astrocommerce
English

מדיניות פרטיות

עודכן לאחרונה: 2 באוקטובר 2026

בקצרה: אנחנו קוראים את נתוני החנות, הפרסום והאנליטיקס שחיברתם, כדי לתת לכם דוחות, תשובות והמלצות שיווק. הגישה היא לקריאה בלבד. אנחנו לא שומרים שמות, אימיילים, טלפונים או כתובות של הלקוחות שלכם, לא מוכרים מידע ולא משתמשים בו לפרסום. אפשר לנתק כל חיבור בכל רגע, והנתונים שיובאו ממנו נמחקים.

1. מי אנחנו

AstroCommerce (astrofiy.com) הוא שירות לבעלי חנויות אונליין. מחברים את החנות ואת חשבונות הפרסום, ושואלים על העסק בבוט בטלגרם או בסביבת העבודה באתר app.astrofiy.com.

המדיניות הזו מסבירה איזה מידע אנחנו אוספים, למה, עם מי הוא משותף, כמה זמן הוא נשמר ומה הזכויות שלכם.

בכל שאלה על פרטיות אפשר לכתוב לנו: [email protected]

2. פרטי החשבון והעסק

  • כתובת האימייל שלכם. אליה נשלח קוד ההתחברות. אין סיסמאות.
  • אם אתם משתמשים בבוט: מזהה המשתמש ומזהה הצ׳אט שלכם בטלגרם.
  • שם העסק, השפה, אזור הזמן והמטבע.
  • התשובות שלכם לשאלות ההיכרות של הבוט, כמו תחום העסק, מי הלקוחות, ערוצי המכירה, זמני משלוח, שיווק ותקציב פרסום. אפשר לדלג על כל שאלה.

3. נתוני החנות (WooCommerce או Shopify)

כשאתם מחברים חנות, אנחנו מייבאים את ההזמנות של עד 12 החודשים האחרונים, ואחר כך מעדכנים אותן כל כמה דקות. מכל הזמנה נשמרים:

  • תאריך, סטטוס ומטבע.
  • סכום ההזמנה, מע״מ, משלוח והחזרים כספיים.
  • שורות ההזמנה: שם המוצר, הווריאציה (למשל מידה), שמות התוספות שנבחרו, כמות ומחיר.
  • מאיפה הגיע הביקור שבו נקנתה ההזמנה, כפי שהחנות רשמה אותו: סוג המקור, פרטי הקמפיין (UTM), סוג המכשיר, שם האתר המפנה ודף הכניסה. בלי פרמטרים מהכתובת ובלי פרטים מזהים.

אנחנו לא שומרים שמות, אימיילים, טלפונים או כתובות של הלקוחות שלכם. גם כשהחנות שולחת אותם יחד עם ההזמנה, אנחנו מסננים אותם ולא שומרים אותם. חריג אחד: טקסט קצר שהלקוח בחר או הקליד כאפשרות של מוצר, למשל מידה או שם להדפסה על חולצה, נשמר כפי שהוא מופיע בהזמנה (עד 40 תווים).

ב־WooCommerce אנחנו קוראים גם:

  • את עלות המוצר, אם הפעלתם את שדה העלות בחנות.
  • כשאתם מבקשים אסטרטגיית שיווק למוצר: את התיאור והקטגוריות שלו ואת הביקורות המאושרות עליו. מהביקורות נלקחים רק הדירוג והטקסט, בלי שם הכותב ובלי האימייל שלו. הם לא נשמרים בנפרד. נשמרת רק האסטרטגיה שנכתבה מהם.

הגישה לחנות היא לקריאה בלבד. אנחנו לא משנים הזמנות, מוצרים או הגדרות.

