may request access to, correction of, or deletion of your data. If you are a lead or customer of a business using Maslul, please contact that business first; you may also contact us at inquiries@brandprods.com and we will forward your request.

10. Changes

We will update this page when the policy changes and note the date. Material changes will be announced to business owners in the product.