מדיניות הפרטיות של FitAround
עודכן לאחרונה: 15/07/2026
FitAround ("אנחנו", "השירות") מפעילה פלטפורמת SaaS לניהול סטודיו כושר ובריאות עבור בעלי סטודיו ("סטודיו", "לקוח עסקי") והמתאמנים שלהם ("מתאמן/ת", "חבר/ה"). מסמך זה מסביר אילו מידע אנו אוספים, לשם מה, ועם מי הוא משותף — בהתאם לחוק הגנת הפרטיות, התשמ"א-1981, כפי שתוקן בתיקון 13 (בתוקף מאוגוסט 2025).
1. מידע שאנו אוספים
- פרטי זיהוי: שם מלא, מספר טלפון (לצורך אימות חשבון), כתובת אימייל (כאשר סופקה).
- מידע בריאותי: הצהרות בריאות ("שאלוני בריאות") שהמתאמן ממלא בבקשת הסטודיו, וחתימות דיגיטליות (תמונת חתימה) על הצהרות אלה ועל תקנון הסטודיו.
- מידע תשלומים: אסימון תשלום (token) המונפק על ידי ספק הסליקה שלנו — לעולם לא מספר כרטיס אשראי, CVV, או פרטי חשבון בנק מלאים.
- נתוני שימוש: הזמנות לשיעורים, נוכחות, סטטוס מנוי/מסלול, היסטוריית חיובים וקבלות.
- מידע עסקי (לבעלי סטודיו): שם העסק, פרטי קשר, מספר עוסק/ח.פ. (אופציונלי), הגדרות תמחור ומדיניות ביטולים של הסטודיו.
- מידע טכני: העדפות שפה והתראות, יומני שימוש בסיסיים לצורך אבטחה ותפעול השירות.
2. הבסיס החוקי לעיבוד
אנו מעבדים מידע על בסיס ביצוע ההסכם שבינך לבינינו (מתן השירות), הסכמה מפורשת שניתנה לגבי מידע רגיש (הצהרות בריאות וחתימות), ואינטרס לגיטימי (אבטחת השירות ומניעת הונאות).
3. עם מי המידע משותף
אנו משתמשים בספקי שירות חיצוניים ("מעבדי מידע") הבאים כדי להפעיל את השירות:
- Firebase (Google): אימות משתמשים (כניסה באמצעות מספר טלפון וקוד חד-פעמי).
- Neon: אחסון מסד הנתונים (PostgreSQL), באזור האיחוד האירופי (Frankfurt, גרמניה).
- Google Cloud Platform: הרצת שרתי היישום (Cloud Run), באזור האיחוד האירופי (Belgium).
- ספק דיוור אלקטרוני: שליחת אימיילים תפעוליים (אישורי הרשמה, קבלות, תזכורות).
- InforU: שליחת הודעות SMS תפעוליות בישראל (תזכורות לשיעורים והתראות).
- ספק סליקת תשלומים: טוקניזציה וחיוב אמצעי תשלום (בסביבת הבדיקות/Sandbox כיום; ספק סליקה ישראלי מורשה בהמשך).
כל מעבד מידע מחויב חוזית לשמור על סודיות ואבטחת המידע. איננו מוכרים מידע אישי לצדדים שלישיים לצרכי שיווק.
4. העברת מידע בין-לאומית
חלק מהמידע מאוחסן ומעובד מחוץ לישראל — באזורי האיחוד האירופי אצל Neon (גרמניה) ו-Google Cloud (בלגיה). מדינות האיחוד האירופי מוכרות כבעלות רמת הגנת פרטיות נאותה לצורך העברת מידע מישראל.
5. תקופת השמירה
אנו שומרים מידע כל עוד החשבון פעיל, ובהתאם לדרישות חוקיות (כגון מסמכי חשבונאות). מדיניות שמירה/מחיקה מדויקת נבחנת כעת מול יכולות השחזור של מסד הנתונים (ר' המזכר הפנימי) ותעודכן במסמך זה לפני חשיפה פומבית לציבור.
6. הזכויות שלך
- לעיין במידע השמור עליך.
- לבקש תיקון של מידע שגוי.
- לבקש מחיקת המידע שלך, בכפוף לחובות חוק (כגון שמירת רשומות חשבונאיות) — כך מבקשים מחיקה.
- לפנות לסטודיו שלך ישירות, או אלינו (ר' יצירת קשר למטה) לכל בקשה בנוגע למידע.