4. פרסום, אנליטיקס ורשתות חברתיות

אם תבחרו לחבר אותם, אנחנו קוראים נתונים מצטברים:

  • Meta Ads ו־Google Ads: נתונים יומיים של החשבון ושל כל קמפיין, כמו הוצאה, חשיפות, טווח הגעה, קליקים, המרות ורכישות וערכן, ושמות הקמפיינים.
  • Google Analytics 4: ביקורים, צפיות בדפים, אירועים מרכזיים, משתמשים פעילים וערוצי התנועה, ברמת היום. אנחנו לא מקבלים מידע על מבקרים בודדים.
  • דף Facebook וחשבון Instagram עסקי: עד 25 הפוסטים האחרונים. מכל פוסט נשמרים תחילת הטקסט, התאריך, הקישור ונתוני מעורבות כמו לייקים, תגובות וצפיות.

כדי שתוכלו לבחור איזה חשבון לחבר, אנחנו מציגים לכם את החשבונות שיש לכם גישה אליהם. הרשימה נשמרת מוצפנת עד 15 דקות ונמחקת.

הגישה היא לקריאה בלבד. אנחנו לא מפרסמים פוסטים, לא משנים קמפיינים ולא נוגעים בתקציב. ב־Google Ads יש רק הרשאה אחת, והיא מאפשרת גם שינויים. אנחנו משתמשים בה רק כדי להריץ דוחות.

5. שיחות ומידע שאתם מזינים

  • ההודעות שאתם שולחים לבוט והתשובות שלו, כדי שהבוט יבין את ההקשר של השיחה.
  • עלויות שאתם מזינים: עלות מוצרים, משלוח, עמלות סליקה, הוצאות, כללי עלות, מע״מ ושערי מטבע.
  • אסטרטגיות שיווק שנכתבו למוצרים שלכם, והשלב שאליו הגעתם בבניית קמפיין עם הבוט.

אנחנו לא שומרים את כתובת ה־IP שלכם במסד הנתונים. השרת משתמש בה רק לרגע, כדי להגביל מספר בקשות ולמנוע שימוש לרעה.

6. למה אנחנו משתמשים במידע

  • כדי לחשב ולהציג דוחות: מכירות, הזמנות, החזרים, מוצרים מובילים, רווח והוצאות פרסום.
  • כדי לענות על שאלות בטלגרם ובאתר, ולתת המלצות שיווק ותוכניות קמפיין.
  • כדי לחבר אתכם לחשבון ולשמור עליו.
  • כדי לשלוח לכם הודעות שקשורות לשירות, כמו קוד התחברות או הודעה שהייבוא הסתיים.

אנחנו לא מוכרים מידע, לא משתמשים בו לפרסום ולא משתמשים בו כדי לאמן מודלים של בינה מלאכותית.

7. בינה מלאכותית

את התשובות ואת אסטרטגיות השיווק כותב מודל בינה מלאכותית של Anthropic (Claude) או של OpenAI. כדי לענות, נשלחים לספק:

  • השאלה שלכם וההודעות האחרונות בשיחה.
  • שם העסק ותשובות ההיכרות שלכם.
  • הנתונים שהשאלה צריכה: מכירות, הזמנות, שמות מוצרים, עלויות ונתוני פרסום ואנליטיקס.
  • לאסטרטגיית שיווק: שם המוצר, התיאור, הקטגוריות, המחיר, נתוני מכירה, והטקסט והדירוג של הביקורות.

לא נשלחים פרטים אישיים של הלקוחות שלכם. אנחנו עובדים עם ממשקי ה־API העסקיים של הספקים. לפי התנאים שלהם, מידע שנשלח דרך ה־API לא משמש לאימון המודלים שלהם.

8. מידע שמתקבל מ־Google

כשאתם מחברים Google Analytics 4 או Google Ads, אנחנו מקבלים מ־Google את הנתונים שמתוארים בסעיף 4, ומשתמשים בהם רק כדי להציג לכם דוחות, תשובות והמלצות בתוך השירות.

השימוש של AstroCommerce במידע שמתקבל מממשקי Google API, והעברתו לכל אפליקציה אחרת, יעמדו ב־Google API Services User Data Policy, כולל דרישות השימוש המוגבל (Limited Use).

