מדיניות פרטיות — שעון הכסף (Money Clock)
עדכון אחרון: 18 בספטמבר 2026
האפליקציה "שעון הכסף" (Money Clock), מזהה com.izzy.GoldClockl, פותחה ומופעלת על ידי מפתח עצמאי,
ישראל פריד (Yisrael Fried) ("אנחנו", "אנו"). המסמך הזה מסביר מה האפליקציה אוספת,
למה, איפה זה נשמר, מי יכול לראות את זה ואיך מוחקים את הכול.
בקצרה
- השעון האישי — היסטוריית המשמרות, השכר, היעדים, הפרופילים והמשימות — נשאר במכשיר שלך. אנחנו לא רואים אותו ולא שולחים אותו לשום מקום.
- הצד העסקי — עסק, צוות, לוח משמרות ושעות עבודה — נשמר בשרת שלנו, כי כמה אנשים חייבים לראות את אותו לוח. השרת שלנו מתארח ב-Supabase, באזור פרנקפורט שבאיחוד האירופי.
- אנחנו לא מוכרים מידע, לא מעבירים אותו למפרסמים ולא עוקבים אחריך בין אפליקציות או אתרים. אין באפליקציה פרסומות, אין רכישות מתוך האפליקציה ואין כלי אנליטיקה.
- אפשר למחוק את החשבון מתוך האפליקציה, והמחיקה אמיתית.
1. השעון האישי — מה שלא מגיע אלינו
השעון האישי עובד בלי חשבון ובלי חיבור לאינטרנט. כל מה שהוא שומר — היסטוריית המשמרות, השכר לשעה,
המטבע, היעדים, פרופילי העבודה, המשימות, הגדרות העיצוב ותמונת הרקע — נשמר במכשיר עצמו
(UserDefaults ותיקיית האפליקציה), ומשותף עם הווידג׳ט ועם אפליקציית ה-Apple Watch דרך קבוצת
אפליקציות משותפת במכשיר.
היסטוריית המשמרות מגובה גם ל-iCloud Key-Value Store של Apple, כדי שתחזור אליך אם תחליף מכשיר.
הגיבוי הזה הולך לחשבון ה-iCloud שלך, נשלט על ידי Apple, ואנחנו לא ניגשים אליו ואין לנו אפשרות לקרוא אותו.
"הגדרות → מחיקת כל הנתונים" מוחקת את כל האמור לעיל מהמכשיר ומהגיבוי ב-iCloud.
2. הצד העסקי — מה נאסף ולמה
הצד העסקי נפתח רק אם בחרת להשתמש בו, והוא מבקש התחברות. מרגע זה נאספים הנתונים הבאים:
| מה | למה | מתי |
|---|---|---|
| כתובת אימייל | לזהות אותך בהתחברות ולשלוח קוד כניסה | בהתחברות. ב"התחברות עם Apple" זו יכולה להיות כתובת ההעברה הפרטית של Apple |
| שם תצוגה | כדי שהצוות והמנהל ידעו מי נרשם למשמרת | בהצטרפות, וניתן לשינוי |
| מספר טלפון (רשות) | כדי שהמנהל יוכל ליצור איתך קשר בענייני משמרות | רק אם מילאת אותו בטופס ההצטרפות |
| מזהה משתמש | המפתח שמקשר בין כל הרשומות שלך בשרת | נוצר אוטומטית בהתחברות |
| מזהה מכשיר | אסימון ההתראות של המכשיר ומזהה היצרן (identifierForVendor), כדי לשלוח התראה למכשיר הנכון ולמנוע מאדם אחר לחטוף את ההתראות שלך | כשאתה מאשר התראות |
| תוכן עסקי | עסקים, חברות בצוות, תפקידים, משמרות, שיבוצים, בקשות החלפה, אילוצי זמינות, תבניות, הערות | בזמן השימוש |
| שעות עבודה | זמני התחלה, הפסקה וסיום של משמרות שנרשמו דרך השעון בעסק מסוים, כדי שהמנהל יראה מי עובד עכשיו וכמה שעות נעשו | כשאתה מפעיל שעון על משמרת של אותו עסק |
| מיקום מדויק של מקום העבודה | הקואורדינטות והרדיוס שבעל העסק מסמן כמקום העבודה, כדי שבדיקת "אני במקום העבודה" תעבוד אצל כל הצוות | רק כשבעל עסק מסמן את מקום העבודה |
| שפה | כדי שההתראות יגיעו בשפה שלך | אוטומטית |
מה לא נשלח לשרת מהשעון האישי: סכומי שכר שלך, ההיסטוריה האישית, יעדים, משימות, ועבודות אחרות
שאינן של אותו עסק.
