שעון הכסףהורדה

מדיניות פרטיות — שעון הכסף (Money Clock)

עדכון אחרון: 18 בספטמבר 2026

האפליקציה "שעון הכסף" (Money Clock), מזהה com.izzy.GoldClockl, פותחה ומופעלת על ידי מפתח עצמאי,
ישראל פריד (Yisrael Fried) ("אנחנו", "אנו"). המסמך הזה מסביר מה האפליקציה אוספת,
למה, איפה זה נשמר, מי יכול לראות את זה ואיך מוחקים את הכול.

בקצרה

1. השעון האישי — מה שלא מגיע אלינו

השעון האישי עובד בלי חשבון ובלי חיבור לאינטרנט. כל מה שהוא שומר — היסטוריית המשמרות, השכר לשעה,
המטבע, היעדים, פרופילי העבודה, המשימות, הגדרות העיצוב ותמונת הרקע — נשמר במכשיר עצמו
(UserDefaults ותיקיית האפליקציה), ומשותף עם הווידג׳ט ועם אפליקציית ה-Apple Watch דרך קבוצת
אפליקציות משותפת במכשיר.

היסטוריית המשמרות מגובה גם ל-iCloud Key-Value Store של Apple, כדי שתחזור אליך אם תחליף מכשיר.
הגיבוי הזה הולך לחשבון ה-iCloud שלך, נשלט על ידי Apple, ואנחנו לא ניגשים אליו ואין לנו אפשרות לקרוא אותו.

"הגדרות → מחיקת כל הנתונים" מוחקת את כל האמור לעיל מהמכשיר ומהגיבוי ב-iCloud.

2. הצד העסקי — מה נאסף ולמה

הצד העסקי נפתח רק אם בחרת להשתמש בו, והוא מבקש התחברות. מרגע זה נאספים הנתונים הבאים:

| מה | למה | מתי |
|---|---|---|
| כתובת אימייל | לזהות אותך בהתחברות ולשלוח קוד כניסה | בהתחברות. ב"התחברות עם Apple" זו יכולה להיות כתובת ההעברה הפרטית של Apple |
| שם תצוגה | כדי שהצוות והמנהל ידעו מי נרשם למשמרת | בהצטרפות, וניתן לשינוי |
| מספר טלפון (רשות) | כדי שהמנהל יוכל ליצור איתך קשר בענייני משמרות | רק אם מילאת אותו בטופס ההצטרפות |
| מזהה משתמש | המפתח שמקשר בין כל הרשומות שלך בשרת | נוצר אוטומטית בהתחברות |
| מזהה מכשיר | אסימון ההתראות של המכשיר ומזהה היצרן (identifierForVendor), כדי לשלוח התראה למכשיר הנכון ולמנוע מאדם אחר לחטוף את ההתראות שלך | כשאתה מאשר התראות |
| תוכן עסקי | עסקים, חברות בצוות, תפקידים, משמרות, שיבוצים, בקשות החלפה, אילוצי זמינות, תבניות, הערות | בזמן השימוש |
| שעות עבודה | זמני התחלה, הפסקה וסיום של משמרות שנרשמו דרך השעון בעסק מסוים, כדי שהמנהל יראה מי עובד עכשיו וכמה שעות נעשו | כשאתה מפעיל שעון על משמרת של אותו עסק |
| מיקום מדויק של מקום העבודה | הקואורדינטות והרדיוס שבעל העסק מסמן כמקום העבודה, כדי שבדיקת "אני במקום העבודה" תעבוד אצל כל הצוות | רק כשבעל עסק מסמן את מקום העבודה |
| שפה | כדי שההתראות יגיעו בשפה שלך | אוטומטית |

מה לא נשלח לשרת מהשעון האישי: סכומי שכר שלך, ההיסטוריה האישית, יעדים, משימות, ועבודות אחרות
שאינן של אותו עסק.

3. מיקום — בדיוק מה קורה

4. איפה הנתונים נשמרים

הצד העסקי מאוחסן ב-Supabase (Supabase, Inc.), ספק אירוח מנוהל של מסד נתונים PostgreSQL.
הפרויקט שלנו פועל באזור פרנקפורט, גרמניה — בתוך האיחוד האירופי. כל התקשורת בין האפליקציה
לשרת מוצפנת (HTTPS/TLS).

Supabase משמשת אותנו כספק אירוח בלבד: היא מפעילה את מסד הנתונים ואת שירות ההתחברות עבורנו,
ולא עושה שימוש עצמאי בנתונים.