  • אנחנו לא מוכרים את המידע הזה, לא משתמשים בו לפרסום ולא משתמשים בו כדי לאמן מודלים של בינה מלאכותית.
  • אנחנו מעבירים אותו רק כשזה נחוץ כדי לתת לכם את השירות: לספק הבינה המלאכותית כשאתם שואלים שאלה שקשורה אליו, ול־Zernio כשחיבור Google Ads עובר דרכו.
  • אנשים בצוות שלנו לא קוראים את המידע הזה, אלא אם ביקשתם זאת במפורש (למשל בפנייה לתמיכה), או כשזה נדרש לאבטחה או לפי חוק.

9. עם מי המידע משותף

אנחנו משתפים מידע רק עם ספקים שעוזרים לנו להפעיל את השירות, ורק במידה שצריך:

  • Anthropic ו־OpenAI: כתיבת תשובות ואסטרטגיות שיווק (סעיף 7).
  • Zernio (zernio.com): שותף מאושר של Meta (Meta Marketing Partner). חלק מהחיבורים ל־Meta Ads, ל־Google Ads, ל־Facebook ול־Instagram עוברים דרכו. במקרה כזה Zernio שומר את מפתח הגישה לפלטפורמה, ואנחנו שומרים רק את מזהה החשבון ב־Zernio, מוצפן.
  • Resend: שליחת קודי התחברות באימייל.
  • Telegram: השיחה עם הבוט עוברת דרך Telegram, ולכן חלה עליה גם מדיניות הפרטיות של Telegram.
  • Oracle Cloud: השרתים ומסד הנתונים.
  • Cloudflare: העברת התעבורה לשרת בחיבור מאובטח, ואחסון האתר astrofiy.com.
  • Google Fonts: הגופנים באתר astrofiy.com נטענים מ־Google, ולכן הדפדפן שלכם פונה לשרתים של Google.

הפלטפורמות שאתם מחברים (WooCommerce, Shopify, Meta ו־Google) הן מקור הנתונים, והמדיניות שלהן חלה על המידע אצלן. נמסור מידע לרשויות רק אם החוק מחייב אותנו.

10. מידע מחוץ לישראל

חלק מהספקים שבסעיף 9 מעבדים ושומרים מידע מחוץ לישראל. כשאתם משתמשים בשירות, המידע עשוי לעבור אליהם.

11. אבטחת מידע

  • מפתחות הגישה לחנות ולפלטפורמות נשמרים מוצפנים ב־AES-256-GCM. כל מפתח מוצפן בנפרד ומשויך לעסק ולמקור שלו.
  • מסד הנתונים מפריד בין עסקים (Row-Level Security ב־PostgreSQL), כך שכל עסק ניגש רק לנתונים שלו.
  • הגישה לכל מקור היא לקריאה בלבד, בכל מקום שהפלטפורמה מאפשרת את זה.
  • כל חיבור ב־OAuth מאובטח בקוד חד־פעמי שתוקפו קצר.
  • לעולם לא נבקש מפתחות או סיסמאות בצ׳אט. מחברים בדף מאובטח או בדף של הפלטפורמה עצמה.
  • קוד התחברות באימייל תקף ל־10 דקות ומאפשר עד 5 ניסיונות. החיבור לאתר נשמר בעוגייה מאובטחת עד 30 יום, ויציאה מהחשבון מבטלת אותו.
  • כל התעבורה מוצפנת ב־HTTPS.

אין מערכת מאובטחת לחלוטין, אבל אנחנו עושים מאמץ סביר כדי להגן על המידע.