3. מיקום — בדיוק מה קורה
- המיקום שלך כעובד לא עוזב את המכשיר. כשבעל העסק הפעיל בדיקת מיקום, הטלפון שלך משווה את המיקום הנוכחי לקואורדינטות של מקום העבודה על המכשיר עצמו, ומחליט אם אפשר להתחיל משמרת. התוצאה שנשמרת היא רק "המשמרת התחילה" — לא איפה היית.
- המיקום שבעל העסק מסמן כן נשמר אצלנו. כשבעל עסק מסמן את כתובת העסק לפי מיקומו הנוכחי, הקואורדינטות, שם המקום והרדיוס נשמרים ברשומת העסק בשרת — אחרת הבדיקה לא הייתה יכולה לעבוד אצל שאר הצוות. זו הסיבה שאנחנו מצהירים בחנות על איסוף "מיקום מדויק".
- הרשאת "תמיד" מבוקשת רק אם הפעלת את התזכורת האופציונלית "עדיין בעבודה?", שמתריעה לך כשיצאת מאזור העבודה בזמן משמרת. ההתראה הזו נוצרת במכשיר שלך, והמיקום שהפעיל אותה לא נשלח לאיש.
- אפשר לבטל את הרשאת המיקום בכל רגע בהגדרות iOS. שאר האפליקציה תמשיך לעבוד.
4. איפה הנתונים נשמרים
הצד העסקי מאוחסן ב-Supabase (Supabase, Inc.), ספק אירוח מנוהל של מסד נתונים PostgreSQL.
הפרויקט שלנו פועל באזור פרנקפורט, גרמניה — בתוך האיחוד האירופי. כל התקשורת בין האפליקציה
לשרת מוצפנת (HTTPS/TLS).
Supabase משמשת אותנו כספק אירוח בלבד: היא מפעילה את מסד הנתונים ואת שירות ההתחברות עבורנו,
ולא עושה שימוש עצמאי בנתונים.
נוסף לכך:
- Apple — "התחברות עם Apple", ושליחת ההתראות דרך שירות APNs.
- Google — רק אם בחרת "המשך עם Google" כדרך התחברות.
אין באפליקציה ערכות פיתוח של פרסום, מדידה או אנליטיקה מצד שלישי.
5. מי רואה מה
ההרשאות אינן מוגדרות באפליקציה אלא במסד הנתונים עצמו (Row Level Security), כך שגם בקשה ישירה
לשרת לא תחזיר מידע שאינך אמור לראות:
- עובד רואה רק את העסקים שהוא מאושר בהם: את לוח המשמרות שפורסם, את חברי הצוות ואת השעות שלו עצמו. טיוטות של שבוע או של משמרת אינן נראות לו עד הפרסום.
- מנהל (בעל העסק, או עובד שהוגדר כמנהל) רואה את הצוות של העסק שלו, את הלוח כולל טיוטות, את בקשות ההצטרפות וההחלפה, ואת שעות העבודה של הצוות בעסק שלו.
- שכר ותעריפים — רק בעל העסק. שום עובד, כולל מנהל, אינו יכול לקרוא אותם.
- מספרי טלפון — רק מנהל של אותו עסק, והבעלים של המספר עצמו. חברי צוות אינם רואים את הטלפון של חבריהם.
- אף עסק לא רואה עסק אחר. אם אתה עובד בשני מקומות, כל אחד מהם רואה רק את המשמרות והשעות שלו.
- יומן השינויים של עסק (מי שינה מה ומתי) נקרא רק על ידי מנהל של אותו עסק, ואי אפשר לשנות אותו.
6. התראות
כשקורה משהו שרלוונטי לך — לוח פורסם, שובצת למשמרת, הוגשה בקשת הצטרפות — השרת שלנו כותב שורה
בתור התראות, ופונקציה שלנו בונה את הטקסט בשפה שלך ושולחת אותו ישירות לשירות ההתראות של Apple (APNs).
אין ספק התראות צד-שלישי (אין Firebase). ההתראה עוברת דרך שרתי Apple, כמו כל התראה ב-iOS, ולכן
טקסט ההתראה — שעשוי לכלול שם עסק או שם של אדם — נראה ל-Apple בדרך.
אפשר לכבות התראות בכל רגע בהגדרות iOS.