נוסף לכך:

אין באפליקציה ערכות פיתוח של פרסום, מדידה או אנליטיקה מצד שלישי.

5. מי רואה מה

ההרשאות אינן מוגדרות באפליקציה אלא במסד הנתונים עצמו (Row Level Security), כך שגם בקשה ישירה
לשרת לא תחזיר מידע שאינך אמור לראות:

6. התראות

כשקורה משהו שרלוונטי לך — לוח פורסם, שובצת למשמרת, הוגשה בקשת הצטרפות — השרת שלנו כותב שורה
בתור התראות, ופונקציה שלנו בונה את הטקסט בשפה שלך ושולחת אותו ישירות לשירות ההתראות של Apple (APNs).
אין ספק התראות צד-שלישי (אין Firebase). ההתראה עוברת דרך שרתי Apple, כמו כל התראה ב-iOS, ולכן
טקסט ההתראה — שעשוי לכלול שם עסק או שם של אדם — נראה ל-Apple בדרך.
אפשר לכבות התראות בכל רגע בהגדרות iOS.

7. מה אנחנו לא עושים

8. כמה זמן הדברים נשמרים

9. מחיקת החשבון

באפליקציה: הגדרות → "מחיקת החשבון שלי".

זו מחיקה אמיתית בשרת, לא סימון. מה שנמחק:

השעון האישי שבמכשיר — היסטוריה, יעדים ופרופילים — אינו נמחק בפעולה הזו, כי הוא מעולם לא היה
אצלנו. למחיקתו יש "הגדרות → מחיקת כל הנתונים".

10. הזכויות שלך

אם אתה נמצא באיחוד האירופי או בישראל, יש לך זכות לעיין במידע שנשמר עליך, לתקן אותו, למחוק אותו,
להגביל או להתנגד לעיבודו, ולקבל עותק ממנו בפורמט נגיש. את רוב זה אפשר לעשות ישירות באפליקציה
(עריכת השם, הטלפון והזמינות; יציאה מעסק; מחיקת חשבון). לכל בקשה אחרת אפשר לפנות אלינו בכתובת שבסעיף 12,
ונשיב תוך 30 יום.

הבסיס החוקי לעיבוד הוא קיום השירות שביקשת (ניהול המשמרות שלך בעסק שהצטרפת אליו)
והסכמתך בכל מקום שבו הדבר אופציונלי (טלפון, מיקום, התראות).

11. ילדים

האפליקציה מיועדת לניהול עבודה ושכר ואינה מיועדת לילדים. איננו אוספים ביודעין מידע על ילדים מתחת
לגיל 16. אם נודע לך שילד מסר לנו מידע, פנה אלינו ונמחק אותו.

11ב. תשלומים

המנוי "שעון הכסף פרימיום" נרכש ומנוהל דרך Apple בלבד. פרטי התשלום, אמצעי התשלום
וכתובת החיוב נשארים אצל Apple — אנחנו לא מקבלים אותם ולא רואים אותם. האפליקציה שומרת
על המכשיר רק אם יש מנוי פעיל, כדי לדעת מה לפתוח.

11א. תנאי השימוש

לצד מסמך זה חלים תנאי השימוש של האפליקציה, ובהם, בין היתר, ההבהרה שהאפליקציה אינה
מערכת שכר ואינה תחליף לרישומי נוכחות ושכר, והגדרת האחריות בין בעל העסק, העובד ובינינו:
https://goldclockapp.com/terms

12. יצירת קשר

לשאלות, בקשות מידע או בקשת מחיקה: support@goldclockapp.com

13. שינויים במדיניות

אם המדיניות תשתנה, התאריך בראש המסמך יתעדכן, והשינויים יפורסמו באותה כתובת. שינוי מהותי
באופן השימוש בנתונים יוצג גם בתוך האפליקציה.



Privacy Policy — Money Clock (שעון הכסף)

Last updated: 18 September 2026

The app "Money Clock" (Hebrew: שעון הכסף), bundle identifier com.izzy.GoldClockl, is built and
operated by an independent developer, Yisrael Fried
("we", "us"). This document explains what the app collects, why, where it is stored, who can see it,
and how to delete all of it.

In short

1. The personal clock — what never reaches us

The personal clock works with no account and no internet connection. Everything it stores — shift
history, hourly pay, currency, goals, work profiles, tasks, appearance settings and wallpaper — is
kept on the device itself (UserDefaults and the app's own folder) and shared with the widget and
the Apple Watch app through an on-device app group.