12. כמה זמן המידע נשמר

  • נתוני חנות, פרסום ואנליטיקס: כל עוד המקור מחובר. ניתוק מוחק אותם.
  • השיחה עם הבוט: 30 יום. הודעות ישנות יותר נמחקות.
  • משימות רקע, כמו הודעה שממתינה לטיפול (מוצפנות): נמחקות 7 ימים אחרי שהסתיימו.
  • מזהים של הודעות טלגרם שהתקבלו, כדי לא לטפל באותה הודעה פעמיים: 30 יום.
  • קישורי התחברות וקישורים לחיבור מקורות: תקפים 10 עד 15 דקות. חיבור לאתר: עד 30 יום. אחרי שפג תוקפם הם נמחקים תוך שעה.
  • רשומות של קודי התחברות באימייל, כולל כתובת האימייל שאליה נשלח הקוד: נמחקות יום אחרי שפג תוקפן.
  • פרטי החשבון, הגדרות העסק, העלויות ותשובות ההיכרות: עד שתבקשו למחוק את החשבון.
  • גיבויים: גיבוי יומי של מסד הנתונים נשמר 14 יום. מידע שנמחק יכול להישאר בגיבוי עד שהגיבוי נמחק.

13. ניתוק ומחיקה

  • ניתוק מקור בעמוד החיבורים מוחק מיד את מפתח הגישה שלו ואת ההזמנות והדוחות שיובאו ממנו. בחיבור דרך Zernio, הניתוק מסיר את החשבון גם מ־Zernio.
  • אפשר גם לבטל את הגישה ישירות בפלטפורמה: בהגדרות האבטחה בחשבון Google, באינטגרציות העסקיות בהגדרות של Facebook, במפתחות ה־REST API ב־WooCommerce או בהסרת האפליקציה ב־Shopify.

כדי למחוק את החשבון ואת כל המידע של העסק, שלחו בקשה ל־[email protected] מהאימייל שמחובר לחשבון. נמחק את המידע ונאשר לכם במייל.

14. הזכויות שלכם

לפי חוק הגנת הפרטיות, התשמ״א־1981, אתם יכולים:

  • לעיין במידע שנשמר עליכם.
  • לבקש לתקן או למחוק מידע לא נכון, לא שלם, לא ברור או לא מעודכן.
  • לבקש למחוק את החשבון ואת המידע.

כדי לממש זכות, כתבו ל־[email protected]. אם לדעתכם לא טיפלנו בפנייה כמו שצריך, אפשר לפנות לרשות להגנת הפרטיות.

15. עוגיות

באתר app.astrofiy.com יש עוגייה אחת, astro_session, שנדרשת כדי שתישארו מחוברים. היא נשמרת עד 30 יום. אין לנו עוגיות של אנליטיקס או פרסום, ובאתר astrofiy.com אנחנו לא שומרים עוגיות.

16. קטינים

השירות מיועד לבעלי עסקים בני 18 ומעלה. אנחנו לא אוספים ביודעין מידע על קטינים.

17. שינויים במדיניות

אם נשנה את המדיניות, נעדכן את התאריך בראש העמוד. על שינוי מהותי נודיע מראש בבוט או באימייל.

18. יצירת קשר

AstroCommerce · astrofiy.com · [email protected]

astrocommerce
מדיניות פרטיותתנאי שימושיצירת קשר
astrocommerce
עברית

Privacy Policy

Last updated: 2 October 2026

In short: we read the store, advertising and analytics data you connect so we can give you reports, answers and marketing advice. Access is read-only. We don’t store your customers’ names, emails, phone numbers or addresses, we don’t sell data and we don’t use it for advertising. You can disconnect any source at any time, and the data imported from it is deleted.

1. Who we are

AstroCommerce (astrofiy.com) is a service for online store owners. You connect your store and ad accounts, then ask about your business in our Telegram bot or in the web workspace at app.astrofiy.com.

This policy explains what information we collect, why, who it is shared with, how long we keep it and what your rights are.

For any privacy question, write to us at [email protected].

2. Your account and business details

  • Your email address, where we send your sign-in code. There are no passwords.
  • If you use the bot: your Telegram user ID and chat ID.
  • Your business name, language, time zone and currency.
  • Your answers to the bot’s getting-to-know-you questions, such as your industry, customers, sales channels, delivery times, marketing and ad budget. Every question can be skipped.