7. מה אנחנו לא עושים
- לא מוכרים ולא משכירים מידע לאף אחד.
- לא עוקבים אחריך בין אפליקציות או אתרים, ולא מעבירים מידע למפרסמים או למתווכי מידע. האפליקציה מצהירה על כך גם במניפסט הפרטיות שלה (
NSPrivacyTracking = false, ללא דומייני מעקב). - לא בונים פרופיל שיווקי ולא מקבלים החלטות אוטומטיות לגביך.
- לא שולחים דיוור פרסומי. המייל היחיד שנשלח הוא קוד ההתחברות שביקשת.
8. כמה זמן הדברים נשמרים
- תוכן עסקי (משמרות, שיבוצים, שעות, זמינות) נשמר כל עוד העסק קיים ואתה חבר בו, מפני שזה רישום התפעול של העסק.
- משמרת שנמחקה אינה נמחקת מיד מהשרת אלא מסומנת כמוסרת, כדי שמנהל יוכל לשחזר מחיקה בטעות.
- יומן השינויים (
change_log) — רישום של כל שינוי בטבלאות המרכזיות, כולל צילום השורה לפני ואחרי — נשמר 180 יום ואז נמחק אוטומטית מדי יום. ייתכן שהוא מכיל עותק של שורות שנגעו בך בתקופה הזו, והוא נגיש למנהל של אותו עסק בלבד. - יציאה מעסק (או הסרה על ידי הבעלים) מסירה אותך מהצוות, מוחקת את השיבוצים שלך למשמרות עתידיות, מבטלת בקשות ממתינות ומוחקת את בקשת ההצטרפות. מאותו רגע אינך רואה עוד את העסק. השעות שכבר עבדת נשארות אצל העסק כרישום נוכחות, כמו כרטיס עבודה.
- מחיקת חשבון מוחקת הכול — ראה בסמוך.
9. מחיקת החשבון
באפליקציה: הגדרות → "מחיקת החשבון שלי".
זו מחיקה אמיתית בשרת, לא סימון. מה שנמחק:
- החשבון עצמו ופרטיו (אימייל, שם, טלפון), והמכשירים הרשומים לקבלת התראות;
- החברות שלך בכל עסק, האילוצים שהגשת והשעות שרשמת;
- המשמרות העתידיות שנרשמת אליהן משוחררות חזרה למנהל לפני המחיקה, כדי שלא ייווצר חור בסידור;
- אם אתה בעל עסק — העסק נמחק יחד איתך, על הצוות, הלוח, השעות והשכר של כולם. המסך מזהיר על כך בשם העסק לפני שממשיכים, והפעולה בלתי הפיכה.
השעון האישי שבמכשיר — היסטוריה, יעדים ופרופילים — אינו נמחק בפעולה הזו, כי הוא מעולם לא היה
אצלנו. למחיקתו יש "הגדרות → מחיקת כל הנתונים".
10. הזכויות שלך
אם אתה נמצא באיחוד האירופי או בישראל, יש לך זכות לעיין במידע שנשמר עליך, לתקן אותו, למחוק אותו,
להגביל או להתנגד לעיבודו, ולקבל עותק ממנו בפורמט נגיש. את רוב זה אפשר לעשות ישירות באפליקציה
(עריכת השם, הטלפון והזמינות; יציאה מעסק; מחיקת חשבון). לכל בקשה אחרת אפשר לפנות אלינו בכתובת שבסעיף 12,
ונשיב תוך 30 יום.
הבסיס החוקי לעיבוד הוא קיום השירות שביקשת (ניהול המשמרות שלך בעסק שהצטרפת אליו)
והסכמתך בכל מקום שבו הדבר אופציונלי (טלפון, מיקום, התראות).
11. ילדים
האפליקציה מיועדת לניהול עבודה ושכר ואינה מיועדת לילדים. איננו אוספים ביודעין מידע על ילדים מתחת
לגיל 16. אם נודע לך שילד מסר לנו מידע, פנה אלינו ונמחק אותו.
11ב. תשלומים
המנוי "שעון הכסף פרימיום" נרכש ומנוהל דרך Apple בלבד. פרטי התשלום, אמצעי התשלום
וכתובת החיוב נשארים אצל Apple — אנחנו לא מקבלים אותם ולא רואים אותם. האפליקציה שומרת
על המכשיר רק אם יש מנוי פעיל, כדי לדעת מה לפתוח.