Shift history is also backed up to Apple's iCloud Key-Value Store, so it follows you to a new
phone. That backup goes to your own iCloud account, is controlled by Apple, and we have no
access to it and no way to read it.

"Settings → Delete all data" erases all of the above from the device and from that iCloud backup.

2. The business side — what is collected and why

The business side only opens if you choose to use it, and it asks you to sign in. From that point
the following data is collected:

| What | Why | When |
|---|---|---|
| Email address | To identify you at sign-in and to send you a sign-in code | At sign-in. With "Sign in with Apple" this may be Apple's private relay address |
| Display name | So the team and the manager know who signed up for a shift | When joining; can be changed |
| Phone number (optional) | So a manager can reach you about shifts | Only if you fill it in on the join form |
| User ID | The key that links your rows on the server | Created automatically at sign-in |
| Device ID | The device's push token and its vendor identifier (identifierForVendor), so a notification reaches the right phone and nobody else can hijack your notifications | When you allow notifications |
| Business content | Businesses, memberships, roles, shifts, assignments, swap requests, availability, templates, notes | While you use the app |
| Worked hours | Start, break and end times of shifts you clocked for a given business, so the manager can see who is working now and how many hours were worked | When you run the clock on a shift of that business |
| Precise workplace location | The coordinates and radius a business owner marks as the workplace, so the "am I at work" check works for the whole team | Only when a business owner marks the workplace |
| Language | So notifications arrive in your language | Automatically |

What is never sent to the server from the personal clock: your pay amounts, your personal
history, goals, tasks, or any job that does not belong to that business.

3. Location — exactly what happens

4. Where the data is stored

The business side is hosted on Supabase (Supabase, Inc.), a managed PostgreSQL hosting provider.
Our project runs in the Frankfurt, Germany region — inside the European Union. All traffic
between the app and the server is encrypted (HTTPS/TLS).

Supabase acts as our hosting provider only: it runs the database and the sign-in service on our
behalf and makes no independent use of the data.

In addition:

The app contains no third-party advertising, measurement or analytics SDKs.

5. Who can see what

Permissions are not enforced in the app but in the database itself (Row Level Security), so even
a direct request to the server cannot return data you are not meant to see:

6. Notifications

When something relevant happens — a schedule is published, you are assigned to a shift, someone asks
to join — our server writes a row to a notification queue, and our own function composes the text in
your language and sends it directly to Apple's notification service (APNs). There is no
third-party push provider (no Firebase). The notification travels through Apple's servers, like every
iOS notification, so its text — which may contain a business name or a person's name — is visible to
Apple on the way. You can turn notifications off at any time in iOS Settings.

7. What we do not do

8. How long things are kept

9. Deleting your account

In the app: Settings → "Delete my account".

This is a real server-side deletion, not a flag. What is deleted:

The personal clock on your device — history, goals and profiles — is not deleted by this action,
because it was never with us. To erase that, use "Settings → Delete all data".

10. Your rights

If you are in the European Union or in Israel, you have the right to access the data held about you,
correct it, delete it, restrict or object to its processing, and receive a copy of it in a portable
format. Most of this can be done directly in the app (edit your name, phone and availability; leave a
business; delete your account). For anything else, contact us at the address in section 12 and we
will reply within 30 days.

The legal basis for processing is performance of the service you asked for (managing your shifts
in the business you joined) and your consent wherever something is optional (phone number,
location, notifications).

11. Children

The app is made for managing work and pay and is not directed at children. We do not knowingly
collect data about children under 16. If you become aware that a child has given us data, contact us
and we will delete it.

11b. Payments

The "Money Clock Premium" subscription is bought and managed through Apple only. Payment
details, the payment method and the billing address stay with Apple — **we never receive or see
them**. The app keeps on the device only whether a subscription is active, to know what to unlock.

11a. Terms of Use

The App's Terms of Use apply alongside this document. Among other things they set out
that the App is not a payroll system and not a substitute for attendance and payroll records,
and how responsibility is divided between a business owner, an employee and us:
https://goldclockapp.com/terms

12. Contact

For questions, data requests or deletion requests: support@goldclockapp.com

13. Changes to this policy

If this policy changes, the date at the top will be updated and the new version published at the same
address. A material change in how data is used will also be shown inside the app.