Legal document

Privacy policy.

What we collect, why, where it's stored, and who sees it. The short answer: only what's needed to provide the service — and your data is never sold to anyone, ever.

Last updated: September 27, 2026

We collect the minimumOnly what's needed to contact you and provide service. Ad measurement only with your consent.
We sell nothingYour data is never sold or rented. Information is shared with an advertising platform only if you’ve consented to tracking.
You're in controlView, edit, or delete — in one email. Disconnect linked accounts — anytime.

About this policy

This policy explains how "Revoza" (REVOZA), operating at revoza.co.il, collects and processes data — of site visitors, those who leave details, customers, and social media accounts clients connect to our social services. It applies to the website and our management systems, and is part of Terms of Use.

Question? Request? [email protected] — we respond during business hours, Sun–Thu 8:30 to 22:00.

What information we collect

Information you provide us

  • Contact form: Name, phone, business type, and message if you attached one. That’s all the form sends.
  • Clients: contact details, business details, and materials provided for building the site (texts, images, logo).
  • Client area: email address and password. The password is stored encrypted (hash) — even we can't read it.

Automatically collected information

  • Aggregated usage statistics: counting page views to understand site performance. We do not build personal profiles. The only advertising measurement tool, TikTok Pixel, loads only after you have approved it (see Cookies and Advertising Measurement)).
  • Security logs: IP addresses of login attempts to the admin systems, for intrusion protection.

How we use your information

  • Get back to you when you reach out, and deliver the service you ordered.
  • To operate, secure, and improve our site and systems.
  • Publish content on social media on behalf of a client who requested and explicitly approved it.
  • To comply with legal obligations.

What we don't do: we don't sell information, don't rent it out, don't hand it over to mailing lists, and don't send spam.

Connecting TikTok and Instagram accounts

When a client orders social media management, the connection to accounts is made through the platforms' official API interfaces — TikTok (TikTok for Developers) and Instagram (Meta) — via an explicit authorization process (OAuth) in which the account owner personally approves access from within the platform.

  • What we store: Access tokens issued by the platform, the account ID and username, and the content we create and publish for the client (texts, images, publish times).
  • What this is used for: Only for publishing content the client has approved, at the agreed times, and for reading the account data required to do so. Not for collecting information about other visitors and not for any other purpose.
  • Where it’s stored: on our servers only (see the security section), in files with restricted access. Tokens are never shared with any third party.
  • Disconnect: You can revoke access at any time — from TikTok or Instagram security settings, or by requesting it from us. Upon disconnect, the tokens we hold stop working and we delete them.
  • Use is also subject to the platforms' policies: TikTok · Instagram.

Artificial intelligence

Some of our internal tools use AI. Guiding principle: The language model that summarizes inquiries and drafts content runs locally, on our server — customer inquiries are not sent to external AI services. For image generation we use an external service (fal.ai) to which only the image description is sent — never personal details of inquirers or customers.

Cookies & ad measurement

Essential cookies: A login (Session) cookie in the admin and customer areas. It is required for account security, time‑limited, and deleted on exit. Additionally, your choice regarding ad measurement (a cookie and browser record named rz_consent) is stored so we don't ask again on every page. It is kept for up to one year.

Ad measurement, only with consent: On your first visit to the site, a request appears to approve the TikTok Pixel, a TikTok measurement tool that helps us know which ads bring visitors. Until you approve, it does not load at all. If you approve, it may use cookies and TikTok identifiers, and if you arrived from an ad click, the click ID (ttclid) is also stored for thirty days.

Lead reporting, only with consent: If you consented to measurement and submitted details in the form, our server reports to TikTok that a lead was received, to measure which campaigns bring leads. Sent: phone number hashed (SHA-256, not the number itself), IP address, browser type, page URL, and click ID if present. Without consent, this report is not sent.

Data sent to TikTok is processed according to its privacy policy. You can change your choice at any time: Cookie settings. Beyond that, there are no profiling cookies or additional tracking tools on the site.

Subcontractors

We work with several operational providers, each receiving only the minimum data needed for its role:

  • Server hosting: OVH (European Union) — the server hosting the site and systems.
  • Backups: Cloudflare R2 — encrypted backup copies in transit, retained for 30 days.
  • Image generation: fal.ai — accepts only image descriptions.
  • Social platforms: TikTok and Meta — as part of the API connections described above.
  • Ad measurement: TikTok (Pixel and server‑side lead reporting), only after you’ve approved measurement, to measure campaign performance.

We don't share personal data with other providers, and we don't sell data to anyone.

Information security

  • All traffic is encrypted (HTTPS/TLS), including between our internal systems.
  • The server is hardened: firewall, intrusion attempt protection (automatic blocking), ongoing security updates, and minimal permissions for every component.
  • Passwords are stored only as a cryptographic hash. Access to admin systems is restricted and logged in an audit trail.
  • Automatic daily backup, including an external copy, so a glitch won't delete your information.

No system is one hundred percent immune, but should a security incident ever affect you, we will notify you and the authorities as the law requires.

How long data is stored

  • Inquiries: as long as they are relevant for handling, and for no more than three years — unless you requested deletion earlier.
  • Active client data: For the duration of the engagement, and afterward as required for statutory accounting needs.
  • Network access tokens: until the connection is disconnected or the service ends — whichever comes first.
  • Security logs: a limited period required to protect the systems.

Your rights

Under the Privacy Protection Law, 1981, you have the right to access information stored about you, to request its correction or deletion. Send a request to [email protected] and we will process it promptly, within 30 days at most. Deletion is subject to legal retention obligations (e.g., accounting records).

Minors

Our services are intended for business owners and are not directed at minors under 18. We do not knowingly collect information about minors; if we become aware of such information, we will delete it.

Policy changes

We'll update the policy when we add services or when the law changes. The binding version is the one on this page, with the update date at the top. A material change will also be communicated directly to existing customers.

Contact us

For any privacy questions: [email protected] · 051-544-9553 · Contact page.