11א. תנאי השימוש
לצד מסמך זה חלים תנאי השימוש של האפליקציה, ובהם, בין היתר, ההבהרה שהאפליקציה אינה
מערכת שכר ואינה תחליף לרישומי נוכחות ושכר, והגדרת האחריות בין בעל העסק, העובד ובינינו:https://goldclockapp.com/terms
12. יצירת קשר
לשאלות, בקשות מידע או בקשת מחיקה: support@goldclockapp.com
13. שינויים במדיניות
אם המדיניות תשתנה, התאריך בראש המסמך יתעדכן, והשינויים יפורסמו באותה כתובת. שינוי מהותי
באופן השימוש בנתונים יוצג גם בתוך האפליקציה.
Privacy Policy — Money Clock (שעון הכסף)
Last updated: 18 September 2026
The app "Money Clock" (Hebrew: שעון הכסף), bundle identifier com.izzy.GoldClockl, is built and
operated by an independent developer, Yisrael Fried
("we", "us"). This document explains what the app collects, why, where it is stored, who can see it,
and how to delete all of it.
In short
- The personal clock — your shift history, pay, goals, work profiles and tasks — **stays on your device**. We never see it and never send it anywhere.
- The business side — a business, its team, its schedule and worked hours — is stored on our server, because several people have to see the same schedule. Our server is hosted on Supabase, in the Frankfurt (EU) region.
- We do not sell your data, do not share it with advertisers, and do not track you across apps or websites. There are no ads, no in-app purchases and no analytics tools in the app.
- You can delete your account from inside the app, and the deletion is real.
1. The personal clock — what never reaches us
The personal clock works with no account and no internet connection. Everything it stores — shift
history, hourly pay, currency, goals, work profiles, tasks, appearance settings and wallpaper — is
kept on the device itself (UserDefaults and the app's own folder) and shared with the widget and
the Apple Watch app through an on-device app group.
Shift history is also backed up to Apple's iCloud Key-Value Store, so it follows you to a new
phone. That backup goes to your own iCloud account, is controlled by Apple, and we have no
access to it and no way to read it.
"Settings → Delete all data" erases all of the above from the device and from that iCloud backup.
2. The business side — what is collected and why
The business side only opens if you choose to use it, and it asks you to sign in. From that point
the following data is collected:
| What | Why | When |
|---|---|---|
| Email address | To identify you at sign-in and to send you a sign-in code | At sign-in. With "Sign in with Apple" this may be Apple's private relay address |
| Display name | So the team and the manager know who signed up for a shift | When joining; can be changed |
| Phone number (optional) | So a manager can reach you about shifts | Only if you fill it in on the join form |
| User ID | The key that links your rows on the server | Created automatically at sign-in |
| Device ID | The device's push token and its vendor identifier (identifierForVendor), so a notification reaches the right phone and nobody else can hijack your notifications | When you allow notifications |
| Business content | Businesses, memberships, roles, shifts, assignments, swap requests, availability, templates, notes | While you use the app |
| Worked hours | Start, break and end times of shifts you clocked for a given business, so the manager can see who is working now and how many hours were worked | When you run the clock on a shift of that business |
| Precise workplace location | The coordinates and radius a business owner marks as the workplace, so the "am I at work" check works for the whole team | Only when a business owner marks the workplace |
| Language | So notifications arrive in your language | Automatically |
What is never sent to the server from the personal clock: your pay amounts, your personal
history, goals, tasks, or any job that does not belong to that business.
3. Location — exactly what happens
- Your own location as an employee never leaves your device. When a business owner has enabled the location check, your phone compares your current position with the workplace coordinates on the device itself and decides whether a shift may start. What gets stored is only "the shift started" — not where you were.
- The location a business owner marks is stored with us. When an owner marks the workplace from their current position, the coordinates, the place name and the radius are saved on the business record on the server — otherwise the check could not work for the rest of the team. This is why the App Store listing declares that precise location is collected.
- "Always" permission is requested only if you turn on the optional "Still at work?" reminder, which alerts you when you leave the work area during a shift. That alert is created on your own device, and the location that triggered it is not sent to anyone.
- You can revoke location permission at any time in iOS Settings. The rest of the app keeps working.
4. Where the data is stored
The business side is hosted on Supabase (Supabase, Inc.), a managed PostgreSQL hosting provider.
Our project runs in the Frankfurt, Germany region — inside the European Union. All traffic
between the app and the server is encrypted (HTTPS/TLS).
Supabase acts as our hosting provider only: it runs the database and the sign-in service on our
behalf and makes no independent use of the data.