7. אבטחת מידע
אנו נוקטים באמצעי אבטחה מקובלים בתעשייה: הצפנת תעבורה (HTTPS/TLS), הפרדת מידע בין סטודיו לסטודיו ברמת מסד הנתונים, ואחסון אסימוני תשלום בלבד (ללא פרטי כרטיס מלאים).
8. עוגיות ומעקב
האפליקציה עצמה (לאחר התחברות) אינה משתמשת בעוגיות מעקב שיווקיות. אתר השיווק הציבורי (fitaround.com) שומר במכשיר שלך רק פריט אחסון מקומי אחד — בחירת ההסכמה שלך לעוגיות (מאושר/נדחה) — כדי לא להציג את הבאנר שוב. נכון להיום, אתר השיווק אינו טוען עדיין סקריפטים של מדידה/פרסום (כגון Google Analytics או Meta Pixel); כאשר אלה יופעלו, הם ייטענו רק לאחר הסכמה מפורשת, ולא באפליקציה עצמה. עוגיות/אחסון הכרחיים לתפעול הבסיסי (כגון אימות ההתחברות) פטורים מהסכמה.
9. יצירת קשר
לשאלות בנוגע למדיניות זו או למימוש הזכויות שלך, ניתן לפנות אלינו בכתובת privacy@fitaround.co.
FitAround Privacy Policy
Last updated: 15/07/2026
FitAround ("we", "the Service") operates a SaaS platform for fitness and wellness studio management, serving studio owners ("Studio", "business customer") and their trainees ("Member"). This page explains what data we collect, why, and who it's shared with — in line with Israel's Privacy Protection Law, 1981, as amended by Amendment 13 (in force since August 2025).
1. Data we collect
- Identity: full name, phone number (for account verification), email address (when provided).
- Health data: health declarations completed by a member at their studio's request, and digital signatures (image) on those declarations and the studio's own terms.
- Payment data: a payment token issued by our payment processor — never a full card number, CVV, or bank account details.
- Usage data: class bookings, attendance, subscription/plan status, billing history and receipts.
- Business data (studio owners): business name, contact details, business registration number (optional), the studio's own pricing and cancellation policies.
- Technical data: language and notification preferences, basic usage logs for security and operational purposes.
2. Lawful basis for processing
We process data on the basis of contract performance (providing the Service), explicit consent for sensitive data (health declarations and signatures), and legitimate interest (securing the Service and preventing fraud).
3. Who we share data with
We use the following external service providers ("processors") to operate the Service:
- Firebase (Google): user authentication (phone number + one-time code sign-in).
- Neon: database hosting (PostgreSQL), in the EU region (Frankfurt, Germany).
- Google Cloud Platform: application hosting (Cloud Run), in the EU region (Belgium).
- Our transactional email provider: operational emails (signup confirmations, receipts, reminders).
- InforU: operational SMS delivery in Israel (class reminders and notifications).
- Our payment processor: payment tokenization and charging (Sandbox/test today; a licensed Israeli payment provider at go-live).
Every processor is contractually bound to keep data confidential and secure. We do not sell personal data to third parties for marketing purposes.
4. International data transfer
Some data is stored and processed outside Israel — in EU regions with Neon (Germany) and Google Cloud (Belgium). EU member states are recognized as providing an adequate level of privacy protection for data transferred from Israel.
5. Retention
We retain data for as long as an account is active, and as required by law (e.g. accounting records). The exact retention/deletion schedule is being finalized alongside a database backup-and-restore review (see the internal memo) and will be updated here before public launch.
6. Your rights
- Access the data held about you.
- Request correction of inaccurate data.
- Request deletion of your data, subject to legal retention obligations (e.g. accounting records) — how to request deletion.
- Contact your studio directly, or us (see Contact below), for any data request.
7. Security
We use industry-standard security measures: encrypted transport (HTTPS/TLS), per-tenant data isolation at the database level, and storage of payment tokens only (never full card details).
8. Cookies & tracking
The app itself (once signed in) does not use marketing tracking cookies. The public marketing site (fitaround.com) stores exactly one local-storage item on your device — your cookie-consent choice (accepted/declined) — so the banner doesn't reappear. As of today, the marketing site does not yet load any analytics/advertising scripts (e.g. Google Analytics or Meta Pixel); once it does, they will only load after explicit consent, and never inside the app itself. Strictly necessary storage (e.g. your login session) is exempt from consent.
9. Contact
For questions about this policy or to exercise your rights, contact us at privacy@fitaround.co.