Privacy Policy — TaharaSmart
Current service status: paid subscriptions, billing, trial activation, referral credits and Email/SMS delivery are not yet active. The provisions about them apply when those services are offered and activated; they do not authorise a purchase or charge. Your statutory rights remain protected.
Contents
1. Controller and scope
The controller of information collected through TaharaSmart is יהלום זקס. Privacy enquiries and rights requests: contact@taharasmart.com.
This policy covers the public website, authentication, personal account, calendar, payments, reminders, feedback and referral programme. It describes processing by the operator and its providers. Independent third-party services, such as your Google account or email service, are also governed by those parties' policies.
2. Sensitive information and your choice to provide it
Information may reveal private family and intimate matters, religious practice or belief, bodily or health information, including information about cycles, pregnancy or personal circumstances where entered, and location. Some is “specially sensitive information” under Israeli law and may be special-category or consumer health data under other laws.
Providing information is not legally mandatory unless we expressly identify a specific statutory requirement. It is your choice. However, basic identification is necessary for a personal account, required data are necessary to calculate the calendar, and a phone number is necessary for SMS. You need not provide free text, precise location or additional contact details beyond what the chosen function requires. An alternative to precise location is offered where the function and supported region allow.
We request separate, express consent to processing sensitive information for the service. Use is not conditional on advertising consent or supplying information not objectively necessary for the requested function.
3. Account and authentication details
Google sign-in supplies a unique account identifier, email address and verification status, and a name and profile image where provided under the permissions. We also retain an internal user identifier, creation and update dates, account preferences and name details edited by the user.
These details enable account creation, repeat authentication, ownership association, profile display and service communication. We do not receive your Google password and ordinary sign-in does not request permission to read Gmail, Google Drive or Google Calendar.
This basic information may be received before the post-login consent screen. Notice of collection and a policy link are provided before the Google button. The created account information will not activate a sensitive calendar before the required consent is received.
4. Calendar data, settings and calculations
We store entered events, dates and times, Onot, event types, Bedikot results or markings where entered, titles, notes and personal instructions or adjustments. Information may include Taharah stages, separation dates, Hefsek Taharah, Shivah Nekiyim, Tevilah and other personal information voluntarily entered in available fields.
We also retain the selected Minhag, rule version, effective dates and personal settings, including personal circumstances where entered. Being able to save information does not mean the system can automatically determine its implications.
We process these data to create the calendar and calculated results, show history and check consistency. Calculated results derive from source facts and settings; they do not confirm that an event occurred. Calculated information may itself be personal and sensitive.
5. Location, time and language
To calculate times, we process city, country, time zone and coordinates according to the location-selection method. Device location is requested only after an express action and browser permission. We do not continuously collect movement routes in the background.
When location identification is requested, coordinates pass through our server to OpenStreetMap's Nominatim service to resolve a place name. We do not intentionally attach your name, email address or calendar content. Coordinates alone may be personal information; the external service may process technical request details under its terms.
Coordinates and time zones may be stored in settings and historical events for calculation and replay. There is no continuous tracking, but selected location information is not necessarily deleted when the request ends. Location lookup results may be briefly cached on the server to reduce repeat requests.
Language preference is retained if you choose to save it. Otherwise, the browser's language preference is used. Language is not used to determine a Minhag or medical condition.
6. Payments, subscriptions and contractual evidence
We process plans, prices and price versions, trial dates, payment authorisations, billing and renewal dates, cancellations, refunds, payment status, processor transaction and customer identifiers, and records needed for accounting documents. Depending on the provider, limited payment-method details may be retained for identification, such as card type and last four digits.
The service does not collect payment cards or perform active commercial billing. Consent to data processing is not consent to a charge.
7. Reminders and contact details
Email and SMS reminder delivery services are not currently enabled. Personal information is not transferred to delivery providers for these services.
Ordinary reminders have limited content. Service messages, sender identity or links may nevertheless reveal system use. Sending, delivery and failure statuses and handling data are retained as needed; logs need not contain complete halachic event content.
You can change or disable reminders in settings. Necessary account, security, billing and rights communications are provided as needed, separately from marketing.