In addition:
- Apple — Sign in with Apple, and delivery of notifications through the APNs service.
- Google — only if you chose "Continue with Google" as your way of signing in.
The app contains no third-party advertising, measurement or analytics SDKs.
5. Who can see what
Permissions are not enforced in the app but in the database itself (Row Level Security), so even
a direct request to the server cannot return data you are not meant to see:
- An employee sees only the businesses they are approved in: the published schedule, the team, and their own hours. Draft weeks and draft shifts are invisible until they are published.
- A manager (the owner, or a member marked as a manager) sees their own business's team, the schedule including drafts, join and swap requests, and the **worked hours of their team in that business**.
- Pay rates are readable by the business owner only. No employee, manager included, can read them.
- Phone numbers are visible to a manager of that business and to the owner of the number. Team members cannot see each other's phone numbers.
- No business can see another business. If you work in two places, each one sees only its own shifts and hours.
- A business's change log (who changed what, and when) is readable only by a manager of that business, and cannot be altered by anyone.
6. Notifications
When something relevant happens — a schedule is published, you are assigned to a shift, someone asks
to join — our server writes a row to a notification queue, and our own function composes the text in
your language and sends it directly to Apple's notification service (APNs). There is no
third-party push provider (no Firebase). The notification travels through Apple's servers, like every
iOS notification, so its text — which may contain a business name or a person's name — is visible to
Apple on the way. You can turn notifications off at any time in iOS Settings.
7. What we do not do
- We do not sell or rent your data to anyone.
- We do not track you across apps or websites, and we pass nothing to advertisers or data brokers. The app declares this in its privacy manifest as well (
NSPrivacyTracking = false, no tracking domains). - We do not build marketing profiles and make no automated decisions about you.
- We send no marketing email. The only email we send is the sign-in code you asked for.
8. How long things are kept
- Business content (shifts, assignments, hours, availability) is kept for as long as the business exists and you are a member of it, because it is that business's operational record.
- A deleted shift is not erased from the server immediately but marked as removed, so a manager can undo an accidental deletion.
- The change log (
change_log) — a record of every change to the main tables, including a snapshot of the row before and after — is kept for 180 days and then deleted automatically by a daily job. It may contain a copy of rows concerning you during that period, and it is readable only by a manager of that business. - Leaving a business (or being removed by its owner) takes you off the team, deletes your assignments to future shifts, cancels pending requests and deletes your join request. From that moment you no longer see the business. The hours you already worked stay with the business as an attendance record, like a timesheet.
- Deleting your account removes everything — see below.
9. Deleting your account
In the app: Settings → "Delete my account".
This is a real server-side deletion, not a flag. What is deleted:
- the account itself and its details (email, name, phone), and the devices registered for notifications;
- your membership in every business, the availability you submitted and the hours you recorded;
- future shifts you had signed up for are given back to the manager before deletion, so the schedule is not left with a hole;
- if you are a business owner, the business is deleted along with you — its team, schedule, hours and pay settings, for everyone who works there. The screen names the business and warns you before you go ahead, and the action cannot be undone.
The personal clock on your device — history, goals and profiles — is not deleted by this action,
because it was never with us. To erase that, use "Settings → Delete all data".
10. Your rights
If you are in the European Union or in Israel, you have the right to access the data held about you,
correct it, delete it, restrict or object to its processing, and receive a copy of it in a portable
format. Most of this can be done directly in the app (edit your name, phone and availability; leave a
business; delete your account). For anything else, contact us at the address in section 12 and we
will reply within 30 days.
The legal basis for processing is performance of the service you asked for (managing your shifts
in the business you joined) and your consent wherever something is optional (phone number,
location, notifications).
11. Children
The app is made for managing work and pay and is not directed at children. We do not knowingly
collect data about children under 16. If you become aware that a child has given us data, contact us
and we will delete it.
11b. Payments
The "Money Clock Premium" subscription is bought and managed through Apple only. Payment
details, the payment method and the billing address stay with Apple — **we never receive or see
them**. The app keeps on the device only whether a subscription is active, to know what to unlock.
11a. Terms of Use
The App's Terms of Use apply alongside this document. Among other things they set out
that the App is not a payroll system and not a substitute for attendance and payroll records,
and how responsibility is divided between a business owner, an employee and us:https://goldclockapp.com/terms
12. Contact
For questions, data requests or deletion requests: support@goldclockapp.com
13. Changes to this policy
If this policy changes, the date at the top will be updated and the new version published at the same
address. A material change in how data is used will also be shown inside the app.