3. Store data (WooCommerce or Shopify)

When you connect a store, we import orders from up to the last 12 months and then keep them up to date every few minutes. For each order we store:

  • Date, status and currency.
  • Order total, tax, shipping and refunds.
  • Order lines: product name, variant (such as size), names of the options chosen, quantity and price.
  • Where the visit that ended in the order came from, as the store recorded it: the kind of source, campaign details (UTM), device type, the referring site’s name and the landing page. No address parameters and nothing that identifies a person.

We don’t store your customers’ names, emails, phone numbers or addresses. Even when the store sends them along with an order, we filter them out and don’t save them. One exception: short text a customer chose or typed as a product option, such as a size or a name to print on a shirt, is kept as it appears on the order (up to 40 characters).

For WooCommerce we also read:

  • The product cost, if you have turned on the cost field in your store.
  • When you ask for a marketing strategy for a product: its description, its categories and its approved reviews. From reviews we take only the rating and the text, without the reviewer’s name or email. They are not stored separately; only the strategy written from them is saved.

Store access is read-only. We don’t change orders, products or settings.

4. Advertising, analytics and social media

If you choose to connect them, we read aggregate figures:

  • Meta Ads and Google Ads: daily figures for the account and for each campaign, such as spend, impressions, reach, clicks, conversions, purchases and their value, plus campaign names.
  • Google Analytics 4: daily sessions, page views, key events, active users and traffic channels. We don’t receive information about individual visitors.
  • Facebook Page and Instagram professional account: up to 25 recent posts. For each post we store the beginning of its text, its date, its link and engagement figures such as likes, comments and views.

So you can choose which account to connect, we show you the accounts you have access to. That list is stored encrypted for up to 15 minutes and then deleted.

Access is read-only. We don’t publish posts, change campaigns or touch budgets. Google Ads offers only one permission, which also allows changes; we use it only to run reports.

5. Conversations and information you enter

  • The messages you send the bot and its replies, so the bot understands the context of the conversation.
  • Costs you enter: product costs, shipping, payment fees, expenses, cost rules, VAT and exchange rates.
  • Marketing strategies written for your products, and how far you have got when building a campaign with the bot.

We don’t store your IP address in our database. The server uses it only momentarily to limit the number of requests and prevent abuse.

6. How we use information

  • To calculate and show reports: sales, orders, refunds, top products, profit and ad spend.
  • To answer your questions in Telegram and on the web, and to give marketing advice and campaign plans.
  • To sign you in and keep your account secure.
  • To send you service messages, such as a sign-in code or a note that your import has finished.

We don’t sell information, we don’t use it for advertising and we don’t use it to train AI models.

7. Artificial intelligence

Answers and marketing strategies are written by an AI model from Anthropic (Claude) or OpenAI. To answer, we send the provider:

  • Your question and the latest messages in the conversation.
  • Your business name and your getting-to-know-you answers.
  • The figures the question needs: sales, orders, product names, costs, and advertising and analytics figures.
  • For a marketing strategy: the product name, description, categories, price, sales figures, and the text and rating of its reviews.

No personal details of your customers are sent. We use the providers’ business APIs; under their terms, data sent through the API is not used to train their models.

8. Information we receive from Google

When you connect Google Analytics 4 or Google Ads, we receive the data described in section 4 from Google and use it only to show you reports, answers and recommendations inside the service.

AstroCommerce’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We don’t sell this data, use it for advertising or use it to train AI models.
  • We transfer it only when needed to provide the service to you: to the AI provider when you ask a question that involves it, and to Zernio when your Google Ads connection goes through Zernio.
  • People on our team don’t read this data unless you explicitly ask us to (for example, in a support request), or when it is needed for security or required by law.