8. Feedback, support and legal enquiries
Feedback is stored separately from the calendar. It includes enquiry content, subject and category, the name and email associated with the account, a reference, handling status and relevant correspondence. If the account lacks a suitable name, one may be requested solely for the enquiry.
With optional consent, limited technical details such as browser and operating-system families, display size and application version may be attached for diagnosis. Authorised personnel may read the enquiry; sending it does not automatically grant access to the whole calendar. Do not attach another person's information or intimate information unnecessary for handling. Ordinary help-centre searches are not personal enquiries to the team.
Cancellation, access or deletion requests may include identification and evidence permitted and necessary for verification. We do not require an identity-document photograph by default where less intrusive verification is possible.
9. Referral programme
We process referral codes, referral-account associations, registration and qualifying-payment dates, credit balances and information needed to prevent fraud. Referrers see aggregate information or balances only, without the referred user's name, email, phone number or account content.
Despite limited display, a referrer who knows whom they sent a link to, or has few referrals, may infer information from the timing of balance changes. This does not authorise disclosure of the user's identity or private content.
10. Technical information, Cookies and device storage
Website systems and infrastructure providers process technical information needed for connections, security and diagnosis, such as IP addresses, request times, connection identifiers, browser or device details and error data. We work to avoid logging sensitive calendar content and minimise unnecessary information.
Cookies support authentication and connection security, with limited local storage for display preferences, installation prompts and technical coordination between tabs. Displayed calendar information may reside temporarily in tab memory; this configuration does not offer permanent calendar storage for offline use.
We do not operate behavioural advertising pixels, session recording or deliberate cross-site tracking. See the Cookies and Local Storage page for details. Authentication providers or external websites you open may use their own technologies under their policies.
11. Purposes and legal bases
Account processing, service supply, billing and enquiries serve the contract and requested service; tax and accounting records are retained for legal obligations; security, misuse prevention and protection of rights use an appropriate legal basis with required proportionality. In Israel, we comply with applicable consent, notice and lawful-purpose requirements.
Where the GDPR or UK GDPR applies, ordinary account and service details are processed insofar as necessary to perform a contract; legally required information is processed on that obligation; and security and rights protection may rely on legitimate interests after balancing users' rights. Service-related calendar and sensitive data processing also relies on explicit consent to special-category processing. The contract alone does not replace the appropriate condition for such processing. Sensitive information needed for legal proceedings will be handled only where an appropriate condition and legal basis also exist.
We will not use calendar data for targeted advertising, trading in data, training artificial-intelligence models or external research outside the requested service. Technical improvements may use limited operational information, test data or information anonymised so identification is not reasonably possible; removing a name alone does not anonymise information.
12. Recipients
Hosting, database, authentication, messaging, payment and location providers process information to the extent required for their role. Providers, processing purposes and locations appear on the “Service Providers and Data Transfers” page, which forms part of this policy.
Authorised support or infrastructure personnel may receive limited access when necessary and permitted for troubleshooting, security, recovery or legal obligations. Admin status in the interface does not grant calendar-content access. Special infrastructure access, where necessary, will be limited by purpose, scope and authorised personnel and recorded according to risk and law. There is no promise that no person can ever technically access data.
Professional advisers receive only information necessary for advice, subject to confidentiality. Authorities or parties to proceedings receive information only under a valid legal obligation or authority and to the necessary extent. Transfer of business operations does not authorise unrestricted changes to processing purposes; we will give notice and obtain fresh consent where required.
We do not sell personal information or share it for cross-context behavioural advertising. We do not disclose the calendar, Minhag, location or fact of service use to advertisers or data brokers to create advertising profiles.
13. Processing outside Israel
Some information may be stored or processed outside Israel through the providers and processing countries in the provider list. Primary hosting location is not necessarily the only location for support, backups or delivery.
Transfers will follow applicable law, including Israeli transfer conditions and required commitments. Where the GDPR or UK GDPR applies, we will use a valid mechanism, such as an applicable adequacy decision or appropriate contractual commitments and supplementary safeguards where needed. General acceptance of terms will not be treated as unrestricted consent to transfer sensitive information anywhere.
You may request details of processing countries and relevant transfer mechanisms and a copy or summary of safeguards, subject to redacting commercial or security information unnecessary for exercising the right.
