Privacy Policy

Last updated: 2026-05-15

Data controller: KNOT Delivery Ltd. · knot4israel@gmail.com

1. Scope & Legal Basis

This policy is governed by Israel's Privacy Protection Law 5741-1981 (as amended, including Amendment 13 of 2024), Privacy Protection Regulations (Data Security) 5777-2017, and Israeli Consumer Protection Law 5741-1981. Lawful bases for processing: contract performance (Article 8(2) PPL), legitimate interest, and your explicit consent for optional processing.

2. Information We Collect

  • Account data: name, email, phone, password hash (bcrypt). Provided by you.
  • Delivery data: pickup/drop-off addresses, contact details for recipient, package description.
  • Location data — couriers: live GPS coordinates while courier status is online. Stored only when online, used for dispatch, route optimization, and rider safety. We do not track couriers when status is offline or break.
  • Location data — senders: approximate IP-based location only.
  • KYC data — couriers only: ID card, driver's license, vehicle insurance certificate. Used solely for verification under Article 23A PPL.
  • Device data: browser, OS, app version, basic analytics.

3. Use of Information

We use data strictly for: (a) executing delivery contracts, (b) matching senders with couriers, (c) safety and fraud prevention, (d) issuing tax invoices (cheshbonit mas) as required by Israeli VAT Law, (e) responding to support and disputes, (f) regulatory reporting required by law.

We do not sell personal data. We do not use your data for advertising profiling without separate explicit opt-in.

4. Sharing With Third Parties

  • The courier assigned to your order receives only the data needed to complete delivery.
  • Payment processors (PayPal, licensed Israeli aggregators) — for subscription payments only.
  • Hosting and infrastructure providers under written data-processing agreements.
  • Government authorities only under a valid court order or statutory obligation.

5. International Transfers

Data is stored on servers within Israel and the EU (adequate-jurisdiction). Transfers comply with Privacy Protection Regulations (Transfer of Data Abroad) 5761-2001.

6. Retention

  • Active account data: while your account is active.
  • Inactive account data: up to 3 years from last activity, then deleted or anonymized.
  • Delivery records (incl. tax invoices): 7 years, per Israeli Tax Ordinance §17.
  • Courier KYC documents: 5 years after last engagement.

7. Your Rights

Under Articles 13–14 PPL you have the right to: access your data, request correction, request deletion, withdraw consent, request data portability, and file a complaint with the Privacy Protection Authority (PPA).

To exercise these rights, email knot4israel@gmail.com. You may also delete your account from your profile page; we will honor deletion within 30 days subject to legally-mandated retention (tax records).

8. Security Measures

We implement administrative, technical, and physical safeguards per the Data Security Regulations 5777-2017, including: TLS 1.3 in transit, bcrypt for passwords, JWT with rotation, rate limiting, audit logging, role-based access. We have registered our database with the PPA where required.

9. Cookies & Tracking

Strictly necessary cookies for authentication and session management. Optional analytics cookies require explicit consent. No cross-site advertising cookies.

10. Children

KNOT is not directed to users under 18. We do not knowingly collect data from minors.

11. Changes

Material changes will be notified by email and in-app banner 14 days prior to taking effect.

12. Contact

Data Protection Officer: knot4israel@gmail.com

Privacy Protection Authority — Israel: www.gov.il/en/departments/the_privacy_protection_authority