9. Who we share information with

We share information only with providers that help us run the service, and only as much as they need:

  • Anthropic and OpenAI: writing answers and marketing strategies (section 7).
  • Zernio (zernio.com): an approved Meta Marketing Partner. Some Meta Ads, Google Ads, Facebook and Instagram connections go through Zernio. In that case Zernio holds the platform access token, and we store only the Zernio account ID, encrypted.
  • Resend: sending sign-in codes by email.
  • Telegram: your conversation with the bot runs through Telegram, so Telegram’s privacy policy also applies to it.
  • Oracle Cloud: our servers and database.
  • Cloudflare: carrying traffic to our server over a secure connection, and hosting astrofiy.com.
  • Google Fonts: fonts on astrofiy.com load from Google, so your browser contacts Google’s servers.

The platforms you connect (WooCommerce, Shopify, Meta and Google) are the source of the data, and their own policies apply to the data they hold. We disclose information to authorities only when the law requires it.

10. Processing outside Israel

Some of the providers in section 9 process and store information outside Israel. When you use the service, your information may be transferred to them.

11. Security

  • Access keys for your store and platforms are stored encrypted with AES-256-GCM. Each key is encrypted separately and bound to its business and source.
  • The database separates businesses (PostgreSQL row-level security), so each business reaches only its own data.
  • Access to every source is read-only wherever the platform allows it.
  • Every OAuth connection is protected by a single-use code with a short expiry.
  • We will never ask for keys or passwords in chat. You connect on a secure page or on the platform’s own page.
  • An email sign-in code is valid for 10 minutes and allows up to 5 attempts. Your web sign-in is kept in a secure cookie for up to 30 days, and signing out ends it.
  • All traffic is encrypted with HTTPS.

No system is completely secure, but we make reasonable efforts to protect your information.

12. How long we keep information

  • Store, advertising and analytics data: as long as the source is connected. Disconnecting deletes it.
  • Your conversation with the bot: 30 days. Older messages are deleted.
  • Background tasks, such as a message waiting to be handled (encrypted): deleted 7 days after they finish.
  • IDs of incoming Telegram messages, so the same message is not handled twice: 30 days.
  • Sign-in links and source-connection links: valid for 10 to 15 minutes. Web sign-in: up to 30 days. Once expired, they are deleted within an hour.
  • Email sign-in code records, including the address the code was sent to: deleted a day after they expire.
  • Account details, business settings, costs and getting-to-know-you answers: until you ask us to delete your account.
  • Backups: a daily database backup is kept for 14 days. Deleted information can remain in a backup until that backup is deleted.

13. Disconnecting and deleting

  • Disconnecting a source on the connections page immediately deletes its access key and the orders and reports imported from it. For a connection through Zernio, disconnecting also removes the account from Zernio.
  • You can also revoke access directly on the platform: in your Google account’s security settings, under Business integrations in Facebook settings, in WooCommerce’s REST API keys, or by removing the app in Shopify.

To delete your account and all of your business’s information, send a request to [email protected] from the email address linked to your account. We will delete the information and confirm by email.

14. Your rights

Under Israel’s Privacy Protection Law, 5741-1981, you can:

  • Review the information we hold about you.
  • Ask us to correct or delete information that is wrong, incomplete, unclear or out of date.
  • Ask us to delete your account and your information.

To use any of these rights, write to [email protected]. If you think we have not handled your request properly, you can contact the Israeli Privacy Protection Authority.

15. Cookies

app.astrofiy.com uses one cookie, astro_session, which keeps you signed in. It lasts up to 30 days. We have no analytics or advertising cookies, and we don’t set cookies on astrofiy.com.

16. Children

The service is for business owners aged 18 or over. We don’t knowingly collect information about minors.

17. Changes to this policy

If we change this policy, we will update the date at the top of this page. We will tell you in advance, in the bot or by email, about any significant change.

18. Contact

AstroCommerce · astrofiy.com · [email protected]

astrocommerce
Privacy PolicyTerms of UseContact