Privacy Policy

Updated: 20-09-2026

The binding text is the Hebrew text. Translations into other languages are generated automatically for reading convenience only, and in any case of conflict or ambiguity the Hebrew text prevails.

1. General

This policy explains how information is collected, processed and secured in the Weluf service, including the search engine, the request for quote (RFQ) marketplace and the customers module, in accordance with the Israeli Protection of Privacy Law, 5741-1981 and Amendment 13 thereto.

2. What information is collected

Account and registration: Name, email, organizational affiliation, and know-your-customer (KYC) data entered when opening a portal.

Communication and content: The content of chat messages, files and attachments (documents, images, videos), requests, quotes and execution confirmations.

The customers module: End-customer details entered by the forwarder (name, contact person, email and secondary email, phone, SOP notes), and the customer's sign-in identity (email, hashed password or Google identifier).

Email ingestion: Daily sheets and schedules received in a dedicated Gmail inbox, used to update the index.

Usage and technical: Searches, sign-in times, usage/token data, and basic technical information (device identifier, User-Agent, IP address) for security purposes.

3. Purposes of processing

Providing the service and managing access, transmitting messages and quotes between users, enforcing quotas and billing, information security and preventing misuse, sending email notifications, improving the service and complying with legal requirements.

4. Legal basis

Processing relies on the user's consent at registration, on performance of the contract, and on the operator's legitimate interest (security and operations).

5. Controller and processor, the customers module

With respect to end-customer data that the forwarder enters and manages, the forwarder is the data controller and Weluf acts as a processor on its behalf and under its instructions. The forwarder is responsible for the lawfulness of collecting the data and for obtaining its customers' consent.

6. Sharing with third parties

Information is not sold. It is processed through infrastructure providers, each subject to its own terms: hosting (Render), database and file storage (Supabase), identity verification and email ingestion (Google, Sign-In and Gmail), email delivery (Resend), text translation on request (a translation service), and campaign measurement on the marketing pages (Meta — see section 12). Sailing data originates from the shipping carriers and the agencies.

7. Sharing initiated by the user

Using the "share" action (WhatsApp, email, copy, download) sends the selected content out to an external service or to the user's device. Once the content has left, it is subject to the terms of that service and to the user's responsibility.

8. Data retention

Information is retained for as long as the account is active and for a reasonable period afterwards for billing, audit and legal purposes. Logs and usage data are retained for defined periods.

When an account is closed or a subscription is cancelled (including for non-payment), access is blocked and user content (messages, attachments and documents) is deleted or minimized at the end of the retention period. Aggregate usage data, such as the number of searches, request volume and activity times, is retained for statistical assessment and service operation, to the extent required for performance analysis, capacity planning, abuse prevention and compliance with legal requirements.

9. Information security

The system implements security controls: secret encryption (AES-256-GCM), TLS in transit, multi-tenant isolation, per-endpoint permissions, a single session, signed links for attachments, security headers (CSP/HSTS) and 2FA for the administrator. A "database registration" document is maintained.

10. Right of access, correction and deletion

The user has the right to review the information collected about them and to request its correction or deletion, subject to law. An end customer should first contact the forwarder who invited them. General inquiries: noar48@gmail.com.

11. Cookies and session

Essential cookies: secure sign-in, portal session and customer session (SameSite=Lax, httpOnly). They are required for the service to function and cannot be switched off while using it.

Marketing cookies: the public marketing pages run the Meta Pixel, which sets the _fbp and _fbc cookies. Full details in section 12.

12. Campaign measurement (Meta Pixel)

The public marketing pages run the Meta Pixel of Meta Platforms Ireland Ltd., to measure advertising effectiveness and attribute sign-ups to the campaign they came from. It does not run inside the signed-in area: not in chat, not in requests and quotes, and not in the customers module.

What is sent to Meta: The event name (page view, plan selection, trial start, registration), a one-time event identifier, the plan name and its value, campaign parameters (utm), the page address, the IP address, the browser type, the country code derived from the browser's language setting, and the _fbp and _fbc cookies.

What is not sent: Message content, attachments, requests, quotes, pricebooks, end-customer details and payment details. An email address is not sent as plain text; if one is sent in future for matching purposes, it will be hashed (SHA-256) beforehand.

Legal basis and objection: The service operator's legitimate interest in measuring advertising. The tracking can be prevented by blocking third-party cookies in the browser, through the ad settings in a Meta account, or by writing to the address in section 14 — blocking does not impair use of the service.

13. Changes to the policy

The policy may be updated. Material changes will be brought to users' attention; continued use constitutes consent.

14. Contact and database registration

For privacy inquiries and exercising rights: noar48@gmail.com. Database registration details (as required) will be published in accordance with law.