14. Retention periods
Account and calendar data are retained as long as necessary for active service or at the user's request. Subscription cancellation or trial expiry is neither automatic deletion nor permission for indefinite unnecessary retention. We periodically assess inactive-account retention considering inactivity duration, sensitivity, user requests and reasonable likelihood of return. Before inactivity-based deletion, notice will allow a copy request or continued retention where appropriate, unless law or security requires otherwise.
Service enquiries are retained for handling, follow-up and related disputes; delivery data and logs to the extent and duration needed for security, diagnosis and law; billing evidence, tax documents, consent and cancellation records under retention duties and a defined legal need. Keeping a receipt does not justify retaining the entire calendar.
When a purpose ends and no other lawful basis exists, information will be deleted or anonymised so reasonable identification is not possible. A legal hold will be limited to the information and time needed for those proceedings, not indiscriminately cover the entire account.
Active-system deletion follows requests and statutory deadlines. Deletions and consent withdrawals must be reapplied after recovery. A shorter retention limit applies wherever legally required.
15. Consent, withdrawal and deletion
You can withdraw consent to consent-based processing through the data rights page or privacy email. Withdrawal is easy and accessible and does not require a subscription purchase. Reminders, location or optional processing can be disabled separately where possible.
Withdrawing consent to sensitive core calculation may prevent further calendar use because required information cannot be omitted from the calculation. We will stop consent-based processing, address future-charge cancellation and any refund due, and determine permitted deletion or retention. Withdrawal does not affect earlier lawful processing and does not permit continued sensitive processing merely because subscription time remains.
Account deletion and other requests are described on the Data Rights and Account Deletion page. Non-paying accounts may also exercise rights. We will not require a new account to submit a request.
16. Rights under Israeli and other laws
Under Israeli law, you may request access to information about you and correction or deletion of inaccurate, incomplete, unclear or outdated information, subject to statutory conditions. You may also request account deletion under our policy. Additional rights, including deletion or minimisation duties for information transferred from the European Economic Area, will be honoured where applicable.
Where the GDPR or UK GDPR applies, rights may include access and copies, rectification, erasure, restriction, portability, objection, withdrawal and rights concerning automated decisions with legal or similarly significant effects. Calendar calculations do not serve our decisions about your legal rights and are not binding instructions; we will explain calculation methods as required for the service and law.
We will respond without undue delay within mandatory deadlines, generally one month for GDPR or UK GDPR requests, with extensions only on permitted conditions and notice. Shorter required deadlines apply. Identity verification will be proportionate; refusals and complaint or appeal options will be communicated according to law.
In US states granting applicable privacy rights, we also honour access, deletion, correction, portability, consent withdrawal and appeal rights. Unlawful discrimination for exercising rights is prohibited. Authorised agents may use the same channel subject to appropriate verification. Dedicated policies apply to consumer health data in Washington and Nevada.
17. Security and incidents
We use technical and organisational safeguards designed for the information's sensitivity: permissions, account isolation, secure communications, minimisation and access and operational procedures. No system is entirely immune; absolute security or end-to-end encryption is not promised.
On suspected incidents, we will investigate, mitigate harm, correct and document. Authorities and affected individuals will be notified where required within mandatory deadlines. Exercise of rights will not be conditional on waiving incident-related claims.
18. Minors
The service is intended for adults aged 18 and over. We do not knowingly seek minors' information. If we learn an account fails the age requirement, we will assess restrictions and deletion under law without collecting excessive identification. Suspected collection can be reported through the privacy email.
19. Policy changes
The update date and version appear at the beginning. Material changes will be appropriately communicated before taking effect where required. A new processing purpose or sensitive-data use will not begin on silence where fresh consent is necessary. Accepted versions and material-change evidence will be retained for contractual enquiries.
20. Contact, representatives and complaints
Enquiries and appeals: contact@taharasmart.com. You need not describe intimate halachic information to submit a rights request.
Privacy contact: יהלום זקס, contact@taharasmart.com.
You may complain to Israel's Privacy Protection Authority. Where other laws apply, you may also contact the competent supervisory authority, including the authority in your European country of residence or the UK ICO. These rights do not depend on first exhausting enquiries with us.

